Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
418 changes: 133 additions & 285 deletions AGENTS.md

Large diffs are not rendered by default.

64 changes: 42 additions & 22 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,36 +1,56 @@
# FedRAMP Consolidated Rules

This repository contains the machine-readable FedRAMP Consolidated Rules for
the 2026.
2026. Use it to read, analyze, and integrate structured definitions, process
rules, and security indicators.

The source of truth is:
## Repository Contents

- [fedramp-consolidated-rules.json](fedramp-consolidated-rules.json)
- [fedramp-consolidated-rules.json](fedramp-consolidated-rules.json) is the
canonical rules dataset. It contains dataset metadata (`info`), FedRAMP
Definitions (`FRD`), FedRAMP Rules (`FRR`), Key Security Indicators (`KSI`),
and control guidance and parameters (`CTL`, an optional schema section).
- [schemas/fedramp-consolidated-rules.schema.json](schemas/fedramp-consolidated-rules.schema.json)
defines the dataset's expected structure, required fields, and allowed values.

Everything else in this repository supports those two files.
The JSON defines the rule content; the schema defines its machine-readable
shape. Other files in this repository provide supporting documentation and
maintenance infrastructure.

## What Is Here
## Using The Information

- [fedramp-consolidated-rules.json](fedramp-consolidated-rules.json)
The canonical rules dataset.
- [schemas/fedramp-consolidated-rules.schema.json](schemas/fedramp-consolidated-rules.schema.json)
The schema for the dataset.
- [AGENTS.md](AGENTS.md)
Guidance for AI agents analyzing the dataset.
- [tools](tools)
Validation, normalization, tests, and export tooling.
Start with the dataset and schema for structured analysis. Definitions explain
terms used in the rules. Process rules describe requirements and recommendations;
security indicators describe capabilities and evidence expectations. Account for
framework applicability, service class, document status, and effective dates
when interpreting the information.

**AI agents:** Read [AGENTS.md](AGENTS.md) before ingesting or analyzing the
information. For maintenance tasks, also read
[tools/AGENTS-TOOLS.md](tools/AGENTS-TOOLS.md).

## Related Resources

## Working With The Repository
- [FedRAMP/2026](https://github.com/fedramp/2026) contains the narrative content
and website project that accompanies the structured rules.
- [FedRAMP/2026-markdown](https://github.com/fedramp/2026-markdown) provides
generated Markdown combining the structured rules and narrative content for
direct reading and AI ingestion. Its `_sources.json` records source commits.
- [FedRAMP community discussions](https://github.com/FedRAMP/community/discussions/)
and [FedRAMP 2026 discussions](https://github.com/FedRAMP/2026/discussions/)
provide additional discussion and context.
- [FedRAMP Help](https://help.fedramp.gov) provides help articles and support.

Use the JSON file and schema for analysis.
Related resources can reflect different revisions. Check their source versions
and dates when comparing them with this dataset.

From [tools](tools), the primary maintenance commands are:
## Maintenance

```bash
bun run check
bun run fix
```
The [tools/](tools/) directory is internal maintenance infrastructure for
FedRAMP developers. Most users and agents analyzing the information should
ignore it; installing or running these tools is not required to consume the
dataset.

