Skip to content

Agency Use of FedRAMP Certified Cloud Services (Needs Review)

The Agency Use rules summarize the many demands made on agencies by the FedRAMP Authorization Act and OMB Memorandum M-24-15 in a simple, clear, easy-to-follow set of FedRAMP-style rules. These rules align agency policies, authorization letters, machine-readable tools, secure configuration review, continuous monitoring, and communication with FedRAMP so certifications can be reused consistently across government.

Rule Sections


General Agency Responsibilities

These rules apply to agencies based on the FedRAMP Authorization Act, OMB M-24-15, and related FedRAMP policies.

Agency Internal Policies

AGU-AGC-AIP

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies MUST maintain agency-wide internal policies aligned with FedRAMP standards and the principles and directives of OMB Memorandum M-24-15.

Notify FedRAMP After Authorization

AGU-AGC-NAL

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

This FRR includes a notification requirement!

  • Notify FedRAMP by email using ato-letter@fedramp.gov.

Agencies MUST notify FedRAMP after authorizing an in-scope cloud service by supplying the agency Authorization to Operate letter to ato-letter@fedramp.gov.

Governance, Risk, and Compliance Tools

AGU-AGC-GRC

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies MUST ensure that internal governance, risk, compliance, and inventory tools can produce and ingest machine-readable artifacts using formats identified by FedRAMP, including at least:

  1. Open Security Controls Assessment Language (OSCAL)
  2. JSON

Terms: Artifacts, Machine-Readable

Commercial Cloud Adoption

AGU-AGC-CCA

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies SHOULD encourage adoption of commercial cloud services without incentivizing government-specific services.

No Additional Security Requirements

AGU-AGC-NAR

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies MUST NOT place additional security requirements on FedRAMP Certified cloud service offerings beyond those required by FedRAMP UNLESS the head of the agency or an authorized delegate determines there is a demonstrable need; this does not apply to seeking clarification or asking general questions about FedRAMP Certification Data.


Note: This is related to the Presumption of Adequacy for a FedRAMP Certification.


Terms: Certification Data, Cloud Service Offering, FedRAMP Certified

Notify Additional Information Requests

AGU-AGC-NAI

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

This FRR includes a notification requirement!

  • Notify FedRAMP by email using info@fedramp.gov.

Agencies MUST notify FedRAMP after requesting any additional information or materials from a FedRAMP Certified cloud service offering beyond those FedRAMP requires by sending an email to info@fedramp.gov.


Note: Agencies are expected to notify FedRAMP under OMB Memorandum M-24-15 section IV (a).


Terms: Cloud Service Offering, FedRAMP Certified

Lessons Learned Reporting

AGU-AGC-LLR

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies SHOULD contribute to FedRAMP lessons-learned reporting, including sharing risk acceptance rationales, to improve government-wide reuse and transparency.

FedRAMP Working Groups

AGU-AGC-WKG

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies SHOULD participate in FedRAMP working groups, communities of practice, and stakeholder engagements to supply feedback and align practices across government.

Agency Liaison Program

AGU-AGC-LIA

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies SHOULD assign at least 1 federal employee to be an active participant in the FedRAMP agency liaison program.

Shared FedRAMP Inbox

AGU-AGC-SIN

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies SHOULD establish and maintain a dedicated shared FedRAMP agency inbox to serve as the official point of contact for communications between FedRAMP and the agency.


Note: A shared FedRAMP agency inbox may follow an agency-specific format such as agency-fedramp@agency.gov.

Use of FedRAMP Certifications

These rules apply when agencies use FedRAMP Certifications to make agency authorization decisions.

Authorization Before Use

AGU-USE-ABU

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies MUST complete an agency authorization before using a cloud service inside a federal information system.

Existing Certification Package

AGU-USE-ERP

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies MUST use the existing FedRAMP Certification package to make agency authorization decisions for FedRAMP Certified cloud services.


Terms: Certification Package, FedRAMP Certified

Compensating Controls and Risk Acceptance

AGU-USE-CRC

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies MAY accept compensating controls or risk-acceptance decisions in cases of control misalignment between federal and external frameworks.

Resolve Certification Package Conflicts

AGU-USE-RCF

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies MUST collaborate with FedRAMP when discrepancies or conflicts arise between agency-specific security determinations and the baseline FedRAMP Certification package.


Terms: Certification Package

Review Secure Configuration Guides

AGU-USE-RSG

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies MUST review the Secure Configuration Guides supplied by Providers and configure relevant security settings.

Collaborative Continuous Monitoring Plan

AGU-USE-CCP

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies MUST develop a plan with the Provider to follow Collaborative Continuous Monitoring rules and complete ongoing authorization activities.

Review Ongoing Authorization Reports

AGU-USE-ROR

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies MUST review each Ongoing Authorization Report to understand how changes to the cloud service offering may impact the risk tolerance documented in the agency Authorization to Operate for the federal information system that includes the cloud service offering in its boundary.


Note: This agency review supports agency responsibilities under 44 USC ยง 35, OMB Circular A-130, FIPS-200, and OMB Memorandum M-24-15.


Terms: Cloud Service Offering

Notify FedRAMP of Concerns

AGU-USE-NFC

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

This FRR includes a notification requirement!

  • Notify FedRAMP by email using info@fedramp.gov.

Agencies MUST notify FedRAMP by sending an email to info@fedramp.gov if information presented in an Ongoing Authorization Report, Quarterly Review, or other ongoing authorization data causes significant concerns that may lead the agency to stop operation of the cloud service offering.


Note: Agencies are expected to notify FedRAMP under OMB Memorandum M-24-15 section IV (a).


Terms: Cloud Service Offering, Quarterly Review

Assign Security Category Resources

AGU-USE-ASC

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies SHOULD consider the Security Category noted in the agency Authorization to Operate and assign appropriate information security resources for reviewing Ongoing Authorization Reports, attending Quarterly Reviews, and reviewing other ongoing authorization data.


Terms: Quarterly Review, Security Category

Designate Senior Official

AGU-USE-DSO

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies SHOULD designate a senior information security official to review Ongoing Authorization Reports and represent the agency at Quarterly Reviews for cloud service offerings included in agency information systems.


Terms: Cloud Service Offering, Quarterly Review

Notify Provider of Concerns

AGU-USE-NPC

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

This FRR includes a notification requirement!

  • Notify Provider by email using Provider security contact.

Agencies SHOULD formally notify the Provider if information presented in an Ongoing Authorization Report, Quarterly Review, or other ongoing authorization data causes significant concerns that may lead the agency to remove the cloud service offering from operation.


Terms: Cloud Service Offering, Quarterly Review

Review Inherited Services

AGU-USE-INH

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies SHOULD review the certification packages and continuous monitoring information for third-party independent information resources, such as other cloud services, that are used by a FedRAMP Certified cloud service when available.


Terms: Certification Package, FedRAMP Certified, Information Resource

Agency Sponsored Certifications

These rules apply when an agency sponsors a FedRAMP Rev5 Certification after completing an agency authorization.

Most Recent Consolidated Rules

AGU-SPN-MRC

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies MUST follow the most recent FedRAMP Consolidated Rules when initiating agency-sponsored FedRAMP Certification of in-scope cloud services.

Follow Ongoing Authorization Rules

AGU-SPN-OAR

Changelog:

  • 2026-05-04: Initial reset for the Consolidated Rules for 2026 Public Preview.

Agencies MUST follow the ongoing agency authorization rules after FedRAMP issues a FedRAMP Certification they sponsored.

Comments