|
2 | 2 | "info": { |
3 | 3 | "title": "FedRAMP Machine-Readable Documentation", |
4 | 4 | "description": "This datafile contains FedRAMP documentation for cloud service providers seeking FedRAMP Authorization. This includes definitions, requirements, recommendations, and key security indicators.", |
5 | | - "version": "0.9.2-beta", |
6 | | - "last_updated": "2026-02-11" |
| 5 | + "version": "0.9.3-beta", |
| 6 | + "last_updated": "2026-02-20" |
7 | 7 | }, |
8 | 8 | "FRD": { |
9 | 9 | "info": { |
|
3074 | 3074 | "end_date": "2027-12-22", |
3075 | 3075 | "comments": [ |
3076 | 3076 | "Rev5 Authorized providers or those seeking FedRAMP authorization MAY adopt this process in place of the traditional FedRAMP Significant Change Request process after February 27, 2026.", |
3077 | | - "Providers MUST address all requirements and recommendations in this process prior to full adoption.", |
3078 | 3077 | "Rev5 Authorized Providers who switch to the Significant Change Notification process MUST notify FedRAMP via the Sign-up Form.", |
| 3078 | + "Providers MUST address all requirements and recommendations in their authorization data - either in their System Security Plan with the appropriate controls or via an addendum.", |
3079 | 3079 | "It is up to providers to coordinate with their active agency customers to ensure agency customers will not be negatively impacted by the provider's adoption of this process.", |
3080 | | - "Providers seeking FedRAMP authorization who plan to follow the Significant Change Notification process must clearly note this in their authorization package", |
3081 | | - "The FedRAMP Marketplace will include a section that indicates if a cloud service offering is following this process." |
| 3080 | + "Providers seeking FedRAMP authorization who plan to follow the Significant Change Notification process must clearly note this in their authorization package.", |
| 3081 | + "The FedRAMP Marketplace will eventually include a section that indicates if a cloud service offering is following this process." |
3082 | 3082 | ] |
3083 | 3083 | }, |
3084 | 3084 | "20x": { |
|
3152 | 3152 | "comment": "Moved to FRP; removed italics and changed the ID as part of new standardization in v0.9.0-beta; no material changes." |
3153 | 3153 | } |
3154 | 3154 | ], |
| 3155 | + "note": "The circumstances and conditions of such a Corrective Action Plan will vary and be documented in the Correcive Action Plan.", |
3155 | 3156 | "terms": ["Significant change"] |
3156 | 3157 | } |
3157 | 3158 | }, |
|
3186 | 3187 | "SCN-CSO-MAR": { |
3187 | 3188 | "fka": "FRR-SCN-04", |
3188 | 3189 | "name": "Maintain Audit Records", |
3189 | | - "statement": "Providers MUST maintain auditable records of significant change evaluation activities and make them available to all necessary parties.", |
| 3190 | + "statement": "Providers MUST maintain auditable records of the significant change evaluation activities required by SCN-CSO-EVA (Evaluate Changes) and make them available to FedRAMP.", |
3190 | 3191 | "affects": ["Providers"], |
3191 | 3192 | "primary_key_word": "MUST", |
| 3193 | + "note": "These audit records must be available to FedRAMP on request; these records do not need to be included in the authorization package by default.", |
3192 | 3194 | "updated": [ |
| 3195 | + { |
| 3196 | + "date": "2026-02-20", |
| 3197 | + "comment": "Clarified that this applies to SCN-CSO-EVA evaluation activities." |
| 3198 | + }, |
3193 | 3199 | { |
3194 | 3200 | "date": "2026-02-04", |
3195 | 3201 | "comment": "Clarified wording; removed italics and changed the ID as part of new standardization in v0.9.0-beta; no material changes." |
|
3221 | 3227 | "comment": "Removed italics and changed the ID as part of new standardization in v0.9.0-beta; no material changes." |
3222 | 3228 | } |
3223 | 3229 | ], |
| 3230 | + "note": "Structure of the information may vary depending on how the provider tracks this internally.", |
3224 | 3231 | "terms": ["Persistent Validation", "Significant change"] |
3225 | 3232 | }, |
3226 | 3233 | "SCN-CSO-HIS": { |
3227 | 3234 | "fka": "FRR-SCN-05", |
3228 | 3235 | "name": "Historical Notifications", |
