# SDR-CSF-CTF — Rev5 Controls

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /requirement/sdr-csf-ctf

Security Decision Record (`SDR`) · group rev5 · subset CSF
Force: MUST

## Statement

Providers MUST also include short and simple high-level summaries of at least the following for each applicable Rev5 Control:

## Who it binds

- Providers

## Certification classes

_Applies regardless of certification class._

## Which certifications it binds

Certification type: 20x, Rev5 (this subset states no type restriction)
Path: Program, Agency (this subset states no path restriction)

## Machine-readable form

_This requirement names no JSON schema. FRC-CSO-JSN binds a provider to a schema only where a rule contains one._

## Artifacts

_No requirement-specific artifact is named._

## Timeframes

_This requirement states no deadline._

## Notifications

_This requirement demands no notification._
