What Keel scores in FedRAMP's Consolidated Rules, and what it does not
FedRAMP publishes 246 rules for 2026. Keel scores 165 of them: every rule that states a duty a cloud service provider can actually carry out. The other 81 are named below, one by one, with the reason.
Out of scope is not the same as irrelevant. A rule addressed to your assessor still shapes what you have to hand them. What it does not do is give you something to implement, so scoring you against it would put a permanent gap in your readiness figure with no action behind it.
Rules that grant a permission
FedRAMP writes these with the force MAY. They tell a provider it is allowed to do
something, not that it has to. Keel has no notion of an optional requirement, so scoring these
would mark you incomplete for declining a permission FedRAMP explicitly gave you. These are
the calls most worth contesting, which is why they come first.
-
CCM-OCR-RPSCollaborative Continuous Monitoring MAYResponsible Public Certification Report Sharing -
CCM-QTR-SRRCollaborative Continuous Monitoring MAYShare Recordings Responsibly -
CCM-QTR-SCRCollaborative Continuous Monitoring MAYShare Content Responsibly -
CDS-CSO-RPSCertification Data Sharing MAYResponsible Public Package Sharing -
FRC-CLA-OFRFedRAMP Certification MAYAddress Optional FedRAMP Rules for Class A -
FRC-CLA-IVVFedRAMP Certification MAYOptional Independent Verification and Validation -
FRC-APP-USAFedRAMP Certification MAYUpdating Stale Assessments -
IVV-CSO-USRIndependent Verification and Validation MAYUse Representative Samples -
IVV-CSO-RAAIndependent Verification and Validation MAYReceiving Assessor Advice -
MAS-CSO-SUPMinimum Assessment Scope MAYSupplemental Information -
SCN-CSO-ARISignificant Change Notification MAYAdditional Relevant Information -
SCN-CSO-NOMSignificant Change Notification MAYNotification Mechanisms -
SCN-CSO-EMGSignificant Change Notification MAYEmergency Changes -
VDR-CSO-SIRVulnerability Detection and Response MAYSampling -
VER-RPT-RPDVulnerability Evaluation and Reporting MAYResponsible Public Disclosure
Rules addressed to someone other than the provider
FedRAMP's rules bind agencies, independent assessors, advisors and FedRAMP itself as well as providers. Each rule below states its own audience, and none of them names providers.
Addressing FedRAMP Communication 8
-
AFC-FRP-VREVerified Emails FedRAMP -
AFC-FRP-CDSCriticality Designators FedRAMP -
AFC-FRP-UFSUse FedRAMP_Security Email in Emergencies FedRAMP -
AFC-FRP-PNTPublic Notice of Emergency Tests FedRAMP -
AFC-FRP-RQARequired Actions FedRAMP -
AFC-FRP-ERTElevated Reaction Timeframes FedRAMP -
AFC-FRP-CORExplain Corrective Actions FedRAMP -
AFC-FRP-RPMReaction Metrics FedRAMP
Agency Use of FedRAMP Certified Cloud Services 20
-
AGU-AGC-AIPAgency Internal Policies Agencies -
AGU-AGC-NAANotify FedRAMP After Authorization Agencies -
AGU-AGC-GRCGovernance, Risk, and Compliance Tools Agencies -
AGU-AGC-NAINotify Additional Information Requests Agencies -
AGU-AGC-NARNo Additional Security Requirements Agencies -
AGU-AGC-TPPNo Certification Type or Path Preferences Agencies -
AGU-AGC-WKGFedRAMP Working Groups Agencies -
AGU-AGC-LIAAgency Liaison Program Agencies -
AGU-AGC-SINShared FedRAMP Inbox Agencies -
AGU-USE-ABUAuthorization Before Use Agencies -
AGU-USE-RCFResolve Certification Package Conflicts Agencies -
AGU-USE-RSGReview Secure Configuration Guides Agencies -
AGU-USE-AFRAccept FedRAMP Rules Agencies -
AGU-USE-NFCNotify FedRAMP of Monitoring Concerns Agencies -
AGU-USE-RORReview Ongoing Certification Reports Agencies -
AGU-USE-DSODesignate Senior Official Agencies -
AGU-USE-NPCNotify Provider of Concerns Agencies -
AGU-USE-RIRReview All Information Resources Agencies -
AGU-USE-CLAUsing FedRAMP Class A Certifications Agencies -
AGU-SPN-MRCMost Recent Consolidated Rules Agencies
Collaborative Continuous Monitoring 2
-
CCM-AGM-RORReview Ongoing Reports Agencies -
CCM-AGM-CSCConsider Security Category Agencies
FedRAMP Recognition of Independent Assessment Services 16
-
REC-FRP-FOCForeign Ownership Collection FedRAMP -
REC-FRP-RAORecognized Assessors Only FedRAMP -
REC-FRP-DRDDouble Revocation Disqualification FedRAMP -
REC-IAS-ACCA2LA Accreditation Assessors -
REC-IAS-ADAActually Do Assessments Assessors -
REC-IAS-PSCPolicy and Standards Compliance Assessors -
REC-IAS-ANRAnnual Surveillance Assessment Assessors -
REC-IAS-RASFull A2LA Reassessment Assessors -
REC-IAS-RARRe-entry after Revocation Assessors -
REC-IAS-RQURoles and Qualifications Assessors -
REC-IAS-AFIAnnual Foreign Interest Reports Assessors -
REC-IAS-CFIChanges in Foreign Interest Assessors -
REC-IAS-PSTPerformance Standards Assessors -
REC-IAS-CAPCorrective Action Plan Assessors -
REC-IAS-INVInvalid Deliverables Assessors -
REC-IAS-SEPAdvisory Separation Assessors
Incident Evaluation and Communication 1
-
IEC-FRP-ORVOngoing Review FedRAMP
Independent Verification and Validation 7
-
IVV-IAS-VIMVerify Implementation Assessors -
IVV-IAS-VEFValidate Effectiveness Assessors -
IVV-IAS-SUMAssessment Summary Assessors -
IVV-IAS-OSAOverall Summary of Assessment Assessors -
IVV-IAS-VIPVerify Inclusion in Certification Package Assessors -
IVV-IAS-EPXEngage Provider Experts Assessors -
IVV-IAS-SHASharing Advice Assessors
Marketplace Listing 7
-
MKT-FRP-SOFScope of FedRAMP FedRAMP -
MKT-IAS-OFROnly FedRAMP Recognized Assessors Assessors -
MKT-IAS-WEBWebsite Requirements for Assessors Assessors -
MKT-IAS-LRQListing Requests for Assessors Assessors -
MKT-CAS-WEBWebsite Requirements for Advisors Advisors -
MKT-CAS-LRQListing Requests for Advisors Advisors -
MKT-CAS-RFRAdvisor Responses to FedRAMP Advisors
Significant Change Notification 1
-
SCN-FRP-CAPCorrective Action Plan Conditions FedRAMP
Vulnerability Evaluation and Reporting 4
-
VER-FRP-ARPAdditional Requirements FedRAMP -
VER-FRP-ADVSensitive Details FedRAMP -
VER-AGM-RVRReview Vulnerability Reports Agencies -
VER-AGM-MAPMaintain Agency Plans of Action and Milestones Agencies
Where the inventory came from
Think one of these belongs in scope? That is the point of publishing it, so tell us which rule. The full framework is at FedRAMP Consolidated Rules.