3229 | | - "statement": "Providers MUST keep historical Significant Change Notifications available to all necessary parties at least until the service completes its next annual assessment.", |
| 3236 | + "statement": "Providers MUST keep 12 months of historical Significant Change Notifications available with their authorization data.", |
3230 | 3237 | "affects": ["Providers"], |
3231 | 3238 | "primary_key_word": "MUST", |
3232 | 3239 | "updated": [ |
| 3240 | + { |
| 3241 | + "date": "2026-02-20", |
| 3242 | + "comment": "Updated requirement to specify 12 months of retention to showcase historical performance." |
| 3243 | + }, |
3233 | 3244 | { |
3234 | 3245 | "date": "2026-02-04", |
3235 | 3246 | "comment": "Removed italics and changed the ID as part of new standardization in v0.9.0-beta; no material changes." |
|
3240 | 3251 | "SCN-CSO-HRM": { |
3241 | 3252 | "fka": "FRR-SCN-08", |
3242 | 3253 | "name": "Human and Machine-Readable", |
3243 | | - "statement": "Providers MUST make ALL Significant Change Notifications and related audit records available in similar human-readable and compatible machine-readable formats.", |
| 3254 | + "statement": "Providers MUST make ALL Significant Change Notifications and related audit records available in human-readable and machine-readable formats.", |
3244 | 3255 | "affects": ["Providers"], |
3245 | 3256 | "primary_key_word": "MUST", |
3246 | 3257 | "updated": [ |
| 3258 | + { |
| 3259 | + "date": "2026-02-20", |
| 3260 | + "comment": "Clarified wording and added note." |
| 3261 | + }, |
3247 | 3262 | { |
3248 | 3263 | "date": "2026-02-04", |
3249 | 3264 | "comment": "Removed italics and changed the ID as part of new standardization in v0.9.0-beta; no material changes." |
3250 | 3265 | } |
3251 | 3266 | ], |
| 3267 | + "note": "During the SCN beta, many cloud service providers met this requirement by using carefully structured and organized csv files to meet human-readable and machine-readable requirements simultaneously.", |
3252 | 3268 | "terms": ["Machine-Readable", "Significant change"] |
3253 | 3269 | }, |
3254 | 3270 | "SCN-CSO-ARI": { |
|
3258 | 3274 | "affects": ["Providers"], |
3259 | 3275 | "primary_key_word": "MAY", |
3260 | 3276 | "updated": [ |
| 3277 | + { |
| 3278 | + "date": "2026-02-20", |
| 3279 | + "comment": "Added note." |
| 3280 | + }, |
3261 | 3281 | { |
3262 | 3282 | "date": "2026-02-04", |
3263 | 3283 | "comment": "Removed italics and changed the ID as part of new standardization in v0.9.0-beta; no material changes." |
3264 | 3284 | } |
3265 | 3285 | ], |
| 3286 | + "note": "This allows providers to convey whatever additional information they think is relevant without worrying about negative consequences from not following an exact template.", |
3266 | 3287 | "terms": ["Significant change"] |
3267 | 3288 | }, |
3268 | 3289 | "SCN-CSO-NOM": { |
3269 | 3290 | "fka": "FRR-SCN-07", |
3270 | 3291 | "name": "Notification Mechanisms", |
3271 | | - "statement": "Providers MAY notify necessary parties in a variety of ways as long as the mechanism for notification is clearly documented and easily accessible.", |
| 3292 | + "statement": "Providers MAY notify necessary parties in a variety of ways as long as the mechanism for notification is clearly documented in the authorization package and easily accessible.", |
3272 | 3293 | "affects": ["Providers"], |
3273 | 3294 | "primary_key_word": "MAY", |
3274 | 3295 | "updated": [ |
| 3296 | + { |
| 3297 | + "date": "2026-02-20", |
| 3298 | + "comment": "Clarified wording and added notes." |
| 3299 | + }, |
3275 | 3300 | { |
3276 | 3301 | "date": "2026-02-04", |
3277 | 3302 | "comment": "Removed italics and changed the ID as part of new standardization in v0.9.0-beta; no material changes." |
3278 | 3303 | } |
| 3304 | + ], |
| 3305 | + "notes": [ |
| 3306 | + "The sharing mechanism should be designed based on the needs of the provider and their customers and may vary between providers.", |
| 3307 | + "The default sharing mechanism for most providers during the SCN beta was to send an email to agency customers and upload a copy of the notification to the provider's secure sharing location." |
3279 | 3308 | ] |
3280 | 3309 | }, |
3281 | 3310 | "SCN-CSO-EMG": { |
3282 | 3311 | "fka": "FRR-SCN-EX-02", |
3283 | 3312 | "name": "Emergency Changes", |
