{"dataset_version":"2026.07.14.01","last_updated":"2026-07-14","title":"FedRAMP Consolidated Rules for 2026","build":{"sha":"f365df9454bd04c1f07119c580ad3d7497095869"},"license":{"spdx":"CC-BY-4.0","url":"https://creativecommons.org/licenses/by/4.0/","covers":"The DATA in this response (derived slices and authored overlays). The site code is not licensed by it.","attribution":"ramprules.com"},"contract":{"contract_version":"1.0.0","envelope":"Every slice response is {dataset_version, last_updated, slice, contract_version, license, data}. Pin dataset_version alongside anything you scope against it, and contract_version alongside anything that parses it.","units":"Deadlines are quoted in the dataset's own unit (`num` + `type`) and are never converted. Comparing a 48-hour and a 3-day entry is the consumer's decision to make explicitly.","ordering":"Every array below is totally ordered and tie-broken on an id, so two builds of the same dataset are byte-identical. Per-slice guarantees are in `slices[].ordering`.","authored":"`aws-evidence`, `evidence-recipes` and `evidence-plan` include this project's AUTHORED overlays, each versioned separately from the dataset and stamped with the dataset version it was written against. Every recipe row names the plane it came from in `source`. Everything else is derived from the upstream ruleset alone."},"control_text":{"titles_and_statements":"NIST SP 800-53 Rev5, not FedRAMP.","catalog_version":"5.2.0","source":"https://github.com/usnistgov/oscal-content/blob/78650f02ad9321bb7b817846f8fbd4f2bcd620de/nist.gov/SP800-53/rev5/json/NIST_SP-800-53_rev5_catalog.json","commit":"78650f02ad9321bb7b817846f8fbd4f2bcd620de","parameters":"Organization-defined parameters render as `[label]`, never as a value. ODPs are the provider's to set in their SSP; a plausible default printed here would be this site inventing a FedRAMP fact."},"nomenclature":{"rule":"Canonical ids are FedRAMP's own machine forms, named per kind below. URLs are the lowercase of the canonical id, site-wide.","url":"/nomenclature","schema":"https://github.com/FedRAMP/rules — `docs/fedramp-consolidated-rules.schema.json` in this repo is the vendored mirror the patterns are read from.","aliases":"Alternate spellings (`AC-02.01`, `AC-06-01`, `AC-2 (13)`) are accepted as INPUT by the site's search and resolver. They are never emitted, never stored, and never a URL we link to — do not join on them.","addressable":"A canonical id is not a promise of a page — addressability is keyed to KSI edges, not to the id space. See `namespaces[].addressable` below, and `map` for `hasPage` per control.","namespaces":[{"kind":"control","label":"NIST 800-53 control","named":419,"addressable":209,"route":"/control/[id]"},{"kind":"family","label":"Control family","named":19,"addressable":0,"route":null},{"kind":"ksi","label":"KSI indicator","named":46,"addressable":46,"route":"/ksi/[id]"},{"kind":"theme","label":"KSI theme","named":10,"addressable":10,"route":"/plan/[class]/[theme]"},{"kind":"requirement","label":"FRR requirement","named":246,"addressable":246,"route":"/requirement/[id]"},{"kind":"document","label":"FRR document","named":17,"addressable":0,"route":null},{"kind":"class","label":"Certification class","named":4,"addressable":3,"route":"/plan/[class]"},{"kind":"odp","label":"ODP parameter","named":19,"addressable":0,"route":null},{"kind":"recipe","label":"evidence recipe","named":64,"addressable":64,"route":"/collect/[recipeId]"},{"kind":"party","label":"Affected party","named":5,"addressable":5,"route":"/for/[party]"},{"kind":"term","label":"FRD term anchor","named":75,"addressable":0,"route":"/glossary#term-[slug]"}],"control_universe":{"named":419,"ksiReached":209,"inAnyBaseline":409,"withGuidance":79,"guidanceWithoutPage":33},"kinds":[{"kind":"control","label":"NIST 800-53 control","canonical_def":"control_id","display_def":"rev5_control_id","route":"/control/[id]","example":{"canonical":"ac-2.13","display":"AC-02 (13)","slug":"ac-2.13"}},{"kind":"family","label":"Control family","canonical_def":null,"display_def":null,"route":null,"example":{"canonical":"AC","display":"AC","slug":"ac"}},{"kind":"ksi","label":"KSI indicator","canonical_def":"ksi_indicator_id","display_def":"ksi_indicator_id","route":"/ksi/[id]","example":{"canonical":"KSI-CNA-DFP","display":"KSI-CNA-DFP","slug":"ksi-cna-dfp"}},{"kind":"theme","label":"KSI theme","canonical_def":"ksi_theme_key","display_def":"ksi_theme_key","route":"/plan/[class]/[theme]","example":{"canonical":"CNA","display":"CNA","slug":"cna"}},{"kind":"requirement","label":"FRR requirement","canonical_def":"frr_requirement_id","display_def":"frr_requirement_id","route":"/requirement/[id]","example":{"canonical":"AFC-CSO-EMR","display":"AFC-CSO-EMR","slug":"afc-cso-emr"}},{"kind":"document","label":"FRR