FedRAMP 20x: Handle Denied Agency Package Access Requests
For providers using a FedRAMP-compatible trust center instead of USDA Connect, CDS-UTC-AAD requires notification within five business days of denying an agency request for Certification Data. Record the decision and notify through the official form while preserving broader sharing obligations.
In this article
Main question
When does a Class B/C provider need to notify FedRAMP about denied agency access?
When an agency's request for package access is denied, the decision needs a clear owner and a reliable notification path. For Class B and C providers using a FedRAMP-compatible trust center instead of USDA Connect, FedRAMP 20x agency access denial notification has a specific trigger and a five-business-day timeframe.
Confirm that the trust-center subset applies
The Using a Trust Center subset applies to providers using a FedRAMP-compatible trust center instead of USDA Connect. It expressly does not apply to providers using USDA Connect. Check that applicability before building an operating procedure around CDS-UTC-AAD.
Under CDS-UTC-AAD, providers MUST notify FedRAMP within five business days of denying an agency access request for Certification Data. The rule directs providers to the official [CSP] Agency Access Denial form.
Keep the triggering decision clear. A failed login, expired invitation or temporary retrieval error does not by itself establish that an agency access request was denied. Investigate what happened and identify the actual request and decision before classifying an event. Do not let that investigation become an excuse to lose track of an actual denial and its notification window.
Record the decision while its context is available
As an operating practice, record the requesting agency, the offering and FedRAMP identifier, the requested materials, the decision time, the rationale and the responsible owner. Keep the original request and decision evidence linked to that record. These fields are an internal workflow suggestion, not a new FedRAMP form specification.
Assign a notification owner when the denial is recorded. Track the five-business-day window from the denial and retain the submission evidence. A second owner can cover absence or a handoff, so the notification does not depend on one person's memory.
For example, a support ticket may start as a broken-link complaint and later reach a formal access decision. Preserve both events and their timestamps. Treat technical troubleshooting and the access decision as distinguishable work, so the team can explain which event triggered the notification.
Preserve the broader access obligations
CDS-UTC-AGA says providers SHOULD supply agencies access to the Certification Package upon request. Separately, CDS-TRC-USH requires trust centers to share Certification Data with all necessary parties without interruption. The denial-notification rule does not grant permission to withhold data or create a list of approved reasons for denial.
Review an access decision against the applicable sharing obligations. Use the responsible package-sharing guidance when deciding how to present sensitive details without obscuring risk information. Our agency package-handoff guide addresses the earlier delivery workflow.
The five-business-day notification is a report after a denial; the rule does not describe an advance-approval process. Avoid inventing an internal sign-off chain that makes timely notification depend on waiting for unrelated approvals.
Close the notification loop
Keep the submission reference with the decision record and assign any follow-up correspondence to an owner. If access is later supplied, preserve that later event as part of the history. The operational goal is a reconstructable sequence from request to decision, notification and subsequent action.
The CDS adoption page lists optional and initial certification adoption from July 4, 2026, ongoing adoption on January 1, 2027, and grace until the first independent assessment started after January 1, 2027. These are adoption milestones; the five-business-day period is tied to a denied request. Test the workflow with a sample decision and confirm that the owner can find the official form and the supporting record.
Frequently asked questions
Does this subset apply to providers using USDA Connect?
No. The Using a Trust Center subset expressly applies to compatible trust centers instead of USDA Connect and excludes providers using USDA Connect.
Does every failed login trigger denial notification?
The rule's trigger is denial of an agency access request for Certification Data. A technical login failure alone does not establish that decision; investigate and record what actually occurred.
Does notifying FedRAMP authorize withholding Certification Data?
CDS-UTC-AAD establishes notification after a denial, not permission to withhold data. Preserve the separate agency-access recommendation and uninterrupted-sharing requirement.
Next step
If you want to turn this guidance into an execution plan, the product side handles control mapping, SSP drafting, and evidence collection.
Related articles
FedRAMP 20x: Do You Need a Separate Government Deployment?
Compare shared and dedicated deployment designs for Class B/C using the shared-infrastructure policy, actual assessment scope and agency needs.
FedRAMP 20x: Reconcile Agency Access Records in Your Trust Center
Reconcile Class B/C trust-center permission history and access activity, with the right six-month summary retention and request-specific retrieval.
FedRAMP 20x: Handle FedRAMP-Issued Certification Reports
Handle FedRAMP-issued reports for Class C offerings, preserve the received material and track the two-week availability requirement from receipt.