FedRAMP OSCAL September 30 Mandate: What AI Vendors Need to Know

The US Federal Risk and Authorization Management Program (FedRAMP) has mandated that effective 30 September 2026, all cloud service offerings seeking federal authorisation must submit their System Security Plans (SSPs) in machine-readable OSCAL (Open Security Controls Assessment Language) format. OSCAL — developed by NIST and maintained at pages.nist.gov/OSCAL — replaces PDF-based SSPs with structured XML/JSON/YAML artifacts that automated tools can ingest, validate, and cross-reference against NIST SP 800-53 control baselines. For AI vendors seeking FedRAMP authorisation, this deadline carries two layers of implication.

First, the compliance layer: AI systems that process federal data must now produce OSCAL-compliant SSPs covering their model training pipelines, inference APIs, data provenance records, and supply-chain components — a materially larger scope than traditional IaaS/PaaS authorisations. Second, the measurement layer: the Council of AI's verified measurement credential format is designed to be emitted as an OSCAL-adjacent artifact, meaning that AI-specific measurement evidence (governance scores, Art-5 screening results, care-obligation adherence metrics) can be embedded alongside traditional NIST 800-53 control attestations. This creates a single machine-readable authorisation package: the OSCAL SSP says what controls are in place; the verified measurement credential says what those controls actually measured.

For AI vendors in the federal pipeline, the Sept-30 mandate is the forcing function to move from narrative self-attestation to machine-readable, independently verifiable measurement evidence. The Council of AI's measurement board produces OSCAL-compatible attestation artifacts today.

Standards and sources referenced

  • FedRAMP OSCAL Adoption Memorandum (GSA, March 2026)
  • NIST OSCAL Specification v1.1 (pages.nist.gov/OSCAL)
  • NIST SP 800-53 Rev. 5 Security and Privacy Controls
  • FedRAMP AI System Authorisation Boundary Guidance (draft, August 2026)
  • Council of AI Verified Measurement Credential — OSCAL Compatibility Profile
  • OMB M-24-10 (Advancing Governance, Innovation, and Risk Management for Agency Use of AI)