Behind the Shield

FedRAMP CR26 Explained: What the 2026 Consolidated Rules Mean for CSPs

InfusionPoints Season 1 Episode 41

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 23:04

In this bonus episode of Behind the Shield, we’re breaking down one of the biggest FedRAMP updates of the year: the release of the FedRAMP Consolidated Rules for 2026, also known as CR26.

FedRAMP has been moving quickly, and for cloud service providers, agencies, assessors, advisors, and anyone working in the federal cloud ecosystem, CR26 marks an important shift toward a more unified, structured, and transparent approach to FedRAMP certification. Instead of navigating scattered updates, public notices, RFCs, legacy documentation, and evolving pilot language, the Consolidated Rules for 2026 are designed to bring the program’s expectations together into one clearer reference point.

In this timely bonus conversation, the InfusionPoints team walks through what CR26 means in practical terms, why it matters now, and how organizations should begin thinking about the transition. The discussion covers how the rules impact FedRAMP 20x, Rev5, certification classes, the Marketplace, machine-readable requirements, and the broader move away from static, narrative-heavy compliance toward structured, automation-friendly security evidence.

This episode is especially relevant for cloud service providers evaluating their FedRAMP strategy, teams preparing for Class A, B, C, or D certification paths, organizations currently working through Rev5, and stakeholders trying to understand where FedRAMP 20x fits into the future of the program.

Chapters: 
00:00 — Consolidated Rules Overview
01:08 — Rule Automation and Management
05:46 — Initial Implementation Phase
08:09 — Key Dates and Deadlines
14:10 — Certification Paths and Timelines
19:48 — AI, Documentation, and Resources

What You’ll Learn:

• What the FedRAMP Consolidated Rules for 2026 are and why they matter
• Why CR26 is more than just another policy update
• How FedRAMP is organizing rules, definitions, timelines, and responsibilities
• What the shift to FedRAMP Certification language means for CSPs and agencies
• How certification classes are changing the way stakeholders talk about FedRAMP baselines
• What CR26 signals about the future of FedRAMP 20x and Rev5
• Why machine-readable requirements and structured evidence are becoming increasingly important
• How cloud service providers should think about transition planning
• Key dates and milestones organizations need to keep on their radar
• The importance of understanding applicability, responsibilities, and timing before making major program decisions

Resources: 
Consolidated Rules- https://www.fedramp.gov/2026/
Important Dates Table- https://preview.fedramp.gov/2026/timeline/
https://infusionpoints.com/blogs/fedramp-consolidated-rules-2026-cr26-released

Learn more about InfusionPoints:
https://www.linkedin.com/company/infusionpoints/
Jason Shropshire: https://www.linkedin.com/in/shrop/
Chad Spears: https://www.linkedin.com/in/chad-spears007/
Tanner Bailey: https://www.linkedin.com/in/tanner-b-37a50a132/
Request a Demo: https://xbu40.com/
FedRAMP 20x Quick Look Assessment: https://xbu40.com/assessment

InfusionPoints & AWS:
InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments.

About Us:
InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.
We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.
Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

unknown

Cool.

SPEAKER_01

I was getting ready to ask, are we recording?

SPEAKER_02

I I literally we got like you you started riffing off of what I said and I was like, I guess we're recording. Yeah. So if you're joining us today, we are uh we're gonna be talking about Consolidated Rules 2026. It's uh it's June 25th at about 240, about a time about the time of recording this. Uh consolidated rules have been out for less than 24 hours, and we are excited, but we know a lot of people are very confused, and a lot of people are very excited just like us.

SPEAKER_00

So we're getting out of here. I know one thing, you know, going through it today. I haven't had time to to to get through everything, um, because it's it's it's a lot of information, right? I feel really bad for anybody who's been just waiting for this and not really staying up to date with what's going on because it's there there's uh there's a lot here. Sure.