See [tools/README.md](tools/README.md) for the tooling workflow and
[AGENTS.md](AGENTS.md) for agent-focused analysis guidance.
FedRAMP developers can use [tools/README.md](tools/README.md) for setup,
validation, normalization, tests, exports, and Git hooks. Maintenance agents
must also follow [tools/AGENTS-TOOLS.md](tools/AGENTS-TOOLS.md).
49 changes: 37 additions & 12 deletions fedramp-consolidated-rules.json
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,8 @@
"info": {
"title": "FedRAMP Consolidated Rules for 2026",
"description": "This datafile contains the Consolidated Rules for FedRAMP in structured machine-readable text. It includes definitions, requirements, recommendations, and key security indicators.",
"version": "2026.07.14.01",
"last_updated": "2026-07-14",
"version": "2026.09.13.01",
"last_updated": "2026-09-13",
"default_artifacts": {
"FRR": [
"Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.",
Expand Down Expand Up @@ -1654,11 +1654,15 @@
"name": "Agency Liaison Program",
"statement": "Agencies SHOULD assign at least 1 federal employee to be an active participant in the FedRAMP Agency Liaison program.",
"reference": "Agency Liaison Program",
"reference_url": "https://www.fedramp.gov/preview/2026/agencies/support/liaisons",
"reference_url": "https://www.fedramp.gov/2026/agencies/support/liaisons",
"force": "SHOULD",
"affects": ["Agencies"],
"terms": ["Agency"],
"updated": [
{
"date": "2026-09-13",
"comment": "Fixed broken reference URL for the Agency Liaison Program."
},
{
"date": "2026-06-24",
"comment": "Official launch of the FedRAMP Consolidated Rules for 2026."
Expand Down Expand Up @@ -1686,7 +1690,7 @@
"statement": "Agencies MUST complete the Authorization to Operate process for federal information systems that use FedRAMP Certified cloud service offerings.",
"note": "FedRAMP provides technical assistance to help agencies navigate this process.",
"reference": "Using a FedRAMP Certified Cloud Service Offering",
"reference_url": "https://fedramp.gov/preview/2026/agencies/use",
"reference_url": "https://www.fedramp.gov/2026/agencies/use",
"force": "MUST",
"affects": ["Agencies"],
"terms": [
Expand Down Expand Up @@ -2014,7 +2018,7 @@
"OCR": {
"CCM-OCR-AVL": {
"name": "Report Availability",
"statement": "Providers MUST supply an Ongoing Certification Report to all necessary parties every 3 months, covering the entire period since the previous summary, in a consistent format that is human readable; this report MUST include high-level summaries of at least the following information:",
"statement": "Providers MUST supply an Ongoing Certification Report to all necessary parties every 3 months, covering the entire period since the previous summary, in a consistent format that is human readable; this report MUST include high-level summaries of at least the following information (if applicable):",
"following_information": [
"Changes to FedRAMP Certification Data",
"Planned changes to FedRAMP Certification Data during at least the next 3 months",
Expand All @@ -2037,6 +2041,8 @@
"name": "FedRAMP Ongoing Certification Report (CCM-OCR-AVL)",
"url": "https://fedramp.gov/schemas/fedramp-ongoing-certification-report-schema-2026-06-24.json"
},
"timeframe_type": "months",
"timeframe_num": 3,
"terms": [
"Accepted Vulnerability",
"Agency",
Expand All @@ -2053,6 +2059,10 @@
"Vulnerability"
],
"updated": [
{
"date": "2026-09-13",
"comment": "Added (if applicable) to clarify that some of these items are not always required depending on the FedRAMP Certification Type or Class."
},
{
"date": "2026-06-24",
"comment": "Official launch of the FedRAMP Consolidated Rules for 2026."
Expand Down Expand Up @@ -2305,6 +2315,9 @@
"statement": "Providers SHOULD regularly schedule Quarterly Reviews to occur at least 3 business days after releasing an Ongoing Certification Report AND within 10 business days of such release.",
"force": "SHOULD",
"affects": ["Providers"],
"timeframe_type": "bizdays",
"timeframe_num_min": 3,
"timeframe_num_max": 10,
"terms": [
"FedRAMP Certification Report",
"Ongoing Certification",
Expand Down Expand Up @@ -3260,7 +3273,7 @@
"maintain": "2027-07-01",
"optional_adoption": "2026-07-04",
"grace": {
"default": "2027-01-01",
"default": "2027-07-01",
"until_next_assessment": true
}
}
Expand All @@ -3272,7 +3285,7 @@
"applicability": {
"types": ["Rev5"],
"paths": ["Program", "Agency"],
"classes": ["A", "B", "C", "D"],
"classes": ["B", "C", "D"],
"affects": ["Providers"]
}
}
Expand Down Expand Up @@ -3543,7 +3556,7 @@
"applicability": {
"types": ["Rev5"],
"paths": ["Agency"],
"classes": ["A", "B", "C", "D"],
"classes": ["B", "C", "D"],
"affects": ["Providers"]
}
}
Expand Down Expand Up @@ -5828,7 +5841,7 @@
"name": "Ongoing Incident Reports",
"varies_by_class": {
"a": {
