Obligation Clock
Every deadline the rules impose, ordered by how soon it bites. The dataset buries most of them — the majority of the 68 timeframes live inside per-class overrides, so a tool reading only requirement level finds 17 and reports a quarter of the truth.
Every deadline, tightest first (68)
Units are never converted. “48 hours” and “2 days” are the same duration and not the same obligation, so each row shows the dataset’s own number and unit. Ordering spans all 6 units.
All 68 deadlines, every party. Requirement-level split: Providers 180 · Agencies 24 · Assessors 23 · FedRAMP 16 · Advisors 3 (246 total).
| Deadline | Class | Requirement | Force |
|---|---|---|---|
| 1 day | D | VDR-TFR-PSD Persistent Sample Detection Providers with Class D Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once per day. | SHOULD |
| 48 hours | all | REC-IAS-CFI Changes in Foreign Interest Assessors MUST report updated information relating to any foreign interest, foreign influence, or foreign control of the independent assessment service within 48 hours of any change in foreign ownership or control. | MUST |
| 2 days | D | VER-TFR-EVU Evaluate Vulnerabilities Quickly Providers with Class D Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 2 days of detection. | SHOULD |
| 3 days | C | VDR-TFR-MVX Persistent Machine Verification and Validation for 20x Providers of FedRAMP 20x Class C offerings MUST verify and validate the status of machine-based information resources at least once every 3 days. | MUST |
| 3 days | C | VDR-TFR-PSD Persistent Sample Detection Providers with Class C Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 3 days. | SHOULD |
| 5 days | C | VER-TFR-EVU Evaluate Vulnerabilities Quickly Providers with Class C Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 5 days of detection. | SHOULD |
| 5 business days | all | CDS-UTC-AAD Agency Access Denial Providers MUST notify FedRAMP within 5 business days of denying an agency access request for FedRAMP Certification Data. | MUST |
| 1 week | D | CPO-CSX-CPM Certification Package Maintenance for 20x Providers with 20x Class D Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every week. | MUST |
| 5 business days | all | SCN-TRF-NAF Notification After Finishing Providers MUST notify all necessary parties within 5 business days after finishing transformative changes, including updates to all previously sent information. | MUST |
| 5 business days | all | SCN-TRF-NAV Notification After Verification Providers MUST notify all necessary parties within 5 business days after completing the verification, assessment, and/or validation of transformative changes, also including the following information: | MUST |
| 7 days | B | VDR-TFR-MVX Persistent Machine Verification and Validation for 20x Providers of FedRAMP 20x Class B offerings MUST verify and validate the status of machine-based information resources at least once every 7 days. | MUST |
| 7 days | D | VDR-TFR-PDD Persistent Drift Detection Providers with Class D Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 7 days. | SHOULD |
| 7 days | B | VDR-TFR-PSD Persistent Sample Detection Providers with Class B Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 7 days. | SHOULD |
| 7 days | B | VER-TFR-EVU Evaluate Vulnerabilities Quickly Providers with Class B Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 7 days of detection. | SHOULD |
| 7 days | D | VER-TFR-MRH Historical Activity Providers with Class D Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every 7 days. | SHOULD |
| 10 business days | all | AFC-FRP-PNT Public Notice of Emergency Tests FedRAMP MUST post a public notice at least 10 business days in advance of sending an Emergency Test message; such notices MUST include explanation of the likely expected actions and timeframes for the Emergency Test message. | MUST |
| 2 weeks | all | CDS-CSO-FRC FedRAMP Certification Reports Providers MUST include FedRAMP Certification Reports with their FedRAMP Certification Data without inappropriate modifications, and make such reports available within 2 weeks of receiving the materials from FedRAMP. | MUST |
| 2 weeks | C | CPO-CSX-CPM Certification Package Maintenance for 20x Providers with 20x Class C Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every 2 weeks. | MUST |
| 10 business days | all | SCN-ADP-NTF Notification Requirements Providers MUST notify all necessary parties within 10 business days after finishing adaptive changes, also including the following information: | MUST |
| 10 business days | all | SCN-TRF-NFP Notification of Final Plans Providers MUST notify all necessary parties of final plans for transformative changes at least 10 business days before starting transformative changes, including updates to all previously sent information. | MUST |
