Skip to main content

Public Sector

New updates on AWS GovCloud (US) | Issue #5 (2026)

July 16–31, 2026 | New updates on AWS GovCloud (US): This issue features insights on FedRAMP Consolidated Rules 2026 (CR26), new foundation models now available on Amazon Bedrock in AWS GovCloud (US) including Claude Sonnet 5, Grok 4.3, and Gemma 4, model migration guidance for retiring models, plus the latest features and services.

Missing alt text value

Executive Insights

What the New FedRAMP Consolidated Rules for 2026 (CR26) Mean for AWS GovCloud (US) Customers

Missing alt text value

FedRAMP Consolidated Rules for 2026 (CR26) went into effect on July 4, 2026, for early adoption, ahead of mandatory adoption on January 1, 2027. The rules change how cloud services are approved for AWS GovCloud (US) customers with FedRAMP compliance needs, but do not affect customers with DoD CC SRG IL-4 and IL-5 compliance needs. As part of this change, FedRAMP now designates certifications by class rather than impact level, with Classes A through D indicating increasing depth of security evidence. FedRAMP High approval is now expressed as Class D certification, and AWS GovCloud (US) has adopted the Class D (High) certification. All existing FedRAMP authorizations carry forward under the new class designations. This applies to AWS services authorized on AWS GovCloud (US), so the AWS services customers use today remain FedRAMP certified. The new process replaces documentation-heavy, point-in-time assessments with continuous, automated validation of machine-readable Key Security Indicators (KSIs). AWS has aligned its services to this automation-first model of assurance. For agencies, continuous validation provides current visibility into provider security posture. Machine-readable Significant Change Notifications (SCNs) add visibility into service changes as they happen, with notice requirements scaled to the significance of the change. For technology partners, automation can reduce authorization timelines to a matter of weeks, and those building on AWS GovCloud (US) inherit AWS security controls and can automate KSI evidence collection with services such as AWS Audit Manager, AWS Config, and AWS Security Hub. For industrial base members, faster authorizations and a lower documentation burden mean new capabilities reach federal missions sooner. Organizations planning a federal authorization should factor the new rules into their compliance roadmaps now. To learn more, including how to request the AWS FedRAMP Security Package or a FedRAMP Partner Package, visit AWS FedRAMP Compliance and Prepare for FedRAMP 20x with AWS automation and validation on the AWS Public Sector Blog, or reach out to your AWS account team.

Resources: AWS FedRAMP Compliance | Prepare for FedRAMP 20x with AWS automation and validation | AWS DoD SRG Compliance | FedRAMP CR26 Timeline | FedRAMP Certification Classes | FedRAMP Significant Change Notification | FedRAMP Marketplace: AWS GovCloud

Solutions Insights

Newer, More Capable Models Are Here — and Upgrading Is Straightforward

Here's what practitioners need to know about the latest model launches and how to upgrade from retiring models on Amazon Bedrock in AWS GovCloud (US).

Missing alt text value

Here's what practitioners need to know about the latest model launches and how to upgrade from retiring models on Amazon Bedrock in AWS GovCloud (US). 

Three new foundation models are now available in AWS GovCloud (US), bringing the authorized model catalog to 20+ models spanning Amazon, Anthropic, Meta, NVIDIA, OpenAI, Google DeepMind, and xAI. 

  • Claude Sonnet 5 (Anthropic) is now available in both AWS GovCloud (US) Regions via cross-Region inference on the runtime endpoint and on the Bedrock Mantle endpoint in AWS GovCloud (US-West), with FedRAMP Class D and DoD CC SRG IL-4/5 authorization. Sonnet 5 is Anthropic's most capable Sonnet model, built for coding, agents, and professional knowledge work, handling large codebases and multi-file changes with fewer correction rounds while holding state reliably across long tool-using workflows. 

