If you are looking for the FedRAMP authorization boundary, the honest answer is that FedRAMP has stopped using the term. The Consolidated Rules for 2026 do not define it. Scope is now set by a ruleset called the Minimum Assessment Scope, and the test it applies is different from the one the old guidance asked.
The concept behind the authorization boundary survives. The diagram you were about to draw does not.
What replaced the FedRAMP authorization boundary

The FedRAMP Consolidated Rules for 2026 gather the rules, definitions and timelines into one public reference. Search the definitions page for “boundary” and you get nothing — the vocabulary is now cloud service offering, information resource and third-party information resource.
Scope lives in a group of rulesets published as The 20x FedRAMP Boundary, of which the Minimum Assessment Scope is one. Its stated purpose is worth quoting because it inverts the old incentive: the rules exist to help providers define assessment boundaries narrowly enough to avoid unnecessary review of components that do not affect the offering’s security, while still covering the resources and connections needed to understand confidentiality, integrity and availability.
Under the legacy model, an over-inclusive FedRAMP authorization boundary was the safe answer. Under this one it is a cost you are being told not to incur.
The authorization boundary test is now a likelihood test
Rule MAS-CSO-IIR sets it out. Providers must identify a set of information resources that includes all information resources likely to handle federal customer data, or likely to impact the confidentiality, integrity or availability of federal customer data handled by the offering — and then states plainly that this set of information resources is the cloud service offering.
Two things follow from that sentence.
Scope is defined by data, not by network topology. The old authorization boundary drawing exercise started from what sits inside your VPC. This one starts from where federal customer data goes and what could affect it. Those are not the same set, and the second one is usually smaller and less obvious.
The offering and the scope are the same object. There is no longer a product on one side and a boundary drawn around part of it on the other. What you scope is what you are certifying.
Flows and categories, for everything
Rule MAS-CSO-FLO requires providers to clearly identify, document and explain information flows and security categories for all information resources, or sets of information resources, in the cloud service offering.
“Explain” is doing real work there. A data flow diagram satisfies “identify” and “document”; it does not on its own explain why a flow exists or why a category was assigned. The rule also allows resources to be grouped into sets, which is the practical relief for anyone with a large estate — you are not required to enumerate every instance.
Anything outside the authorization boundary is now third-party
The definition is mechanical, and it replaces what the authorization boundary used to settle: a third-party information resource is any information resource that is not entirely included in the Minimum Assessment Scope. Note “entirely” — partial inclusion makes it third-party.
Rule MAS-CSO-TPR then requires providers to address the potential impact on federal customer data by documenting, for each one:
- general usage and configuration;
- an explanation or justification for use;
- mitigation measures in place to reduce the potential impact; and
- compensating controls in place to reduce the potential impact.
This is where narrowing scope stops being free. Every resource you exclude reappears here needing a justification and a compensating control. The optimisation is not “make the scope small”, it is “make the scope match where the data actually is”.
The rule that catches people: metadata
MAS-CSO-MDI requires providers to include metadata, including metadata about federal customer data, in the Minimum Assessment Scope.
Logging, telemetry, billing records, support ticket indexes, backup catalogues — systems that hold no federal customer data but a great deal of information about it. Under a topology-drawn authorization boundary these routinely sat outside. Under this rule they are in.
What is outside FedRAMP entirely
One exclusion is worth knowing because it is categorical rather than a scoping judgement. Software produced by a provider that is delivered separately for installation on agency systems and not operated in a shared responsibility model — agents, application clients, mobile applications that the provider does not fully manage — is not a cloud computing product or service and is entirely outside the scope of FedRAMP under the FedRAMP Certification Act.
Certain categories are also placed outside FedRAMP by the Director of the Office of Management and Budget.
The dates that matter
For the 20x path, the Minimum Assessment Scope rules carry an optional adoption and obtain date of 4 July 2026, a maintain date of 1 January 2027, and a grace period that ends on the first FedRAMP independent assessment started after 1 January 2027.
That last one is the deadline to plan against, because it is triggered by your assessment schedule rather than by the calendar. A Rev5 boundary ruleset also still exists for providers on the legacy path.
How the FedRAMP authorization boundary connects
| Area | Connection |
|---|---|
| FedRAMP authorization | What FedRAMP 20x changed about the wider programme, and where the 2026 rules came from |
| Data classification | Security categories under MAS-CSO-FLO are the same exercise, and FIPS 199 is where the levels come from |
| GovRAMP | The state-level programme, for providers selling below the federal tier |
| NIST SP 800-53 | The control catalogue the Rev5 path still runs on |
Where to start
- Stop drawing the authorization boundary from the network diagram and start from where federal customer data is handled.
- Apply the likelihood test in MAS-CSO-IIR to each resource, and record the reasoning.
- Explain your flows and categories, since documenting them is only two thirds of the rule.
- List everything excluded, because each item needs a justification and a compensating control.
- Sweep for metadata systems — logging, telemetry, billing, backup catalogues.
- Work back from your next independent assessment, not from 1 January 2027.
This guide reflects the FedRAMP Consolidated Rules for 2026 as published at fedramp.gov/2026, read at 16 August 2026. FedRAMP is changing quickly and the consolidated rules are versioned — check the changelog before relying on a date.
The FedRAMP Authorization Toolkit provides 43 editable templates covering the scope and information resource records, the information flow and security categorisation documentation, and the third-party resource justifications the Minimum Assessment Scope rules require.