| 14 days | C | VDR-TFR-PDD Persistent Drift Detection Providers with Class C Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 14 days. | SHOULD |
| 14 days | A | VDR-TFR-PSD Persistent Sample Detection Providers with Class A Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 14 days. | SHOULD |
| 14 days | A | VER-TFR-EVU Evaluate Vulnerabilities Quickly Providers with Class A Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 14 days of detection. | SHOULD |
| 14 days | C | VER-TFR-MRH Historical Activity Providers with Class C Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every 14 days. | SHOULD |
| 1 month | B | CPO-CSX-CPM Certification Package Maintenance for 20x Providers with 20x Class B Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every month. | MUST |
| 1 month | B | VDR-TFR-MVF Persistent Machine Verification and Validation for Rev5 Providers of FedRAMP Rev5 Class B offerings SHOULD verify and validate the status of machine-based information resources at least once every month. | SHOULD |
| 1 month | C | VDR-TFR-MVF Persistent Machine Verification and Validation for Rev5 Providers of FedRAMP Rev5 Class C offerings MUST verify and validate the status of machine-based information resources at least once every month. | MUST |
| 1 month | D | VDR-TFR-MVF Persistent Machine Verification and Validation for Rev5 Providers of FedRAMP Rev5 Class D offerings MUST verify and validate the status of machine-based information resources at least once every month. | MUST |
| 1 month | A | VDR-TFR-MVX Persistent Machine Verification and Validation for 20x Providers of FedRAMP 20x Class A offerings SHOULD verify and validate the status of machine-based information resources at least once every month. | SHOULD |
| 1 month | C | VDR-TFR-PCD Persistently Complete Detection Providers with Class C Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every month. | SHOULD |
| 1 month | D | VDR-TFR-PCD Persistently Complete Detection Providers with Class D Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every month. | SHOULD |
| 1 month | B | VDR-TFR-PDD Persistent Drift Detection Providers with Class B Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every month. | SHOULD |
| 1 month | all | VER-TFR-MHR Monthly Activity Report Providers MUST report vulnerability detection and response activity to all necessary parties in a consistent format that is human readable at least monthly. | MUST |
| 1 month | A | VER-TFR-MRH Historical Activity Providers with Class A Certifications MAY make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information MAY be updated persistently, at least once every month. | MAY |
| 1 month | B | VER-TFR-MRH Historical Activity Providers with Class B Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every month. | SHOULD |
| 30 business days | all | SCN-TRF-NIP Notification of Initial Plans Providers MUST notify all necessary parties of initial plans for transformative changes at least 30 business days before starting transformative changes, including a summary of any likely security impacts or changes in risk. | MUST |
| 30 business days | all | SCN-TRF-UPD Update Documentation Providers MUST publish updated service documentation and other materials to reflect transformative changes within 30 business days after finishing transformative changes. | MUST |
| 3 months | A | CCM-QTR-MTG Quarterly Review Meeting Providers with Class A Certifications MAY host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies. | MAY |
| 3 months | B | CCM-QTR-MTG Quarterly Review Meeting Providers with Class B Certifications SHOULD host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies. | SHOULD |
| 3 months | C | CCM-QTR-MTG Quarterly Review Meeting Providers with Class C Certifications MUST host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies. | MUST |
| 3 months | D | CCM-QTR-MTG Quarterly Review Meeting Providers with Class D Certifications MUST host a synchronous Quarterly Review every 3 months, open to all necessary parties, to review aspects of the most recent Ongoing Certification Reports that the provider determines are of the most relevance to agencies. | MUST |
| 3 months | A | CPO-CSX-CPM Certification Package Maintenance for 20x Providers with 20x Class A Certifications SHOULD persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every 3 months. | SHOULD |
| 3 months | A | FRC-APP-FIA Fresh Independent Assessment Providers seeking Class A Certification MAY supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months. | MAY |
| 3 months | B | FRC-APP-FIA Fresh Independent Assessment Providers seeking Class B Certification MUST supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months. | MUST |
| 3 months | C | FRC-APP-FIA Fresh Independent Assessment Providers seeking Class C Certification MUST supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months. | MUST |
