Skip to main content

Policy and Guidance Updates

FedRAMP is fostering transparency for its policy and guidance development efforts. This page reflects the current status of policy and guidance that has been released recently or is expected to be released soon. Public feedback is welcome anytime at info@fedramp.gov.

Requests for Comment

For a list of active Requests for Comment (RFCs), please review the RFCs page.

Recently Completed

Finalizing

The following documents are being prepared for final publication.

FedRAMP Metrics Propose a set of metrics that will measure the FedRAMP authorization experience and measure the program's security impact.
  • 2024-07-30 Draft Published
  • 2024-09-05 Public Comment Closed
  • Revising document
  • Government consensus
  • Board approval
  • Publish final guidance
  • End of FY25 Q3
    FedRAMP Penetration Test Guidance Provide guidelines for conducting a penetration test to identify weaknesses in a FedRAMP cloud service.
  • 2024-03-04 Draft Published
  • 2024-04-24 Public Comment Closed
  • Revising document
  • Government consensus
  • Board approval
  • Publish final guidance
  • End of FY25 Q3

    In Development

    The following documents are under active development and have not yet been published for public comment.

    Guidance or Policy Goal
    Authorization boundary guidance This update to the boundary guidance is based on stakeholder feedback, common issues identified during review, and to revise requirements related to leveraged cloud and corporate services. Additionally, all JAB mentions and specific JAB requirements that conflict with the current policy memo are being removed.
    Program authorization approach Work in progress