From 1a94e2cb5a8ea6b658c031c9e17063c1ca3432c3 Mon Sep 17 00:00:00 2001 From: pete-gov Date: Mon, 5 Oct 2026 10:35:05 -0400 Subject: [PATCH 1/8] addresses #35 --- fedramp-consolidated-rules.json | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/fedramp-consolidated-rules.json b/fedramp-consolidated-rules.json index fa0925e..f691d78 100644 --- a/fedramp-consolidated-rules.json +++ b/fedramp-consolidated-rules.json @@ -1322,7 +1322,7 @@ "updated": [ { "date": "2026-06-24", - "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." + "comment": "Official launch of thCe FedRAMP Consolidated Rules for 2026." } ] }, @@ -2535,7 +2535,7 @@ "Sales Contact Information", "Security Contact Information", "Product Website Link", - "Link to Product Logo", + "Link to Product Logo (must be a valid image link, properly named, that will display in a browser without processing - transparent PNG preferred)", "Overall Service Description", "Detailed list of specific services and their security categories (see CDS-CSO-SVC (Public Service List) (Service List))", "Link to Secure Configuration Guidance", @@ -2544,7 +2544,10 @@ "Next Ongoing Certification Report date (see CCM-OCR-NRD (Next Report Date))", "Current FedRAMP Recognized independent assessment service" ], - "note": "Generally, this information should be available on a public webpage or publicly shared in a FedRAMP-compatible trust center.", + "notes": [ + "Generally, this information should be available on a public webpage or publicly shared in a FedRAMP-compatible trust center.", + "The JSON data for this rule will be consumed by FedRAMP and agency GRC tools using automation with web-based tools. Do not expect FedRAMP or your customers to download this data directly, it should be accessible for common web frameworks. FedRAMP strongly recommends that application engineering experts be involved in making public JSON data and the related information available in a way that can work with web-based applications." + ], "related": ["CDS-CSO-SVC", "CCM-OCR-NRD"], "force": "MUST", "affects": ["Providers"], @@ -2568,6 +2571,10 @@ "Trust Center" ], "updated": [ + { + "date": "2026-10-05", + "comment": "Clarified that logo link must be a viewable web image. Added note recommending the involvement of web-based application engineers." + }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." From 2d05318edc08dc8e128a8563155868e428f071a8 Mon Sep 17 00:00:00 2001 From: pete-gov Date: Mon, 5 Oct 2026 10:45:08 -0400 Subject: [PATCH 2/8] fixes #30 --- fedramp-consolidated-rules.json | 18 +++++++++++++++--- 1 file changed, 15 insertions(+), 3 deletions(-) diff --git a/fedramp-consolidated-rules.json b/fedramp-consolidated-rules.json index f691d78..fbb0def 100644 --- a/fedramp-consolidated-rules.json +++ b/fedramp-consolidated-rules.json @@ -3677,12 +3677,24 @@ }, "FRC-CSO-JSN": { "name": "FedRAMP JSON Schemas", - "statement": "Providers MUST supply machine-readable information in JSON documents that are valid against the corresponding JSON schema when a rule contains a FedRAMP JSON schema, UNLESS otherwise specified in the rule.", - "note": "FedRAMP JSON schemas are designed to be lightweight and flexible to establish a minimum set of structured information while allowing providers to improve on the format and structure of the information as needed to meet their needs and the needs of their customers.", + "statement": "Providers MUST supply machine-readable information in JSON documents that are valid against the corresponding JSON schema when a rule contains a FedRAMP JSON schema, UNLESS otherwise specified in the rule; public JSON data MUST be supplied in a manner compatible with modern web frameworks, including:", + "following_information": [ + "Cross-Origin Resource Sharing (CORS) should allow web applications running on a different domain to access the public JSON data directly.", + "Proper web application headers should be supplied for public JSON data, including at least setting Content-Type to application/json and X-Content-Type-Options: nosniff." + ], + "notes": [ + "FedRAMP JSON schemas are designed to be lightweight and flexible to establish a minimum set of structured information while allowing providers to improve on the format and structure of the information as needed to meet their needs and the needs of their customers.", + "Public JSON data is intended to be consumed by FedRAMP, agency GRC tools, and more - it should be available in a way that enables standard