{
	"version": "https://jsonfeed.org/version/1.1",
	"title": "FedRAMP news from Infosec Standards",
	"description": "News about FedRAMP, including major updates to our page on it.",
	"home_page_url": "https://infosecstandards.org/standards/fedramp",
	"feed_url": "https://infosecstandards.org/standards/fedramp/feed.json",
	"authors": [
		{
			"name": "Infosec Standards",
			"url": "https://infosecstandards.org"
		}
	],
	"language": "en-US",
	"items": [
		{
			"id": "https://infosecstandards.org/news/fedramp-inbox-remediation",
			"url": "https://infosecstandards.org/news/fedramp-inbox-remediation",
			"title": "FedRAMP puts 10 cloud offerings in remediation after Security Inbox test",
			"summary": "After the July 1, 2026 grace period ended, FedRAMP's quarterly Security Inbox test left 10 certified cloud offerings in remediation pending possible revocation.",
			"content_text": "After the July 1, 2026 grace period ended, FedRAMP's quarterly Security Inbox test left 10 certified cloud offerings in remediation pending possible revocation.",
			"date_published": "2026-09-09T00:00:00.000Z",
			"tags": [
				"enforcement",
				"program-changes",
				"email-all"
			]
		},
		{
			"id": "https://infosecstandards.org/news/fedramp-rev5-pipelines",
			"url": "https://infosecstandards.org/news/fedramp-rev5-pipelines",
			"title": "FedRAMP opens temporary Rev5 Ready Conversion and Lost Sponsor pipelines",
			"summary": "On August 10, 2026, FedRAMP opened limited sponsorless Rev5 Class B and Class C Program Certification paths for eligible Ready Conversion and Lost Sponsor providers.",
			"content_text": "On August 10, 2026, FedRAMP opened limited sponsorless Rev5 Class B and Class C Program Certification paths for eligible Ready Conversion and Lost Sponsor providers.",
			"date_published": "2026-09-09T00:00:00.000Z",
			"tags": [
				"program-changes",
				"email-standard"
			]
		},
		{
			"id": "https://infosecstandards.org/news/fedramp-20x-rules",
			"url": "https://infosecstandards.org/news/fedramp-20x-rules",
			"title": "FedRAMP 20x Class A pipeline opens under Consolidated Rules",
			"summary": "FedRAMP opened the 20x Class A submission pipeline on August 3, 2026. Class B and C follow August 31, and Rev5 is on a fixed sunset path.",
			"content_text": "FedRAMP opened the 20x Class A submission pipeline on August 3, 2026. Class B and C follow August 31, and Rev5 is on a fixed sunset path.",
			"date_published": "2026-08-04T00:00:00.000Z",
			"tags": [
				"program-changes",
				"version-updates",
				"email-standard"
			]
		},
		{
			"id": "https://infosecstandards.org/news/fedramp-vdr-mandate",
			"url": "https://infosecstandards.org/news/fedramp-vdr-mandate",
			"title": "FedRAMP makes VDR and VER rules mandatory by December 7, 2026",
			"summary": "To align with CISA BOD 26-04, FedRAMP requires all certified cloud services to adopt Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules by December 7, 2026.",
			"content_text": "To align with CISA BOD 26-04, FedRAMP requires all certified cloud services to adopt Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules by December 7, 2026.",
			"date_published": "2026-08-04T00:00:00.000Z",
			"tags": [
				"program-changes",
				"email-standard"
			]
		}
	]
}