  • Grok 4.3 (xAI) is available in AWS GovCloud (US-West) on the Bedrock Mantle endpoint with FedRAMP Class D and DoD CC SRG IL-4/5 authorization, offering Standard, Priority, and Flex service tiers so teams can match cost and throughput to the workload using in-Region inference.  

  • Gemma 4 (Google DeepMind) is an open-weight (Apache 2.0) family, including 31B dense, 26B-A4B mixture-of-experts, and E2B variants, with built-in reasoning, native function calling, multimodal (text + image) input, and a 256K-token context window. Gemma 4 is available in AWS GovCloud (US-West) on the Bedrock Mantle endpoint, with FedRAMP Class D and DoD CC SRG IL-4/5 authorization in progress, and is a strong fit for multimodal agents, document-understanding pipelines, and cost-efficient software workflows.

 
Whether the workload calls for frontier reasoning, cost-efficient inference, multimodal document understanding, or high-throughput embeddings, practitioners can match the right model to the mission. 

 

With the breadth of models now available in AWS GovCloud (US), teams running earlier-generation models have a clear path forward. Upgrades are a deliberate model-ID change you control, not an automatic switch, and newer models improve both capability and price-performance. Bedrock's model lifecycle provides at least 12 months of availability for every model, followed by at least 6 months in Legacy state before end-of-life, with notifications along the way. That said, Claude Sonnet 3.5 and 3.7 retired on July 30, so teams still calling these models should migrate immediately. The next retirement is Claude 3 Haiku on September 10, 2026.

The migration process is straightforward, and the tools to validate it run natively in AWS GovCloud (US). Start by inventorying what you run, checking the modelLifecycle field via ListFoundationModels/GetFoundationModel or the Bedrock console. Then pick your target. Before you switch, validate by running your candidate side-by-side with your current model using Bedrock Evaluations, available in both us-gov-west-1 and us-gov-east-1 alongside batch inference, so you can benchmark automatically, with human review, or using LLM-as-a-judge before you cut over. Take the opportunity to re-tune prompts for the new model's strengths. Once validated, ship by updating the model ID in your applications, agents, and Knowledge Bases. Enabling a new model starts in your linked commercial account (us-east-1 or us-west-2) by establishing the model agreement. Then enable the same model on the Model Access page in your AWS GovCloud (US) Region. Entitlements propagate in a few minutes. 

Learn more: Bedrock model support by Region | Understanding the Amazon Bedrock model lifecycle  | Bedrock Evaluations|LLM-as-a-judge best practices | Optimize and migrate prompts in Amazon Bedrock | Bedrock in AWS GovCloud (US) 

Service and Feature Releases

Source: What's New Posts, July 16–31, 2026.

 

 

 

 

 

 

Service Area 

 

 

 

 

 

 

 

Service 

 

 

 

 

 

 

 

Region 

 

 

 

 

 

 

 

Announcement 

 

 

 

 

Analytics 

 

 

 

 

Amazon Kinesis Data Streams 

 

 

 

 

Both  

 

 

 

 

Amazon Kinesis Data Streams now supports scaling down ingest capacity with warm throughput 

 

 

 

 

Analytics 

 

 

 

 

Amazon Managed Service for Apache Flink 

 

 

 

 

Both  

 

 

 

 

Amazon Managed Service for Apache Flink now supports Apache Flink 2.3 

 

 

 

 

Analytics 

 

 

 

 

Amazon MSK 

 

 

 

 

Both  

 

 

 

 

Amazon MSK Express brokers now deliver data to streaming tables for Apache Iceberg 

 

 

 

 

Analytics 

 

 

 

 

Amazon MSK 

 

 

 

 

Both  

 

 

 

 

Amazon MSK Express brokers now delivers Apache Kafka data to Amazon S3 

 

 

 

 

Analytics 

 

 

 

 

Amazon Redshift 

 

 

 

 

Both  

 

 

 

 

Amazon Redshift Serverless now offers All Upfront pricing for 3-year Serverless Reservations 

 

 

 

 

Analytics 

 

