Independent Verification and Validation¶
This ruleset explains the expectations for independent verification and validation assessments.
Subsets
- General Provider Responsibilities
- General Independent Assessor Responsibilities
- 20x-Specific Provider Responsibilities
Effective Date(s) & Overall Applicability for 20x
- Required (Consolidated Rules for 2026)
- Optional Adoption: 2026-07-04
- Obtain: 2026-07-04
- Maintain: 2027-01-01
- Grace Ends: On the first FedRAMP independent assessment completed after 2027-01-01
General Provider Responsibilities¶
These rules apply to cloud service providers obtaining and maintaining any FedRAMP Certification.
Path: ProgramAgency
Class: Class B
Audience: Providers
FedRAMP Independent Assessments¶
IVV-CSO-FIA
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Providers with Class B Certifications MUST persistently complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized independent assessment service OR FedRAMP at least once per year; this is a FedRAMP independent assessment.
Timeframe: 1 year
Notes:
- The first such completed assessment is typically called an "initial assessment" while following assessments are called "annual assessments."
- The specific requirements for independent verification and validation assessments are documented by the FedRAMP Certification Class and Type.
- The option for assessment by FedRAMP directly is limited to cloud services that are explicitly prioritized by FedRAMP, in consultation with the FedRAMP Board and the federal Chief Information Officers Council; this is _extremely rare._
- FedRAMP Recognized independent assessment services are listed on the FedRAMP Marketplace.
Terms: Certification Class, FedRAMP Independent Assessment, FedRAMP Recognized, Persistently, Validation, Verification
Supply Evidence of Implementation¶
IVV-CSO-SEI
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Providers MUST supply evidence to all necessary assessors of the implementation of the measures that have been documented to meet FedRAMP Practices; this evidence is the result of verification.
Note: For example, if the documentation says that firewall rules are used to block traffic then the cloud service provider would verify that firewall rules are in place to block traffic and supply that evidence to assessors (preferably by allowing them to see how firewall configurations are deployed from a source of truth).
Terms: All Necessary Assessors, FedRAMP Practices, Verification
Supply Evidence of Effectiveness¶
IVV-CSO-SEE
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Providers MUST supply evidence to all necessary assessors of the effectiveness of the measures that have been implemented to meet FedRAMP Practices; this evidence is the result of validation.
Note: For example, after verifying that firewalls are configured to block traffic following IVV-CSO-SEI (Supply Evidence of Implementation), the provider would validate that traffic is actually being blocked and supply evidence of that validation to assessors (such as by allowing them to see metrics on the traffic that is blocked vs not).
Terms: All Necessary Assessors, FedRAMP Practices, Validation
Inclusion in Certification Package¶
IVV-CSO-ICP
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Providers MUST supply the results of FedRAMP independent assessments in their FedRAMP Certification Package without inappropriate modification.
Notes:
- Inappropriate modification in this context means changing the underlying intent/etc. of the content provided by the independent assessment service - the content itself may be modified for presentation, formatting, etc. as needed.
- This rule is related to IVV-IAS-VIP (Verify Inclusion in Certification Package).
Terms: Certification Package, FedRAMP Independent Assessment, Verification
Document Use of Representative Samples¶
IVV-CSO-DUS
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Providers MUST document and explain the use of representative samples during verification and validation when using representative samples as allowed by IVV-CSO-USR (Use Representative Samples).
Terms: Validation, Verification
Supply Technical Explanations¶
IVV-CSO-STE
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Providers SHOULD supply all necessary assessors with technical explanations, demonstrations, and other relevant supporting information about the technical capabilities they employ to address FedRAMP rules; this SHOULD be supplied as necessary to ensure the assessor can effectively complete verification and validation.
Use Representative Samples¶
IVV-CSO-USR
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Providers MAY use representative samples as appropriate during verification and validation.
Note: Many modern cloud services using effective automation do not need to use representative sampling and are capable of persistently verifying and validating the majority of their security measures automatically.
