When Do You Have to Report an Incident to FedRAMP?

An incident is reportable to FedRAMP only if it has affected, or is likely to affect, the confidentiality or integrity of federal customer data. Reportable incidents require three reports, initial, ongoing, and final, all using the FedRAMP Incident Report JSON schema, with timeframes ranging from 15 minutes at Class D to six hours at Class A and B. For Rev 5 systems, the grace period for this ruleset ends June 1, 2027.

Isaac Teuscher
|
53
min read

In This Article

Something went wrong in production and you need to know, right now, whether the incident needs to be reported to FedRAMP.

The short version: only if the incident has affected, or is likely to affect, the confidentiality or integrity of federal customer data. Availability alone does not trigger anything.

Here are the specifics you will need to plan around: the reportability test, the exact timeframes at every class, and the grace period deadline that is closer than most teams think.

The Overview:

  • Only confidentiality and integrity trigger a report. Availability is not in the reportability test under IEC-CSO-EFR, even though it is part of minimum assessment scope.
  • Skip the PAIN estimate and you get PAIN 5. IEC-CSO-DPR defaults you to the rating with the shortest clocks.
  • Three reports, one schema. Initial, ongoing, and final all use the FedRAMP Incident Report JSON schema.
  • Class D initial reports are due in 15 minutes. Class C gets an hour, Class A and B get six.
  • The final report is a MUST at every class. Class A can treat initial and ongoing as SHOULD, but not the final.
  • June 1, 2027 is the grace period cliff for Rev 5 systems adopting this ruleset, with no extensions.

Read on to get the details you need.

What is the incident evaluation and communication ruleset?

The Incident Evaluation and Communication ruleset in the FedRAMP Consolidated Rules for 2026 (CR26) defines when a FedRAMP certified cloud service offering has to tell FedRAMP and its agency customers that something happened, how fast, and in what format.

Here's how it works and what you're required to do:

  1. Identify an incident
  2. Evaluate whether it is FedRAMP reportable
  3. Rate how badly it is likely to land on an agency
  4. File three reports on a fixed schedule: initial, ongoing, and final

All of these reports use the same machine-readable file. FedRAMP publishes it as the Incident Report schema, described as a unified schema for the three incident report types in the IEC-CSO lifecycle.

What counts as a FedRAMP reportable incident

FedRAMP Reportable Incidents are those that affect, or are likely to affect, the confidentiality or integrity of federal customer data.

Under IEC-CSO-EFR, providers must promptly evaluate incidents for this factor.

Note what is absent: availability.

Example: Your site goes down for 30 seconds. Nothing exposed, nothing tampered with, no reason to think either is coming. That is an availability incident and it does not trigger a FedRAMP report.

But, malicious activity in a production bucket or database holding federal customer data is a concern, because it has either affected confidentiality or integrity or is likely to.

Take note: Minimum assessment scope covers confidentiality, availability, and integrity of federal customer data. Incident reportability covers only confidentiality and integrity. Two different tests, and one of them drops availability. Do not carry the scope definition into the reportability decision.

PAIN, and why you default to 5

Once an incident is reportable, you rate it.

PAIN stands for Potential Agency Impact N-rating. Ratings go N1 through N5. It is your best estimate of the likely adverse impact on an agency customer, and you update it as your investigation turns up more.

FYI: IEC-CSO-DPR requires the incident be treated as PAIN 5 until you estimate it. Given that PAIN 5 carries the shortest clocks at every class, skipping the estimate is the most expensive way to save five minutes.

The three reports and timelines

Initial incident report

Class Requirement PAIN 5, 4, 3 PAIN 2 PAIN 1
Class A SHOULD 6 hours 1 business day 1 business day
Class B MUST 6 hours 1 business day 1 business day
Class C MUST 1 hour 24 hours 1 business day
Class D MUST 15 minutes 1 hour 1 hour

Class A and Class B carry the same clock. The difference is that at Class A the initial report is a SHOULD, meaning best practice rather than required.

Fifteen minutes at Class D is the window to evaluate reportability, assign a PAIN rating, generate the JSON, email FedRAMP, notify your agency contacts, and update your trust center.

Ongoing incident reports

Class PAIN 5, 4, 3 PAIN 2 PAIN 1
Class A SHOULD 1 business day 1 business day 1 business day
Class B 1 business day 1 business day 1 business day
Class C 6 hours 24 hours 1 business day
Class D 3 hours 6 hours 24 hours

Ongoing reports carry new indicators of compromise and new activity as the investigation develops. At Class D that is a three-hour cadence on a live incident.

Final incident report

The final report is a MUST at every class, including Class A. This is the one requirement in the ruleset nobody escapes.

Class PAIN 5, 4, 3 PAIN 2 PAIN 1
Class A 3 business days 3 business days 3 business days
Class B 3 business days 3 business days 3 business days
Class C 6 hours 1 business day 1 business day
Class D 3 hours 6 hours 24 hours

Source: FedRAMP's Incident Evaluation and Communication rulesets for Class B, Class C and Class D, plus Class A related rules.

