If your organization provides cloud services to U.S. federal agencies, or is working toward that market, FedRAMP is the program that decides whether your service can legally operate in that space. This guide covers everything you need to understand it: what it is, who needs it, how authorization actually works, what’s changing this year, and how to start.
We’ve built this as a living reference. FedRAMP is in the middle of its biggest transformation since the program launched, and a meaningful amount of what’s true today will be formally superseded by the end of 2026. We’ll flag what’s settled, what’s in transition, and what’s still being finalized, so you know exactly how much weight to put on each section.
What FedRAMP Is
FedRAMP, the Federal Risk and Authorization Management Program, is a U.S. government program that standardizes how cloud services are assessed, authorized, and monitored for use by federal agencies.
It’s grounded in OMB policy that requires agencies to presume the adequacy of a FedRAMP-authorized package for their own authorization decisions, as long as that authorization is actively maintained through continuous monitoring, and it was codified into law through the FedRAMP Authorization Act, enacted in December 2022 as part of the National Defense Authorization Act for Fiscal Year 2023.
The program solves a coordination problem. Without it, every federal agency would need to independently assess every cloud vendor it wants to use, a massive duplication of effort across government. FedRAMP creates a single, reusable assessment standard that any agency can rely on, dramatically reducing redundant security reviews while giving agencies a consistent way to evaluate cloud risk.
For cloud service providers, FedRAMP authorization is not optional if you want to sell to the federal government. It is mandatory for any cloud service provider aiming to offer products or services to U.S. federal agencies, covering IaaS, PaaS, and SaaS offerings alike. TrustCloud
An Important Terminology Note Before We Go Further
If you’ve researched FedRAMP before, you’ll see two sets of vocabulary in this guide, and that’s intentional, both are currently in active use as the program transitions.
FedRAMP is replacing “FedRAMP Authorization” and “FedRAMP Authorized” with “FedRAMP Certification” and “FedRAMP Certified” as the single official designation across all certification types, reflecting a more precise legal distinction: FedRAMP itself only certifies completed assessments, it’s the sponsoring agency, not FedRAMP, that issues the actual Authority to Operate (ATO) under the NIST Risk Management Framework. “Authorization” had blurred that line for years.
Existing FedRAMP Authorized services don’t lose their status under this change, they continue operating under their existing authorizations, with the language updating as new certifications are issued under the new rules. We’ll use “authorization” and “certification” somewhat interchangeably throughout this guide since both terms are in active circulation, but going forward, expect “FedRAMP Certified” to become the dominant term in official documentation and marketplace listings.
Who Needs FedRAMP
FedRAMP compliance is mandatory for any cloud service provider aiming to offer products or services to U.S. federal agencies. If your organization runs a cloud-based product, software, infrastructure, or platform, and federal agencies are part of your target market, this applies to you regardless of your company’s size.
The requirement extends beyond pure federal sales, too. Many state, local, and education (SLED) agencies accept FedRAMP authorization through reciprocity with StateRAMP, now rebranded as GovRAMP. And defense contractors offering cloud services to the DoD specifically may need both FedRAMP (or DoD equivalency) for their cloud infrastructure and CMMC compliance for how they handle Controlled Unclassified Information more broadly, these are related but distinct requirements that often apply together.
If your organization is targeting any federal market, civilian agency, defense, or SLED through reciprocity, FedRAMP needs to be part of your compliance roadmap from the start, not an afterthought once a deal is on the table.
Impact Levels (and the Certification Classes Replacing Them)
FedRAMP categorizes cloud systems by the potential damage a security breach could cause, to confidentiality, integrity, and availability. This categorization determines how many security controls you need to implement and how rigorous your assessment will be.
The system as it exists today. The FedRAMP Low baseline requires 156 controls, Moderate requires 323, and High requires 410, all three drawing from the same 17 NIST SP 800-53 control families, with the key difference being how deep the requirements go within each. About 80 percent of authorized CSPs fall under the Moderate level, which covers systems handling controlled unclassified information, sensitive operational data, and personally identifiable information, the most common use case for commercial SaaS selling into government.
What’s changing, and when. Anchored in NTC-0004, published February 25, 2026, and formalized in the Consolidated Rules for 2026 (CR26) by the end of June 2026, FedRAMP is retiring the FIPS 199 Low/Moderate/High labels entirely. Low (with Li-SaaS) becomes Class B, Moderate becomes Class C, and High becomes Class D, with a new Class A pilot tier added. The main reason for the change is to create unique terminology that doesn’t overlap or conflict with DoD Impact Level designations, which use similar-sounding terms for an entirely different framework.
