Blog

FedRAMP Now Requires a Trust Center and It Has to Be Machine-Readable

August 19, 2026
Share

If you hold a FedRAMP certification, or you're working toward one, the rules just changed and you need to take action. You’re now required to provide a trust center. And one that humans and machines can read alike. 

FedRAMP published its Consolidated Rules for 2026 on June 24. Inside them is a ruleset called Certification Data Sharing, and it creates two new obligations:

  1. You must use a trust center to store and share your FedRAMP certification data.
  2. That trust center must be programmatically accessible — an agency has to be able to pull all of your certification data through an API or connector, without a human in the loop.

The first one is a procurement problem. The second one is the one that will catch most providers, because almost no trust center on the market can do it.

Start with the hard part: programmatic access

Here's the rule, CDS-TRC-PAC, in full:

Trust centers MUST provide documented programmatic access to all FedRAMP Certification Data, including programmatic access to human-readable materials.

Read that against how your trust center works today. A visitor lands on a page, logs in, waits on a one-time email code or completes an OAuth flow, clicks through an NDA gate, then downloads a PDF.

That's a wall only a human can climb. An agency running its own risk management platform hits it and stops. So does an agency pointing an AI agent at your trust center, which is increasingly how this work gets done.

Two details make this harder than it first looks:

  • "All certification data." Not just the public overview page. Your certification data is generally gated, so it isn't enough to expose a public JSON file and call it done. The gated material has to be reachable programmatically too.
  • "Including programmatic access to human-readable materials." Your SOC 2 report, your policies, your SSP, the actual PDFs and documents. Not just metadata about them.

And CDS-TRC-USH, the companion rule, closes the obvious workaround. "Uninterrupted sharing" means no manual approval on every request. FedRAMP explicitly names just-in-time access provisioning as the preferred model. A "email us and we'll send you a link" process doesn't satisfy this, and neither does a person approving each agency one at a time.

This is the requirement to evaluate your trust center against first. If it can't do this, nothing else on the list matters.

The rest of what FedRAMP-compatible means

"FedRAMP-compatible" isn't a marketing term. FedRAMP defines it with six rules:

Rule Requirement Strength
CDS-TRC-PAC Programmatic access. Documented programmatic access to all certification data, including the human-readable materials. MUST
CDS-TRC-USH Uninterrupted sharing. No manual approval on every request. Just-in-time provisioning preferred. MUST
CDS-TRC-AAI Agency access inventory. An inventory and history of every federal agency user or system with access, available to FedRAMP on request. MUST
CDS-TRC-ACL Access logging. Log all access, keep summaries at least six months, and share them with the accessing party on request. MUST
CDS-TRC-HMR Human and machine-readable data. Certification data viewable and downloadable in both formats. SHOULD
CDS-TRC-SSM Self-service access management. Let agencies provision and manage access for their own users and services. SHOULD

The core rule that pulls all of this in is CDS-CSO-UTC:

Providers MUST use a FedRAMP-compatible trust center to store and share FedRAMP Certification Data with all necessary parties.

Not "may." Not "should." MUST. If you're certified under 20x or Rev5, on the Program or Agency path, at Class B, C, or D, this applies to you.

The requirements that land on you, not your trust center

A few more rules shape what you'll need your trust center to support:

  • CDS-CSO-PUB — Publish 16 specific data points about your service offering in both human-readable and JSON formats, including a link to a trust center landing page with access instructions.
  • CDS-CSO-CBF — Use automation to keep human-readable and machine-readable versions consistent. Maintaining a second copy by hand isn't compliant.
  • CDS-CSO-IRP — Every policy and procedure needs a human- and machine-readable reference: name, filename, summary, word count, version, last-updated date, and related FedRAMP Practices.
  • CDS-CSO-HAD — Keep point-in-time snapshots of your certification data tied to each Ongoing Certification Report, for the life of your certification.
  • CDS-CSO-AVR — Maintain an availability service covering at least 30 days, in both formats, that stays up even when your product doesn't.
  • CDS-UTC-AAD — Deny an agency's access request and you have five business days to notify FedRAMP.
  • CDS-CSF-TCM — Migrating from USDA Connect? Notify FedRAMP and every agency customer, and leave instructions behind in your old secure folders.

Your deadlines

Milestone 20x Rev5
Optional adoption July 4, 2026 July 4, 2026
Obtain July 4, 2026 January 1, 2027
Maintain January 1, 2027 August 1, 2027
Grace ends First independent assessment started after Jan 1, 2027 February 1, 2028

January 1, 2027 is the date to plan around. If you're on 20x, that's when maintain obligations start. If you're on Rev5, that's when you need this in place. Either way you have months, not quarters.

If you don't have a trust center yet

You're not behind in the way you might think. Plenty of providers have shared certification data through USDA Connect, secure file shares, or email, and that was fine until June.

What's different now is that the destination is specified. You need a trust center, and standing one up is no longer a project competing for budget against everything else. It's a line item on your certification.

The good news: the requirements above are a clear spec, so you can evaluate options directly instead of guessing. Lead with the programmatic access question. Ask any vendor to show you documented, machine-accessible retrieval of gated documents, not the public page, the real certification data. That one question will narrow the field fast.

How Conveyor meets these requirements

Conveyor is the only trust center that's programmatically accessible today. We deliver it two ways, a trust center API and an MCP server, so an agency can pull your certification data with whatever they already run.

Programmatic access (CDS-TRC-PAC). Our trust center API gives agencies documented, machine-readable access to your certification data. Our AI Connector does the same thing for agents: an agency adds the Conveyor visitor MCP server to Claude, ChatGPT, Gemini, or whatever they use, authenticates once with their work email, and their agent finds and downloads the documents they're entitled to, public or gated, and asks your trust center agent follow-up questions. Both paths cover all certification data, including the human-readable materials.

Uninterrupted sharing (CDS-TRC-USH). Access rules run automatically against the visitor's authenticated identity. Access groups, gated folders, click-wrap NDA, and CRM-based auto-approval against Salesforce all apply the same way they do for a human visitor. Nobody on your team approves requests one at a time.

Access logging (CDS-TRC-ACL). Sign-ins, documents accessed, and questions asked are all recorded and feed your per-customer audit trail and analytics.

Agency access inventory (CDS-TRC-AAI). You can see exactly which agencies have access, what they accessed, and when — and produce that inventory when FedRAMP asks.

Human and machine-readable data (CDS-TRC-HMR). Everything in your trust center is available in both formats, kept in sync automatically.

Self-service access management (CDS-TRC-SSM). Agencies provision and manage access for their own users and systems directly, including their agents.

Your access controls don't change. Programmatic access doesn't mean open access. An agent whose human isn't approved for a document doesn't get the document. It can request access, and you approve, deny, or gate behind an NDA exactly like you always have. Watermarking works the same too.

Turning it on

If you're already a Conveyor customer, go to Settings > Trust Center > Trust Center Agent and enable Enable visitors to connect via MCP.

Full documentation is at docs.conveyor.com/docs/visitor-ai-connector.

If you're evaluating trust centers with January 2027 in mind, get in touch and we'll walk through the requirements against what you have today.