Skip to main content
Pricing
Sign inRequest demo
CCM-OCR-LSIMUST NOTAll frameworksImplementation guide coming soon

Limit Sensitive Information

Collaborative Continuous Monitoring (CCM) · Ongoing Certification Reports

Applies to: Providers
Who this applies to
Providers
Service class
All service classes
Force
MUST NOT
Timeframe
No fixed timeframe

Reviewed implementation guidance for CCM-OCR-LSI is not published yet. The official source below remains complete and authoritative.

Official FedRAMP source

Verbatim from FedRAMP/rules

Providers MUST NOT irresponsibly disclose sensitive information in an Ongoing Certification Report that would likely have an adverse effect on the cloud service offering.

Defined terms in this requirement

Operationalize this rule

Boundera turns FedRAMP 20x requirements like CCM-OCR-LSI into assigned evidence, remediation work, and validation workflows.

See it on your cloud

Change history

  • 2026-06-24Official launch of the FedRAMP Consolidated Rules for 2026.

Content provenance

Official requirement text is sourced from FedRAMP/rules . Boundera implementation guidance has not been fully reviewed for this item.