| 3 months | D | FRC-APP-FIA Fresh Independent Assessment Providers seeking Class D Certification MUST supply a fresh initial FedRAMP independent assessment that was completed by a FedRAMP Recognized independent assessment service within the previous 3 months. | MUST |
| 3 months | A | VDR-TFR-PDD Persistent Drift Detection Providers with Class A Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 3 months. | SHOULD |
| 6 months | D | CPO-CSF-CPM Certification Package Maintenance for Rev5 Providers with Rev5 Class D Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every six months. | MUST |
| 6 months | A | VDR-TFR-PCD Persistently Complete Detection Providers with Class A Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every 6 months. | SHOULD |
| 6 months | B | VDR-TFR-PCD Persistently Complete Detection Providers with Class B Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every 6 months. | SHOULD |
| 192 days | all | VER-TFR-MAV Mark Accepted Vulnerabilities Providers MUST categorize any vulnerability that is not or will not be fully mitigated or remediated within 192 days of evaluation as an accepted vulnerability. | MUST |
| 1 year | B | CPO-CSF-CPM Certification Package Maintenance for Rev5 Providers with Rev5 Class B Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every year. | MUST |
| 1 year | C | CPO-CSF-CPM Certification Package Maintenance for Rev5 Providers with Rev5 Class C Certifications MUST persistently maintain their FedRAMP Certification Package to ensure it is up to date and complete at least once every year. | MUST |
| 1 year | B | IVV-CSF-AIA Annual Independent Assessments for Rev5 Providers with Rev5 Class B Certifications MUST include the following Rev5 Controls in a FedRAMP independent assessment at least once per year: | MUST |
| 1 year | C | IVV-CSF-AIA Annual Independent Assessments for Rev5 Providers with Rev5 Class C Certifications MUST include the following Rev5 Controls in a FedRAMP independent assessment at least once per year: | MUST |
| 1 year | D | IVV-CSF-AIA Annual Independent Assessments for Rev5 Providers with Rev5 Class D Certifications MUST include the following Rev5 Controls in a FedRAMP independent assessment at least once per year: | MUST |
| 1 year | A | IVV-CSO-FIA FedRAMP Independent Assessments Providers with Class A Certifications MAY persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment. | MAY |
| 1 year | B | IVV-CSO-FIA FedRAMP Independent Assessments Providers with Class B Certifications MUST persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment. | MUST |
| 1 year | C | IVV-CSO-FIA FedRAMP Independent Assessments Providers with Class C Certifications MUST persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment. | MUST |
| 1 year | D | IVV-CSO-FIA FedRAMP Independent Assessments Providers with Class D Certifications MUST persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment. | MUST |
| 1 year | B | IVV-CSX-AIA Annual Independent Assessments for 20x Providers with 20x Class B Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year. | MUST |
| 1 year | C | IVV-CSX-AIA Annual Independent Assessments for 20x Providers with 20x Class C Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year. | MUST |
| 1 year | D | IVV-CSX-AIA Annual Independent Assessments for 20x Providers with 20x Class D Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year. | MUST |
| 1 year | all | REC-IAS-AFI Annual Foreign Interest Reports Assessors MUST report information relating to any foreign interest, foreign influence, or foreign control of the independent assessment service to FedRAMP annually. | MUST |
| 1 year | all | REC-IAS-ANR Annual Surveillance Assessment Assessors MUST achieve a favorable annual surveillance assessment by the American Association for Laboratory Accreditation (A2LA) to maintain FedRAMP Recognition. | MUST |
| 2 years | all | REC-IAS-ADA Actually Do Assessments Assessors MUST complete at least 2 initial or ongoing assessments for Class B, C, or D FedRAMP Certifications every 2 years to maintain FedRAMP Recognition. | MUST |
| 2 years | all | REC-IAS-RAS Full A2LA Reassessment Assessors MUST achieve a favorable full reassessment by the American Association for Laboratory Accreditation (A2LA) at least once every 2 years to maintain FedRAMP Recognition. | MUST |
| 2 years | all | REC-IAS-SEP Advisory Separation Assessors MUST NOT perform a FedRAMP independent assessment of the same cloud service offering within 2 years after supplying advisory or consulting services for that offering, unless FedRAMP publishes a specific exception for a limited pilot or other explicitly scoped process. | MUST NOT |
PAIN grids (16)
Severity level crossed with scenario. Columns are derived per requirement, never fixed — the carrying requirements do not share a column set.
