Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

Obligation Clock

Every deadline the rules impose, ordered by how soon it bites. The dataset buries most of them — the majority of the 68 timeframes live inside per-class overrides, so a tool reading only requirement level finds 17 and reports a quarter of the truth.

Every deadline, tightest first (68)

Units are never converted. “48 hours” and “2 days” are the same duration and not the same obligation, so each row shows the dataset’s own number and unit. Ordering spans all 6 units.

months · 24years · 17days · 15bizdays · 8weeks · 3hours · 1

All 68 deadlines, every party. Requirement-level split: Providers 180 · Agencies 24 · Assessors 23 · FedRAMP 16 · Advisors 3 (246 total).

DeadlineClassRequirementForce
1 dayDVDR-TFR-PSD Persistent Sample Detection

Providers with Class D Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once per day.

SHOULD
48 hoursallREC-IAS-CFI Changes in Foreign Interest

Assessors MUST report updated information relating to any foreign interest, foreign influence, or foreign control of the independent assessment service within 48 hours of any change in foreign ownership or control.

MUST
2 daysDVER-TFR-EVU Evaluate Vulnerabilities Quickly

Providers with Class D Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 2 days of detection.

SHOULD
3 daysCVDR-TFR-MVX Persistent Machine Verification and Validation for 20x

Providers of FedRAMP 20x Class C offerings MUST verify and validate the status of machine-based information resources at least once every 3 days.

MUST
3 daysCVDR-TFR-PSD Persistent Sample Detection

Providers with Class C Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 3 days.

SHOULD
5 daysCVER-TFR-EVU Evaluate Vulnerabilities Quickly

Providers with Class C Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 5 days of detection.

SHOULD
5 business daysallCDS-UTC-AAD Agency Access Denial

Providers MUST notify FedRAMP within 5 business days of denying an agency access request for FedRAMP Certification Data.

MUST
1 weekDCPO-CSX-CPM Certification Package Maintenance for 20x

Providers with 20x Class D Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every week.

MUST
5 business daysallSCN-TRF-NAF Notification After Finishing

Providers MUST notify all necessary parties within 5 business days after finishing transformative changes, including updates to all previously sent information.

MUST
5 business daysallSCN-TRF-NAV Notification After Verification

Providers MUST notify all necessary parties within 5 business days after completing the verification, assessment, and/or validation of transformative changes, also including the following information:

MUST
7 daysBVDR-TFR-MVX Persistent Machine Verification and Validation for 20x

Providers of FedRAMP 20x Class B offerings MUST verify and validate the status of machine-based information resources at least once every 7 days.

MUST
7 daysDVDR-TFR-PDD Persistent Drift Detection

Providers with Class D Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 7 days.

SHOULD
7 daysBVDR-TFR-PSD Persistent Sample Detection

Providers with Class B Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 7 days.

SHOULD
7 daysBVER-TFR-EVU Evaluate Vulnerabilities Quickly

Providers with Class B Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 7 days of detection.

SHOULD
7 daysDVER-TFR-MRH Historical Activity

Providers with Class D Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every 7 days.

SHOULD
10 business daysallAFC-FRP-PNT Public Notice of Emergency Tests

FedRAMP MUST post a public notice at least 10 business days in advance of sending an Emergency Test message; such notices MUST include explanation of the likely expected actions and timeframes for the Emergency Test message.

MUST
2 weeksallCDS-CSO-FRC FedRAMP Certification Reports

Providers MUST include FedRAMP Certification Reports with their FedRAMP Certification Data without inappropriate modifications, and make such reports available within 2 weeks of receiving the materials from FedRAMP.

MUST
2 weeksCCPO-CSX-CPM Certification Package Maintenance for 20x

Providers with 20x Class C Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every 2 weeks.

MUST
10 business daysallSCN-ADP-NTF Notification Requirements

Providers MUST notify all necessary parties within 10 business days after finishing adaptive changes, also including the following information:

MUST
10 business daysallSCN-TRF-NFP Notification of Final Plans

Providers MUST notify all necessary parties of final plans for transformative changes at least 10 business days before starting transformative changes, including updates to all previously sent information.