SPEAKER_01

Yeah, absolutely. Yeah, big tsunami wave. And we were just speaking uh prior to officially going live with the podcast here and riffing back and forth. I know I've had a brief moment to jump on the site, and one of the things I mentioned as well is it's a whole new look and feel. Go to fedramp.gov if you've not been there yet and check it out. Um, very, very little mention of Rev5. I think you're speaking to the as a as legacy. Jason, you mentioned that yeah, the information is still there, but you got to go dig for it. It's it's in the archives, so you can still find that information, but it definitely shows everything that we've been hearing and everything that we've been putting out there for the public on the podcast about 20x, that 20x is the future and 20x is here to stay. And so I think that's very important for us to see. And I know everybody was sitting back waiting on these uh consolidated rules to to release and um could have been watching them the whole time in the in the GitHub repo.

SPEAKER_00

Yeah, yeah.

SPEAKER_02

Yeah, and I was uh you saying that, you know, people have been waiting. I, you know, I know we've been heavily involved, you know, you know, Chad and you and I and Alex and the team especially, but I kind of regret not diving into the preview more than I did. Yeah. Just because it's that there's there's some structural changes here. So if you've been in in line with the KSIs and what were called the balance improvements, yeah, then there's some changes here. Uh it took me a minute to wrap my mind around it this morning, slash yesterday evening, but um so some some major uh terminology changes. Uh the balance improvements was the term that FedEp was using for things like VDR, authorization data sharing, um significant change or excuse me, secure configuration guide, significant change notification. Those are now called rule sets, right? Moving away from the modernization language as far as the like the temporary or the uh the placeholder language into the finalized rules. So you have your rule sets, which what they just if you've been involved, they were the balance improvements, or the rule sets are more like the how do you do FedRAMP as a framework, as a like operational body. Right. And then you have your KSIs, which are still rules, but they're your key security indicators inside of your environment. Yeah.

SPEAKER_00

So yeah, it's really more of what you're what you're op the KSIs are what you're operationalizing, right? Yes. Right. And and then the rules are more about the process to get there.

SPEAKER_02

Yeah, how do you apply? Yeah, how do you interact with your agency? Um, how do you pivot if you need to pivot from one level to another?

SPEAKER_00

That's a good point. It's it's like a full life cycle. Yeah. Yeah.

SPEAKER_02

Yeah.

unknown

Yeah.

SPEAKER_02

So that's something. And uh one thing that we wanted to also call and just make sure that the rule sets, we highly recommend having the same level of scrutiny on the rule sets as far as proving you're following the rule sets that you do with the KSIs.

SPEAKER_00

Yeah.

SPEAKER_02

You know, it's gonna be better if you automate your rule sets. Right. It's gonna be better if you automate just like you automate your KSIs. If you can prove that, like specifically like certification, excuse me. It's called certification data sharing. Now it was called authorization data sharing. So formerly, the balance improvement known as authorization data sharing or ADS is now CDS certification data sharing. That lines up with all the terminology changes that uh Pete and team have promised and have now fulfilled. That's uh one of the main themes I'm seeing here is fulfillment of promises.

SPEAKER_00

Um Yeah, and uh, you know, the the thing that stuck out to me too is is um you know, we've all wondered like, gosh, well, you what why the setback in the date, you know, that's happened a couple times. And but when you see the the vast you know expanse of change to the whole FedRAMP program, you know, based on this, including the Red Five side, well, it makes total sense now. Like this is so integrated together that it all had to be done as a as one big body of work, right? And you have to grind through the whole thing in order to do a release like this.

SPEAKER_01

Yeah, well and you know, with that, I I kind of appreciate the the path that they took right through this, right? Even the pilot phase and everything, and even the terminology, right? You were just speaking of balance improvements, and now it's okay. Uh even in that balance improvement uh period, people had the opportunity to post comments and and kind of give their thoughts on it. And now it's it's like, okay, hey, we we took a period of time, we took those comments, and now it's a hard rule, like that this is it. Um, and going to what you were saying, right? It's like it all had to happen together. Um and and and I'm you you stated, right? It's it's a fulfillment of promises, right? These things have been spoke about. Um, but seeing it out there live on the website now is actually really, really promising in my book, um, because it shows that, hey, this is the future. Um, and this stuff is coming to life. And so heads down, future points will continue.

