# CDS-CSO-SVC — Public Service List

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /requirement/cds-cso-svc

Certification Data Sharing (`CDS`) · group all · subset CSO
Force: MUST

## Statement

Providers MUST publicly share a detailed list of specific services and their security categories that are included in the cloud service offering using clear feature or service names that align with standard public marketing materials; this list MUST be complete enough for a potential customer to determine which services are and are not included in the FedRAMP Minimum Assessment Scope without requesting access to underlying FedRAMP Certification Data.

## Who it binds

- Providers

## Certification classes

_Applies regardless of certification class._

## Which certifications it binds

Certification type: 20x, Rev5
Path: Program, Agency

## Machine-readable form

FedRAMP Certification Package Overview (FRC-CSO-PKG) — https://fedramp.gov/schemas/fedramp-certification-package-overview-schema-2026-06-24.json

## Artifacts

- {"text":"URL to the human-readable data.","scope":"all","class":null,"source":"requirement"}
- {"text":"URL to the machine-readable data (if applicable).","scope":"all","class":null,"source":"requirement"}

## Timeframes

_This requirement states no deadline._

## Notifications

_This requirement demands no notification._