document","canonical_def":"frr_document_key","display_def":"frr_document_key","route":null,"example":{"canonical":"AFC","display":"AFC","slug":"afc"}},{"kind":"class","label":"Certification class","canonical_def":"class_key","display_def":"class_name","route":"/plan/[class]","example":{"canonical":"b","display":"B","slug":"b"}},{"kind":"odp","label":"ODP parameter","canonical_def":null,"display_def":null,"route":null,"example":{"canonical":"ac-6.1_odp.2","display":"AC-06 (01) ODP 2","slug":"ac-6.1_odp.2"}},{"kind":"recipe","label":"evidence recipe","canonical_def":null,"display_def":null,"route":"/collect/[recipeId]","example":{"canonical":"iam-credential-report","display":"iam-credential-report","slug":"iam-credential-report"}},{"kind":"party","label":"Affected party","canonical_def":null,"display_def":null,"route":"/for/[party]","example":{"canonical":"Providers","display":"Providers","slug":"providers"}},{"kind":"term","label":"FRD term anchor","canonical_def":null,"display_def":null,"route":"/glossary#term-[slug]","example":{"canonical":"fedramp-authorized","display":"FedRAMP Authorized","slug":"fedramp-authorized"}}]},"class_artifacts":{"note":"One per certification class (b, c, d). Substitute the class letter.","runbook":{"url":"/plan/{class}/runbook.sh","description":"A bash runbook that COLLECTS: one function per recipe, every command's output written to $OUT/<recipe>/<n>.<ext>, failures recorded in failures.jsonl rather than aborting the run, and a manifest.json naming the account, partition, Regions and a sha256 per file."},"checklist":{"url":"/plan/{class}/checklist.json","description":"The machine-readable class plan: every theme, every recipe, the dataset and overlay versions it was true of."},"sdr":{"url":"/plan/{class}/sdr.json","description":"A SKELETON Security Decision Record (SDR-CSO-FRR), valid against FedRAMP's published schema. Every field this site can know is filled; every field only the provider can answer is `TODO` and listed under `_todo`. `ksiEvidence[].evidenceLocation` is the path the runbook writes, so manifest.json's `files` joins against it by sha256.","schema":"https://fedramp.gov/schemas/fedramp-security-decision-record-schema-2026-06-24.json"}},"slices":[{"name":"class-overview","description":"The four certification classes side by side: the invariant KSI layer, each class's Rev5 baseline and KSI-covered subset, and the automated-method quota FRC-CSX-VVK sets per class — scored at BOTH readings of the quota's unit, since the rule never says whether \"each Key Security Indicator\" means one of the 10 themes or one of the 46 indicators.","ordering":"`classes` ascending by class letter (a-d, including the class with no baseline); `themes` within each class in KSI theme order; `indicators` in KSI theme order then indicator order, filtered to those stating a level at that class.","url":"/api/class-overview","schema":"/schema/class-overview.envelope.schema.json"},{"name":"coverage","description":"Rev5 baseline coverage per certification class, with orphan controls, and the class-scoped indicator reach beside the all-classes one.","ordering":"`classes` ascending by class letter; `orphanControls`, `reachLostAtClass` and family rows ascending by canonical id / family code.","url":"/api/coverage","schema":"/schema/coverage.envelope.schema.json"},{"name":"baseline","description":"Full Rev5 baseline enumeration per class: every control id with family, annual-assessment and KSI-coverage flags.","ordering":"`classes` ascending by class letter; `controls` ascending by canonical control id; `families` ascending.","url":"/api/baseline","schema":"/schema/baseline.envelope.schema.json"},{"name":"baseline-delta","description":"Every upward migration between two Rev5 baselines: the controls the higher class adds, each joined to whether a KSI reaches it and whether any recipe covers it or its base control; the added controls grouped by that mechanism; the per-class requirement clocks that tighten across the step; and the class-varying obligations that carry no timeframe at all, which is where the automated-method quota and the metrics-history window live.","ordering":"`deltas` ascending by `from` then `to`; `added`/`removed` ascending by canonical control id; `byFamily` by count DESCENDING, ties on family code; `mechanisms` by control count DESCENDING with the null-recipe residue always last; `clocks` and `obligations` ascending by requirement id.","url":"/api/baseline-delta","schema":"/schema/baseline-delta.envelope.schema.json"},{"name":"checks","description":"Per-KSI collector scaffold: statement, terms, controls, classes in scope and the class vulnerability-response clock.","ordering":"`checks` in dataset theme order, then indicator order within a theme; `controls` ascending by canonical id; `cadence` and `clocks` ascending by class