3284 | | - "statement": "Providers MAY execute significant changes (including transformative changes) during an emergency or incident without meeting Significant Change Notification requirements in advance ONLY if absolutely necessary. In such emergencies, providers MUST follow all relevant procedures, notify all necessary parties, retroactively provide all Significant Change Notification materials, and complete appropriate assessment after the incident.", |
| 3313 | + "statement": "Providers MAY execute significant changes (including transformative changes) during an emergency or incident without meeting Significant Change Notification requirements in advance. In such emergencies, providers MUST follow all relevant procedures, notify all necessary parties, retroactively provide all Significant Change Notification materials, and complete appropriate assessment after the incident.", |
3285 | 3314 | "affects": ["Providers"], |
3286 | 3315 | "primary_key_word": "MAY", |
3287 | 3316 | "updated": [ |
| 3317 | + { |
| 3318 | + "date": "2026-02-20", |
| 3319 | + "comment": "Clarified wording and added note." |
| 3320 | + }, |
3288 | 3321 | { |
3289 | 3322 | "date": "2026-02-04", |
3290 | 3323 | "comment": "Removed italics and changed the ID as part of new standardization in v0.9.0-beta; no material changes." |
|
3295 | 3328 | "Incident", |
3296 | 3329 | "Significant change", |
3297 | 3330 | "Transformative" |
3298 | | - ] |
| 3331 | + ], |
| 3332 | + "note": "Procedures for emergency changes should be documented in the authorization package." |
3299 | 3333 | } |
3300 | 3334 | }, |
3301 | 3335 | "RTR": { |
|
3399 | 3433 | } |
3400 | 3434 | }, |
3401 | 3435 | "TRF": { |
3402 | | - "SCN-TRF-OPT": { |
3403 | | - "fka": "FRR-SCN-TR-07", |
3404 | | - "name": "Option to Opt Out", |
3405 | | - "statement": "Providers MUST allow agency customers to OPT OUT of transformative changes whenever feasible.", |
3406 | | - "affects": ["Providers"], |
3407 | | - "primary_key_word": "MUST", |
3408 | | - "updated": [ |
3409 | | - { |
3410 | | - "date": "2026-02-04", |
3411 | | - "comment": "Removed italics and changed the ID as part of new standardization in v0.9.0-beta; no material changes." |
3412 | | - } |
3413 | | - ], |
3414 | | - "terms": ["Agency", "Transformative"] |
3415 | | - }, |
3416 | 3436 | "SCN-TRF-NIP": { |
3417 | 3437 | "fka": "FRR-SCN-TR-02", |
3418 | 3438 | "name": "Notification of Initial Plans", |
|
3526 | 3546 | "timeframe_num": 30, |
3527 | 3547 | "primary_key_word": "MUST", |
3528 | 3548 | "updated": [ |
| 3549 | + { |
| 3550 | + "date": "2026-02-20", |
| 3551 | + "comment": "Added note." |
| 3552 | + }, |
3529 | 3553 | { |
3530 | 3554 | "date": "2026-02-04", |
3531 | 3555 | "comment": "Removed italics and changed the ID as part of new standardization in v0.9.0-beta; no material changes." |
3532 | 3556 | } |
3533 | 3557 | ], |
3534 | | - "terms": ["Transformative"] |
| 3558 | + "terms": ["Transformative"], |
| 3559 | + "note": "This requirement is focused on service documentation like user guides, information listed in the marketplace, and other such materials; it does not require updating the system security plan or authorization package." |
3535 | 3560 | }, |
3536 | 3561 | "SCN-TRF-TPR": { |
3537 | 3562 | "fka": "FRR-SCN-TR-01", |
|
3677 | 3702 | "Rev5 Authorized providers MAY adopt this process beginning February 2, 2026 as part of the Open Beta.", |
3678 | 3703 | "Providers MUST plan to address all requirements and recommendations in this process by the end of the Open Beta on May 22, 2026.", |
3679 | 3704 | "It is up to providers to coordinate with their active agency customers to ensure agency customers will not be negatively impacted by the provider's participation in this beta.", |
3680 | | - "FedRAMP recommends that participants in the Vulnerability Detection and Response beta also adopt the Authorization Data Sharing process and the Significant Change Notifications process." |
| 3705 | + "FedRAMP recommends that participants in the Vulnerability Detection and Response beta also adopt the Collaborative Continuous Monitoring process and the Significant Change Notifications process." |
3681 | 3706 | ] |
3682 | 3707 | }, |
3683 | 3708 | "20x": { |
|
0 commit comments