For the most part, Certification Classes map 1:1 to the old impact levels, this is a naming and structural cleanup, not a wholesale rewrite of what the underlying security requirements are. FedRAMP Class A is the equivalent of the current FedRAMP Ready baseline; FedRAMP Ready is being retired, though there’s an easy conversion path to Class A. Paramify
The timeline. CR26 will apply to all cloud service providers by December 31, 2026, and will be valid until December 31, 2028. Beginning in January 2027, the Low/Moderate/High labels will be fully removed and the class structure will take full effect. If you’re early in scoping your FedRAMP path right now, you’ll likely be planning and building under Class terminology rather than the legacy labels by the time you complete your assessment, worth keeping in mind when you read older content (including, frankly, some of our own earlier coverage) that still uses Low/Moderate/High as if it were permanent. Vanta
The Authorization Process: Step by Step
Step 1, Determine your path. The 2026 rules give CSPs a genuine choice between two paths: Rev5, the traditional documentation-heavy process, and FedRAMP 20x, the newer automation-first model. Rev5 is the right choice if you run your own data centers and physical infrastructure, if your sponsor or customer contracts specifically require Rev5, or if you need Class D, Rev5 is currently the only path to Class D. If you’re cloud-native, hosted on already-certified infrastructure, and not pursuing the highest class, the program is actively nudging you toward 20x.
Step 2, Determine whether you need an agency sponsor. This is one of the most significant practical changes in 2026. Program Certification, brand new this year, lets CSPs submit directly to FedRAMP for initial certification without needing an agency sponsor at all, a meaningful shift, since the sponsor requirement has historically been one of the biggest barriers to market entry. Program Certification is available for 20x at Class A, B, or C, and for Rev5 at Class A (with Rev5 at Class B or C available only in extremely limited cases). Agency Certification, the traditional path where an agency conducts the initial review and grants an agency-specific ATO before FedRAMP issues official certification, is required for Rev5 Class B, C, and D, and remains the only option for Class D entirely.
Step 3, Build your evidence package. Under Rev5, this means a System Security Plan (SSP) describing your system and how it implements every applicable NIST SP 800-53 control, historically a lengthy, narrative document. Across either path, a machine-readable authorization package is now a near-term requirement: Rev5 providers face an initial compliance deadline of September 30, 2026, and a hard final deadline of September 30, 2027, after which non-compliant Rev5 authorizations will be revoked entirely, requiring a completely new initial authorization process. That’s not a soft target, providers should be planning for it now, regardless of which path they’re on. Davis Wright Tremaine
Step 4, Independent assessment. A 3PAO (Third-Party Assessment Organization) conducts your formal security assessment, testing controls, scanning for vulnerabilities, and performing penetration testing where applicable, then producing a Security Assessment Report. Under 20x, the assessor’s role shifts: rather than reviewing written narratives and static evidence, they independently verify the accuracy, reliability, and effectiveness of your automated validation, confirming that your machine-readable evidence and Key Security Indicators genuinely reflect your real security posture, not just that the paperwork looks right.
Step 5, Certification and continuous monitoring. Once certified, your authorization is listed on the FedRAMP Marketplace and other agencies can reuse your package under the presumption-of-adequacy principle. Ongoing continuous monitoring, vulnerability scans, incident reporting, periodic reassessment, is required to maintain that status indefinitely.
FedRAMP 20x: What It Actually Changes
20x is not a minor process tweak. It’s a structural rethink of how security gets verified.
Under Rev5, security controls are documented in narrative form. Under 20x, vendors use Key Security Indicators (KSIs), specific capabilities a system has or lacks, automatically verified against the running infrastructure. There are 56 KSIs for the Low/Class B baseline and 61 for Moderate/Class C, spanning categories like configuration management, identity and access, and incident response.
The underlying NIST SP 800-53 Rev5 control baseline is unchanged, what differs is validation cadence. Continuous, machine-readable attestation replaces the old annual point-in-time audit, which many practitioners argue provides meaningfully stronger real-time assurance against configuration drift than a once-a-year snapshot ever could.
The rollout has been deliberately staged. Phase 2 was a closed pilot with 13 selected participants. Phase 3, opening in Q3 2026, opens 20x to all qualifying providers. Phase 5, targeted for Q3–Q4 of FY27, is when FedRAMP aims to stop accepting new Rev5-based authorizations entirely. Rev5 authorizations already granted remain valid, but all new authorizations after 2027 are expected to go through 20x.
One requirement applies regardless of which path you choose: RFC-0024 mandates machine-readable packages, including OSCAL format, for all FedRAMP providers, not just those on the 20x path, by September 2026.