Fifteen minutes is not enough time to build a JSON file by hand.

See how it works

Dates that matter for Incident Reporting Requirements

If you hold a Rev 5 authorization, the Incident Evaluation and Communication ruleset has its own schedule, and it is one of the earlier cliffs in CR26.

Date Milestone
January 1, 2027 Required for both initial and ongoing certification.
June 1, 2027 Grace period for the incident ruleset ends.
February 1, 2028 All remaining CR26 grace periods end.

Circle June 1, 2027 in red on your comically large desk calendar, friend. FedRAMP's deadlines page states there will be no extensions past the ending of the default grace period, and that it applies regardless of notification, corrective action, or progress.

Our CR26 deadlines post covers the wider rollout.

What you need in place before an incident

Three things have to exist before you have an incident to report.

  1. A reportability decision your on-call can make. Someone at 2am needs to answer "confidentiality or integrity of federal customer data, yes or no" without convening a meeting.
    If that question routes to a compliance lead who is asleep, your fifteen minutes are gone.
  1. A generated JSON file (not a handcrafted one). The Incident Report schema covers all three report types and carries a provider tracking ID, incident description, timeline, milestones, and both your historical and current PAIN ratings with the reasoning behind them. Ask your GRC or incident response vendor directly whether they emit this schema.
  2. A notification path that hits every party at once. FedRAMP by email, each agency point of contact by their appropriate method, and your trust center updated. Three destinations, one clock.

What this means for your FedRAMP program

Incident reporting is the clearest example of why CR26 rewards automation over documentation. Nothing about a fifteen-minute window is solvable with a better template.

The deliverable is a machine-readable file whose contents come from things you already know: your environment, your data flows, your impact assessment. If those live in a Security Decision Record rather than a Word document, the incident report becomes a generation problem instead of a writing problem.

That is the difference between a program that meets these clocks and one that discovers on the worst day of its year that it cannot.

Generate incident reports from your Security Decision Record.

Demo Paramify

How Paramify helps with FedRAMP incident reporting

The hard part of this ruleset is producing a valid, complete JSON file inside a window measured in minutes, three separate times, while an incident is still active.

Paramify keeps your environment, data flows, and security decisions in one source of truth, and generates CR26 JSON deliverables from that data rather than from a person filling in a form. The same source feeds your Security Decision Record and your trust center, so what agencies see during an incident matches what your program actually knows.

We have been through CR26 ourselves. Paramify holds its own FedRAMP 20x Class C certification, which means these clocks apply to us too.

FEDRAMP INCIDENT REPORTING

Find out whether you could file in fifteen minutes before you have to.

Paramify generates CR26 JSON deliverables from the data you already have, and publishes them through a FedRAMP-ready trust center.

Book a demo

Learn More:

Frequently asked questions

When do you have to report an incident to FedRAMP?

When the incident has affected, or is likely to affect, the confidentiality or integrity of federal customer data. That is the test in rule IEC-CSO-EFR. Incidents with no confidentiality or integrity impact are not FedRAMP reportable.

Do I have to report an outage to FedRAMP?

Not for the downtime itself. Availability is not part of the reportability test. An outage becomes reportable only if it also affects, or is likely to affect, the confidentiality or integrity of federal customer data.

What is a PAIN rating?

PAIN is the Potential Agency Impact N-rating, from N1 to N5. It is your estimate of the likely adverse impact on an agency customer, and you revise it as you learn more. If you do not estimate it, the rules treat the incident as PAIN 5.

How fast do I have to file an initial incident report?

It depends on your certification class and PAIN rating. At Class D, 15 minutes for PAIN 3 and above. At Class C, one hour. At Class A and B, six hours. Lower PAIN ratings get longer windows.

Is the final incident report required at every class?

Yes. The final report is a MUST at Class A, B, C, and D. At Class A the initial and ongoing reports are SHOULD requirements, but the final report is not optional anywhere.

Schedule Your Demo Today to Start Automating Your Incident Reporting

Isaac Teuscher
A Security Engineer leading the technical implementation of cloud and AI-driven security. With experience in NIST 800-53 and FedRAMP, Isaac collaborates with executive teams to build scalable security programs that meet the highest federal compliance standards.
Oct 2026
Related posts

Paramify blog

Interviews, tips, guides, industry best practices, and news.

FedRAMP Class C (Moderate) vs Class D (High)

FedRAMP Class C (formerly Moderate, ~323–325 controls) and Class D (formerly High, ~421 controls) differ in far more than control count — cost roughly doubles to triples, encryption and MFA requirements change categorically, and Class D remains Rev 5-only until FedRAMP 20x Class D opens in early 2027. Most federal SaaS companies need Class C; Class D is reserved for law enforcement, health, financial, and emergency services data.
Read post

What is FedRAMP Class B?

