Who the rules bind
Every one of the 246 requirements names exactly one party. Pick yours and the ruleset shrinks to the part with your name on it — including the deadlines that are actually yours, which is a much smaller set than the requirements that bind you.
You build and operate the cloud service seeking FedRAMP certification. The bulk of the ruleset is yours — implementation, evidence production, continuous reporting, incident handling, and every vulnerability clock. If a deadline in this dataset bites, it almost certainly bites you first.
You are the federal customer authorizing and consuming a certified cloud service. Your requirements are about selection, use, and oversight of certified services — and notably, none of them carry a deadline. Binding is not owing a clock: your obligations are standing duties, not timed ones.
You are a Third-Party Assessment Organization performing independent verification and validation. Your slice covers assessment conduct, independence, and reporting — including the handful of deadlines on delivering assessment results. Read the Provider rules too, but these are the ones with your name on them.
Rules FedRAMP imposes on itself: how the program publishes, reviews, and maintains the certification machinery. Useful to everyone else as a service-level expectation — what you are entitled to expect back from the program, and on what clock.
You support providers or agencies in a consulting capacity without operating the service or signing the assessment. The smallest slice in the ruleset — three requirements, zero deadlines — mostly about staying honest about what an advisor may and may not do.
Requirement counts sum to 246 — each requirement binds exactly one party. Deadline counts do not: only 68 of the requirements carry a timeframe at all.