IEC-CSO-IIR Initial Incident Report(class A)
| Level | iir |
|---|---|
| 1 | 1 business day |
| 2 | 1 business day |
| 3 | 6 hours |
| 4 | 6 hours |
| 5 | 6 hours |
IEC-CSO-IIR Initial Incident Report(class B)
| Level | iir |
|---|---|
| 1 | 1 business day |
| 2 | 1 business day |
| 3 | 6 hours |
| 4 | 6 hours |
| 5 | 6 hours |
IEC-CSO-IIR Initial Incident Report(class C)
| Level | iir |
|---|---|
| 1 | 1 business day |
| 2 | 24 hours |
| 3 | 1 hour |
| 4 | 1 hour |
| 5 | 1 hour |
IEC-CSO-IIR Initial Incident Report(class D)
| Level | iir |
|---|---|
| 1 | 1 hour |
| 2 | 1 hour |
| 3 | 0.25 hours |
| 4 | 0.25 hours |
| 5 | 0.25 hours |
IEC-CSO-OIR Ongoing Incident Reports(class A)
| Level | oir |
|---|---|
| 1 | 1 business day |
| 2 | 1 business day |
| 3 | 1 business day |
| 4 | 1 business day |
| 5 | 1 business day |
IEC-CSO-OIR Ongoing Incident Reports(class B)
| Level | oir |
|---|---|
| 1 | 1 business day |
| 2 | 1 business day |
| 3 | 1 business day |
| 4 | 1 business day |
| 5 | 1 business day |
IEC-CSO-OIR Ongoing Incident Reports(class C)
| Level | oir |
|---|---|
| 1 | 1 business day |
| 2 | 24 hours |
| 3 | 6 hours |
| 4 | 6 hours |
| 5 | 6 hours |
IEC-CSO-OIR Ongoing Incident Reports(class D)
| Level | oir |
|---|---|
| 1 | 24 hours |
| 2 | 6 hours |
| 3 | 3 hours |
| 4 | 3 hours |
| 5 | 3 hours |
IEC-CSO-FIR Final Incident Report(class A)
| Level | fir |
|---|---|
| 1 | 3 business days |
| 2 | 3 business days |
| 3 | 3 business days |
| 4 | 3 business days |
| 5 | 3 business days |
IEC-CSO-FIR Final Incident Report(class B)
| Level | fir |
|---|---|
| 1 | 3 business days |
| 2 | 3 business days |
| 3 | 3 business days |
| 4 | 3 business days |
| 5 | 3 business days |
IEC-CSO-FIR Final Incident Report(class C)
| Level | fir |
|---|---|
| 1 | 1 business day |
| 2 | 1 business day |
| 3 | 6 hours |
| 4 | 6 hours |
| 5 | 6 hours |
IEC-CSO-FIR Final Incident Report(class D)
| Level | fir |
|---|---|
| 1 | 24 hours |
| 2 | 6 hours |
| 3 | 3 hours |
| 4 | 3 hours |
| 5 | 3 hours |
VDR-TFR-PVR Mitigation and Remediation Expectations(class A)
| Level | irv_lev | nirv_lev | nlev |
|---|---|---|---|
| 1 | — | — | — |
| 2 | 96 days | 160 days | 192 days |
| 3 | 32 days | 64 days | 192 days |
| 4 | 8 days | 32 days | 64 days |
| 5 | 4 days | 8 days | 32 days |
VDR-TFR-PVR Mitigation and Remediation Expectations(class B)
| Level | irv_lev | nirv_lev | nlev |
|---|---|---|---|
| 1 | — | — | — |
| 2 | 96 days | 160 days | 192 days |
| 3 | 32 days | 64 days | 192 days |
| 4 | 8 days | 32 days | 64 days |
| 5 | 4 days | 8 days | 32 days |
VDR-TFR-PVR Mitigation and Remediation Expectations(class C)
| Level | irv_lev | nirv_lev | nlev |
|---|---|---|---|
| 1 | — | — | — |
| 2 | 48 days | 128 days | 192 days |
| 3 | 16 days | 32 days | 128 days |
| 4 | 4 days | 8 days | 64 days |
| 5 | 2 days | 4 days | 16 days |
VDR-TFR-PVR Mitigation and Remediation Expectations(class D)
| Level | irv_lev | nirv_lev | nlev |
|---|---|---|---|
| 1 | — | — | — |
| 2 | 24 days | 96 days | 192 days |
| 3 | 8 days | 16 days | 64 days |
