Rev5 questions and discussion on the Consolidated Rules for 2026 (or Legacy) #146
Replies: 15 comments 36 replies
|
Can you confirm whether the March 7, 2027 grace period defined in NTC-0014 remains accurate and unchanged? Specifically, is this grace period still authoritative, or has it been superseded or modified by the CR26 Consolidated Rules timeline, including the January 1, 2027 mandatory adoption date? As per NTC-0014: "FedRAMP will provide a grace period through March 7, 2027 where cloud service offerings may maintain their FedRAMP Certification under a corrective action plan (which will include notice to all agencies). After this date, FedRAMP Certification will be revoked for all cloud service offerings not following these rules." |
|
After review of the Rev 5 SCN process ahead of the July 4 optional adoption date, we noticed the published schema (fedramp-significant-change-notification-schema-2026-06-24.json) does not match the SCN-CSO-INF required fields SCN-CSO-INF, which mandates 10 fields in every notification. The schema marks only 3 as required (certificationPackageOverviewUri, changeType, changeDescription) and does not include:
|
|
Thanks Pete--I appreciate the approach your describe, however, the schema marks 3 fields as "required" with one, certificationPackageOverviewUri not even being in SCN-CSO-INF. Can we change "required" to "recommended"? |
|
If going for a new Rev5 certification prior to Jan 1, 2027, are CSPs required to follow the new CR26 Rev5 baseline/control guidance, or can they still use the old Legacy Rev5 parameters, SSP templates, SAP/SAR templates, etc? Similarly for assessors, for new Rev5 certification assessments prior to Jan 1, are they required to assess against the new CR26 Rev5 baseline/control guidance, or should/can they continue to follow the Legacy Rev5 rules/templates? Or is this choice up to the CSP/agency? I think I can intuit the answer from the Important Dates/Deadlines, without an explicit statement about which elements of Legacy Rev5 are still officially allowed (though maybe I am just not finding that statement) - which is that this is ultimately up to what the agency customer wants/agrees to with the CSP. Ie, the assessor can assess against the set of rules they are directed to assess by the CSP/agency, whether Legacy Rev5 or CR26 Rev5, up until a given CR26 rule or the full CR26 ruleset is explicitly stated to be mandatory for Rev5. This is especially relevant to CSPs who were already well along the path toward Rev5 and did not want to wait for the finalized CR26 rules to be available. For example, if they are about to be assessed now or in the next few months, and had worked over X time period to set up their system/documentation/etc using Legacy Rev5 rules, templates, etc. Corollary - what needs to be done by Jan 1, 2027 - is it enough to have completed the Legacy Rev5 assessment with the assessor, or does the agency/FedRAMP need to also approve the Legacy Rev5 certification prior to Jan 1? |
|
For a Rev5 Class C (Moderate) CSO with multiple agency ATOs, what are the consequences if they do not implement any CR26 Rev5 rules? At which date would they be exposed to those consequences? |
|
For the CDS-TRC-USH Rev. 5 requirement stating that “Trust Centers MUST share FedRAMP certification data with all necessary parties without interruption,” we are considering leveraging our Trust Center as the primary mechanism for providing stakeholders, including agency customers, with access to certification information. Under this model, we, as the Cloud Service Provider (CSP), would retain responsibility for provisioning and deprovisioning access to the Trust Center. Our interpretation is that the existence of a dedicated Trust Center, combined with an established operational process and support team responsible for managing access, satisfies the intent of providing certification data to authorized stakeholders without interruption. Given that we maintain a dedicated process and team to provision access, support affected customers, and provide alternative access mechanisms when necessary to the same Trust Center, our position is that these customer-imposed network restrictions should not constitute noncompliance with the “without interruption” requirement. We believe we are taking reasonable and proactive measures to ensure continuous availability of certification information to authorized parties despite circumstances that are outside our direct control. Do you have any concerns or objections to this interpretation and approach? |
|
I know the answer to this question will be "we're reasonable people", but confusion is still rampant. For the deadline where "FedRAMP will stop accepting any new FedRAMP Rev5 Certifications on June 11, 2027," does this mean a CSP cannot apply for a new Rev5 Marketplace Listing after June 10, 2027? Or FedRAMP will not accept Rev5 packages for CSPs who are already in process? Thanks. |
|
VDR-TFR-NMV states "Providers MUST verify and validate the status of non-machine-based information resources at least once every 3 months" and once you break down the definitions, I'm interpreting the requirement as: "CSPs must verify and validate documentation, personnel, and budgets every 3 months"