FedRAMP and GovRAMP (Formerly StateRAMP)
FedRAMP only covers federal agencies. If your target market includes state, local, tribal, or educational government buyers, you’re looking at a related but separate program, recently rebranded from StateRAMP to GovRAMP in February 2025 to reflect that broader scope.
The reciprocity between the two runs one direction. A FedRAMP-authorized vendor can reuse their existing security package to pursue GovRAMP authorization through a Fast Track process, without a full new assessment. Going the other direction doesn’t work the same way, a GovRAMP-only authorization does not satisfy FedRAMP, and federal agencies still require their own independent FedRAMP certification. If your roadmap includes both markets, pursuing FedRAMP first is almost always the more efficient sequence.
What This Means for Your Compliance Strategy Right Now
If you’re early in scoping a FedRAMP path today, here’s the practical takeaway: you’re not choosing between “the old way” and “the new way” in the abstract. You’re choosing a path, Rev5 or 20x, that has real, near-term consequences for your sponsor requirements, your evidence format, your assessment timeline, and your long-term maintenance burden.
If you’re cloud-native, hosted on already-FedRAMP-certified infrastructure, and targeting Class A, B, or C, the sponsor-free Program Certification path under 20x is worth serious consideration, it removes what has historically been the single biggest barrier to entry. If you need the highest assurance tier, run your own infrastructure, or have a customer specifically requiring Rev5, that path remains available and necessary, but plan now for the machine-readable evidence deadlines that apply regardless of path.
Either way, building your evidence and architecture with automation and continuous validation in mind, even if you start on Rev5, positions you better for where the entire program is heading.
Where RSI Security Fits
RSI Security helps organizations navigate FedRAMP readiness from initial scoping through SSP development, control implementation, and assessment preparation, whether you’re pursuing Rev5 or building toward 20x. We help you determine which path and certification class fits your architecture and timeline, close control gaps before assessment, and build documentation that holds up under 3PAO scrutiny.
We are currently pursuing 3PAO accreditation as part of our broader federal compliance practice. Until that process is complete, our role in the FedRAMP authorization process is readiness and advisory, helping you build a package that holds up, regardless of which 3PAO ultimately conducts your assessment.
If you’re trying to determine which path, class, and timeline fits your organization, [schedule a FedRAMP readiness consultation] or [download the Unified Federal Compliance Roadmap] to map out your next steps.
Frequently Asked Questions
What is FedRAMP?
FedRAMP (Federal Risk and Authorization Management Program) is a U.S. government program that standardizes how cloud services are assessed, authorized, and monitored for use by federal agencies. It’s legally required for any cloud service provider seeking to offer products or services to federal agencies, and it’s codified in law through the FedRAMP Authorization Act.
What’s the difference between FedRAMP “Authorization” and “Certification”?
These terms are converging as FedRAMP transitions its official terminology. “FedRAMP Certification” and “FedRAMP Certified” are becoming the single official designation, replacing “FedRAMP Authorization” and “FedRAMP Authorized.” The distinction reflects that FedRAMP itself certifies a completed assessment, while the sponsoring federal agency is the one that actually issues the Authority to Operate.
What are FedRAMP Certification Classes A, B, C, and D?
Certification Classes are replacing the legacy Low, Moderate, and High impact level labels under the 2026 Consolidated Rules. Class A is a new pilot tier replacing FedRAMP Ready, Class B maps to the former Low baseline, Class C maps to Moderate, and Class D maps to High. The change is primarily a naming and structural cleanup intended to eliminate confusion with DoD Impact Level terminology, the underlying security control requirements are not being fundamentally rewritten.
Do I need an agency sponsor to get FedRAMP authorized?
Not necessarily, as of 2026. A new Program Certification path allows providers to submit directly to FedRAMP for initial certification without a pre-committed agency sponsor, for 20x at Classes A, B, or C, and for Rev5 at Class A. The traditional Agency Certification path, which requires a sponsoring agency, is still required for Rev5 Classes B, C, and D, and remains the only path for Class D.
What is FedRAMP 20x and is it required?
FedRAMP 20x is a modernized authorization path that replaces narrative control documentation with Key Security Indicators verified through continuous, automated validation. It is not currently required, Rev5 remains available and is necessary for certain use cases, including Class D certifications. However, FedRAMP is actively transitioning the program toward 20x, with new Rev5 authorizations expected to stop being accepted after FY27, and all FedRAMP providers, regardless of path, must meet new machine-readable evidence requirements by September 2026.

