Government / NIST
Available nowFedRAMP Consolidated Rules · 2026
The Consolidated Rules for 2026 that bind cloud service providers, across 15 rulesets. They apply for both certification types, Rev5 and 20x, at Certification Classes B, C and D. At Class A a named subset applies, the rules FedRAMP lists for a Class A certification.
165
requirements tracked
Premium
Access
Add-on from $49/mo
Scope
How much of the standard Keel models
Keel authors every leaf requirement in the scope declared below, all 165 of them, with nothing inside that scope left out. A test fails the build if the authored count and the declared count ever diverge, so this framework cannot quietly lose requirements after the fact.
- Authored in Keel
- 165 requirements
- In Keel’s scored scope
- 165 leaf requirements
What Keel scores here, and what it does not
Keel publishes this for every framework it ships, complete or not, so a readiness percentage can be read against a denominator you can see. Compare every framework
What Keel does
How Keel helps with FedRAMP Consolidated Rules
- Track FedRAMP Consolidated Rules as a control set with a live readiness score
- Crosswalked to your other frameworks, so shared controls are evidenced once
- Collect evidence in one place and reuse it everywhere
Collect once, comply everywhere
FedRAMP Consolidated Rules shares canonical controls with FedRAMP Rev5 Class B, FedRAMP Rev5 Class C and FedRAMP Rev5 Class D and others in the catalog. Implement one of those controls and it counts toward every framework it satisfies, so adding FedRAMP Consolidated Rules rarely means starting from scratch.
- ISO/IEC 27001 shares canonical controls
- CIS Critical Security Controls shares canonical controls
- PCI DSS shares canonical controls
- SOC 2 shares canonical controls
- SOX (Sarbanes-Oxley) Section 404 shares canonical controls
- NIST Cybersecurity Framework shares canonical controls
- NIST SP 800-53 shares canonical controls
- FedRAMP Rev5 Class B shares canonical controls
- FedRAMP Rev5 Class C shares canonical controls
- FedRAMP Rev5 Class D shares canonical controls
- FedRAMP 20x shares canonical controls
- NIST SP 800-171 shares canonical controls
- HIPAA shares canonical controls
- GDPR shares canonical controls
- COPPA shares canonical controls
- Google Play Families no shared canonical controls
- Amazon Appstore Child-Directed Apps no shared canonical controls
- Apple App Store Kids Category no shared canonical controls
- PIPEDA shares canonical controls
- ISO 9001 shares canonical controls
- AI Governance Essentials no shared canonical controls
- ISO/IEC 42001 shares canonical controls
- NIST AI Risk Management Framework no shared canonical controls
- EU AI Act no shared canonical controls
- ESG Essentials no shared canonical controls
- US Employment Law - Federal Baseline no shared canonical controls
A framework is lit when at least one canonical control satisfies both FedRAMP Consolidated Rules and that framework. Unlit means none of them do, which is an absence rather than a judgment about that standard. 18 of 26 are lit here.
Other frameworks: ISO/IEC 27001 · CIS Critical Security Controls · PCI DSS · SOC 2 · SOX (Sarbanes-Oxley) Section 404 · NIST Cybersecurity Framework · All frameworks