Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cloud

FedRAMP Seeks Comment on Updated Incident Communications Procedures

by Jane Edwards
April 9, 2026
in Cloud, Cybersecurity, News
FedRAMP Seeks Comment on Updated Incident Communications Procedures

FedRAMP Seeks Comment on Updated Incident Communications Procedures

The Federal Risk and Authorization Management Program has issued a request for comments to update its incident communications procedures as part of efforts to clarify reporting requirements for cloud service providers, or CSPs.

You might also like

CISA Names Ryan Donaghy Chief Operating Officer

Sheriff Michael Adkinson to Chair FirstNet Authority Board

Vice Adm. Douglas Williams to Lead Navy PAE Strategic Systems Programs

FedRAMP Seeks Comment on Updated Incident Communications Procedures

As FedRAMP seeks public input on updated incident reporting rules, government and industry leaders will continue the conversation on cybersecurity priorities at the 2026 Cyber Summit on May 21. Sign up now for the May 21 event and join experts as they discuss zero trust, post-quantum cryptography, AI in cyber defense and other trends shaping the cyber landscape.

FedRAMP said Wednesday the comment period will run through May 12. Stakeholders can submit feedback through a GitHub RFC thread or via email to FedRAMP.

Table of Contents

  • What Are the Proposed Changes to FedRAMP Incident Communications Procedures?
  • What Are the Updated & New FedRAMP Definitions?
  • What Does the ICP-FRP-ORV Ongoing Review Entail?

What Are the Proposed Changes to FedRAMP Incident Communications Procedures?

The RFC outlines several updates intended to establish a rules-based framework for incident reporting. FedRAMP proposes shifting reporting of availability-related incidents to publicly accessible status pages or similar notification mechanisms, rather than requiring federal-specific reporting.

The updated approach would focus federal reporting requirements on incidents that are likely or confirmed to affect the confidentiality or integrity of federal customer data.

The proposal seeks to clearly define the expected reporting data elements for federal reportable incidents and introduces revised reporting timeframes based on the severity of the incident and the provider’s certification level.

What Are the Updated & New FedRAMP Definitions?

RFC-0031 proposes updates to several FedRAMP definitions for Rev5 and 20x, including the definition of “incident.” FedRAMP previously limited the definition of an “incident” to events involving federal customer data. The updated definition broadens the term to cover any event that impacts a cloud service offering, regardless of whether federal data is involved.

New definitions include initial, ongoing and final incident reports.

What Does the ICP-FRP-ORV Ongoing Review Entail?

The request for comment introduces ICP-FRP-ORV, an ongoing review requirement under which FedRAMP will periodically assess whether CSPs are following incident communication procedures.

FedRAMP will initiate reviews based on factors such as lack of reporting or other indicators. If a provider is found to be unaware of the requirements or has not implemented appropriate procedures, FedRAMP will request a corrective action plan.

Providers will have a three-month grace period to address deficiencies. Failure to implement proper procedures may result in remediation actions and potential revocation of FedRAMP certification.

The ongoing review requirement is scheduled to take effect Jan. 1, 2027.

In 2021, FedRAMP issued an update to its Incident Communications Procedures document, detailing the roles and responsibilities of each stakeholder in the cyber incident communication process and the appropriate timeframes for reporting information regarding security incidents.

Share5Tweet19

Recommended For You

CISA Names Ryan Donaghy Chief Operating Officer

by Kristen Smith
May 22, 2026
Ryan Donaghy. CISA has appointed Ryan Donaghy as COO.

CISA has named Ryan Donaghy as its first COOThe veteran cybersecurity and infrastructure leader previously served at TSADonaghy will oversee operations, policy and strategic coordination effortsThe Cybersecurity and...

Read moreDetails

Sheriff Michael Adkinson to Chair FirstNet Authority Board

by Miles Jamison
May 22, 2026
Michael Adkinson. Sheriff Michael Adkinson has been named chairman of the First Responder Network Authority Board.

Walton County Sheriff Michael Adkinson Jr. has officially been named chairman of the FirstNet Authority BoardThe veteran law enforcement leader will bring extensive experience from national and state...

Read moreDetails

Vice Adm. Douglas Williams to Lead Navy PAE Strategic Systems Programs

by Elodie Collins
May 22, 2026
Vice Adm. Douglas Williams. Williams will assume the role of director of PAE Strategic Systems Programs

Vice Adm. Douglas L. Williams will lead the Navy's PAE SSP starting in JuneHe will replace Vice Adm. Johnny Wolfe Jr., who is retiring after over three decades of...

Read moreDetails

Pentagon AI User Base Hits 1.5M as Battlefield Integration Accelerates

by Kristen Smith
May 22, 2026
Emil Michael. The DOW CTO said DOW’s AI user base has reached 1.5 million, up from 80,000 a year ago.

Pentagon AI users have surged to 1.5 million users in one yearDefense leaders have pushed AI deeper into the battlefield and operational systemsDOW has accelerated efforts to scale...

Read moreDetails

Snowflake Offers Agencies Discounts for Data Tools Under OneGov Agreement With GSA

by Elodie Collins
May 22, 2026
GSA Administrator Edward Forst. Forst said GSA's new OneGov deal with Snowflake supports AI adoption across agencies

 Snowflake is offering agencies discounts for its computer and storage services under a OneGov agreement with GSA GSA Administrator Edward Forst said the agreement will break down data silos to...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • General News
  • GovCon Expert
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved.

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved.

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!