FedRAMP deadlines
Optional adoption, required to obtain, required to maintain, and when the grace period runs out — for every ruleset, both certification types.
A FedRAMP date is really four dates, and they are not the same for 20x and Rev 5. The one people quote is usually obtain — the date the rule starts applying to a new certification. Maintain is when it starts applying to one you already hold, and the grace column is how long an existing authorization has before non-compliance bites.
Dates in the past are red, dates inside 90 days are amber. Hover any date for how far away it is.
| Ruleset | Certification | Optional adoption | Required to obtain | Required to maintain | Grace ends |
|---|---|---|---|---|---|
| Collaborative Continuous Monitoring CCM | FedRAMP 20x | 2026-07-04 | 2026-07-04 | 2027-01-01 | 2027-01-01 or next assessment |
| Collaborative Continuous Monitoring CCM | FedRAMP Rev 5 | 2026-07-04 | 2027-01-01 | 2027-04-02 | 2027-10-01 fixed |
| Certification Data Sharing CDS | FedRAMP 20x | 2026-07-04 | 2026-07-04 | 2027-01-01 | 2027-01-01 or next assessment |
| Certification Data Sharing CDS | FedRAMP Rev 5 | 2026-07-04 | 2027-01-01 | 2027-08-01 | 2028-02-01 fixed |
| Cryptographic Module Use CMU | FedRAMP 20x | 2026-07-04 | 2026-07-04 | 2027-01-01 | 2027-01-01 or next assessment |
| Cryptographic Module Use CMU | FedRAMP Rev 5 | 2026-07-04 | 2027-01-01 | 2027-01-01 | 2027-06-01 fixed |
| Certification Package Overview CPO | FedRAMP 20x | 2026-07-04 | 2026-07-04 | 2027-01-01 | 2027-01-01 or next assessment |
| Certification Package Overview CPO | FedRAMP Rev 5 | 2026-07-04 | 2027-01-01 | 2027-07-01 | 2027-01-01 or next assessment |
| FedRAMP Certification FRC | FedRAMP 20x | 2026-07-04 | 2026-07-04 | 2027-01-01 | 2027-01-01 or next assessment |
| FedRAMP Certification FRC | FedRAMP Rev 5 | 2026-07-04 | 2027-01-01 | 2027-01-01 | 2027-01-01 or next assessment |
| Incident Evaluation and Communication IEC | FedRAMP 20x | 2026-07-04 | 2026-07-04 | 2027-01-01 | 2027-01-01 or next assessment |
| Incident Evaluation and Communication IEC | FedRAMP Rev 5 | 2026-07-04 | 2027-01-01 | 2027-01-01 | 2027-06-01 fixed |
| Independent Verification and Validation IVV | FedRAMP 20x | 2026-07-04 | 2026-07-04 | 2027-01-01 | 2027-01-01 or next assessment |
| Independent Verification and Validation IVV | FedRAMP Rev 5 | 2026-07-04 | 2027-01-01 | 2027-01-01 | 2027-01-01 or next assessment |
| Minimum Assessment Scope MAS | FedRAMP 20x | 2026-07-04 | 2026-07-04 | 2027-01-01 | 2027-01-01 or next assessment |
| Minimum Assessment Scope MAS | FedRAMP Rev 5 | 2026-07-04 | 2027-01-01 | 2027-01-01 | 2027-01-01 or next assessment |
| Significant Change Notification SCN | FedRAMP 20x | 2026-07-04 | 2026-07-04 | 2027-01-01 | 2027-01-01 or next assessment |
| Significant Change Notification SCN | FedRAMP Rev 5 | 2026-07-04 | 2027-01-01 | 2027-01-01 | 2027-06-01 fixed |
| Security Decision Record SDR | FedRAMP 20x | 2026-07-04 | 2026-07-04 | 2027-01-01 | 2027-01-01 or next assessment |
| Security Decision Record SDR | FedRAMP Rev 5 | 2026-07-04 | 2027-01-01 | 2027-08-01 | 2027-08-01 or next assessment |
How to read this
Optional adoption is the earliest you may be assessed against the rule. Required to obtain applies to certifications granted on or after that date. Required to maintain applies to certifications you already hold — this is the column that surprises providers who read the rules once, at authorization. Grace ends is the outside date; where a ruleset says "or next assessment", the earlier of the two wins, so a provider assessed in the spring loses the rest of the grace period.
Stop assembling this by hand.
Zenibit tracks these requirements against your live infrastructure and publishes a trust center agencies can verify themselves. Get in touch.