MUST
14 daysCVDR-TFR-PDD Persistent Drift Detection

Providers with Class C Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 14 days.

SHOULD
14 daysAVDR-TFR-PSD Persistent Sample Detection

Providers with Class A Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 14 days.

SHOULD
14 daysAVER-TFR-EVU Evaluate Vulnerabilities Quickly

Providers with Class A Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 14 days of detection.

SHOULD
14 daysCVER-TFR-MRH Historical Activity

Providers with Class C Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every 14 days.

SHOULD
1 monthBCPO-CSX-CPM Certification Package Maintenance for 20x

Providers with 20x Class B Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every month.

MUST
1 monthBVDR-TFR-MVF Persistent Machine Verification and Validation for Rev5

Providers of FedRAMP Rev5 Class B offerings SHOULD verify and validate the status of machine-based information resources at least once every month.

SHOULD
1 monthCVDR-TFR-MVF Persistent Machine Verification and Validation for Rev5

Providers of FedRAMP Rev5 Class C offerings MUST verify and validate the status of machine-based information resources at least once every month.

MUST
1 monthDVDR-TFR-MVF Persistent Machine Verification and Validation for Rev5

Providers of FedRAMP Rev5 Class D offerings MUST verify and validate the status of machine-based information resources at least once every month.

MUST
1 monthAVDR-TFR-MVX Persistent Machine Verification and Validation for 20x

Providers of FedRAMP 20x Class A offerings SHOULD verify and validate the status of machine-based information resources at least once every month.

SHOULD
1 monthCVDR-TFR-PCD Persistently Complete Detection

Providers with Class C Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every month.

SHOULD
1 monthDVDR-TFR-PCD Persistently Complete Detection

Providers with Class D Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every month.

SHOULD
1 monthBVDR-TFR-PDD Persistent Drift Detection

Providers with Class B Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every month.

SHOULD
1 monthallVER-TFR-MHR Monthly Activity Report

Providers MUST report vulnerability detection and response activity to all necessary parties in a consistent format that is human readable at least monthly.

MUST
1 monthAVER-TFR-MRH Historical Activity

Providers with Class A Certifications MAY make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information MAY be updated persistently, at least once every month.

MAY
1 monthBVER-TFR-MRH Historical Activity

Providers with Class B Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every month.

SHOULD
30 business daysallSCN-TRF-NIP Notification of Initial Plans

Providers MUST notify all necessary parties of initial plans for transformative changes at least 30 business days before starting transformative changes, including a summary of any likely security impacts or changes in risk.

MUST
30 business daysallSCN-TRF-UPD Update Documentation

Providers MUST publish updated service documentation and other materials to reflect transformative changes within 30 business days after finishing transformative changes.

MUST
3 monthsACCM-QTR-MTG Quarterly Review Meeting

Providers with Class A Certifications MAY host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies.

MAY
3 monthsBCCM-QTR-MTG Quarterly Review Meeting

Providers with Class B Certifications SHOULD host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies.

SHOULD
3 monthsCCCM-QTR-MTG Quarterly Review Meeting

Providers with Class C Certifications MUST host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies.

MUST
3 monthsDCCM-QTR-MTG Quarterly Review Meeting

Providers with Class D Certifications MUST host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies.

MUST
3 monthsACPO-CSX-CPM Certification Package Maintenance for 20x

Providers with 20x Class A Certifications SHOULD persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every 3 months.

SHOULD
3 monthsAFRC-APP-FIA Fresh Independent Assessment

Providers seeking Class A Certification MAY supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.

MAY
3 monthsBFRC-APP-FIA Fresh Independent Assessment

Providers seeking Class B Certification MUST supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.

MUST
3 monthsCFRC-APP-FIA Fresh Independent Assessment

Providers seeking Class C Certification MUST supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.

MUST
3 monthsDFRC-APP-FIA Fresh Independent Assessment

Providers seeking Class D Certification MUST supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months.

MUST
3 monthsAVDR-TFR-PDD Persistent Drift Detection

Providers with Class A Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 3 months.

SHOULD
6 monthsDCPO-CSF-CPM Certification Package Maintenance for Rev5

Providers with Rev5 Class D Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every six months.

