Table Of Contents
-
What has happened since CR26 was released
-
The first thing to understand: type, path, and class are different decisions
-
FedRAMP certifies. Agencies authorize.
-
If you are entering the federal market now
-
What FedRAMP 20x changes in practice
-
What belongs in the Certification package
-
If you already have a Rev 5 Certification
-
CR26 reaches well beyond the compliance team
-
The bottom line
A little over a month has passed since FedRAMP released the Consolidated Rules for 2026, or CR26, on June 24, 2026. The rules took effect for widespread adoption on July 4, Marketplace access opened for Cloud Service Providers (CSPs or cloud providers) entering initial implementation on July 6, and FedRAMP Ready moved to legacy status on July 28. The first FedRAMP 20x submission pipelines open in August.
In other words, CR26 is no longer an announcement about where FedRAMP is headed. It is the operating model cloud providers need to plan around now.
The release does two major things. It brings FedRAMP 20x into the formal certification program, with Classes A, B, and C available in 2026 and Class D planned for 2027. It also changes how cloud providers obtain and maintain Rev 5 Certification during the transition. Whether you are considering the federal market for the first time or already hold a Rev 5 Certification, the same rulebook now shapes your next steps.
If you need help comparing Rev 5 and 20x, our decision guide breaks down the differences.
What has happened since CR26 was released
FedRAMP has already moved from publication into implementation, and it has continued to clarify the rules and correct the supporting JSON schemas. Cloud providers should treat the online rules and changelog as the current source of truth rather than relying on a downloaded copy from June 24.
| Date | What it means for cloud providers |
| June 24, 2026 | FedRAMP released CR26 and formally launched the new 20x rules for Classes A, B, and C. |
| July 4, 2026 | CR26 took effect for widespread adoption. New 20x applications must follow the applicable 2026 rules. |
| July 6, 2026 | Marketplace listing opened for cloud providers entering the initial implementation stage. FedRAMP also clarified the limited Rev 5 Ready Conversion and Lost Sponsor paths. |
| July 14, 2026 | FedRAMP published additional rule clarifications and corrections to the JSON schemas. |
| July 28, 2026 | FedRAMP Ready became a legacy status. FedRAMP is no longer accepting new FedRAMP Ready submissions. |
| August 3, 2026 | The FedRAMP 20x Class A application pipeline opens. |
| August 10, 2026 | Temporary Rev 5 Program Certification pipelines open for eligible Class B and C CSPs through the Ready Conversion and Lost Sponsor paths. |
| August 31, 2026 | The FedRAMP 20x Class B and Class C application pipelines open. |
The first thing to understand: type, path, and class are different decisions
Under CR26, a provider’s target is described by a Certification Profile. That profile combines three separate choices: the certification type, the certification path, and the certification class.
| Decision | Options | What it tells you |
| Certification type | FedRAMP 20x or FedRAMP Rev 5 | The model used to demonstrate and maintain security. Rev 5 remains centered on documented control implementation. 20x is centered on measured outcomes, current validation information, and recurring reporting. |
| Certification path | Program or Agency | Whether the Certification comes directly through the FedRAMP Program or through an agency-sponsored Rev 5 process. All 20x Certifications use the Program path. |
| Certification class | Class A, B, C, or D | The amount of assurance information and ongoing commitment the provider supplies to federal customers. |
This is an important break from the old shorthand. Certification Classes do not simply rename Low, Moderate, and High impact levels. Agencies still categorize their systems and information as Low, Moderate, or High. Classes A through D describe the level of assurance a cloud offering provides, not how secure the product is or what type of government data it may automatically handle.
FedRAMP certifies. Agencies authorize.
CR26 also makes the program’s terminology more precise. A cloud offering that meets FedRAMP requirements is now FedRAMP Certified. An agency still reviews the offering for its own use case and issues its own Authorization to Operate, or ATO.
