This website uses cookies

Read our Privacy policy and Terms of use for more information.

FedRAMP's Machine-Readable Deadline Is 9 Days Out

From 30 September 2026 (9 days), new FedRAMP Rev5 authorization packages must be submitted in an approved machine-readable format — OSCAL as the primary standard — under RFC-0024 / Notice NTC-0009, folded into the Consolidated Rules for 2026 (CR26).

Why It Matters

The change is narrow but real: new Rev5 packages must arrive in an approved machine-readable format (OSCAL) from 30 September. A grace period runs to 30 September 2027, and the more demanding comprehensive package is a phased Class D (High) requirement due by November 2027 — not a universal 30 September obligation. FedRAMP has said missing the applicable timelines results in public notification, and non-compliant services may eventually lose their authorization.

For compliance and cloud teams this is a tooling-and-evidence deadline, not a controls change: the underlying security requirements are unchanged, but how you package and submit them is now machine-first. CR26 becomes mandatory for all stakeholders on 1 January 2027 and governs FedRAMP through 31 December 2028.

Action Items

  1. Confirm format now — ensure any new or forthcoming Rev5 authorization package is prepared in an approved OSCAL machine-readable format before 30 September.

  2. Schedule OSCAL conversion for existing authorizations — treat 30 September 2027 as the drop-dead date; Class D (High) services must plan for the comprehensive package by November 2027.

  3. Plan for CR26 — align to the Consolidated Rules for 2026 ahead of mandatory adoption on 1 January 2027.

📅 On the Calendar This Week

  • 25 Sep (4 days) — NIST draft SP 800-239 (AI data-center security) public comment closes.

  • 30 Sep (9 days) — FedRAMP machine-readable/OSCAL required for new Rev5 packages; FedRAMP Day.

  • End Sep — CISA discontinues its weekly Vulnerability Summary Bulletin (shift to KEV/advisories).

  • 1 Oct (10 days) — Austria's NISG 2026 enters full force.

  • 3 Oct (12 days) — Poland's NIS2 registration deadline for essential and important entities.

Get the full analysis. Pro subscribers receive the complete deep dive, all 5 action items, source documents, and jurisdiction-specific compliance checklists.

logo

Subscribe to Pro to read the rest.

Become a paying subscriber of Pro to get access to this post and other subscriber-only content.

Upgrade

A subscription gets you:

  • Deep dives of each updated regulation
  • Source verification documents
  • Extended jurisdiction-specific analysis
  • Compliance deadline tracker
  • Regulation crosswalk