CDS-CSO-PUBPublic Information
allMUST
Providers MUST publicly share up-to-date information about the cloud service offering in both human-readable and JSON formats, including at least the following information that is available and applicable:
Who it binds
Which certifications it binds
- Certification type
- 20x · Rev5
- Path
- Program · Agency
Machine-readable form
FedRAMP Certification Package Overview (FRC-CSO-PKG)
https://fedramp.gov/schemas/fedramp-certification-package-overview-schema-2026-06-24.json
Evidence this requirement demands
- URL to the human-readable data.
- URL to the machine-readable data.
5 default artifacts owed by every FRR requirement
- Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.
- Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.
- Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.
- Independent verification.
- Independent validation.
Group all, subset CSO of Certification Data Sharing. See all obligations on /obligations or the full evidence plan on /evidence.