That distinction matters because a FedRAMP Certification is not a government-wide acceptance of risk. It gives agencies a reusable body of information for their own authorization decisions.
| Previous language | Current language | What changed |
| FedRAMP Authorized | FedRAMP Certified | FedRAMP certifies the cloud offering. Agencies authorize their own use of it. |
| Authorization package | Certification package | The package supports both initial Certification and agency authorization decisions. |
| Low, Moderate, High as provider labels | Classes A, B, C, and D | Certification Class is now separated from agency impact categorization. |
| Authorization Data Sharing | Certification Data Sharing | The official term now reflects the sharing of FedRAMP Certification information. |
| Continuous monitoring as the umbrella term | Ongoing Certification | The post-certification model is broader than monthly scans and POA&M updates. |
If you are entering the federal market now
The new structure gives cloud providers more than one starting point, but the right choice depends on the product, architecture, commercial maturity, and federal opportunity. The easiest path to describe is not always the right path to operate.
| Your situation | Path to evaluate first | Why |
| You have a mature commercial product and a recent SOC 2 Type II, GovRAMP, or legacy FedRAMP Ready assessment | FedRAMP 20x Class A | Class A is designed as a lower-assurance entry point for established commercial products. It uses an approved alternative security framework as part of the starting package. |
| Your service is built on FedRAMP Certified infrastructure or platforms and your federal customers need more assurance | FedRAMP 20x Class B or C | These classes require a stronger operating model, including more automation, validation history, recurring reporting, and independent assessment. |
| You already have an agency sponsor and are actively pursuing Rev 5 | Rev 5 Agency Certification | Rev 5 remains available during the transition, especially for cloud providers already moving through a sponsored process. |
| You previously reached FedRAMP Ready or lost an agency sponsor | Temporary Rev 5 Program Certification, if eligible | Limited Ready Conversion and Lost Sponsor pipelines open August 10, 2026. These are narrow exceptions, not a general sponsorless Rev 5 path. |
| You operate your own underlying infrastructure rather than building on FedRAMP Certified infrastructure or platforms | Rev 5 may still be the more appropriate type | FedRAMP positions 20x as the cloud-native model. Architecture and inheritance should be reviewed before choosing a path. |
For many companies entering the market without a federal customer already requiring a higher class, FedRAMP’s guidance is to start with the lowest class that supports the business need and upgrade as demand develops. Going directly to Class C or D can create a large operating commitment before the revenue case is proven.
What FedRAMP 20x changes in practice
FedRAMP 20x changes how a provider demonstrates and maintains security. The core shift is from reconstructing evidence around periodic reviews to maintaining current information that shows what is implemented, whether it is working, and what has changed over time.
| Traditional pattern | FedRAMP 20x expectation |
| Evidence is assembled around an assessment or agency request | Verification and validation information is maintained as the system operates |
| Security is described mainly through static narrative documents | Decisions, implementation details, validation results, and assessment information are maintained in a Security Decision Record |
| Automation is helpful but secondary | Automation expectations increase by class and are central to how applicable Key Security Indicators are validated |
| A current snapshot is the primary proof point | Historical metrics show whether validation has remained successful over time |
| Continuous monitoring is often organized around scans, inventory, and POA&Ms | Ongoing Certification includes broader reporting, data sharing, change communication, incidents, availability, vulnerability operations, and recurring reviews |
Key Security Indicators, in plain English
Key Security Indicators, or KSIs, are outcome-oriented security expectations. Instead of only describing a control in a document, the provider explains how the security outcome is implemented and shows current information that verifies and validates whether it is working.
The level of automation and history depends on the class. Class B cloud providers should use at least one automated method per KSI and supply historical metrics. Class C CSPs must use at least two automated methods per KSI and provide at least six months of validation history. Class D is established as a Certification Class, but the 20x Class D path is planned for 2027.
For a deeper look at how KSIs work in the 20x model, see our plain‑English explainer.
Annual independent assessments still exist
Continuous validation does not eliminate independent assessment. Classes B, C, and D require an independent verification and validation assessment at least annually. The difference is what the provider maintains between those assessments.
A well-designed 20x operating model should allow the annual assessment to begin with current validation results and historical information rather than a last-minute effort to rebuild the evidence base from scattered systems. That is the practical value of maintaining assurance continuously, even though the annual assessment still remains.
You can explore how the full 20x model works and what it requires here.
