CR26 · required before your next assessment

An agency verifies your package, ungated. No one else can show you that.

CR26 makes you serve your certification data programmatically, ungated, with an access log. We generate that package and serve it through a conformant trust center that runs in your own account. A practitioner signs it. An agency verifies it against your account, and we never touch the bytes.

See a 90-second demo
A login wall or an email-for-access form does not meet the rule. Conformance is the difference.
What CR26 requires of a trust center

Three obligations, satisfied on their face.

CR26 turns 'publish a trust page' into a hard, testable contract. A gated portal fails it. A conformant trust center meets each rule the way an assessor checks it.

  • CDS-TRC-PAC

    Programmatic access

    An agency pulls all of your certification data over one documented API route, the human-readable materials included, with no login in the way.

    served from your account, one route
  • CDS-TRC-USH

    Uninterrupted sharing

    Every authorized party gets the data on demand. No request-and-approve step stands between an agency and a pull.

    on demand, no manual approval
  • CDS-TRC-ACL

    Access logging

    Every pull is logged, and the summaries are retained for at least six months.

    logged, 6-month retention
Where it runs

In your account, read-only, never ours.

The agents run read-only inside your own account. CR26 binds the provider, and the provider is you. Only aggregate counts, one-way digests, a signature, and a rules version reach TRGR.

What is in the package

Generated from live state. Signed by a practitioner.

We generate every artifact CR26 requires from your running system and validate it against the FedRAMP schema. A practitioner reviews and signs before an agency can pull anything. AI drafts the narrative, but never gets the last word.

certification-package · CR26 · validated against the FedRAMP schemasigned by a practitioner
Security Decision Record replaces the SSPFedRAMP JSON
Certification Package OverviewJSON + human
Vulnerability report and POA&MJSON + human
Ongoing certification reportper period
Significant change notification and incident reporton event
After it is signed

The authorization keeps pace with the system.

A package is accurate the day it is signed. Continuous monitoring compares the running system to the authorized baseline, surfaces drift from the approved state, and routes a change to a practitioner. The checking is deterministic, and nothing is applied on its own. You choose the cadence, from one hour to thirty days.

Explore the agent suite

Get this in place before your next assessment.

Book the paid consultation. In 90 seconds we show an agency verifying a package with no human in the loop, then scope the path to yours.

TRGR: FedRAMP certification packages and the CR26 trust center