SPEAKER_00

I mean, to Tanner and I got to cut a podcast today with with one of our uh really good customers and partner. And um, you know, we've we've been we were taking them down the old way. I mean, we've been engaged with them for a couple of years uh as a provider, putting putting them on flat on platform, worked with them as as um, you know, they had contract issues um that that arose just just because of the change of administrations and all. And um it's like we're at this, I feel like we're at this midpoint where it's like halftime and we're kind of huddling, and it's like it's gonna be a whole different game in the second half with them. Let's adjust, yeah. We're really looking forward to to seeing how that plays out. It's gonna be a great story, I think.

SPEAKER_01

It is. And there's so many people when we were out at RamCon, we heard this exact same scenario, right? It's like, hey, man, I've I've already had investment and and went down this Rev 5 path. Now what? Um, and the fact remains is like it's it's not all hope lost, right? There's still a path for you there. Pete even spoke to that as well. Um, and again, we're seeing that if he speaks it, there's there's promise there, and yeah, we'll see it come to fruition. It may take some time. Um, but the fact is, is we can still help our customers do both or or transition if they will, right? And so uh that's the great thing about our platform, just throwing that in in there. xb40.com, go check it out.

SPEAKER_02

Yeah, well, and you know, as we were looking through the balance improvements when they were initially announced, you know, they were optional for Rev5. And now they're the rule sets, you know, the the the final version of said balance improvements, they are required for Rev5. And because of that, I'll be honest, the balance the rule sets, excuse me, still getting used to these new terms. Yeah, the rule sets were for us because we already had the security built in to the platform, the rule sets were probably the hardest part for us to wrap our minds around. Yeah. Uh and you know, they also include things like Vader or VDR, which are like fundamental changes in comparison to what the Rev5 path looked like.

SPEAKER_00

So we've known the controls and how to implement implement the controls for a long time, right? But the structure of the program and how to work a customer into the program and through the paces, the continuous all that has changed, right? Or it's a lot of terminology's changed. Yeah.

SPEAKER_02

And thankfully, since we've been through, we're gonna be able to use our pilot experience through the class B and C pilots to really just apply what we learn directly to our Rev5 customers and also prepare them for the eventual, you know, discontinuation of Rev5. Right. Um, or transition to 20X just once the industry sees that it is gonna be better in the launch.

SPEAKER_01

Right. Yeah, I think there's so much to be said about the fact of those companies that jumped in early on the pilot because I couldn't imagine coming into this, you know, and not being a part of the pilot and trying to come in and figure all this terminology change out and everything. Yeah. Um, it's really allowed us to stay ahead of things and uh even in a lot of times give our input as well.

SPEAKER_02

Well, first corrective actions come in in less than five months. Yep. Right. You know, the uh VDR, uh the FedRamp notice, I want to say it was number 14, but no one checked my I checked my mouth on that. But um they with their alignment with CISA, the most recent SISA BOD document, they had to push the timeline up for VDR to December, first week of December. Right. And that's that's like two months faster than I think a lot of people were expecting. And it's not December, that's not when it starts to apply, that's when you start to get corrective action.

SPEAKER_00

Yeah.

SPEAKER_02

And then after the end of the grace period, you lose your certification. So it's it's fast. If you haven't been paying attention, I my heart goes down to you.

SPEAKER_00

Oh, I know, yeah. I mean we saw um a reaction in um in in um I think in the comments uh on uh a change that was made to to Red Five and the controls about you know removing the parameter uh the parameters from all the red five controls, right? And uh, you know, there was there were some folks who were you know had a heartburn over that. But um I mean I think effectively FedRamp has deparamified um the controls.

SPEAKER_02

Yeah.

SPEAKER_00

Yeah.

SPEAKER_02

Yeah, it's it's it and it goes to the build your own story. I thought our um our our partner, our customer selects partner earlier today, he had some really good insight in talking through you know, hey, the agency, you know, you they know the application or the engineers know the application and the system better than the agency is going to. And the agency doesn't have the staff to decry, you know, decrypt all of your your processes. They need it to be explained to them by the people that know it the best. Yeah. And then build the right story and prove that and instead of imposing some parameter requirement.

SPEAKER_00

Exactly. Yeah.

SPEAKER_02

Because they're they're you know, the CISO offices at these agencies, they're gonna know if something's secure. They're gonna be able to call BS on something if it's not secure. Well, it's funny.