MUST
6 monthsAVDR-TFR-PCD Persistently Complete Detection

Providers with Class A Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every 6 months.

SHOULD
6 monthsBVDR-TFR-PCD Persistently Complete Detection

Providers with Class B Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every 6 months.

SHOULD
192 daysallVER-TFR-MAV Mark Accepted Vulnerabilities

Providers MUST categorize any vulnerability that is not or will not be fully mitigated or remediated within 192 days of evaluation as an accepted vulnerability.

MUST
1 yearBCPO-CSF-CPM Certification Package Maintenance for Rev5

Providers with Rev5 Class B Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every year.

MUST
1 yearCCPO-CSF-CPM Certification Package Maintenance for Rev5

Providers with Rev5 Class C Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every year.

MUST
1 yearBIVV-CSF-AIA Annual Independent Assessments for Rev5

Providers with Rev5 Class B Certifications MUST include the following Rev5 Controls in a FedRAMP independent assessment at least once per year:

MUST
1 yearCIVV-CSF-AIA Annual Independent Assessments for Rev5

Providers with Rev5 Class C Certifications MUST include the following Rev5 Controls in a FedRAMP independent assessment at least once per year:

MUST
1 yearDIVV-CSF-AIA Annual Independent Assessments for Rev5

Providers with Rev5 Class D Certifications MUST include the following Rev5 Controls in a FedRAMP independent assessment at least once per year:

MUST
1 yearAIVV-CSO-FIA FedRAMP Independent Assessments

Providers with Class A Certifications MAY persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.

MAY
1 yearBIVV-CSO-FIA FedRAMP Independent Assessments

Providers with Class B Certifications MUST persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.

MUST
1 yearCIVV-CSO-FIA FedRAMP Independent Assessments

Providers with Class C Certifications MUST persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.

MUST
1 yearDIVV-CSO-FIA FedRAMP Independent Assessments

Providers with Class D Certifications MUST persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.

MUST
1 yearBIVV-CSX-AIA Annual Independent Assessments for 20x

Providers with 20x Class B Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year.

MUST
1 yearCIVV-CSX-AIA Annual Independent Assessments for 20x

Providers with 20x Class C Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year.

MUST
1 yearDIVV-CSX-AIA Annual Independent Assessments for 20x

Providers with 20x Class D Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year.

MUST
1 yearallREC-IAS-AFI Annual Foreign Interest Reports

Assessors MUST report information relating to any foreign interest, foreign influence, or foreign control of the independent assessment service to FedRAMP annually.

MUST
1 yearallREC-IAS-ANR Annual Surveillance Assessment

Assessors MUST achieve a favorable annual surveillance assessment by the American Association for Laboratory Accreditation (A2LA) to maintain FedRAMP Recognition.

MUST
2 yearsallREC-IAS-ADA Actually Do Assessments

Assessors MUST complete at least 2 initial or ongoing assessments for Class B, C, or D FedRAMP Certifications every 2 years to maintain FedRAMP Recognition.

MUST
2 yearsallREC-IAS-RAS Full A2LA Reassessment

Assessors MUST achieve a favorable full reassessment by the American Association for Laboratory Accreditation (A2LA) at least once every 2 years to maintain FedRAMP Recognition.

MUST
2 yearsallREC-IAS-SEP Advisory Separation

Assessors MUST NOT perform a FedRAMP independent assessment of the same cloud service offering within 2 years after supplying advisory or consulting services for that offering, unless FedRAMP publishes a specific exception for a limited pilot or other explicitly scoped process.

MUST NOT

PAIN grids (16)

Severity level crossed with scenario. Columns are derived per requirement, never fixed — the carrying requirements do not share a column set.

