Skip to content

FedRAMP mapping

  • Draft
  • v0.3.0
  • Compliance, legal, privacy, and assurance teams
  • Reviewed 2026-09-28

Informative mapping only

This page traces the framework's architecture capabilities and evidence to an external source. It is not legal advice, and it is not an audit, a certification, an authorization or a conformity assessment. Mapping a capability does not show that a control is implemented or effective.

Confirm applicability, edition and dates against the authoritative source, and obtain review from qualified legal, compliance, security, privacy and audit professionals before relying on it. Standards text is copyrighted: this page gives identifiers and short titles only, so obtain the licensed standard for the full requirements.

FedRAMP authorizes cloud services that United States federal agencies use. An AI capability inside a cloud service sits inside that service's authorization boundary. Its models, endpoints, vector stores, tools and external AI services need the same evidence as the rest of the system. This page shows where the framework supplies that evidence.

FedRAMP is changing quickly. The facts below were checked on 2026-09-28. Confirm them on fedramp.gov before you plan an authorization.

Current FedRAMP model

Item Status on 2026-09-28
Consolidated Rules for 2026 (CR26) One ruleset for FedRAMP, launched 2026-06-24. It replaces the separate Rev5 and 20x documentation, which is now legacy.
Certification classes Class A (pilot), Class B (formerly Low), Class C (formerly Moderate). Class D (High) is expected as a pilot in late 2026 and formally in early 2027.
Class B and C pipelines Open since 2026-08-31
CR26 mandatory for all providers 2027-01-01
New Rev5 certifications FedRAMP stops accepting them on 2027-06-11
FedRAMP 20x The outcome-based, automation-first model behind CR26. Providers show continuous, machine-validated evidence against Key Security Indicators (KSIs) instead of static annual assessments.
AI prioritization Ran from August 2025 to April 2026 for conversational AI services for federal workers. It is closed to new entrants.

Key Security Indicators

KSIs express security outcomes that a provider proves with automated evidence. The Class A reference groups them into six themes. Each theme has direct AI implications.

KSI theme AI-specific evidence
CED Cybersecurity Education Staff training on prompt injection, data leakage and safe tool use
CMT Change Management Versioned models, prompts, policies, retrieval indexes and tool definitions, with approvals
CNA Cloud Native Architecture Isolation of model runtimes, tool sandboxes and tenant data
IAM Identity and Access Management Workload identity for agents, scoped tool credentials, retrieval authorization
INR Incident Response AI incident playbooks and exercises (see AI incident response)
SVC Service Configuration Hardened configuration for model gateways, vector stores and AI endpoints

Classes B and C use a larger KSI set. Read the class reference that applies to your service.

SP 800-53 control families

FedRAMP baselines draw on NIST SP 800-53 Rev. 5. The latest release is 5.2.0, dated 2025-08-27. The table covers the families where AI changes what evidence looks like. The other families (MA, MP, PE, PS) apply to AI systems as they do to any system.

Family AI-specific considerations Framework evidence
AC Access Control Human and workload identity, agent delegation, retrieval authorization at query time Zero-trust AI design, access tests, role matrix
AT Awareness and Training AI-specific misuse, social engineering through generated content Training records, acceptable-use rules
AU Audit and Accountability Prompt and output sensitivity, correlation across agents and tools, provider logs Logging design, retention schedule, integrity controls
CA Assessment, Authorization, and Monitoring AI evaluations and red teaming as assessment inputs, continuous monitoring of model behavior Evaluation reports, red-team findings, monitoring plan
CM Configuration Management Model, prompt, policy, retrieval, tool and supplier versions as configuration items Registries, baselines, change approvals
CP Contingency Planning Fallback when a model or AI supplier is unavailable, rollback of model versions Degradation design, recovery tests, exit plans
IA Identification and Authentication Identities for models, agents and tools, not only for people Workload identity inventory, credential scoping
IR Incident Response Prompt injection, model abuse, data leakage, agent misbehavior, supplier events AI incident response playbooks, exercises, reporting paths
PL Planning AI components described in the system security plan System description, boundary diagram
PM Program Management AI inventory and governance at the program level Operating model, AI inventory
PT PII Processing and Transparency Personal data in prompts, retrieval, logs, training and provider processing Privacy assessment, minimization, deletion evidence
RA Risk Assessment AI threat modeling and impact assessment Threat model, risk management
SA System and Services Acquisition Secure development of AI components, including SP 800-218A practices Development records, supplier assurance
SC System and Communications Protection Isolation of model runtimes and tools, egress control, encryption Architecture diagrams, network policy, configuration evidence
SI System and Information Integrity Input and output validation, model artifact integrity, behavior monitoring Validation controls, artifact verification, telemetry
SR Supply Chain Risk Management External models, datasets, AI-BOMs, model signing, concentration risk Supplier assessments, provenance, AI-BOM, signature verification

AI control overlays

NIST is developing Control Overlays for Securing AI Systems (COSAiS): SP 800-53 overlays for five AI use cases.

Use case
Using and adapting generative AI assistants
Using and fine-tuning predictive AI
Single-agent AI systems
Multi-agent AI systems
Developing AI systems

NIST released a concept paper on 2025-08-14 and an annotated outline for predictive AI on 2026-01-08. As of 2026-09-28 the project page lists no published overlay. Until one is final, tailor the baseline yourself and record the AI-specific parameters in the system security plan.

Federal AI policy context

These Office of Management and Budget (OMB) memoranda set agency obligations for AI use and acquisition. They sit alongside FedRAMP. They do not replace it.

Memorandum Subject
M-25-21 Accelerating federal use of AI through innovation, governance, and public trust. Rescinds M-24-10.
M-25-22 Driving efficient acquisition of AI in government. Rescinds M-24-18.
M-26-04 Increasing public trust in AI through unbiased AI principles

Using this mapping

Record every AI component inside the authorization boundary, and every external AI service the system depends on. Document inherited controls, including those a model provider supplies, in the system security plan. Follow the current FedRAMP rules, the class that applies, and your sponsoring agency's requirements.

Sources

Checked 2026-09-28.