FR
AGUgovplaceholder

Agency Use of FedRAMP Certified Cloud Services

The Agency Use rules summarize the many demands made on agencies by the FedRAMP Authorization Act and OMB Memorandum M-24-15 in a simple, clear, easy-to-follow set of FedRAMP-style rules. These rules align agency policies, authorization letters, machine-readable tools, secure configuration review, continuous monitoring, and communication with FedRAMP so certifications can be reused consistently across government.

Effective dates

Obtain by
2026-07-04
Maintain by
2026-07-04
Optional adoption
2026-07-04
Grace period
2026-07-04

General Agency ResponsibilitiesAGC

9 rules

These rules apply to agencies based on the FedRAMP Authorization Act, OMB M-24-15, and related FedRAMP policies.

Types20xRev5
PathsProgramAgency
ClassesABCD
AffectsAgencies
AGU-AGC-AIP

Agency Internal Policies

MUST

Agencies MUST maintain agency-wide policy that aligns with the requirements in OMB Memorandum M-24-15.

TermsAgency
AGU-AGC-GRC

Governance, Risk, and Compliance Tools

MUST

Agencies MUST ensure that internal governance, risk, compliance, and inventory tools can produce and ingest machine-readable artifacts using formats identified by FedRAMP, including at least:

  • Open Security Controls Assessment Language (OSCAL)
  • JSON
AGU-AGC-NAA

Notify FedRAMP After Authorization

MUST

Agencies MUST notify FedRAMP upon authorizing the use of a cloud service within the scope of FedRAMP, supplying at least the following information:

  • A copy of the agency's Authorization to Operate letter for the information system leveraging the cloud service, following agency policy and templates.
  • All other supplemental information requested in the Submit an ATO Letter form by FedRAMP.
TermsAgency
AGU-AGC-NAR

No Additional Security Requirements

MUST NOT

Agencies MUST NOT require additional information or materials from FedRAMP Certified cloud service offerings beyond those required by FedRAMP UNLESS the head of the agency or an authorized delegate determines there is a demonstrable need and notifies FedRAMP; this does not apply to seeking clarification or asking general questions about FedRAMP Certification Data.

This is related to the Presumption of Adequacy for a FedRAMP Certification and notification is mandated by OMB Memorandum M-24-15 section IV (a).
AGU-AGC-SIN

Shared FedRAMP Inbox

SHOULD

Agencies SHOULD establish and maintain a dedicated shared FedRAMP agency inbox to serve as the official point of contact for communications between FedRAMP and the agency.

A shared FedRAMP agency inbox may follow an agency-specific format such as agency-fedramp@agency.gov.
TermsAgency
AGU-AGC-TPP

No Certification Type or Path Preferences

MUST NOT

Agencies MUST NOT require cloud service offerings to obtain or maintain a specific FedRAMP Certification Type or FedRAMP Certification Path, UNLESS the head of the agency or an authorized delegate determines there is a demonstrable need and notifies FedRAMP.

This is related to the Presumption of Adequacy for a FedRAMP Certification and notification is mandated by OMB Memorandum M-24-15 section IV (a).
AGU-AGC-WKG

FedRAMP Working Groups

SHOULD

Agencies SHOULD participate in FedRAMP working groups, communities of practice, and stakeholder engagements to supply feedback and align practices across government.

TermsAgency

Use of FedRAMP CertificationsUSE

10 rules

These rules apply when agencies use FedRAMP Certifications to make agency authorization decisions.

Types20xRev5
PathsProgramAgency
ClassesABCD
AffectsAgencies
AGU-USE-CLA

Using FedRAMP Class A Certifications

SHOULD NOT

Agencies SHOULD NOT authorize the use of a FedRAMP Class A Certified cloud service offering for more than 12 months UNLESS the cloud service offering is actively seeking a FedRAMP Class B, C, or D Certification.

AGU-USE-NFC

Notify FedRAMP of Monitoring Concerns

MUST

Agencies MUST notify FedRAMP if information presented in an Ongoing Certification Report, Quarterly Review, or other FedRAMP Certification Data causes significant concerns for the authorizing official that would likely result in rescission of their Authorization to Operate.

Agencies are expected to notify FedRAMP under OMB Memorandum M-24-15 section IV (a).
AGU-USE-NPC

Notify Provider of Concerns

SHOULD

Agencies SHOULD formally notify the cloud service provider if information presented in an Ongoing Certification Report, Quarterly Review, or other FedRAMP Certification Data causes significant concerns for the authorizing official that would likely result in rescission of their Authorization to Operate.

AGU-USE-RCF

Resolve Certification Package Conflicts

MUST

Agencies MUST collaborate with FedRAMP when discrepancies or conflicts arise between agency-specific security determinations and the FedRAMP Certification Package.

AGU-USE-ROR

Review Ongoing Certification Reports

SHOULD

Agencies SHOULD review each Ongoing Certification Report to understand how changes to the cloud service offering may impact the risk tolerance documented in the agency Authorization to Operate for the federal information system that includes the cloud service offering in its boundary.

This agency review supports agency responsibilities under 44 USC § 35, OMB Circular A-130, FIPS-200, and OMB Memorandum M-24-15.
AGU-USE-RSG

Review Secure Configuration Guides

MUST

Agencies MUST review the Secure Configuration Guides supplied by Providers and configure relevant security settings.

Agency Sponsored CertificationsSPN

1 rules

These rules apply when an agency sponsors a FedRAMP Rev5 Certification after completing an agency authorization.

TypesRev5
PathsAgency
ClassesBCD
AffectsAgencies
AGU-SPN-MRC

Most Recent Consolidated Rules

MUST

Agencies MUST follow the most recent FedRAMP Consolidated Rules when initiating agency-sponsored FedRAMP Certification.

TermsAgency