Skip to main content
Pricing
Sign inRequest demo
CDS-CSO-PUBMUSTAll frameworksImplementation guide coming soon

Public Information

Certification Data Sharing (CDS) · General Provider Responsibilities

Applies to: Providers
Who this applies to
Providers
Service class
All service classes
Force
MUST
Timeframe
No fixed timeframe

Reviewed implementation guidance for CDS-CSO-PUB is not published yet. The official source below remains complete and authoritative.

Information required

  • FedRAMP ID
  • Service Model
  • Deployment Model
  • Business Category
  • UEI Number
  • Sales Contact Information
  • Security Contact Information
  • Product Website Link
  • Link to Product Logo
  • Overall Service Description
  • Detailed list of specific services and their security categories (see CDS-CSO-SVC (Public Service List) (Service List))
  • Link to Secure Configuration Guidance
  • Overview of documentation supplied by the provider for the cloud service offering
  • Link to Trust Center landing page that includes instructions on accessing information in the trust center
  • Next Ongoing Certification Report date (see CCM-OCR-NRD (Next Report Date))
  • Current FedRAMP Recognized independent assessment service

Expected evidence artifacts

  • URL to the human-readable data.
  • URL to the machine-readable data.

Official FedRAMP source

Verbatim from FedRAMP/rules

Providers MUST publicly share up-to-date information about the cloud service offering in both human-readable and JSON formats, including at least the following information that is available and applicable:

Defined terms in this requirement

Operationalize this rule

Boundera turns FedRAMP 20x requirements like CDS-CSO-PUB into assigned evidence, remediation work, and validation workflows.

See it on your cloud

Notes

  • Generally, this information should be available on a public webpage or publicly shared in a FedRAMP-compatible trust center.

Change history

  • 2026-06-24Official launch of the FedRAMP Consolidated Rules for 2026.

Content provenance

Official requirement text is sourced from FedRAMP/rules . Boundera implementation guidance has not been fully reviewed for this item.