# MAS-CSO-TPR — Third-Party Information Resources

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /requirement/mas-cso-tpr

Minimum Assessment Scope (`MAS`) · group all · subset CSO
Force: MUST

## Statement

Providers MUST address the potential impact to federal customer data from third-party information resources used by the cloud service offering, ONLY IF MAS-CSO-IIR (Identify Information Resources) APPLIES, by documenting the following information about each applicable third-party information resource:

## Who it binds

- Providers

## Certification classes

_Applies regardless of certification class._

## Which certifications it binds

Certification type: 20x, Rev5
Path: Program, Agency

## Machine-readable form

FedRAMP Certification Package Overview (FRC-CSO-PKG) — https://fedramp.gov/schemas/fedramp-certification-package-overview-schema-2026-06-24.json

## Artifacts

- {"text":"A machine readable output containing all required data of the third-party information resources of the cloud service offering that are likely to handle federal customer data or likely to impact the confidentiality, integrity, or availability of federal customer data handled by the cloud service offering.","scope":"all","class":null,"source":"requirement"}
- {"text":"A human readable explanation of how the machine readable output is derived.","scope":"all","class":null,"source":"requirement"}
- {"text":"The code for the automated process used to generate the machine readable output.","scope":"all","class":null,"source":"requirement"}

## Timeframes

_This requirement states no deadline._

## Notifications

_This requirement demands no notification._
