zenibit

FedRAMP reference

FedRAMP deadlines

Optional adoption, required to obtain, required to maintain, and when the grace period runs out — for every ruleset, both certification types.

A FedRAMP date is really four dates, and they are not the same for 20x and Rev 5. The one people quote is usually obtain — the date the rule starts applying to a new certification. Maintain is when it starts applying to one you already hold, and the grace column is how long an existing authorization has before non-compliance bites.

Dates in the past are red, dates inside 90 days are amber. Hover any date for how far away it is.

RulesetCertificationOptional adoption Required to obtainRequired to maintainGrace ends
Collaborative Continuous Monitoring
CCM
FedRAMP 20x2026-07-042026-07-042027-01-012027-01-01
or next assessment
Collaborative Continuous Monitoring
CCM
FedRAMP Rev 52026-07-042027-01-012027-04-022027-10-01
fixed
Certification Data Sharing
CDS
FedRAMP 20x2026-07-042026-07-042027-01-012027-01-01
or next assessment
Certification Data Sharing
CDS
FedRAMP Rev 52026-07-042027-01-012027-08-012028-02-01
fixed
Cryptographic Module Use
CMU
FedRAMP 20x2026-07-042026-07-042027-01-012027-01-01
or next assessment
Cryptographic Module Use
CMU
FedRAMP Rev 52026-07-042027-01-012027-01-012027-06-01
fixed
Certification Package Overview
CPO
FedRAMP 20x2026-07-042026-07-042027-01-012027-01-01
or next assessment
Certification Package Overview
CPO
FedRAMP Rev 52026-07-042027-01-012027-07-012027-01-01
or next assessment
FedRAMP Certification
FRC
FedRAMP 20x2026-07-042026-07-042027-01-012027-01-01
or next assessment
FedRAMP Certification
FRC
FedRAMP Rev 52026-07-042027-01-012027-01-012027-01-01
or next assessment
Incident Evaluation and Communication
IEC
FedRAMP 20x2026-07-042026-07-042027-01-012027-01-01
or next assessment
Incident Evaluation and Communication
IEC
FedRAMP Rev 52026-07-042027-01-012027-01-012027-06-01
fixed
Independent Verification and Validation
IVV
FedRAMP 20x2026-07-042026-07-042027-01-012027-01-01
or next assessment
Independent Verification and Validation
IVV
FedRAMP Rev 52026-07-042027-01-012027-01-012027-01-01
or next assessment
Minimum Assessment Scope
MAS
FedRAMP 20x2026-07-042026-07-042027-01-012027-01-01
or next assessment
Minimum Assessment Scope
MAS
FedRAMP Rev 52026-07-042027-01-012027-01-012027-01-01
or next assessment
Significant Change Notification
SCN
FedRAMP 20x2026-07-042026-07-042027-01-012027-01-01
or next assessment
Significant Change Notification
SCN
FedRAMP Rev 52026-07-042027-01-012027-01-012027-06-01
fixed
Security Decision Record
SDR
FedRAMP 20x2026-07-042026-07-042027-01-012027-01-01
or next assessment
Security Decision Record
SDR
FedRAMP Rev 52026-07-042027-01-012027-08-012027-08-01
or next assessment

How to read this

Optional adoption is the earliest you may be assessed against the rule. Required to obtain applies to certifications granted on or after that date. Required to maintain applies to certifications you already hold — this is the column that surprises providers who read the rules once, at authorization. Grace ends is the outside date; where a ruleset says "or next assessment", the earlier of the two wins, so a provider assessed in the spring loses the rest of the grace period.

Stop assembling this by hand.

Zenibit tracks these requirements against your live infrastructure and publishes a trust center agencies can verify themselves. Get in touch.