The FedRAMP Consolidated Rules, made usable
Generated from FedRAMP's own datafile, with the parts it makes you derive — applicability, deadlines, and what a machine can actually verify — worked out for you.
Deadlines
Every obtain, maintain and grace date in the rules, per certification type, counted against today.
Which rules apply to me
Pick your certification type, path and class and get the actual requirement list.
Key Security Indicators
All 46 KSIs with their NIST control mappings and their automated-check status.
FedRAMP rules
All 180 FRR requirements across every ruleset, with force and corrective actions.
Glossary
All 75 FedRAMP definitions. The terms have precise meanings; guessing is costly.
20x vs Rev 5
What actually differs between the two paths, and which one you should be on.
What a trust center is
The page agencies check instead of emailing you for your authorization package.
What the Consolidated Rules are
FedRAMP replaced a scattered set of PDFs, baselines and program guidance with one machine-readable rulebook: 180 requirements grouped into rulesets, 46 Key Security Indicators, and 75 definitions that fix what the requirements mean. Everything on these pages is generated from that datafile, so it says what the rules say rather than what a blog post remembers them saying.
Two things it does not tell you directly, and that these pages compute for you: which requirements apply to your certification type, path and class — applicability is expressed in three separate places and has to be resolved — and which of them are shaped so that a machine can check them at all, rather than needing a human to assemble evidence. Zenibit has automated checks implemented for 3 of them so far; the rest are marked as needing evidence.
Stop assembling this by hand.
Zenibit tracks these requirements against your live infrastructure and publishes a trust center agencies can verify themselves. Get in touch.