Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

The clocks you cannot sprint

The automation rules are depth-and-history requirements, not scope: automated methods per indicator, metrics windows measured in months, and detection cadences measured in days — per class, verbatim from the rules.

Rendered from FedRAMP Consolidated Rules for 2026 version 2026.07.14.01

Here is where the automation obligation actually lives — sense 3 from step 3 — and it has a shape most teams do not expect. It is a depth requirement, not a scope requirement. Moving up a class does not hand you more things to automate; it raises the number of independent automated methods owed per indicator, and stretches the history window your metrics must cover. Think redundant probes on the same claim, not new coverage.

Flip the class below and watch all four rules move at once. The statements are the rules’ own sentences, rendered from the dataset (our reading: Rev5 Low):

FRC-CSX-VVKAutomated Verification and Validation of Key Security IndicatorsMUST
Providers seeking 20x Class C Certification MUST implement automated methods to persistently verify and validate the accuracy and completeness of Key Security Indicators with at least 2 automated methods for each Key Security Indicator.
FRC-CSX-MOTMetrics Over Time for Key Security IndicatorsMUST
Providers seeking 20x Class C Certification MUST supply historical metrics including status from persistent validation over at least the past 6 months for all Key Security Indicators.
VDR-TFR-PSDPersistent Sample DetectionSHOULD
Providers with Class C Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 3 days.
VDR-TFR-PDDPersistent Drift DetectionSHOULD
Providers with Class C Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 14 days.

Now the sentence this step exists to deliver: the metrics rule has an accumulation floor that no engineering shortens. Methods can be built, bought or re-pointed later; history cannot be back-filled. A team that wires every method perfectly this afternoon is still months from being able to supply the window its class demands. Whatever else your team decides this quarter, start retaining persistent-validation history now.

Every deadline in the ruleset, not just these four, is on /obligations, in the rules’ own units.

Exit check — what must your team start retaining today, and why can’t it wait?

The run history of every automated validation — status over time, per indicator. Because the metrics rule asks for a window measured backwards from your assessment, and a window can only fill at the speed of the calendar. Everything else in this course can be done later; this one is a clock already running.