Scope
This guide explains the outcome of RFC-0021 and the changes to FedRAMP Marketplace requirements, effective in the FedRAMP Consolidated Rules for 2026 (CR26). Use this when evaluating your listing obligations as a cloud service provider, independent assessor, or advisory service, and when interpreting what information you can expect to find on the Marketplace.
Valid through December 31, 2028.
Key Concepts and Definitions
FedRAMP Marketplace: The directory where authorized cloud services, FedRAMP-recognized independent assessors, and advisory services are listed. Agencies use this during procurement and vendor evaluation.
Program Certification: The authorization path where FedRAMP acts as the primary sponsor for initial and ongoing authorization. This differs from agency-sponsored authorizations where a specific agency serves as the authorizing official.
Continuous Progress: A framework where cloud service providers show advancement against self-defined goals documented in Ongoing Authorization Reports. It's a transparency mechanism for potential customers.
Authorization Data Sharing: The standardized process for sharing package request information. Services using FedRAMP Connect follow this standard; those using legacy processes do not.
Requirements Breakdown
Pricing Information: Removed Entirely
What changed: FedRAMP will not request, store, or publish pricing for cloud services, independent assessors, or advisory services.
Affected rules:
- MKT-GEN-SPI Service Pricing Information (struck)
- MKT-ADV-WEB Website Requirements (modified)
- MKT-RIA-WEB Website Requirements (modified)
Why it changed: Agency commenters wanted centralized pricing, but industry commenters opposed it. FedRAMP sided with providers and explained why pricing won't be available.
What you do: Nothing. You're no longer expected to maintain or update pricing data for Marketplace listing purposes. Agencies will negotiate pricing directly with you during procurement.
Independent Assessor Recognition: Lighter Workload Requirement
What changed: FedRAMP-recognized independent assessors must complete at least 2 assessments (initial or annual) every 2 years to maintain recognition, down from the proposed 3.
Rule: MKT-RIA-ATT Attestation Requirements (modified)
Clock starts: Either your recognition date or the CR26 publication date, whichever is more recent. This gives assessors a full 2-year window before the requirement applies.
Grace period: 6 months, plus a path to prevent loss of recognition if you can demonstrate intent to perform required assessments with delays outside your control.
Why it changed: The requirement targets companies seeking FedRAMP recognition solely to offer advisory services without performing actual assessments. Several commenters inadvertently proved the problem by explaining they obtained A2LA Accreditation "with the sole intent of providing advisory services."
What you do: If you're an active assessment organization, track your initial and annual assessments. If you're approaching the 2-year mark without 2 completed assessments, document circumstances outside your control and notify FedRAMP before the deadline.
Advisory Services: Attestations Now Optional
What changed: Advisory services no longer need positive attestations from cloud service providers to maintain Marketplace listing.
Rule: MKT-ADV-ATT Attestation Requirements (rewritten as optional)
Why it changed: Public comment indicated this requirement created friction without improving advisory service quality.
What you do: If you're an advisory service, you may choose to collect and publish client attestations as a marketing differentiator, but FedRAMP won't enforce it.
Continuous Progress: Applies Only to Pre-ATO Services
What changed: The demonstration of ongoing demand requirement now applies only to cloud services without an agency authorization to operate.
Rule: MKT-GEN-DOD Demonstration of Ongoing Demand (updated)
Exemptions:
- Services with an active agency ATO
- Services not following the Authorization Data Sharing standard
Purpose clarification: This is an aggregate data collection mechanism to justify government resources spent on Program Certification processes.
What you do: If you're pursuing FedRAMP Ready or Program Certification without an agency ATO, track and report agency package requests as part of demonstrating market interest. If you already have an ATO, this doesn't apply to you.
Authorization Paths: One Program Certification Route Only
What changed: Cloud services pursuing Program Certification must choose either Rev 5 or FedRAMP 20x. You cannot maintain both through Program Certification.
Rule: MKT-GEN-PKO Pick One: 20x or Rev5 (clarified)
Exception: You can pursue an agency-sponsored Rev 5 authorization while holding a 20x Certification through Program Certification. You'd maintain two separate certifications following separate processes.
Why it matters: FedRAMP won't waste government resources performing duplicative reviews and continuous monitoring for the same service under two baselines.
What you do: If you're entering Program Certification, choose your path based on your target customer base and risk tolerance. If you need both baselines, plan for agency sponsorship of one while pursuing Program Certification for the other.
Target Authorization Time: Penalties for Substantive Delays Only
What changed: The 1-month penalty for missing target authorization time applies only when packages are demonstrably insufficient or FedRAMP must repeatedly request additional information.
Rule: MKT-FRX-TAT Target Authorization Time (clarified)
What it's not: A penalty for minor, easily correctable submission issues.
What you do: Submit complete packages. If FedRAMP identifies a gap, respond promptly with substantive corrections. The penalty targets services that waste government time with incomplete work, not teams acting in good faith.
Implementation Guidance
JSON schemas incoming: FedRAMP will provide JSON schemas for required web information for independent assessors and advisory services in CR26. MKT-ADV-WEB and MKT-RIA-WEB will include validation information.
Naming convention updates: All final rules will align with the most recent FedRAMP Machine Readable Documentation naming conventions. Expect rule identifier changes between RFC-0021 and CR26.
Corrective action deferral: FedRAMP may defer corrective action if you provide early notification with a documented, achievable corrective action plan before the trigger event. This applies across Marketplace requirements.
Common Pitfalls
Assuming pricing transparency disappeared due to industry pushback alone. Agencies wanted it. Industry opposed it. FedRAMP balanced stakeholder needs and chose not to mandate participation.
Treating the 2-assessment requirement as punitive. It's a filter for companies misusing FedRAMP recognition. If you're performing assessments, you'll clear this bar easily.
Ignoring the grace period mechanisms. Both the independent assessor recognition requirement and target authorization time penalties include documented paths to avoid penalties when delays are outside your control.
Planning for dual Rev 5/20x Program Certifications. FedRAMP explicitly won't do this. If you need both baselines, one must be agency-sponsored.
Quick Reference Table
| Requirement | Old Proposal | Final Outcome | Applies To |
|---|---|---|---|
| Pricing information | Required | Not collected | All Marketplace listings |
| Independent assessor workload | 3 assessments/2 years | 2 assessments/2 years | FedRAMP-recognized assessors |
| Advisory attestations | Required | Optional | Advisory services |
| Continuous progress reporting | All services | Services without ATO only | Cloud service providers |
| Program Certification paths | Choose Rev 5 or 20x | Choose Rev 5 or 20x (unchanged) | Services pursuing Program Certification |
| Authorization time penalties | 1 month for any delay | 1 month for substantive delays only | Services in authorization process |
| JSON schema for web data | Not specified | Provided in CR26 | Independent assessors, advisory services |
CR26 publishes by end of June 2026. Valid through December 31, 2028.