SPEAKER_00

I I was just speaking of this, you know, I was just looking at out of the side of my glasses and I I saw Fed FedRamp subnets. And I it's actually FedRamp subsets. Thankfully. I fed the the the whole subnetting is.

SPEAKER_02

My heart, my heart skip skipped the beat when you said subnet. I'm not gonna lie.

SPEAKER_00

It's like, are we using one? Oh, subsets. Oh, thank God. Yeah.

SPEAKER_02

Yeah. I uh but yeah, there's there's a lot of really interesting stuff in here. One of the things that jumped out at me was uh the initial implementation phase. Uh this is if it formerly in the uh the preview slash the you know the original design and the and the uh the RFCs, it was called in pro or in implementation. So it was in implementation. Now it is initial implementation. Um I'm not confused, I promise. Uh so now the requirement is in order to apply for a FedRAMP certification, you actually get have to be listed on the marketplace before you apply for certification. It's uh this initial implementation phase. It seems like it's sort of a you know spiritual successor to in process, right? But big key difference is you don't have to have an agency sponsor.

SPEAKER_00

This is essentially, you know, you could self-actualize this one.

SPEAKER_02

Equate it to being, you know, hey, uh there's there's some minor requirements. We'll have some more details coming out soon about like what that means, you know, explaining it in layman's terms.

SPEAKER_00

But uh there's all that has to come out before the these pipelines open, right? For class A and B and C.

SPEAKER_02

Yeah, so and the timeline, uh we'll we'll drop a little table in the in the description, but there's a there's a timeline. Sorry, my producer. My producer's cursing me behind the camera. Um just nodding her head. Yeah, yeah, Tanner, I'll do it. Uh who's this we? Yeah, we so uh thank you, Caitlin. Shout out to our our our producer. Um but the initial implementation phase, the uh Federant's gonna allow cloud service providers to be listed, basically to apply for that listing on the marketplace July 6th. So that's so that is like what two weeks?

SPEAKER_03

Yeah, less than we've got.

SPEAKER_01

Not even yeah, not even so so this goes back to that push of allowing organizations to really start marketing, right? And that they're in the marketplace. Yeah, yeah, they're intent. Signaling and and so um I'm excited about that. Um I think it's really gonna allow companies that were looking to get into the federal space uh that opportunity to kind of start building that business case. Right.

SPEAKER_02

So yeah, it'll be it'll be nice that we were always excited when our customers got listed in the marketplace, obviously. But we it was it was it was frustrating that that was the that was the big goalpost. You know, because yeah, that means you did everything. And you know, you want to be listed on the marketplace or be able to market yourself before very true, you know.

SPEAKER_00

Well, and and to know the um the oh the full life cycle. It's it's good to know you know when they started the process all the way through.

SPEAKER_02

It was it was very bi it was very binary in the old the old guard path because it was like you either and you know, yeah, you had some you know, a lot of CSPs that had ready or in process, but usually it was just nothing or full certification. Right and they just come out of nowhere, which isn't good for the agencies either, besides their sponsor, because the other agencies might want to say, hey, you know, we should you know y'all should push for it and because they need the innovation. So yeah.

SPEAKER_00

Well, I I can tell that, you know, you know, FedRamp is really looking at at their game of of tracking metrics and and tracking the process and um you know being able to tell more of a story by the numbers, right? I mean, if you just look at look at the the repos that are out under FedRamp's account, um, you know, they've they've now they're tracking a change log of changes as they're happening to the marketplace, right? So there's not just the marketplace data. Uh and you know you don't have to comb through the the commits like I used to to generate those charts, but but now there's a change log. So you can think of the visualizations that you could do of what you know what's changing with FedRamp over time.

SPEAKER_02

It's very exciting. Yeah, a couple of the other dates that jumped out at me. Um they're sticking with the July 28th date of the end of FedRamp Ready. Uh rest in peace rest in peace. Uh it's uh it's going away, you know. See and specifically on this table, they say providers should seek FedRAMP Rev5 class A certification instead. We're doing a lot of work right now analyzing that and seeing how best to support um our customers and other CSPs. Uh, if you are not in the FedRamp space, but you have just gotten your SOC 2 or are getting ready to get your SOC 2, look at FedRAMP. The class A level of effort is not as great as class B or Class C. It's not even remotely close to the same level of effort or same level of investment.