Is this an accurate interpretation of the requirements involved? And while the -1 controls in each control family in Rev5 would revert back to the ODPs, wouldn't this effectively create a new and different requirement for the policies and procedures (as well as various other documents)? Instead of reviewing them every 1/3 years, now they'd need to be verified and validated every 3 months. And then finally, if all of the above is true, would it make sense to notate this on the "Rev5 Control Guidance" page, given there's no direct mention that a VDR rule is impacting documentation? |
|
We have a Class D CSO with an existing Rev5 Agency ATO that does not meet the Cloud Native Architecture (KSI-CNA) requirement. Since no current 20x pathway exists for a non-cloud-native CSO of this Certification Class, we request clarification on the following: Pathway & Timeline
ATO Continuity
Marketplace Listing
Tracking & Escalation
|
|
Did I hear correctly on this afternoon's CWG call, that if a Rev5 CSP doesn't adopt VDR and VER by 12/7/26 they will be considered non-compliant and labeled as such on the Marketplace? So, even though there is a grace until 3/7/27 we are non-compliant on 12/8/26 if we haven't adopted all of VDR and VER? I also heard that we could let FedRAMP PMO know where we are in implementation and supply a CAP to get there by 3/7/27. Does that mean if we provide implementation status and CAP to get there by 3/7/27 that we wouldn't be labeled as non-compliant on Marketplace? Also, wondering if a Significant Change Assessment is considered an independent assessment for Grace Ends. We are a Rev 5 CSP who has their annual assessment in November 2026 who will receive SAR after 1/1/2027. Do we have a grace period until our next assessment in November 2027, or do we have to adopt the 1/1/2027 rulesets with our first Significant Change Assessment in 2027? Or must we adopt 1/1/2027 rulesets with our November 2026 annual assessment? |
|
For VDR-CSO-SIR, the following is written: "Providers MAY sample effectively identical information resources...". This points to sampling being a optional rule, but not strictly necessary. However, a later VDR rule, VDR-TFR-PSD, states the following: "Providers with Class C Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 3 days." Understanding that technically SHOULD rules have some wiggle room, does the combination of these two rules read as:
|
|
I have similar questions as @zeesharfcspab stated in a comment above. For CSPs who completed their legacy Rev5 annual assessment before CR26 Rev5 was published, and whose next annual assessment does not begin again until H1 of 2027. This creates a window where several rulesets reach their maintain date without an intervening FedRAMP independent assessment. I am trying to confirm how conformance is demonstrated in the interim to avoid the stated CAP that will be given to CSPs if the maintain date is not met (stated in the CR26 Rev5 community update 8/5). My questions are as follows:
|
|
Hello! Question: for an existing Rev 5 adoption of CR 26, I understand that the only rules we are required to implement are those classified as "Rev 5" and "All," and that any that are labeled 20x would be filtered out. Can I get a confirmation on this please? We want to make sure we scope correctly. |
|
Hello, for a Lost Sponsor/Readiness Conversion Rev 5 path, what deliverables are expected at our next annual assessment? I understand that SAP/SAR/RET are legacy now, so it would be great to get clarity on scoping the audit with our independent assessor. Thank you! (and happy Friday!!) |
|
Hello, for CSPs with an existing Rev5 Class C certification looking to uplift their offering to Rev5 Class D via agency sponsor, will this have to be completed/submitted by the June 2027 Rev5 cutoff for new Rev5 submissions? Thanks! |


Uh oh!
There was an error while loading. Please reload this page.
This thread is for any and all Q&A or general discussion related to FedRAMP Rev5 in general that does not need to have its own thread.
FedRAMP released the Consolidated Rules for 2026 on June 24, 2026 with a considerable set of changes for FedRAMP Rev5 that will apply to all cloud service providers.
These changes include:
Some of these changes take effect for all cloud service providers on certain dates no matter what, others take effect at the next annual assessment. In general, these are sweeping changes that will require all cloud service providers to begin planning now to continue to meet FedRAMP Rev5 requirements.
Historical materials are available at https://fedramp.gov/legacy.
You may see some of the following folks from FedRAMP responding in this thread:
pete-gov- Pete, FedRAMP Directornicole-gov- Nicole, Security Directordan-fedramp- Dan, Lead Cloud Security Engineerpaulagosta- Paul, Lead Cloud Security Engineer (Bastion)emu-gov- Emu, Lead Cloud Security Engineer (Vanguard)rhoesing- Ryan, Chief of Staff & Policy Branch ChiefAll reactions