A "FedRAMP Compatible Trust Center" is any secure repository or service used by a cloud service provider to store and share FedRAMP Certification Data. Trust centers must follow the FedRAMP Certification Data Sharing rules to be FedRAMP-compatible but do not need to be FedRAMP certified. For example, a cloud service provider could host a WordPress site that stores and shares FedRAMP Certification Data hosted by any WordPress hosting service. The WordPress PaaS provider would not need to be FedRAMP certified.
A trust center may contain some data that is available anonymously as well as data that is available only to authorized users or groups. Cloud service providers can host their own trust center or use a third-party service to host their trust center. In either case the trust center must meet the requirements in the CDS-TRC (https://www.fedramp.gov/2026/providers/20x/rules/certification-data-sharing/?h=CDS-TRC#fedramp-compatible-trust-centers) Rules.
Logging Requirements
CDS-TRC-AAI Agency Access Inventory specifically requires the cloud service provider to maintain a record of who has access to a system and not a log of who actually used that access. If content is available anonymously, it is sufficient to record that the information is available to everyone.
CDS-TRC-ACL Access Logging does require the cloud service provider to maintain a log of access. If the Trust Center requires authentication, then the log should include the user and the time of access. But for content that is available anonymously, it is sufficient to record that the information was accessed along with the source IP address of the request and the time of access.
CDS-TRC-PAC Programmatic Access requires that the trust center data be available through a programmatic interface. This means that the data can be accessed by a third-party application or script without requiring human interaction.