FedRAMP puts 10 cloud offerings in remediation after Security Inbox test
After the July 1, 2026 grace period ended, FedRAMP's quarterly Security Inbox test left 10 certified cloud offerings in remediation pending possible revocation.
After the July 1, 2026 grace period ended, FedRAMP's quarterly Security Inbox test left 10 certified cloud offerings in remediation pending possible revocation.
On August 10, 2026, FedRAMP opened limited sponsorless Rev5 Class B and Class C Program Certification paths for eligible Ready Conversion and Lost Sponsor providers.
FedRAMP opened the 20x Class A submission pipeline on August 3, 2026. Class B and C follow August 31, and Rev5 is on a fixed sunset path.
To align with CISA BOD 26-04, FedRAMP requires all certified cloud services to adopt Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules by December 7, 2026.