IEC-CSO-IIR Initial Incident Report(class A)

Leveliir
11 business day
21 business day
36 hours
46 hours
56 hours

IEC-CSO-IIR Initial Incident Report(class B)

Leveliir
11 business day
21 business day
36 hours
46 hours
56 hours

IEC-CSO-IIR Initial Incident Report(class C)

Leveliir
11 business day
224 hours
31 hour
41 hour
51 hour

IEC-CSO-IIR Initial Incident Report(class D)

Leveliir
11 hour
21 hour
30.25 hours
40.25 hours
50.25 hours

IEC-CSO-OIR Ongoing Incident Reports(class A)

Leveloir
11 business day
21 business day
31 business day
41 business day
51 business day

IEC-CSO-OIR Ongoing Incident Reports(class B)

Leveloir
11 business day
21 business day
31 business day
41 business day
51 business day

IEC-CSO-OIR Ongoing Incident Reports(class C)

Leveloir
11 business day
224 hours
36 hours
46 hours
56 hours

IEC-CSO-OIR Ongoing Incident Reports(class D)

Leveloir
124 hours
26 hours
33 hours
43 hours
53 hours

IEC-CSO-FIR Final Incident Report(class A)

Levelfir
13 business days
23 business days
33 business days
43 business days
53 business days

IEC-CSO-FIR Final Incident Report(class B)

Levelfir
13 business days
23 business days
33 business days
43 business days
53 business days

IEC-CSO-FIR Final Incident Report(class C)

Levelfir
11 business day
21 business day
36 hours
46 hours
56 hours

IEC-CSO-FIR Final Incident Report(class D)

Levelfir
124 hours
26 hours
33 hours
43 hours
53 hours

VDR-TFR-PVR Mitigation and Remediation Expectations(class A)

Levelirv_levnirv_levnlev
1
296 days160 days192 days
332 days64 days192 days
48 days32 days64 days
54 days8 days32 days

VDR-TFR-PVR Mitigation and Remediation Expectations(class B)

Levelirv_levnirv_levnlev
1
296 days160 days192 days
332 days64 days192 days
48 days32 days64 days
54 days8 days32 days

VDR-TFR-PVR Mitigation and Remediation Expectations(class C)

Levelirv_levnirv_levnlev
1
248 days128 days192 days
316 days32 days128 days
44 days8 days64 days
52 days4 days16 days

VDR-TFR-PVR Mitigation and Remediation Expectations(class D)

Levelirv_levnirv_levnlev
1
224 days96 days192 days
38 days16 days64 days
42 days8 days32 days
512 hours1 day8 days

Notification targets (31)

RequirementPartyMethodTarget
AFC-FRP-PNTEveryonewebhttps://www.fedramp.gov/notices
AFC-CSO-NOCFedRAMPformhttps://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51829466938011
AGU-AGC-NAAFedRAMPformhttps://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51447926193691
AGU-AGC-NAIFedRAMPformhttps://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51822364715035
AGU-AGC-NARFedRAMPemailinfo@fedramp.gov
AGU-AGC-TPPFedRAMPemailinfo@fedramp.gov
AGU-USE-NFCFedRAMPformhttps://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51821301979547
AGU-USE-NPCProvidervariesvaries by provider
CDS-UTC-AADFedRAMPformhttps://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51829826617243
CDS-CSF-TCMFedRAMPemailinfo@fedramp.gov
CDS-CSF-TCMAgency Customersvariesvaries by agency
FRC-APP-AFCFedRAMPformhttps://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51137131584283
IEC-CSO-IIRFedRAMPemailfedramp_security@fedramp.gov
IEC-CSO-IIRAgency Customersvariesvaries by agency
IEC-CSO-IIRAll Necessary Partiesupdatetrust center
IEC-CSO-OIRFedRAMPemailfedramp_security@fedramp.gov
IEC-CSO-OIRAgency Customersvariesvaries by agency
IEC-CSO-OIRAll Necessary Partiesupdatetrust center
IEC-CSO-FIRFedRAMPemailfedramp_security@fedramp.gov
IEC-CSO-FIRAgency Customersvariesvaries by agency
IEC-CSO-FIRAll Necessary Partiesupdatetrust center
MKT-CSO-PMLFedRAMPformhttps://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=50939227168027
MKT-IAS-LRQFedRAMPformhttps://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=52060327520795
MKT-CAS-LRQFedRAMPformhttps://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=52060327520795
REC-IAS-AFIFedRAMPformhttps://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=52006681154587
REC-IAS-CFIFedRAMPformhttps://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=52006681154587
SCN-ADP-NTFAll Necessary PartiesupdateFedRAMP Certification Data
SCN-TRF-NIPAll Necessary PartiesupdateFedRAMP Certification Data
SCN-TRF-NFPAll Necessary PartiesupdateFedRAMP Certification Data
SCN-TRF-NAFAll Necessary PartiesupdateFedRAMP Certification Data
SCN-TRF-NAVAll Necessary PartiesupdateFedRAMP Certification Data

