Who built this
FedRAMP Rules Hubis one person’s work, not a vendor’s. It exists because “go collect FedRAMP evidence on AWS” is a sentence developers get handed with no map attached, and the map was buildable from FedRAMP’s own published dataset.

Sunny Luthra
Founder of mrova.rocks and ohmydog.rocks.
- +91 99702 81930
- Telegram
- @luthrasunny
A projection of one published dataset — the FedRAMP Consolidated Rules for 2026, version 2026.07.14.01. Every requirement, Key Security Indicator and Rev5 control on this site is read out of that file; the AWS calls layered over them are an overlay this site authors and cites. The JSON contract is what to pin against if you are building on it. This build is commit f365df9.
It is not legal advice, not an assessment, and not affiliated with FedRAMP, GSA or AWS. A green row here means an API can produce the artifact — never that an assessor has accepted it. What no API can prove is kept in view rather than quietly dropped, which is the one editorial position this site actually holds.
Found something wrong? The three channels above all reach me, and a defect in the data is the message I most want.