FedRAMP Certification Data Sharing — CDS-CSO-PUB
This page publishes the information required under FedRAMP's Consolidated Rules for 2026 so that federal agencies, government contractors, and the public can review Rohirrim's certification status, contacts, and documentation in one place. This certification effort covers both Rohirrim cloud service offerings.
Rohirrim operates two cloud service offerings on shared infrastructure, currently pursuing FedRAMP 20x Class A Certification. Depending on which side of a solicitation you're on, one of these is the reason this page matters to you.
Classification information applies to the cloud infrastructure being certified for both UnifiedRespond and UnifiedAcquire.
Separate contacts are maintained for commercial and security-related inquiries, consistent with FedRAMP's requirement to route these separately from general support channels.
An overview of the governance documentation supporting this certification, plus guidance for securely configuring and administering the service.
Access Control Policy
FedRAMP · v1.0
Access Control Procedure
FedRAMP · v1.0
Identification and Authentication Policy
FedRAMP · v1.0
System and Communications Protection Policy
FedRAMP · v1.0
System and Information Integrity Policy
FedRAMP · v1.0
Incident Response Policy
FedRAMP · v1.0
Configuration Management Policy
FedRAMP · v1.0
Awareness and Training Policy
FedRAMP · v1.0
Personnel Security Policy
FedRAMP · v1.0
Media Protection Policy
FedRAMP · v1.0
Risk Assessment Policy
FedRAMP · v1.0
Physical and Environmental Protection Policy
FedRAMP · v1.0
Maintenance Policy
FedRAMP · v1.0
Rohirrim's FedRAMP Marketplace listing was approved on August 21, 2026 (FedRAMP ID FR2632436493). The fields below will be completed as each subsequent milestone toward full Certification is reached, rather than filled in advance.
Align engineering security training with Rohirrim's own Secure Development Policy
Target: Q4 2026
Complete independent verification of automated account lifecycle management
Target: Q4 2026
Close remaining enhancements identified in our annual incident response exercise
Target: Q4 2026