FedRAMP 20x: Reconcile Agency Access Records in Your Trust Center
CDS requires an inventory and history of agency users or systems with access, available to FedRAMP on request. It separately requires access logging and at least six months of access summaries. Reconcile permission history with activity while preserving request-specific scope.
In this article
Main question
How should Class B/C trust centers reconcile FedRAMP 20x agency access records?
An agency account can remain on a permissions list without ever opening a package. Another account may appear in access logs after its permissions have changed. For Class B and C trust-center teams, useful FedRAMP 20x agency access records explain both who could access Certification Data and what access actually occurred.
Keep permissions and activity distinguishable
The Certification Data Sharing rules contain two related requirements. CDS-TRC-AAI says trust centers MUST maintain an inventory and history of federal agency users or systems with access to Certification Data. That information MUST be available to FedRAMP upon request.
CDS-TRC-ACL says trust centers MUST log access to Certification Data and store summaries of access for at least six months. Information about specific parties SHOULD be available upon request by those parties.
An access inventory answers a permission question. Activity logs answer an event question. Use the two together, while preserving the different request audiences and rule strengths. The six-month minimum expressly applies to access summaries; it should not be rewritten as a six-month raw-event retention requirement or assumed to define the inventory's entire retention policy.
Make identity changes explainable
As an implementation practice, connect each agency user or system to an identifiable agency, its access scope and its permission changes. Include machine identities in that design: the inventory requirement expressly covers users or systems. Keep administrative display names separate from durable identifiers so a renamed account remains traceable.
For example, an agency might replace a service account used to retrieve package materials. A useful history connects the old and new identities to the appropriate permissions and change times. Preserve enough context to explain the transition without treating them as one indistinguishable account.
When access is revoked, record the change instead of silently removing all evidence that access existed. This is an engineering recommendation for maintaining understandable history, not a prescribed retention period or an official account-deletion procedure. Our trust-center agency-scope guide explains how agency-use scope differs from the provider's dependency analysis.
Reconcile records before a request arrives
Compare a sample of permission changes against actual access events. Look for events whose identity cannot be matched, active permissions missing from the inventory, and summaries that omit retrieval activity. Assign an owner to explain discrepancies and record the outcome of the investigation.
Test two retrieval scenarios. First, assemble the inventory and history for a FedRAMP request. Second, assemble access information pertaining to a particular requesting party. Use scope checks so the second export does not casually include another party's activity. The rules identify these request audiences; they do not call for public disclosure of agency-access records.
Choose a reconciliation frequency that fits the operating environment and record who owns it. AAI and ACL do not specify a universal reconciliation interval. Keep this maintenance plan separate from the required six-month minimum for stored access summaries and from package-history management.
Track adoption and operating ownership
The CDS page lists optional adoption and initial certification adoption from July 4, 2026, ongoing adoption on January 1, 2027, and grace until the first independent assessment started after January 1, 2027. Those adoption dates are distinct from how long access summaries are retained.
Give one owner responsibility for producing coherent records across identity management and trust-center logging. A practical first check is to select one agency user and one system account, trace their permission history, and retrieve the corresponding access summary. That small exercise can reveal whether a future request will be answerable.
Frequently asked questions
Does the six-month rule apply to raw access events?
CDS-TRC-ACL expressly requires logging access and storing summaries of access for at least six months. Do not rewrite the summary-retention requirement as an identical raw-event requirement.
Who can request the access information?
CDS-TRC-AAI requires the agency-user or system inventory and history to be available to FedRAMP upon request. CDS-TRC-ACL separately says information pertaining to specific parties SHOULD be available upon request by those parties.
Next step
If you want to turn this guidance into an execution plan, the product side handles control mapping, SSP drafting, and evidence collection.
Related articles
FedRAMP 20x: Do You Need a Separate Government Deployment?
Compare shared and dedicated deployment designs for Class B/C using the shared-infrastructure policy, actual assessment scope and agency needs.
FedRAMP 20x: Handle Denied Agency Package Access Requests
Handle denied agency package-access requests for Class B/C providers using a compatible trust center, preserving the five-business-day notification trigger.
FedRAMP 20x: Handle FedRAMP-Issued Certification Reports
Handle FedRAMP-issued reports for Class C offerings, preserve the received material and track the two-week availability requirement from receipt.