 

 

 

Amazon Redshift 

 

 

 

 

Both  

 

 

 

 

Amazon Redshift Data API announces long polling, session management, and flexible batch execution 

 

 

 

 

Analytics 

 

 

 

 

AWS Glue 

 

 

 

 

Both  

 

 

 

 

AWS Glue Data Quality now supports anomaly detection and writing results to the AWS Glue Data Catalog 

 

 

 

 

Business Applications 

 

 

 

 

AWS Wickr 

 

 

 

 

West 

 

 

 

 

AWS Wickr announces Data Retention Service feature 

 

 

 

 

Compute 

 

 

 

 

Amazon EC2 

 

 

 

 

Both  

 

 

 

 

Amazon EC2 now surfaces the public SSM parameters associated with public AMIs 

 

 

 

 

Compute 

 

 

 

 

Amazon EC2 

 

 

 

 

Both  

 

 

 

 

Amazon EC2 I8ge instances are now available in AWS GovCloud (US) Regions 

 

 

 

 

Compute 

 

 

 

 

Amazon EC2 

 

 

 

 

Both  

 

 

 

 

AWS Network Load Balancer now supports Listener Rules for custom traffic routing 

 

 

 

 

Compute 

 

 

 

 

Amazon EC2 

 

 

 

 

Both  

 

 

 

 

Amazon EC2 Dedicated Hosts now support host resource groups without self-managed licenses 

 

 

 

 

Compute 

 

 

 

 

Amazon EC2 

 

 

 

 

Both  

 

 

 

 

Amazon EC2 Auto Scaling now supports Instance Refresh in CloudFormation 

 

 

 

 

Compute 

 

 

 

 

AWS Lambda 

 

 

 

 

Both  

 

 

 

 

AWS Lambda now supports Java 8, 11, and 17 on Amazon Linux 2023 

 

 

 

 

Compute 

 

 

 

 

AWS Parallel Computing Service 

 

 

 

 

Both  

 

 

 

 

AWS Parallel Computing Service now supports node lifecycle actions 

 

 

 

 

Container 

 

 

 

 

Amazon ECS 

 

 

 

 

Both  

 

 

 

 

Amazon ECS now provides Action Logs for deployment and orchestration visibility 

 

 

 

 

Container 

 

 

 

 

Amazon ECS 

 

 

 

 

Both  

 

 

 

 

Amazon ECS Service Connect now supports Zone-Aware routing 

 

 

 

 

Container 

 

 

 

 

Amazon EKS 

 

 

 

 

Both  

 

 

 

 

Amazon EKS now supports EFA and placement groups on Amazon EKS Auto Mode and Karpenter 

 

 

 

 

Container 

 

 

 

 

Amazon EKS 

 

 

 

 

Both  

 

 

 

 

Amazon EKS now supports AWS PrivateLink for the cluster OIDC endpoint 

 

 

 

 

Container 

 

 

 

 

Amazon EKS 

 

 

 

 

Both  

 

 

 

 

Amazon EKS Provisioned Control Plane now delivers faster pod autoscaling 

 

 

 

 

Customer Engagement 

 

 

 

 

Amazon Connect 

 

 

 

 

Both  

 

 

 

 

Amazon Connect Customer launches metrics for agent queues on analytics dashboards 

 

 

 

 

Customer Engagement 

 

 

 

 

Amazon SES 

 

 

 

 

Both  

 

 

 

 

Amazon SES simplifies sending emails over SMTP using Mail Manager 

 

 

 

 

Database 

 

 

 

 

Amazon Neptune 

 

 

 

 

Both  

 

 

 

 

Amazon Neptune now supports tag-based access control for IAM 

 

 

 

 

Database 

 

 

 

 

Amazon RDS 

 

 

 

 

Both  

 

 

 

 

Amazon RDS for SQL Server now supports Microsoft SQL Server 2025 

 

 

 

 

Database 

 

 

 

 

