Under the Consolidated Rules for 2026, a service obtains and maintains FedRAMP Certification through a defined type, class, and path; agencies use its package in risk and authorization decisions.
FedRAMP is transitioning under the Consolidated Rules for 2026: optional adoption began July 4, 2026, and mandatory adoption is scheduled for January 1, 2027. The rules support Rev5 and FedRAMP 20x certification types. A provider defines the service boundary, identifies the Certification Profile — its type, class, and path — and supplies validation evidence plus ongoing reporting. An agency authorization to operate remains a separate agency decision.
Key points
Choose the profileDetermine whether the service is eligible, select the certification type, class, and program or agency path, and identify its requirements and evidence.
Establish the packageDescribe the offering and boundary, supply machine-readable information, document inherited and customer responsibilities, validate implementation, and address findings.
Maintain certificationMonitor security conditions, report ongoing information and incidents, manage significant changes, and keep certification data available to FedRAMP and agency customers.
Important limitationFedRAMP Certification does not determine that a service is universally secure or approve every deployment. Each agency must still authorize and govern its own use, data, configurations, integrations, inherited controls, and accepted risk.