FedRAMP Class B is the second of four FedRAMP Certification Classes, replacing the old Low impact level. It requires providers to address every applicable Key Security Indicator directly, with at least one automated validation method per KSI, an annual independent assessment, and a maintained Security Decision Record — without the stricter automation, historical-metrics, or GovCloud requirements that kick in at Class C and up.
Read post

What Does Paramify Do?

Paramify is a risk management platform that unifies and automates implementation, monitoring, and reporting across NIST 800-53, FedRAMP 20x, CMMC, SOC 2, and other federal and commercial frameworks from a single platform. Learn how Paramify works and see customer results.
Read post

Frequently Asked Questions

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Can compliance advisors or consultants work in Paramify with us, and does it help with managed-service models?

Absolutely. Paramify is used by many advisory partners, RPOs, and MSPs to guide, generate, and manage documentation, perform gap assessments, facilitate policy/procedure drafting, and oversee remediation activities. Advisors can fill out templates, manage controls, and generate client-ready documents.

‍

We have privacy or compliance concerns, can we restrict what external reviewers can access?

Yes, you can assign role-based access controls in Paramify. Advisors or auditors can be given access only to certain programs, assessment and their related evidence.

Sensitive information can be withheld or redacted as needed, and only certified reviewers see specific items.

‍

Can auditors or advisory partners get direct access to our Paramify environment, or do we have to export everything for them?

Yes, Paramify allows external assessors/auditors and advisors to be invited as users, with controlled permission levels. They can review specific evidence, policies, SSPs, POA&Ms, or assessment modules without accessing broader company data. 

Documentation — such as Appendix A, SSPs, procedures, and POAMs — can also be exported in multiple standard formats (Word, Excel, OSCAL, EMASS, PDF) as needed.

Can I get matched with an Advisor based on my specific needs?

Yes. You can use the Get Matched feature on our website. We will review your specific compliance goals and connect you with the partner best suited for your industry and timeline.

How do Advisors use Paramify during a FedRAMP engagement?

Advisors use Paramify to conduct Gap Assessments, map controls, Automate SSPs, and manage POA&Ms.

Instead of spending months writing Word documents, the Advisor inputs the system architecture and control implementations into Paramify, which then generates the required NIST-formatted documentation.

Does Paramify compete with its Advisors?

No. Paramify is a software company. We do not offer independent audit or long-term consulting services. Our goal is to empower Advisors with better tools so they can serve more clients effectively.

‍

What are the different partner tiers?

We feature Premier Partners prominently on our site. These are firms that have demonstrated a high level of proficiency with the Paramify platform and have successfully helped many clients through the certification process using our tools.

How do I become an official Paramify Advisor Partner?

We look for firms with a proven track record in federal compliance. If you are interested in joining our network and leveraging our automation products, you can reach out via our contact page or schedule a demo to see how our tools fit into your workflow.

What is the benefit of using an Advisor who uses Paramify vs. one who doesn't?

Advisors using Paramify can accelerate your implementation and typically deliver documentation in a fraction of the time it takes without Paramify. This means:

  • Faster Implementation: An accelerated implementation roadmap keeps timelines predictable.
  • Lower Costs: Reduced manual consultant hours.
  • Higher Accuracy: Automation eliminates the "copy-paste" errors common in traditional SSPs.‍
  • Easier Maintenance: Your Advisor can help you manage POA&Ms and continuous monitoring within the platform.
Does working with an Advisor on this list guarantee FedRAMP or CMMC authorization?

No firm can "guarantee" authorization, as the final decision rests with the government authorizing body (e.g., the FedRAMP PMO or the DoD).

However, working with a Paramify Advisor significantly reduces the risk of documentation errors and ensures your package is built on a technically sound, automated foundation.

‍

How do I choose the right Advisor for my organization?

Our Advisor page allows you to filter partners by their specific expertise, such as FedRAMP, CMMC, FISMA, or GovRAMP.

Why does Paramify partner with Advisors?

Paramify is an “Iron Man suit” for GRC experts. We provide automation technology to generate and manage compliance documentation (like SSPs snd POA&Ms) while Advisors provide the expert human oversight and implementation expertise.

Together, we offer a "best-of-both-worlds" solution: expert consulting powered by industry-leading automation and risk management planning.

What is the Paramify Advisor Partner Network?

The Paramify Advisor Partner Network is a curated group of cybersecurity and compliance firms — including CMMC Registered Practitioner Organizations (RPOs) and accredited Independent Assessors— that use Paramify’s platform to deliver faster, more accurate compliance outcomes for their clients.

I already have an advisor or very capable GRC team. Why do I need Paramify?

Use Paramify's Risk Solution platform to automate ATO packages, improving cost efficiency, speed, and accuracy. This frees your team to focus on more valuable efforts like security posture enhancement and compliance improvements.