FedRAMP Ongoing Certification Report — 2026-Q3
Rule: CCM-OCR-AVL / CCM-OCR-NRD. Machine-readable mirror:
2026-Q3.json, schema-valid against
fedramp-ongoing-certification-report-schema-2026-06-24.json.
Report period: 2026-07-01 to 2026-09-08. This is the first Ongoing
Certification Report — no prior certification history exists, which
CCM-OCR-AVL's own artifact note allows for.
Next report due: 2026-12-01 (see
fedramp-certification-package-overview.json).
Changes to FedRAMP Certification Data
- Adopted a FIPS 140-3 validated cryptographic module (OpenSSL FIPS
Provider 3.1.2, NIST doc 140sp4985) in both production images, replacing
a musl-libc base image not covered by any OpenSSL FIPS certificate.
- Completed a full mapping of all 10 real FedRAMP Key Security Indicator
categories (46 indicators, 41 applicable to Class A), correcting an
earlier draft that referenced a category not present in the current
taxonomy.
- Reviewed the Assurance ruleset against the rules that actually govern
applying for Certification (
FRC-CLA-MFR/FRC-CLA-ASF), correcting the
scope of the Ongoing Certification Reporting obligation and identifying
the SOC 2 Type II completion requirement.
- Closed a subprocessor-disclosure sweep, adding 9 previously-undisclosed
third-party data flows to the public subprocessor list.
- Designated a FedRAMP Security Inbox.
- Ran and logged the first quarterly incident-response tabletop exercise,
closing 4 identified gaps in the incident response plan the same day.
Planned changes (through 2026-12-01)
- Complete the SOC 2 Type II audit — the eligibility gate for applying for
FedRAMP Certification.
- Confirm the FedRAMP Marketplace listing is live and publicly resolvable.
- Resolve Trust Center compatibility with the
CDS-TRC rules for a fully
public, unauthenticated Trust Center.
- Apply for FedRAMP Certification (Program path, no agency sponsor) once
SOC 2 Type II completes.
Accepted vulnerabilities
None. No vulnerabilities are currently in an accepted (risk-tolerated,
unremediated) state per the risk register.
Transformative changes
None during this period.
Updated recommendations
- Customers and agencies evaluating Meterbox's cryptographic posture should
note the move to a FIPS 140-3 validated module — documented in
system-boundary.md.
- Incident response guidance updated following the first tabletop exercise
— see incident-response.md's decision tree and
communications templates.
Agencies directly using the product
None yet.
FedRAMP Reportable Incidents
None occurred during this period.