| 4 | 2 days | 8 days | 32 days |
| 5 | 12 hours | 1 day | 8 days |
Notification targets (31)
| Requirement | Party | Method | Target |
|---|---|---|---|
| AFC-FRP-PNT | Everyone | web | https://www.fedramp.gov/notices |
| AFC-CSO-NOC | FedRAMP | form | https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51829466938011 |
| AGU-AGC-NAA | FedRAMP | form | https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51447926193691 |
| AGU-AGC-NAI | FedRAMP | form | https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51822364715035 |
| AGU-AGC-NAR | FedRAMP | info@fedramp.gov | |
| AGU-AGC-TPP | FedRAMP | info@fedramp.gov | |
| AGU-USE-NFC | FedRAMP | form | https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51821301979547 |
| AGU-USE-NPC | Provider | varies | varies by provider |
| CDS-UTC-AAD | FedRAMP | form | https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51829826617243 |
| CDS-CSF-TCM | FedRAMP | info@fedramp.gov | |
| CDS-CSF-TCM | Agency Customers | varies | varies by agency |
| FRC-APP-AFC | FedRAMP | form | https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=51137131584283 |
| IEC-CSO-IIR | FedRAMP | fedramp_security@fedramp.gov | |
| IEC-CSO-IIR | Agency Customers | varies | varies by agency |
| IEC-CSO-IIR | All Necessary Parties | update | trust center |
| IEC-CSO-OIR | FedRAMP | fedramp_security@fedramp.gov | |
| IEC-CSO-OIR | Agency Customers | varies | varies by agency |
| IEC-CSO-OIR | All Necessary Parties | update | trust center |
| IEC-CSO-FIR | FedRAMP | fedramp_security@fedramp.gov | |
| IEC-CSO-FIR | Agency Customers | varies | varies by agency |
| IEC-CSO-FIR | All Necessary Parties | update | trust center |
| MKT-CSO-PML | FedRAMP | form | https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=50939227168027 |
| MKT-IAS-LRQ | FedRAMP | form | https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=52060327520795 |
| MKT-CAS-LRQ | FedRAMP | form | https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=52060327520795 |
| REC-IAS-AFI | FedRAMP | form | https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=52006681154587 |
| REC-IAS-CFI | FedRAMP | form | https://help.fedramp.gov/hc/en-us/requests/new?ticket_form_id=52006681154587 |
| SCN-ADP-NTF | All Necessary Parties | update | FedRAMP Certification Data |
| SCN-TRF-NIP | All Necessary Parties | update | FedRAMP Certification Data |
| SCN-TRF-NFP | All Necessary Parties | update | FedRAMP Certification Data |
| SCN-TRF-NAF | All Necessary Parties | update | FedRAMP Certification Data |
| SCN-TRF-NAV | All Necessary Parties | update | FedRAMP Certification Data |
Rollout calendar (106)
- 2026-01-05Addressing FedRAMP Communication obtain
- 2026-01-05Addressing FedRAMP Communication maintain
- 2026-03-01Secure Configuration Guide obtain
- 2026-03-01Secure Configuration Guide maintain
- 2026-07-01Addressing FedRAMP Communication grace
- 2026-07-01Secure Configuration Guide grace
- 2026-07-04Agency Use of FedRAMP Certified Cloud Services obtain
- 2026-07-04Agency Use of FedRAMP Certified Cloud Services maintain