"statement": "Providers with Class A Certifications SHOULD responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the the following additional information that is available and/or the current relevant status for each item:",
"statement": "Providers with Class A Certifications SHOULD responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the following additional information that is available and/or the current relevant status for each item:",
"following_information": [
"Observed incident activity",
"Indicators of compromise",
Expand Down Expand Up @@ -5881,7 +5894,7 @@
}
},
"b": {
"statement": "Providers with Class B Certifications MUST responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the the following additional information that is available and/or the current relevant status for each item:",
"statement": "Providers with Class B Certifications MUST responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the following additional information that is available and/or the current relevant status for each item:",
"following_information": [
"Observed incident activity",
"Indicators of compromise",
Expand Down Expand Up @@ -5934,7 +5947,7 @@
}
},
"c": {
"statement": "Providers with Class C Certifications MUST responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the the following additional information that is available and/or the current relevant status for each item:",
"statement": "Providers with Class C Certifications MUST responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the following additional information that is available and/or the current relevant status for each item:",
"following_information": [
"Observed incident activity",
"Indicators of compromise",
Expand Down Expand Up @@ -5987,7 +6000,7 @@
}
},
"d": {
"statement": "Providers with Class D Certifications MUST responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the the following additional information that is available and/or the current relevant status for each item:",
"statement": "Providers with Class D Certifications MUST responsibly notify all affected parties of ongoing activity as new information becomes available during incident response for FedRAMP Reportable Incidents, including updates (or lack of updates) to all previously reported information and as much of the following additional information that is available and/or the current relevant status for each item:",
"following_information": [
"Observed incident activity",
"Indicators of compromise",
Expand Down Expand Up @@ -6074,6 +6087,10 @@
"Vulnerability Response"
],
"updated": [
{
"date": "2026-09-13",
"comment": "Removed the extra the in all statements."
},
{
"date": "2026-06-24",
"comment": "Official launch of the FedRAMP Consolidated Rules for 2026."
Expand Down Expand Up @@ -7101,6 +7118,8 @@
"related": ["IVV-CSF-PCA"],
"force": "MUST",
"affects": ["Providers"],
"timeframe_type": "years",
"timeframe_num": 3,
"terms": ["FedRAMP Independent Assessment", "Provider"],
"updated": [
{
Expand Down Expand Up @@ -7604,6 +7623,8 @@
],
"force": "MUST",
"affects": ["Advisors"],
"timeframe_type": "bizdays",
"timeframe_num": 5,
"terms": ["Advisor"],
"updated": [
{
Expand Down Expand Up @@ -7664,6 +7685,8 @@
],
"force": "MUST",
"affects": ["Providers"],
"timeframe_type": "years",
"timeframe_num": 2,
"terms": ["Certification Class", "Provider"],
"updated": [
{
Expand Down Expand Up @@ -9383,6 +9406,8 @@
"statement": "Providers MUST verify and validate the status of non-machine-based information resources at least once every 3 months.",
"force": "MUST",
"affects": ["Providers"],
"timeframe_type": "months",
"timeframe_num": 3,
"terms": [
"Information Resource",
"Machine-Based (Information Resources)",
Expand Down
24 changes: 22 additions & 2 deletions schemas/fedramp-consolidated-rules.schema.json
Original file line number Diff line number Diff line change
Expand Up @@ -607,6 +607,8 @@
},
"timeframe_type": { "$ref": "#/$defs/timeframe_type" },
"timeframe_num": { "$ref": "#/$defs/positive_number" },
"timeframe_num_min": { "$ref": "#/$defs/positive_number" },
"timeframe_num_max": { "$ref": "#/$defs/positive_number" },
"notification": {
"type": "array",
"items": {
Expand All @@ -631,8 +633,26 @@
"updated": { "$ref": "#/$defs/updated_list" }
},
"dependentRequired": {
"timeframe_type": ["timeframe_num"],
"timeframe_num": ["timeframe_type"]
"timeframe_num": ["timeframe_type"],
"timeframe_num_min": ["timeframe_type", "timeframe_num_max"],
"timeframe_num_max": ["timeframe_type", "timeframe_num_min"]
},
"dependentSchemas": {
"timeframe_type": {
"oneOf": [
{
"properties": { "timeframe_num": {} },
"required": ["timeframe_num"]
},
{
"properties": {
"timeframe_num_min": {},
"timeframe_num_max": {}
},
"required": ["timeframe_num_min", "timeframe_num_max"]
}
]
}
},
"additionalProperties": false
},
Expand Down
Loading
Loading