FedRAMP Official Sources
Generated from the official FedRAMP/rules GitHub repo. Source path:
fedramp-consolidated-rules.jsononmainat blob7d628b63fdd9. Consolidated Rules version:2026.07.02.02· upstreamlast_updated:2026-07-02. Supporting narrative documentation is available from the officialFedRAMP/2026-markdownrepository.
FedRAMP Official Sources
This section is generated from the official FedRAMP GitHub organization. grclanker uses these machine-readable materials for both CLI lookups and reviewed docs snapshots so the public site stays fast without drifting away from upstream.
Current Grounding
- Primary source: FedRAMP/rules →
fedramp-consolidated-rules.jsononmain - Consolidated Rules version:
2026.07.02.02 - Upstream
last_updated:2026-07-02 - Rev5 remains a first-class lane beside 20x in grclanker.
Process Docs
- Addressing FedRAMP Communication —
AFC· applies toboth· requirements:both 16,20x 0,rev5 0 - Agency Use of FedRAMP Certified Cloud Services —
AGU· applies toboth· requirements:both 20,20x 0,rev5 0 - Collaborative Continuous Monitoring —
CCM· applies toboth· requirements:both 21,20x 0,rev5 0 - Certification Data Sharing —
CDS· applies toboth,rev5· requirements:both 20,20x 0,rev5 1 - Cryptographic Module Use —
CMU· applies toboth· requirements:both 3,20x 0,rev5 0 - Certification Package Overview —
CPO· applies toboth,20x,rev5· requirements:both 2,20x 1,rev5 1 - FedRAMP Certification —
FRC· applies toboth,20x,rev5· requirements:both 21,20x 4,rev5 4 - Incident Evaluation and Communication —
IEC· applies toboth· requirements:both 8,20x 0,rev5 0 - Independent Verification and Validation —
IVV· applies toboth,20x,rev5· requirements:both 15,20x 1,rev5 4 - Minimum Assessment Scope —
MAS· applies toboth· requirements:both 5,20x 0,rev5 0 - Marketplace Listing —
MKT· applies toboth· requirements:both 12,20x 0,rev5 0 - FedRAMP Recognition of Independent Assessment Services —
REC· applies toboth· requirements:both 16,20x 0,rev5 0 - Secure Configuration Guide —
SCG· applies toboth· requirements:both 9,20x 0,rev5 0 - Significant Change Notification —
SCN· applies toboth· requirements:both 17,20x 0,rev5 0 - Security Decision Record —
SDR· applies toboth,20x,rev5· requirements:both 2,20x 2,rev5 1 - Vulnerability Detection and Response —
VDR· applies toboth,20x,rev5· requirements:both 16,20x 1,rev5 1 - Vulnerability Evaluation and Reporting —
VER· applies toboth· requirements:both 25,20x 0,rev5 0
KSI Domains
- Cybersecurity Education —
CED· 1 indicator - Change Management —
CMT· 4 indicators - Cloud Native Architecture —
CNA· 8 indicators - Identity and Access Management —
IAM· 6 indicators - Incident Response —
INR· 3 indicators - Monitoring, Logging, and Auditing —
MLA· 5 indicators - Policy and Inventory —
PIY· 5 indicators - Recovery Planning —
RPL· 4 indicators - Supply Chain Risk —
SCR· 2 indicators - Service Configuration —
SVC· 8 indicators