SPEAKER_00

Yeah, and we've got uh an offering that we're launching here really soon to help take that output and map that to class A and basically get you submitted um so that you can get your class A.

SPEAKER_02

Yeah, and those submissions you could be submitting to get your class A as soon as August 3rd.

SPEAKER_00

Yep. That's that's that when it's we'll be open for business by then and ready to ready to submit. Yep.

SPEAKER_02

Yep. Yeah. And then uh August 10th, they're opening up the temporary Rev5 program certifications for class B and C. Uh so back uh I guess it was um February time, early Q1 time frame when they released that set of six RFCs. There was one RFC specific to program certifications for basically those that were stuck. They wanted to have a valve release for a lot of CSPs that had received a ready or a full SAR, either a RAR or a SAR, but they didn't, they lost their sponsor or they didn't have a sponsor to begin with. And uh there was specific dates that they called out that you are eligible during that time to go through and get a five program certification directly from the PMO because you did all the work to get there, but you got screwed over by extenuating circumstances or just you know, it it economic I mean the economy or the war in Iraq or Doge or whatever end up being your extenuating circumstances, you you got the short end of the stick. That's not fair.

SPEAKER_00

So and that that was big a big request from us, you know, to open up a pathway like that. And it's it's awesome that the PMO just hears feedback and provides a way. You know, they they they've listened to it, and you know, it's even better than what we asked for, I think, in a lot of cases, right?

SPEAKER_01

Yeah, they specifically spoke on this at RampCon. Uh this exact question was asked because there was uh uh a CSP there that had lost their sponsor. They were already all the way down the path, and they were like, now what? And Pete spoke to the fact that they were gonna be releasing this as a as a pathway for them to get in there. So it's awesome to see that people are still gonna be able to take advantage of their investment that they've made.

SPEAKER_02

Yep. Yeah, end of August, that's when class B and C open up. So just over two months from now, you can start applying for your class B or Class C cert. Again, reminder for everybody, class D pilot has not occurred yet. That is scheduled for um sometime beginning of 2027. So more to come on that. Uh and then mandatory adoption, January 1st. The clock has started. The clock, the the alarm rings on January 1st. That this is a grace period. They're already effective. Technically, they're starting to do that.

SPEAKER_00

Start adopting now.

SPEAKER_02

Yeah, start adopting now. Uh, and then June 11th of 2027 is the big date. No more Rev5 certs. Starting June 11th. That's crazy.

SPEAKER_01

It's a date put to that.

SPEAKER_02

Yeah, less than one year from now, 20 Rev5 certs will not be.

SPEAKER_01

Because I'm gonna be honest with you, I from what I was hearing, I I thought that that date would actually be a little further out. Now dates could slip. We've seen that.

SPEAKER_00

But uh yeah. That's a lot of transitioning.

SPEAKER_02

And not a lot of time.

SPEAKER_00

Right.

unknown

Yeah.

SPEAKER_02

Now to clarify, that doesn't mean that existing red five certifications are required to control. Right. I that like this is Tanner speaking, not in fusion points. I think that's coming. I think that date is gonna get gonna get established. Um just because you know, at this time I agree with Pete and the PMO's decision to not set that date yet because they wanna, you know, see the fruits of the adopt agency adoption. But once that gets off the ground and past pilot, yeah.

SPEAKER_00

I it's well they need to get to operations, steady state operations with new before they tackle, okay, let's manage change. What do we do with legacy? Yeah, yeah.

SPEAKER_02

Yeah. Uh there's a whole lot of stuff. Let me double check my notes before we drop. There's a lot of info, so we're not gonna be able to explain it all here. Um uh they there was some fulfillment of promises regarding class C specifically. The PMO has noted that the idea is not necessarily the level of security being you know related to your Federant level, right? It's how much data are you showing. So class B was like all the KSIs, are you are you following them? And can you continuously prove them at any point in time? Um, which it's almost an oxymoron continuously at any point in time. Um the second of all, for class C, they want historical data. So they've called out there's a couple requirements specific to class C at this point that say, you know, class C, for example, your validation data is gonna require at least the past six months of data. Um so and then um all one big one that jumped out at me having been through the pilots is all KSIs are gonna require more than one validation method.

