FedRAMP Rev5 Security Decision Record (human-readable and JSON) — obtain / maintain deadlines under the Consolidated Rules for 2026
Jan 2027 / Aug 2027observed
| Value kind | observed — Reported measurements, counts, and specifications keep the precision and scope stated by their source; an exact specification is not treated as a range. |
|---|---|
| Scope | Rev5 Class B–D providers. Optional adoption opened 2026-07-04; obtain 2027-01-01; maintain 2027-08-01. |
| Caveat | The grace period ends at the first FedRAMP independent assessment started after 2027-08-01. RFC-0024's proposed blanket September-2026 OSCAL requirement for existing Rev5 authorizations was a proposal and is not the operative rule. |
| As of | 2026-06 |
| Source | FedRAMP Consolidated Rules for 2026, Security Decision Record (SDR-CSO-FRR), launched 2026-06-24 |
| Review | checking…review by 2027-01-01 · standard cadence |
| Recorded changes | last 2026-09-04 · 3 revisions tracked |
| Claim id | rfc-0024-deadline-machine-readable-oscal |
Where the guide uses it
← Full numbers register — every date-stamped figure in the guide, with revision history.