Scope: For users seeking a first-time Marketplace listing as initial implementation, or CSPs submitting a JSON package to update the content of an existing listing.
User Expectations:
- Use the Marketplace Listing Request Form or request a new FedRAMP Marketplace listing or to request updates to an existing listing.
- The JSON should be publicly accessible without authentication, approval workflows, or access justification and follow the Certification Package Overview (FRC-CSO-PKG) rules
- The URL you provide should point directly to the JSON package endpoint or a raw GitHub link to the JSON file on the main branch; not to a general website, Google/Box drive, Trust Center, or landing page.
- Use the FRC-CSO-PKG Schema Validator to ensure your JSON data matches the requirements for submission, and can be fetched from the URL.
- If the CSP has already provided FedRAMP with its Certification package JSON, content updates MUST be made directly in the existing JSON URL by the CSP.
- CSPs MUST NOT submit a new form to request manual content changes.
- If the URL does change, the CSP must provide the new URL to FedRAMP using the Marketplace Listing Request Form and select “update listing.”
Estimated Timeline:
- Marketplace Publication: 3-5 business days after approval