web-application use following standard web frameworks. Generally, if you can't write a web app to parse this data without configuring a browser to bypass security defaults then there has likely been a problem.", + "The Schema Validator available at fedramp.gov will not work properly if Cross-Origin Resource Sharing is not properly configured." + ], "force": "MUST", "affects": ["Providers"], - "terms": ["Machine-Readable"], + "terms": ["Likely", "Machine-Readable"], "updated": [ + { + "date": "2026-10-05", + "comment": "Clarified expectations for public JSON data to be compatible with standard web frameworks." + }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." From e9a384330507309bca49ab059fe449e9d3c254ff Mon Sep 17 00:00:00 2001 From: pete-gov Date: Mon, 5 Oct 2026 10:46:31 -0400 Subject: [PATCH 3/8] cleanup on #30 accidental change --- fedramp-consolidated-rules.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/fedramp-consolidated-rules.json b/fedramp-consolidated-rules.json index fbb0def..fe12c9d 100644 --- a/fedramp-consolidated-rules.json +++ b/fedramp-consolidated-rules.json @@ -1322,7 +1322,7 @@ "updated": [ { "date": "2026-06-24", - "comment": "Official launch of thCe FedRAMP Consolidated Rules for 2026." + "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." } ] }, From 0af6dbf7a7b81fc03dfd7e1e65a0562e2f379607 Mon Sep 17 00:00:00 2001 From: pete-gov Date: Mon, 5 Oct 2026 10:48:20 -0400 Subject: [PATCH 4/8] fixes #34 --- fedramp-consolidated-rules.json | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/fedramp-consolidated-rules.json b/fedramp-consolidated-rules.json index fe12c9d..a64e587 100644 --- a/fedramp-consolidated-rules.json +++ b/fedramp-consolidated-rules.json @@ -5332,7 +5332,7 @@ }, "FRC-CSF-RDY": { "name": "FedRAMP Ready Conversion", - "statement": "Providers with FedRAMP Rev5 Ready status MUST convert to a FedRAMP Certification by whichever of the follow dates is later: the expiration of their annual assessment or November 17, 2026 (the legacy FedRAMP Ready status will be entirely removed on December 31, 2027).", + "statement": "Providers with FedRAMP Rev5 Ready status MUST convert to a FedRAMP Certification by whichever of the following dates is later: the expiration of their annual assessment or November 17, 2026 (the legacy FedRAMP Ready status will be entirely removed on December 31, 2027).", "notes": [ "The simplest conversion in most cases would be to a FedRAMP 20x Class A Certification.", "Cloud services that do not wish to convert or do not meet conversion criteria will be renamed Legacy FedRAMP Ready and otherwise retired from FedRAMP Ready." @@ -5341,6 +5341,10 @@ "affects": ["Providers"], "terms": [], "updated": [ + { + "date": "2026-10-05", + "comment": "Adding a missing ing (follow -> following)." + }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." From 76d8bcd2311dd875e9da35bc2cdc389655798fe7 Mon Sep 17 00:00:00 2001 From: pete-gov Date: Mon, 5 Oct 2026 10:53:03 -0400 Subject: [PATCH 5/8] fixes #32 --- fedramp-consolidated-rules.json | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/fedramp-consolidated-rules.json b/fedramp-consolidated-rules.json index a64e587..a7e35b3 100644 --- a/fedramp-consolidated-rules.json +++ b/fedramp-consolidated-rules.json @@ -10059,8 +10059,9 @@ }, "VER-EVA-EPA": { "name": "Estimate Potential Agency Impact", - "statement": "Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to estimate the potential agency impact of exploitation on government customers AND assign one of the following Potential Agency Impact N-ratings (PAIN):", + "statement": "Providers MUST evaluate detected vulnerabilities, considering the context of the cloud service offering, to estimate the likely potential agency impact of exploitation on government customers AND assign one of the following Potential Agency Impact N-ratings (PAIN):", "following_information_bullets": [ + "**N0**: Exploitation is extremely unlikely to have any adverse effects on agencies that use the cloud service offering.", "**N1**: Exploitation could be expected to have minimal customer effects on one or more agencies that use the cloud service offering.", "**N2**: Exploitation could be expected to have narrow customer effects on one or more agencies that use the cloud service offering.", "**N3**: Exploitation could be expected to have a disruptive customer effect on one agency that uses the cloud service offering.", @@ -10080,6 +10081,10 @@ "Vulnerability