Files
republic-os/legal/us/code/title-44/chapter-36/section-3613.md
T
Fabio 76b8ec33a7 Legal corpus: the complete U.S. Code (59,740 sections, all 53 titles)
Ingested titles 12–51 and 54 from OLRC USLM XML @119-100 (the whole Code
now, uniform edition; Title 53 is reserved/empty). LegalText 11,221 ->
59,740; repo total 105,704 records. Deterministic (byte-identical rerun,
verified on Title 42's 8,356 sections); make check green. make
legal-us-code default now covers every title.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-06 10:51:44 -04:00

4.7 KiB
Raw Blame History

type, title, description, jurisdiction, corpus, kind, title_number, title_name, chapter_number, chapter_name, section, citation, status, release_point, release_date, source, source_url, source_identifier, source_file, source_hash, raw_snapshot_hash, text_hash, retrieved_at, confidence, tags
type title description jurisdiction corpus kind title_number title_name chapter_number chapter_name section citation status release_point release_date source source_url source_identifier source_file source_hash raw_snapshot_hash text_hash retrieved_at confidence tags
LegalText 44 U.S.C. § 3613 Roles and responsibilities of agencies us united_states_code code_section 44 PUBLIC PRINTING AND DOCUMENTS 36 MANAGEMENT AND PROMOTION OF ELECTRONIC GOVERNMENT SERVICES 3613 44 U.S.C. § 3613 current 119-100 2026-06-26 official https://uscode.house.gov/download/releasepoints/us/pl/119/100/xml_usc44@119-100.zip /us/usc/t44/s3613 data/legal/raw/us/code/title-44/usc44.xml 20b1e510efb6f18e20f8373038680aa2f422792507b54c93afe29290d2efe51e 2d7109056b4815718203e8d99c9ee6fe3ab744f578883b59654fe3adb211b4a0 1f9dc0ae267aaa65adb9aca4cfc7f1581da0c03481ef04f6efe7b3711ddc6aab 2026-07-04 official
legal
us-code

44 U.S.C. § 3613 - Roles and responsibilities of agencies

Text

(a) In General.— In implementing the requirements of FedRAMP, the head of each agency shall, consistent with guidance issued by the Director pursuant to section 3614—

(1) promote the use of cloud computing products and services that meet FedRAMP security requirements and other risk-based performance requirements as determined by the Director, in consultation with the Secretary;

(2) confirm whether there is a FedRAMP authorization in the secure mechanism provided under section 3609(a)(8) before beginning the process of granting a FedRAMP authorization for a cloud computing product or service;

(3) to the extent practicable, for any cloud computing product or service the agency seeks to authorize that has received a FedRAMP authorization, use the existing assessments of security controls and materials within any FedRAMP authorization package for that cloud computing product or service; and

(4) provide to the Director data and information required by the Director pursuant to section 3614 to determine how agencies are meeting metrics established by the Administrator.

(b) Attestation.— Upon completing an assessment or authorization activity with respect to a particular cloud computing product or service, if an agency determines that the information and data the agency has reviewed under paragraph (2) or (3) of subsection (a) is wholly or substantially deficient for the purposes of performing an authorization of the cloud computing product or service, the head of the agency shall document as part of the resulting FedRAMP authorization package the reasons for this determination.

(c) Submission of Authorizations to Operate Required.— Upon issuance of an agency authorization to operate based on a FedRAMP authorization, the head of the agency shall provide a copy of its authorization to operate letter and any supplementary information required pursuant to section 3609(a) to the Administrator.

(d) Submission of Policies Required.— Not later than 180 days after the date on which the Director issues guidance in accordance with section 3614(1), the head of each agency, acting through the chief information officer of the agency, shall submit to the Director all agency policies relating to the authorization of cloud computing products and services.

(e) Presumption of Adequacy.— (1) In general.— The assessment of security controls and materials within the authorization package for a FedRAMP authorization shall be presumed adequate for use in an agency authorization to operate cloud computing products and services.

(2) Information security requirements.— The presumption under paragraph (1) does not modify or alter—

(A) the responsibility of any agency to ensure compliance with subchapter II of chapter 35 for any cloud computing product or service used by the agency; or

(B) the authority of the head of any agency to make a determination that there is a demonstrable need for additional security requirements beyond the security requirements included in a FedRAMP authorization for a particular control implementation.

(Added Pub. L. 117263, div. E, title LIX, § 5921(b), Dec. 23, 2022, 136 Stat. 3453.)

Notes

Repeal of SectionFor repeal of section by section 5921(d)(1) of Pub. L. 117263, see Effective Date of Repeal note below.

Statutory Notes and Related Subsidiaries

Effective Date of RepealPub. L. 117263, div. E, title LIX, § 5921(d)(1), Dec. 23, 2022, 136 Stat. 3458, provided that the repeal of this section is effective on the date that is 5 years after Dec. 23, 2022.

ConstructionFor rule of construction regarding section 5921 of Pub. L. 117263, see section 5921(e) of Pub. L. 117263, set out as a note under section 3607 of this title.