# CMU-CSO-CAT — Configuration of Agency Tenants

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /requirement/cmu-cso-cat

Cryptographic Module Use (`CMU`) · group all · subset CSO
Force: SHOULD

## Statement

Providers SHOULD configure agency tenants by default to use cryptographic services that use cryptographic modules or update streams of cryptographic modules with active validations under the NIST Cryptographic Module Validation Program when such modules are available.

## Who it binds

- Providers

## Certification classes

_Applies regardless of certification class._

## Which certifications it binds

Certification type: 20x, Rev5
Path: Program, Agency

## Machine-readable form

_This requirement names no JSON schema. FRC-CSO-JSN binds a provider to a schema only where a rule contains one._

## Artifacts

- {"text":"List of cryptographic modules used by default including whether these modules are validated under the NIST Cryptographic Module Validation Program or are update streams of such modules.","scope":"all","class":null,"source":"requirement"}

## Timeframes

_This requirement states no deadline._

## Notifications

_This requirement demands no notification._