Detection" ], "updated": [ + { + "date": "2026-10-05", + "comment": "Clarified that likely potential agency impact should be calculated; added PAIN0 to clarify that likely potential agency impact can be entirely mitigated/remediated." + }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." From 4ad5e92ff83a1d653e8cc527145a6f8fcce75607 Mon Sep 17 00:00:00 2001 From: pete-gov Date: Mon, 5 Oct 2026 12:44:14 -0400 Subject: [PATCH 6/8] fixes #33 --- fedramp-consolidated-rules.json | 18 +++++++++++++----- 1 file changed, 13 insertions(+), 5 deletions(-) diff --git a/fedramp-consolidated-rules.json b/fedramp-consolidated-rules.json index a7e35b3..0098385 100644 --- a/fedramp-consolidated-rules.json +++ b/fedramp-consolidated-rules.json @@ -2,8 +2,8 @@ "info": { "title": "FedRAMP Consolidated Rules for 2026", "description": "This datafile contains the Consolidated Rules for FedRAMP in structured machine-readable text. It includes definitions, requirements, recommendations, and key security indicators.", - "version": "2026.09.13.02", - "last_updated": "2026-09-13", + "version": "2026.10.05.01", + "last_updated": "2026-10-05", "default_artifacts": { "FRR": [ "Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.", @@ -7485,12 +7485,16 @@ { "party": "FedRAMP", "method": "form", - "target": "https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=52060327520795", - "name": "[For Assessors/Advisors] Marketplace Listing Form" + "target": "https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=54220455254427", + "name": "[For Assessors] Marketplace Listing Request Form" } ], "terms": [], "updated": [ + { + "date": "2026-10-10", + "comment": "Updated form name and URL." + }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." @@ -7538,11 +7542,15 @@ "party": "FedRAMP", "method": "form", "target": "https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=52060327520795", - "name": "[For Assessors/Advisors] Marketplace Listing Form" + "name": "[For Advisors] Marketplace Listing Request Form" } ], "terms": [], "updated": [ + { + "date": "2026-10-05", + "comment": "Updated form name." + }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." From e1d4e0b549130cec9b1db733553892e4fea3c860 Mon Sep 17 00:00:00 2001 From: pete-gov Date: Mon, 5 Oct 2026 12:50:26 -0400 Subject: [PATCH 7/8] fixes #31 --- fedramp-consolidated-rules.json | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/fedramp-consolidated-rules.json b/fedramp-consolidated-rules.json index 0098385..ce3e613 100644 --- a/fedramp-consolidated-rules.json +++ b/fedramp-consolidated-rules.json @@ -3189,8 +3189,13 @@ } }, "affects": ["Providers"], + "note": "Cryptographic modules include specific algorithms by definition; if an update stream of a cryptographic module adds new algorithms that were not previously validated then those algorithms can not be considered within the scope of update stream usage under these rules as they are new algorithms within the module that have never been validated.", "terms": ["Federal Customer Data", "Validation"], "updated": [ + { + "date": "2026-10-10", + "comment": "Added a note clarifying that new algorithms in update streams of modules are not included in the scope of updates to validated cryptographic modules." + }, { "date": "2026-06-24", "comment": "Official launch of the FedRAMP Consolidated Rules for 2026." From e419380e9a1cfe1e294dc25897f6884aa07b2cd8 Mon Sep 17 00:00:00 2001 From: pete-gov Date: Mon, 5 Oct 2026 12:51:00 -0400 Subject: [PATCH 8/8] formatting / tests --- fedramp-consolidated-rules.json | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/fedramp-consolidated-rules.json b/fedramp-consolidated-rules.json index ce3e613..27de6b6 100644 --- a/fedramp-consolidated-rules.json +++ b/fedramp-consolidated-rules.json @@ -3188,8 +3188,8 @@ } } }, - "affects": ["Providers"], "note": "Cryptographic modules include specific algorithms by definition; if an update stream of a cryptographic module adds new algorithms that were not previously validated then those algorithms can not be considered within the scope of update stream usage under these rules as they are new algorithms within the module that have never been validated.", + "affects": ["Providers"], "terms": ["Federal Customer Data", "Validation"], "updated": [ { @@ -10087,6 +10087,7 @@ "Cloud Service Offering", "Debilitating Customer Effect", "Disruptive Customer Effect", + "Likely", "Minimal Customer Effect", "Narrow Customer Effect", "Potential Agency Impact",