<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>FedRAMP news from Infosec Standards</title>
    <link>https://infosecstandards.org/standards/fedramp</link>
    <description>News about FedRAMP, including major updates to our page on it.</description>
    <language>en-us</language>
    <atom:link href="https://infosecstandards.org/standards/fedramp/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>FedRAMP puts 10 cloud offerings in remediation after Security Inbox test</title>
      <link>https://infosecstandards.org/news/fedramp-inbox-remediation</link>
      <guid>https://infosecstandards.org/news/fedramp-inbox-remediation</guid>
      <pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate>
      <description>After the July 1, 2026 grace period ended, FedRAMP's quarterly Security Inbox test left 10 certified cloud offerings in remediation pending possible revocation.</description>
    </item>
    <item>
      <title>FedRAMP opens temporary Rev5 Ready Conversion and Lost Sponsor pipelines</title>
      <link>https://infosecstandards.org/news/fedramp-rev5-pipelines</link>
      <guid>https://infosecstandards.org/news/fedramp-rev5-pipelines</guid>
      <pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate>
      <description>On August 10, 2026, FedRAMP opened limited sponsorless Rev5 Class B and Class C Program Certification paths for eligible Ready Conversion and Lost Sponsor providers.</description>
    </item>
    <item>
      <title>FedRAMP 20x Class A pipeline opens under Consolidated Rules</title>
      <link>https://infosecstandards.org/news/fedramp-20x-rules</link>
      <guid>https://infosecstandards.org/news/fedramp-20x-rules</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
      <description>FedRAMP opened the 20x Class A submission pipeline on August 3, 2026. Class B and C follow August 31, and Rev5 is on a fixed sunset path.</description>
    </item>
    <item>
      <title>FedRAMP makes VDR and VER rules mandatory by December 7, 2026</title>
      <link>https://infosecstandards.org/news/fedramp-vdr-mandate</link>
      <guid>https://infosecstandards.org/news/fedramp-vdr-mandate</guid>
      <pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate>
      <description>To align with CISA BOD 26-04, FedRAMP requires all certified cloud services to adopt Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules by December 7, 2026.</description>
    </item>
  </channel>
</rss>