Amazon RDS 

 

 

 

 

Both  

 

 

 

 

Amazon RDS now supports the latest CU and GDR updates for Microsoft SQL Server 

 

 

 

 

Developer Tools 

 

 

 

 

Kiro 

 

 

 

 

Both  

 

 

 

 

Opus 4.8, Sonnet 5, and User Activity Monitoring now available on Kiro in AWS GovCloud (US) 

 

 

 

 

End User Computing 

 

 

 

 

Amazon Workspaces 

 

 

 

 

Both  

 

 

 

 

Amazon WorkSpaces Applications now supports Microsoft OneDrive and Google Drive on Multi-Session fleets 

 

 

 

 

Machine Learning 

 

 

 

 

Amazon Bedrock 

 

 

 

 

Both  

 

 

 

 

Claude Sonnet 5 is now available on Amazon Bedrock in AWS GovCloud (US) 

 

 

 

 

Machine Learning 

 

 

 

 

Amazon Bedrock 

 

 

 

 

East 

 

 

 

 

Announcing region expansion of G6 instances on SageMaker AI Inference 

 

 

 

 

Machine Learning 

 

 

 

 

Amazon Bedrock 

 

 

 

 

Both  

 

 

 

 

Gemma 4 models are now available on Amazon Bedrock in AWS GovCloud (US-West) 

 

 

 

 

Machine Learning 

 

 

 

 

Amazon Bedrock 

 

 

 

 

Both  

 

 

 

 

Grok 4.3 from xAI is now available on Amazon Bedrock in AWS GovCloud (US-West) 

 

 

 

 

Management & Governance 

 

 

 

 

Amazon Cloudwatch 

 

 

 

 

Both  

 

 

 

 

Amazon CloudWatch Logs now supports Application Load Balancer logs 

 

 

 

 

Management & Governance 

 

 

 

 

Amazon Managed Grafana 

 

 

 

 

Both  

 

 

 

 

Amazon Managed Grafana achieves FedRAMP High authorization in AWS GovCloud (US) 

 

 

 

 

Management & Governance 

 

 

 

 

Amazon Managed Service for Prometheus 

 

 

 

 

Both  

 

 

 

 

Amazon Managed Service for Prometheus supports 1.5B active metrics and 200K rules per workspace 

 

 

 

 

Management & Governance 

 

 

 

 

AWS Organizations 

 

 

 

 

Both  

 

 

 

 

AWS Organizations increases RCP quota to 2,000 per organization 

 

 

 

 

Migration & Transfer 

 

 

 

 

AWS Datasync 

 

 

 

 

Both  

 

 

 

 

AWS DataSync Enhanced mode now supports Amazon EFS and Amazon FSx for Lustre 

 

 

 

 

Migration & Transfer 

 

 

 

 

AWS Datasync 

 

 

 

 

Both  

 

 

 

 

AWS DataSync Enhanced mode adds HDFS, Azure Blob, and object storage locations with Hyper-V agent support 

 

 

 

 

Security, Identity, & Compliance 

 

 

 

 

AWS Secrets Manager 

 

 

 

 

Both  

 

 

 

 

AWS Secrets Manager now publishes secret update notifications to Amazon EventBridge 

 

 

 

 

Security, Identity, & Compliance 

 

 

 

 

AWS WAF 

 

 

 

 

Both  

 

 

 

 

AWS WAF adds pre-parse text transformations and new text transformations 

 

 

 

 

Storage 

 

 

 

 

Amazon EFS 

 

 

 

 

Both  

 

 

 

 

Amazon EFS now supports cross-account Replication in AWS GovCloud (US) 

 

 

 

 

Storage 

 

 

 

 

Amazon S3 

 

 

 

 

Both  

 

 

 

 

Amazon S3 removes 30-day minimum for transitions to S3 Standard-IA and S3 One Zone-IA 

 

 

Did you find what you were looking for today?

Let us know so we can improve the quality of the content on our pages