Rollout calendar (106)

  1. 2026-01-05Addressing FedRAMP Communication obtain
  2. 2026-01-05Addressing FedRAMP Communication maintain
  3. 2026-03-01Secure Configuration Guide obtain
  4. 2026-03-01Secure Configuration Guide maintain
  5. 2026-07-01Addressing FedRAMP Communication grace
  6. 2026-07-01Secure Configuration Guide grace
  7. 2026-07-04Agency Use of FedRAMP Certified Cloud Services obtain
  8. 2026-07-04Agency Use of FedRAMP Certified Cloud Services maintain
  9. 2026-07-04Agency Use of FedRAMP Certified Cloud Services optional_adoption
  10. 2026-07-04Agency Use of FedRAMP Certified Cloud Services grace
  11. 2026-07-04Collaborative Continuous Monitoring obtain · 20x
  12. 2026-07-04Collaborative Continuous Monitoring optional_adoption · 20x
  13. 2026-07-04Collaborative Continuous Monitoring optional_adoption · rev5
  14. 2026-07-04Certification Data Sharing obtain · 20x
  15. 2026-07-04Certification Data Sharing optional_adoption · 20x
  16. 2026-07-04Certification Data Sharing optional_adoption · rev5
  17. 2026-07-04Cryptographic Module Use obtain · 20x
  18. 2026-07-04Cryptographic Module Use optional_adoption · 20x
  19. 2026-07-04Cryptographic Module Use optional_adoption · rev5
  20. 2026-07-04Certification Package Overview obtain · 20x
  21. 2026-07-04Certification Package Overview optional_adoption · 20x
  22. 2026-07-04Certification Package Overview optional_adoption · rev5
  23. 2026-07-04FedRAMP Certification obtain · 20x
  24. 2026-07-04FedRAMP Certification optional_adoption · 20x
  25. 2026-07-04FedRAMP Certification optional_adoption · rev5
  26. 2026-07-04Incident Evaluation and Communication obtain · 20x
  27. 2026-07-04Incident Evaluation and Communication optional_adoption · 20x
  28. 2026-07-04Incident Evaluation and Communication optional_adoption · rev5
  29. 2026-07-04Independent Verification and Validation obtain · 20x
  30. 2026-07-04Independent Verification and Validation optional_adoption · 20x
  31. 2026-07-04Independent Verification and Validation optional_adoption · rev5
  32. 2026-07-04Minimum Assessment Scope obtain · 20x
  33. 2026-07-04Minimum Assessment Scope optional_adoption · 20x
  34. 2026-07-04Minimum Assessment Scope optional_adoption · rev5
  35. 2026-07-04Marketplace Listing obtain
  36. 2026-07-04Marketplace Listing maintain
  37. 2026-07-04Marketplace Listing optional_adoption
  38. 2026-07-04Marketplace Listing grace
  39. 2026-07-04FedRAMP Recognition of Independent Assessment Services obtain
  40. 2026-07-04FedRAMP Recognition of Independent Assessment Services maintain
  41. 2026-07-04FedRAMP Recognition of Independent Assessment Services optional_adoption
  42. 2026-07-04FedRAMP Recognition of Independent Assessment Services grace
  43. 2026-07-04Significant Change Notification obtain · 20x
  44. 2026-07-04Significant Change Notification optional_adoption · 20x
  45. 2026-07-04Significant Change Notification optional_adoption · rev5
  46. 2026-07-04Security Decision Record obtain · 20x
  47. 2026-07-04Security Decision Record optional_adoption · 20x
  48. 2026-07-04Security Decision Record optional_adoption · rev5
  49. 2026-07-04Vulnerability Detection and Response optional_adoption
  50. 2026-07-04Vulnerability Evaluation and Reporting optional_adoption
  51. 2026-12-07Vulnerability Detection and Response obtain
  52. 2026-12-07Vulnerability Detection and Response maintain
  53. 2026-12-07Vulnerability Evaluation and Reporting obtain
