FedRAMP puts 10 cloud offerings in remediation after Security Inbox test
On July 22, 2026, FedRAMP published Public Notice NTC-0016 reporting the outcome of its FY26 Q4 Security Inbox test. Ten FedRAMP Certified cloud service offerings failed to respond and were placed in remediation, pending possible revocation of FedRAMP Certification.
The Addressing FedRAMP Communication rules (the former Security Inbox requirements) have applied to all FedRAMP Certified offerings since January 5, 2026. A grace period for adoption ended on July 1, 2026. FedRAMP said the July test was the first quarterly check after that grace period, so it carried immediate consequences for providers that do not receive and address FedRAMP communications.
What the notice says
Of 662 offerings tested, 652 (99%) responded. The 10 that did not are named in NTC-0016, spanning Class B and Class C impact levels. FedRAMP said it emailed security and sales contacts repeatedly, searched for alternate contacts, and asked agency customers for help, still without a response from those providers.
Under the notice:
- Named providers had until 3:00 p.m. EDT on August 4, 2026 to submit a Corrective Action Plan covering the communication rules
- Plans had to include an implementation deadline of August 31, 2026
- Missing the August 4 contact deadline would lead to revocation on August 5, 2026
As of September 9, 2026, FedRAMP had not published a later notice naming which of those offerings submitted a plan, returned to good standing, or lost certification. Check the FedRAMP Marketplace for current status.
FedRAMP also said some other providers responded late. Those offerings were not named publicly if they submitted a corrective plan by the same deadline, but agencies were notified of the deficiency.
This notice does not rewrite the Consolidated Rules for 2026 certification baselines. It shows FedRAMP treating reachable security contacts as a certification-maintaining duty, not optional housekeeping.
What to do now
- If you hold or buy FedRAMP Certification, verify that marketplace security and sales contacts can receive mail from external FedRAMP domains and that bounce or ticket routing is monitored.
- Confirm who owns the Addressing FedRAMP Communication rules inside your continuous monitoring program, including after-hours coverage for emergency directives.
- Agencies and integrators should check whether any of their vendors appear on the NTC-0016 remediation list and ask for current certification status.
- Read NTC-0016 and the related NTC-0015 test announcement, then watch the FedRAMP Marketplace and later notices for revocation or return-to-good-standing updates.
- Follow FedRAMP on this site for further certification and continuous monitoring enforcement signals.