- 2026-07-04Agency Use of FedRAMP Certified Cloud Services optional_adoption
- 2026-07-04Agency Use of FedRAMP Certified Cloud Services grace
- 2026-07-04Collaborative Continuous Monitoring obtain · 20x
- 2026-07-04Collaborative Continuous Monitoring optional_adoption · 20x
- 2026-07-04Collaborative Continuous Monitoring optional_adoption · rev5
- 2026-07-04Certification Data Sharing obtain · 20x
- 2026-07-04Certification Data Sharing optional_adoption · 20x
- 2026-07-04Certification Data Sharing optional_adoption · rev5
- 2026-07-04Cryptographic Module Use obtain · 20x
- 2026-07-04Cryptographic Module Use optional_adoption · 20x
- 2026-07-04Cryptographic Module Use optional_adoption · rev5
- 2026-07-04Certification Package Overview obtain · 20x
- 2026-07-04Certification Package Overview optional_adoption · 20x
- 2026-07-04Certification Package Overview optional_adoption · rev5
- 2026-07-04FedRAMP Certification obtain · 20x
- 2026-07-04FedRAMP Certification optional_adoption · 20x
- 2026-07-04FedRAMP Certification optional_adoption · rev5
- 2026-07-04Incident Evaluation and Communication obtain · 20x
- 2026-07-04Incident Evaluation and Communication optional_adoption · 20x
- 2026-07-04Incident Evaluation and Communication optional_adoption · rev5
- 2026-07-04Independent Verification and Validation obtain · 20x
- 2026-07-04Independent Verification and Validation optional_adoption · 20x
- 2026-07-04Independent Verification and Validation optional_adoption · rev5
- 2026-07-04Minimum Assessment Scope obtain · 20x
- 2026-07-04Minimum Assessment Scope optional_adoption · 20x
- 2026-07-04Minimum Assessment Scope optional_adoption · rev5
- 2026-07-04Marketplace Listing obtain
- 2026-07-04Marketplace Listing maintain
- 2026-07-04Marketplace Listing optional_adoption
- 2026-07-04Marketplace Listing grace
- 2026-07-04FedRAMP Recognition of Independent Assessment Services obtain
- 2026-07-04FedRAMP Recognition of Independent Assessment Services maintain
- 2026-07-04FedRAMP Recognition of Independent Assessment Services optional_adoption
- 2026-07-04FedRAMP Recognition of Independent Assessment Services grace
- 2026-07-04Significant Change Notification obtain · 20x
- 2026-07-04Significant Change Notification optional_adoption · 20x
- 2026-07-04Significant Change Notification optional_adoption · rev5
- 2026-07-04Security Decision Record obtain · 20x
- 2026-07-04Security Decision Record optional_adoption · 20x
- 2026-07-04Security Decision Record optional_adoption · rev5
- 2026-07-04Vulnerability Detection and Response optional_adoption
- 2026-07-04Vulnerability Evaluation and Reporting optional_adoption
- 2026-12-07Vulnerability Detection and Response obtain
- 2026-12-07Vulnerability Detection and Response maintain
- 2026-12-07Vulnerability Evaluation and Reporting obtain
- 2026-12-07Vulnerability Evaluation and Reporting maintain
- 2027-01-01Collaborative Continuous Monitoring maintain · 20x
- 2027-01-01Collaborative Continuous Monitoring grace · 20x
- 2027-01-01Collaborative Continuous Monitoring obtain · rev5
- 2027-01-01Certification Data Sharing maintain · 20x
