---
kind: "section"
citation: "44 U.S.C. § 3613"
title: "44"
title_heading: "Public Printing and Documents"
number: "3613"
heading: "Roles and responsibilities of agencies"
release: "119-102"
date: "2026-07-12"
url: "https://uscodex.org/usc/44/3613"
units:
  - "Chapter 36 — Management and Promotion of Electronic Government Services"
---

# §3613. Roles and responsibilities of agencies

- (a) **In General.—** In implementing the requirements of [FedRAMP](/usc/44/3607.md?p=b-6), the head of each agency shall, consistent with guidance issued by the Director pursuant to [section 3614](/usc/44/3614.md)—
  - (1) promote the use of [cloud computing](/usc/44/3607.md?p=b-4) products and services that meet [FedRAMP](/usc/44/3607.md?p=b-6) security requirements and other risk-based performance requirements as determined by the Director, in consultation with the [Secretary](/usc/44/3607.md?p=b-11);
  - (2) confirm whether there is a [FedRAMP authorization](/usc/44/3607.md?p=b-7) in the secure mechanism provided under [section 3609(a)(8)](/usc/44/3609.md?p=a-8) before beginning the process of granting a [FedRAMP authorization](/usc/44/3607.md?p=b-7) for a [cloud computing](/usc/44/3607.md?p=b-4) product or service;
  - (3) to the extent practicable, for any [cloud computing](/usc/44/3607.md?p=b-4) product or service the agency seeks to authorize that has received a [FedRAMP authorization](/usc/44/3607.md?p=b-7), use the existing assessments of security controls and materials within any [FedRAMP authorization package](/usc/44/3607.md?p=b-8) for that [cloud computing](/usc/44/3607.md?p=b-4) product or service; and
  - (4) provide to the Director data and information required by the Director pursuant to [section 3614](/usc/44/3614.md) to determine how agencies are meeting metrics established by the [Administrator](/usc/44/3601.md?p=1).
- (b) **Attestation.—** Upon completing an assessment or authorization activity with respect to a particular [cloud computing](/usc/44/3607.md?p=b-4) product or service, if an agency determines that the information and data the agency has reviewed under paragraph [(2)](#a-2) or [(3)](#a-3) of subsection (a) is wholly or substantially deficient for the purposes of performing an authorization of the [cloud computing](/usc/44/3607.md?p=b-4) product or service, the head of the agency shall document as part of the resulting [FedRAMP authorization package](/usc/44/3607.md?p=b-8) the reasons for this determination.
- (c) **Submission of Authorizations to Operate Required.—** Upon issuance of an agency [authorization to operate](/usc/44/3607.md?p=b-3) based on a [FedRAMP authorization](/usc/44/3607.md?p=b-7), the head of the agency shall provide a copy of its [authorization to operate](/usc/44/3607.md?p=b-3) letter and any supplementary information required pursuant to [section 3609(a)](/usc/44/3609.md?p=a) to the [Administrator](/usc/44/3601.md?p=1).
- (d) **Submission of Policies Required.—** Not later than 180 days after the date on which the Director issues guidance in accordance with [section 3614(1)](/usc/44/3614.md?p=1), the head of each agency, acting through the chief information officer of the agency, shall submit to the Director all agency policies relating to the authorization of [cloud computing](/usc/44/3607.md?p=b-4) products and services.
- (e) **Presumption of Adequacy.—**
  - (1) **In general.—** The assessment of security controls and materials within the authorization package for a [FedRAMP authorization](/usc/44/3607.md?p=b-7) shall be presumed adequate for use in an agency [authorization to operate](/usc/44/3607.md?p=b-3) [cloud computing](/usc/44/3607.md?p=b-4) products and services.
  - (2) **Information security requirements.—** The presumption under [paragraph (1)](#e-1) does not modify or alter—
    - (A) the responsibility of any agency to ensure compliance with subchapter II of [chapter 35](/usc/44/chch35.md) for any [cloud computing](/usc/44/3607.md?p=b-4) product or service used by the agency; or
    - (B) the authority of the head of any agency to make a determination that there is a demonstrable need for additional security requirements beyond the security requirements included in a [FedRAMP authorization](/usc/44/3607.md?p=b-7) for a particular control implementation.

## Source credit

(Added Pub. L. 117–263, div. E, title LIX, § 5921(b), Dec. 23, 2022, 136 Stat. 3453.)

## Notes

### Repeal of Section

For repeal of section by section 5921(d)(1) of Pub. L. 117–263, see Effective Date of Repeal note below.

### Statutory Notes and Related Subsidiaries

### Effective Date of Repeal

Pub. L. 117–263, div. E, title LIX, § 5921(d)(1), Dec. 23, 2022, 136 Stat. 3458, provided that the repeal of this section is effective on the date that is 5 years after Dec. 23, 2022.

### Construction

For rule of construction regarding section 5921 of Pub. L. 117–263, see section 5921(e) of Pub. L. 117–263, set out as a note under section 3607 of this title.