Terms: Persistently, Validation, Verification
Receiving Assessor Advice¶
IVV-CSO-RAA
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Providers MAY ask for and accept advice from their assessor during assessment regarding techniques and procedures that will improve their security posture or the effectiveness, clarity, and accuracy of their verification, validation and reporting procedures, UNLESS doing so is likely to compromise the objectivity and integrity of the assessment.
Terms: Likely, Validation, Verification
General Independent Assessor Responsibilities¶
These rules apply to independent assessment services supporting all FedRAMP Certification types.
Path: ProgramAgency
Class: Class B
Audience: Assessors
Verify Implementation¶
IVV-IAS-VIM
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Assessors MUST verify that the measures implemented by the cloud service offering matches the measures they documented to meet FedRAMP Practices.
Note: This requires reviewing the actual measures themselves at a technical level, such as reviewing underlying code as appropriate; don't simply review documentation or screenshots.
Terms: Cloud Service Offering, FedRAMP Practices, Verification
Validate Effectiveness¶
IVV-IAS-VEF
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Assessors MUST validate the effectiveness of the implemented measures to ensure they have the intended outcome for meeting FedRAMP Practices.
Note: This requires reviewing the actual measures themselves at a technical level, such as reviewing underlying code as appropriate; don't simply review documentation or screenshots.
Terms: FedRAMP Practices, Validation
Assessment Summary¶
IVV-IAS-SUM
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Assessors MUST supply the provider with a high-level summary of their assessment process and findings for each FedRAMP Practice; this summary will be included by the provider in the FedRAMP Security Decision Record for the cloud service offering.
Note: FedRAMP does not require a separate Security Assessment Plan or Security Assessment Report for FedRAMP 20x or FedRAMP Rev5 Certifications; this information is expected to be included in the Security Decision Record by the cloud service provider.
Terms: Cloud Service Offering, FedRAMP Practices, Security Decision Record (SDR)
Overall Summary of Assessment¶
IVV-IAS-OSA
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Assessors MUST supply the provider with an overall summary of the verification and validation assessment results, including any resulting failures or areas of dispute; this summary will be included by the provider in the FedRAMP Certification Package Overview for the cloud service offering.
Note: FedRAMP does not supply a template for this summary and encourages independent assessment services to optimize for the best customer experience in the creation of these materials.
Terms: Certification Package, Cloud Service Offering, Validation, Verification
Verify Inclusion in Certification Package¶
IVV-IAS-VIP
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Assessors MUST verify that information supplied during a FedRAMP independent assessment is included in the FedRAMP Certification Package by the provider without inappropriate modification.
Note: This rule is related to IVV-CSO-ICP (Inclusion in Certification Package).
Terms: Certification Package, FedRAMP Independent Assessment, Verification
Engage Provider Experts¶
IVV-IAS-EPX
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Assessors SHOULD engage provider experts in discussion to understand the decisions made by the provider and inform expert qualitative assessment, and SHOULD perform independent research to test such information as part of the expert qualitative assessment process.
Sharing Advice¶
IVV-IAS-SHA
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Assessors MAY share advice with providers they are assessing about techniques and procedures that will improve the provider's security posture or the effectiveness, clarity, and accuracy of their verification, validation and reporting procedures, UNLESS doing so is likely to compromise the objectivity and integrity of the assessment.
Terms: Likely, Validation, Verification
20x-Specific Provider Responsibilities¶
These rules apply to providers for FedRAMP 20x Certifications.
Path: Program
Class: Class B
Audience: Providers
Annual Independent Assessments for 20x¶
IVV-CSX-AIA
Changelog:
- 2026-06-24: Official launch of the FedRAMP Consolidated Rules for 2026.
Providers with 20x Class B Certifications MUST include all Key Security Indicators in a FedRAMP independent assessment at least once per year.
Timeframe: 1 year
Terms: FedRAMP Independent Assessment, Persistently, Validation, Verification