  54. 2026-12-07Vulnerability Evaluation and Reporting maintain
  55. 2027-01-01Collaborative Continuous Monitoring maintain · 20x
  56. 2027-01-01Collaborative Continuous Monitoring grace · 20x
  57. 2027-01-01Collaborative Continuous Monitoring obtain · rev5
  58. 2027-01-01Certification Data Sharing maintain · 20x
  59. 2027-01-01Certification Data Sharing grace · 20x
  60. 2027-01-01Certification Data Sharing obtain · rev5
  61. 2027-01-01Cryptographic Module Use maintain · 20x
  62. 2027-01-01Cryptographic Module Use grace · 20x
  63. 2027-01-01Cryptographic Module Use obtain · rev5
  64. 2027-01-01Cryptographic Module Use maintain · rev5
  65. 2027-01-01Certification Package Overview maintain · 20x
  66. 2027-01-01Certification Package Overview grace · 20x
  67. 2027-01-01Certification Package Overview obtain · rev5
  68. 2027-01-01Certification Package Overview grace · rev5
  69. 2027-01-01FedRAMP Certification maintain · 20x
  70. 2027-01-01FedRAMP Certification grace · 20x
  71. 2027-01-01FedRAMP Certification obtain · rev5
  72. 2027-01-01FedRAMP Certification maintain · rev5
  73. 2027-01-01FedRAMP Certification grace · rev5
  74. 2027-01-01Incident Evaluation and Communication maintain · 20x
  75. 2027-01-01Incident Evaluation and Communication grace · 20x
  76. 2027-01-01Incident Evaluation and Communication obtain · rev5
  77. 2027-01-01Incident Evaluation and Communication maintain · rev5
  78. 2027-01-01Independent Verification and Validation maintain · 20x
  79. 2027-01-01Independent Verification and Validation grace · 20x
  80. 2027-01-01Independent Verification and Validation obtain · rev5
  81. 2027-01-01Independent Verification and Validation maintain · rev5
  82. 2027-01-01Independent Verification and Validation grace · rev5
  83. 2027-01-01Minimum Assessment Scope maintain · 20x
  84. 2027-01-01Minimum Assessment Scope grace · 20x
  85. 2027-01-01Minimum Assessment Scope obtain · rev5
  86. 2027-01-01Minimum Assessment Scope maintain · rev5
  87. 2027-01-01Minimum Assessment Scope grace · rev5
  88. 2027-01-01Significant Change Notification maintain · 20x
  89. 2027-01-01Significant Change Notification grace · 20x
  90. 2027-01-01Significant Change Notification obtain · rev5
  91. 2027-01-01Significant Change Notification maintain · rev5
  92. 2027-01-01Security Decision Record maintain · 20x
  93. 2027-01-01Security Decision Record grace · 20x
  94. 2027-01-01Security Decision Record obtain · rev5
  95. 2027-03-07Vulnerability Detection and Response grace
  96. 2027-03-07Vulnerability Evaluation and Reporting grace
  97. 2027-04-02Collaborative Continuous Monitoring maintain · rev5
  98. 2027-06-01Cryptographic Module Use grace · rev5
  99. 2027-06-01Incident Evaluation and Communication grace · rev5
  100. 2027-06-01Significant Change Notification grace · rev5
  101. 2027-07-01Certification Package Overview maintain · rev5
  102. 2027-08-01Certification Data Sharing maintain · rev5
  103. 2027-08-01Security Decision Record maintain · rev5
  104. 2027-08-01Security Decision Record grace · rev5
  105. 2027-10-01Collaborative Continuous Monitoring grace · rev5
  106. 2028-02-01Certification Data Sharing grace · rev5

Force distribution

Both totals, side by side and labelled (D7). They differ because forces also live inside per-class overrides; quoting either alone without saying which it is has already caused one wrong number.

ForceRequirement levelIncl. per-class
MUST136189
MUST NOT1111
SHOULD4584
SHOULD NOT55
MAY2039