letter.","url":"/api/checks","schema":"/schema/checks.envelope.schema.json"},{"name":"aws-evidence","description":"AUTHORED overlay: AWS calls that collect evidence per KSI/control, with cadence, GovCloud notes and an automatable-honesty rating. Versioned separately from the dataset.","ordering":"`recipes` in authored order — the overlay is a hand-maintained file and its sequence is editorial, not derived. Sort by `id` if you need a stable key.","url":"/api/aws-evidence","schema":"/schema/aws-evidence.envelope.schema.json"},{"name":"evidence-recipes","description":"AUTHORED overlays, both planes in one array: every recipe from the AWS estate overlay and the pipeline overlay, each row stamped with the `source` plane it came from and each plane's own version in `overlays`. `aws-evidence` remains the AWS-only slice, unchanged, for consumers already pinned to it.","ordering":"`recipes` grouped by plane in `EVIDENCE_SOURCES` order (aws, then pipeline) and in authored order within a plane — the overlays are hand-maintained files whose sequence is editorial. Sort by `id` if you need a stable key; ids are unique across planes.","url":"/api/evidence-recipes","schema":"/schema/evidence-recipes.envelope.schema.json"},{"name":"automation-frontier","description":"AUTHORED overlay: per-control dispositions for KSI-reached controls no AWS recipe covers — automatable, partial, or honestly closed as narrative, each with a stated reason. Versioned separately from the dataset.","ordering":"`queue` by `leverage` DESCENDING, ties broken on canonical control id; `frontier` ascending by canonical control id.","url":"/api/automation-frontier","schema":"/schema/automation-frontier.envelope.schema.json"},{"name":"evidence-plan","description":"The Evidence Plan: per class, authored recipes from every evidence plane grouped by KSI theme (densest first), the class clock, and the orphan/narrative register. Each item carries the `source` plane that produced it; each class carries one version stamp per contributing plane.","ordering":"`classes` ascending by class letter; `themes` by `controlFootprint` DESCENDING (densest first), ties broken on theme key; `items` in overlay order; `orphanControls` ascending by canonical id.","url":"/api/evidence-plan","schema":"/schema/evidence-plan.envelope.schema.json"},{"name":"obligations","description":"Every timeframed deadline, PAIN grid, notification and rollout date.","ordering":"`deadlines` TIGHTEST FIRST across incompatible units, ties broken on requirement id then class. The comparison is an internal hours-normalized key; the displayed `num`/`type` are always the dataset's own units and are never converted.","url":"/api/obligations","schema":"/schema/obligations.envelope.schema.json"},{"name":"evidence","description":"Every artifact the rules demand, by requirement and deduplicated by artifact.","ordering":"`byRequirement` ascending by requirement id; `byArtifact` by number of demanding requirements DESCENDING (most widely demanded first), ties broken on the artifact text.","url":"/api/evidence","schema":"/schema/evidence.envelope.schema.json"},{"name":"crosswalk","description":"Bidirectional KSI to NIST 800-53 control mapping.","ordering":"controls ascending by display id; families ascending.","url":"/api/crosswalk","schema":"/schema/crosswalk.envelope.schema.json"},{"name":"families","description":"KSI density per control family and theme.","ordering":"rows ascending by class letter; families ascending by family code.","url":"/api/families","schema":"/schema/families.envelope.schema.json"},{"name":"glossary","description":"FRD terms with the KSIs and rules that reference each.","ordering":"terms ascending alphabetically.","url":"/api/glossary","schema":"/schema/glossary.envelope.schema.json"},{"name":"indicator-weight","description":"KSI indicators ranked by control footprint.","ordering":"indicators by control footprint DESCENDING, ties broken on indicator id.","url":"/api/indicator-weight","schema":"/schema/indicator-weight.envelope.schema.json"},{"name":"readiness","description":"Per-class readiness pack: baseline, KSI coverage, artifacts and provider deadlines.","ordering":"`classes` ascending by class letter; control lists ascending by canonical id.","url":"/api/readiness","schema":"/schema/readiness.envelope.schema.json"},{"name":"roles","description":"Requirements, deadlines and documents grouped by the party they bind.","ordering":"parties by requirement count DESCENDING; requirements within a party ascending by requirement id.","url":"/api/roles","schema":"/schema/roles.envelope.schema.json"},{"name":"search","description":"Flat list of every addressable entity, for the global search palette.","ordering":"entities grouped by kind, ascending by id within each kind.","url":"/api/search","schema":"/schema/search.envelope.schema.json"}]}