- 2027-01-01Certification Data Sharing grace · 20x
- 2027-01-01Certification Data Sharing obtain · rev5
- 2027-01-01Cryptographic Module Use maintain · 20x
- 2027-01-01Cryptographic Module Use grace · 20x
- 2027-01-01Cryptographic Module Use obtain · rev5
- 2027-01-01Cryptographic Module Use maintain · rev5
- 2027-01-01Certification Package Overview maintain · 20x
- 2027-01-01Certification Package Overview grace · 20x
- 2027-01-01Certification Package Overview obtain · rev5
- 2027-01-01Certification Package Overview grace · rev5
- 2027-01-01FedRAMP Certification maintain · 20x
- 2027-01-01FedRAMP Certification grace · 20x
- 2027-01-01FedRAMP Certification obtain · rev5
- 2027-01-01FedRAMP Certification maintain · rev5
- 2027-01-01FedRAMP Certification grace · rev5
- 2027-01-01Incident Evaluation and Communication maintain · 20x
- 2027-01-01Incident Evaluation and Communication grace · 20x
- 2027-01-01Incident Evaluation and Communication obtain · rev5
- 2027-01-01Incident Evaluation and Communication maintain · rev5
- 2027-01-01Independent Verification and Validation maintain · 20x
- 2027-01-01Independent Verification and Validation grace · 20x
- 2027-01-01Independent Verification and Validation obtain · rev5
- 2027-01-01Independent Verification and Validation maintain · rev5
- 2027-01-01Independent Verification and Validation grace · rev5
- 2027-01-01Minimum Assessment Scope maintain · 20x
- 2027-01-01Minimum Assessment Scope grace · 20x
- 2027-01-01Minimum Assessment Scope obtain · rev5
- 2027-01-01Minimum Assessment Scope maintain · rev5
- 2027-01-01Minimum Assessment Scope grace · rev5
- 2027-01-01Significant Change Notification maintain · 20x
- 2027-01-01Significant Change Notification grace · 20x
- 2027-01-01Significant Change Notification obtain · rev5
- 2027-01-01Significant Change Notification maintain · rev5
- 2027-01-01Security Decision Record maintain · 20x
- 2027-01-01Security Decision Record grace · 20x
- 2027-01-01Security Decision Record obtain · rev5
- 2027-03-07Vulnerability Detection and Response grace
- 2027-03-07Vulnerability Evaluation and Reporting grace
- 2027-04-02Collaborative Continuous Monitoring maintain · rev5
- 2027-06-01Cryptographic Module Use grace · rev5
- 2027-06-01Incident Evaluation and Communication grace · rev5
- 2027-06-01Significant Change Notification grace · rev5
- 2027-07-01Certification Package Overview maintain · rev5
- 2027-08-01Certification Data Sharing maintain · rev5
- 2027-08-01Security Decision Record maintain · rev5
- 2027-08-01Security Decision Record grace · rev5
- 2027-10-01Collaborative Continuous Monitoring grace · rev5
- 2028-02-01Certification Data Sharing grace · rev5
Force distribution
Both totals, side by side and labelled (D7). They differ because forces also live inside per-class overrides; quoting either alone without saying which it is has already caused one wrong number.
| Force | Requirement level | Incl. per-class |
|---|---|---|
| MUST | 136 | 189 |
| MUST NOT | 11 | 11 |
| SHOULD | 45 | 84 |
| SHOULD NOT | 5 | 5 |
| MAY | 20 | 39 |