Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cloud

FedRAMP Seeks Comment on Updated Incident Communications Procedures

by Jane Edwards
April 9, 2026
in Cloud, Cybersecurity, News
FedRAMP Seeks Comment on Updated Incident Communications Procedures

FedRAMP Seeks Comment on Updated Incident Communications Procedures

The Federal Risk and Authorization Management Program has issued a request for comments to update its incident communications procedures as part of efforts to clarify reporting requirements for cloud service providers, or CSPs.

Table of Contents

    • You might also like
    • Lance Schroyer Nominated as ICE Director
    • USSTRATCOM Seeks to Advance EM Warfare Capabilities Through ETHEREAL FORGE
    • FBI, CISA Issue Alert on Russian Phishing Campaign Targeting Messaging App Users
  • What Are the Proposed Changes to FedRAMP Incident Communications Procedures?
  • What Are the Updated & New FedRAMP Definitions?
  • What Does the ICP-FRP-ORV Ongoing Review Entail?

You might also like

Lance Schroyer Nominated as ICE Director

USSTRATCOM Seeks to Advance EM Warfare Capabilities Through ETHEREAL FORGE

FBI, CISA Issue Alert on Russian Phishing Campaign Targeting Messaging App Users

FedRAMP Seeks Comment on Updated Incident Communications Procedures

As FedRAMP seeks public input on updated incident reporting rules, government and industry leaders will continue the conversation on cybersecurity priorities at the 2026 Cyber Summit on May 21. Sign up now for the May 21 event and join experts as they discuss zero trust, post-quantum cryptography, AI in cyber defense and other trends shaping the cyber landscape.

FedRAMP said Wednesday the comment period will run through May 12. Stakeholders can submit feedback through a GitHub RFC thread or via email to FedRAMP.

What Are the Proposed Changes to FedRAMP Incident Communications Procedures?

The RFC outlines several updates intended to establish a rules-based framework for incident reporting. FedRAMP proposes shifting reporting of availability-related incidents to publicly accessible status pages or similar notification mechanisms, rather than requiring federal-specific reporting.

The updated approach would focus federal reporting requirements on incidents that are likely or confirmed to affect the confidentiality or integrity of federal customer data.

The proposal seeks to clearly define the expected reporting data elements for federal reportable incidents and introduces revised reporting timeframes based on the severity of the incident and the provider’s certification level.

What Are the Updated & New FedRAMP Definitions?

RFC-0031 proposes updates to several FedRAMP definitions for Rev5 and 20x, including the definition of “incident.” FedRAMP previously limited the definition of an “incident” to events involving federal customer data. The updated definition broadens the term to cover any event that impacts a cloud service offering, regardless of whether federal data is involved.

New definitions include initial, ongoing and final incident reports.

What Does the ICP-FRP-ORV Ongoing Review Entail?

The request for comment introduces ICP-FRP-ORV, an ongoing review requirement under which FedRAMP will periodically assess whether CSPs are following incident communication procedures.

FedRAMP will initiate reviews based on factors such as lack of reporting or other indicators. If a provider is found to be unaware of the requirements or has not implemented appropriate procedures, FedRAMP will request a corrective action plan.

Providers will have a three-month grace period to address deficiencies. Failure to implement proper procedures may result in remediation actions and potential revocation of FedRAMP certification.

The ongoing review requirement is scheduled to take effect Jan. 1, 2027.

In 2021, FedRAMP issued an update to its Incident Communications Procedures document, detailing the roles and responsibilities of each stakeholder in the cyber incident communication process and the appropriate timeframes for reporting information regarding security incidents.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19

Recommended For You

Lance Schroyer Nominated as ICE Director

by Jane Edwards
June 29, 2026
Lance Schroyer. The senior adviser to the secretary of DHS has been nominated to serve as director of ICE.

President Trump has nominated Lance Schroyer to lead ICESchroyer has served as a senior adviser at DHS and led immigration enforcement coordination under the 287(g) programThe Potomac Officers...

Read moreDetails

USSTRATCOM Seeks to Advance EM Warfare Capabilities Through ETHEREAL FORGE

by Jane Edwards
June 29, 2026
AnnMarie Anthony. The JEC director at USSTRATCOM commented on the ETHEREAL FORGE initiative to advance EW capabilities.

USSTRATCOM has launched ETHEREAL FORGE to accelerate electromagnetic warfare capability deploymentThe initiative advances rapid, software-centric testing and fielding and supports MOSA-compatible systemsThe Potomac Officers Club will host two...

Read moreDetails

FBI, CISA Issue Alert on Russian Phishing Campaign Targeting Messaging App Users

by Miles Jamison
June 29, 2026
Phishing. The FBI and CISA have issued an alert on a Russian phishing campaign targeting commercial messaging app users.

The FBI has linked an ongoing messaging app phishing campaign to Russian intelligence cyber actorsThe phishing campaign targets government officials, military personnel, journalists and Ukraine-based officialsThe attackers pose...

Read moreDetails

New FedRAMP 20x Launched to Provide Better Cloud Certification

by Jamie Bennet
June 29, 2026
Federal Risk and Authorization Management Program. The FedRAMP 20x cloud certification along with 2026 rules.

The Federal Risk and Authorization Management Program's FedRAMP 20x cloud certification went live after the program released the Consolidated Rules for 2026FedRAMP 20x will eventually replace FedRAMP Rev5...

Read moreDetails

NASA Unveils 41 Awardees for 2025 Announcement of Collaboration Opportunity

by Jamie Bennet
June 29, 2026
NASA. The space agency has named the 37 companies chosen for the 2025 Announcement of Collaboration Opportunity.

NASA has announced the awardees for its 2025 Announcement of Collaboration OpportunityThirty-seven companies will execute 41 proposals centered on technologies to be used on the Moon and in...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved.

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved.

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!