SPEAKER_00

Oh yeah, where they got that from.

SPEAKER_02

I like that one department. I was pretty proud of it.

SPEAKER_01

That was like 11 KSIs and 215 as of this validations.

SPEAKER_02

Yeah. So that um but that was that was nice. I'm I'm curious to see. Yeah, I think that's just gonna force people to be creative, uh, which is good. I like that.

SPEAKER_01

Um because you you could build one big validation for every KSI, but it's just gonna be too bad. Well, there was there was always this thing too, though, that we were uh hearing from the PMO what happens if that validation fails, right? Like or something happens that validation doesn't kick that kick off. Yeah, exactly. What else is checking that? So again, it's um you gotta have something to actually check the check, right? And in this whole cyclical thing that's working here. Yeah.

SPEAKER_02

I also thought the uh what's the uh resiliency or recovery for the I thought the certification data sharing requirement, one thing that I just thinks would be interesting to see how it happens, see uh so certification data sharing was authorization data sharing. So basically your trust center data sharing requirements. You are going to be required to include all of your relevant policies and procedures documentation in the trust center, which was interesting to me because the move, you know, there's a big push not to use documentation. So in instances where it's relevant, yeah. Um I think like narrative type documentation to provide as like a a reference, I think that'll be very important, even if they're not like the gospel source of truth for your system. Well, I think it'll hit the best of both worlds. Because that's what documentation is supposed to help is to help you wrap your mind around a system you can't physically any.

SPEAKER_00

And you know, it's it's we're in 2026, it's it's interesting, we're halfway through. And and um if anything, documentation is getting better and better, right? Yeah, and it's not because a humans are writing it, right? You know, it's because AI is writing it.

SPEAKER_01

Exactly. Well, you I mean, you said right out the gate with 20x when we started looking at it that the KSIs really document the story, they docurate document the the operational uh procedures of the environment in themselves.

SPEAKER_00

And so and you can always back out the machine language into an intent language. Exactly.

SPEAKER_01

I mean, you you could feed even the the the output JSON, right, that we have into some type of model and it would probably come up with a like engineers used to hate doing that, right?

SPEAKER_00

But now engineers, what are they doing? They're they're they're voicing intent to to an a to a coding agent that's building the functionality. So it's it's kind of reversed. It's reversed, yeah. And that documentation's gotten better as as a result. For sure. And it'll stay up to date. Yeah, exactly.

SPEAKER_02

Yeah, I mean, there's a lot happening. Go look at consolidated rules. Um, I'm I'm gonna do this again for fear of being kicked off the podcast forever, but we'll include a link to consolidated rules in the description. So uh thank you, Caitlin. She said um top of that tonight. Yeah, uh yeah, she's gonna like mess with my audio, make me say something terrible uh on the podcast. But yeah, AI my voice, and then let me get it.

SPEAKER_00

She's getting good with AI too, though. Yeah, this isn't a big deal for her. Yeah.

SPEAKER_02

But yeah, uh, other than that, um, yeah, go check it out, ask us questions. We'll have all kinds of content coming out about this soon. But sure, this is brand new. Reach out if you have questions. We're more than obviously we're more than willing to talk about it.

SPEAKER_00

Yeah, reach out about class A. Uh, reach out about if you're on the path to B or C. If you're trying to figure out, you know, I'm I'm in DOD and I've got some customers on the the federal agency side. We're working with customers that are navigating that.

SPEAKER_02

And maybe if you're rev if you're Rev5 and you're like, what does this mean for me? Because it definitely means something for you, do not ever, you know, don't want to understate that. But yeah, for sure.

SPEAKER_01

Yeah, if you're looking to continue with more education, go back and view some of our previous webinars, previous podcast. Um, if you're looking to see this in action, go check out xb u40.com. Our trust center's out there, and that historical data that Tanner was just speaking of is out there as well, so you can see that for yourself.

SPEAKER_03

Cool.

SPEAKER_01

All right, guys.

SPEAKER_03

What he said.