What belongs in the Certification package
The exact requirements vary by type, class, and effective date, but CR26 creates more consistency in the basic structure of the package. Comparing the two models in one place is much clearer than repeating long lists of official package language.
| Package element | 20x | Rev 5 | What it is for |
| Certification Package Overview | Yes | Yes | Describes the cloud offering, scope, information resources, information flows, third parties, and package structure. |
| Security Decision Record | Yes | Yes | Records how applicable FedRAMP requirements are implemented, verified, validated, and assessed. |
| Key Security Indicator information | Yes | No | Shows how the provider meets outcome-oriented 20x security expectations and how those outcomes are validated. |
| Rev 5 control information | No | Yes | Documents implementation, inheritance, parameters, validation, assessment results, and supporting information for applicable NIST SP 800-53 Rev 5 controls. |
| Secure Configuration Guide | Yes | Yes | Helps agency customers configure and operate the service securely. |
| Independent assessment information | Yes for Classes B and C, potentially for class A. | Yes for applicable Rev 5 classes | Gives FedRAMP and agencies independent verification and validation of the provider’s implementation. |
| Ongoing Certification Report | Yes | Yes | Provides current information for ongoing agency risk and authorization decisions. |
| Machine-readable information | Yes, where a FedRAMP schema applies | Yes, where a FedRAMP schema applies | Makes required information structured, reusable, and easier to exchange between systems. |
This does not mean the Rev 5 SSP disappears immediately or that every legacy artifact is replaced overnight. It means Rev 5 cloud service providers should expect more of their Certification information to become structured, current, and aligned to the same broader operating model.
If you already have a Rev 5 Certification
Your Certification remains active. June 11, 2027 is the deadline for new Rev 5 applications, not the expiration date for every existing Rev 5 Certification.
The more immediate issue is that CR26 applies to Rev 5 CSPs too. FedRAMP is introducing the new requirements in phases, and the deadlines vary by ruleset. January 1, 2027 is a major milestone, but it is not the only date that matters.
The next Rev 5 deadline is December 7, 2026
Vulnerability Detection and Response, or VDR, and Vulnerability Evaluation and Reporting, or VER, become maintain requirements for Rev 5 Classes B, C, and D on December 7, 2026. The grace period ends March 7, 2027.
These rules are broader than producing vulnerability scan reports. In practical terms, cloud providers need an operating model that can:
- find vulnerabilities and security failures systematically, including drift and problems outside traditional CVE scanning;
- track, evaluate, monitor, mitigate, remediate, and report detected vulnerabilities;
- consider context such as exploitability, internet reachability, and potential agency impact;
- maintain current status and history rather than reconstructing the story at reporting time; and
- connect vulnerability operations to the teams and systems that actually own the environment.
Other Rev 5 changes arrive in stages
Several rulesets have January 1, 2027 obtain or maintain dates, including FedRAMP Certification, cryptographic module use, incident communication, independent assessment, minimum assessment scope, and significant change notification. Other maintain dates extend later into 2027 for collaborative continuous monitoring, the Certification Package Overview, Certification Data Sharing, and the Security Decision Record.
The practical lesson is simple: do not build a Rev 5 transition plan around one blanket deadline. Map each applicable ruleset to its obtain, maintain, and grace dates, then work backward from the engineering, process, and data changes your system will need.
CR26 reaches well beyond the compliance team
A provider cannot meet the new model through document updates alone. CR26 repeatedly connects Certification information to the systems and teams that operate the cloud service.
A workable plan will usually involve:
- Security teams, which own detection, response, incident communication, vulnerability context, and security telemetry;
- Engineering and platform teams, which own source systems, automation, configuration, integrations, tagging, and system changes;
- Product teams, which need to understand secure customer configuration, federal feature requirements, and the commercial impact of the chosen class;
- GRC and FedRAMP teams, which interpret the rules, maintain the Certification package, coordinate assessments, and make sure current operational information is translated into required formats; and
- Revenue and leadership teams, which need to match the cost and commitment of the target Certification Profile to actual federal market demand.
That last point matters. CR26 gives CSPs more flexibility, but it also makes the operating commitment more visible. Choosing a type and class is now as much a product and market decision as it is a compliance decision.
If you need support building a workable operating model under CR26, our FedRAMP advisory team can help.
The bottom line
A month after its release, CR26 has already changed the practical choices in front of cloud providers. FedRAMP Ready is now legacy, the 20x pipelines are opening, and existing Rev 5 providers have near-term requirements to address before any broader transition decision is complete.
If you are entering the federal market, start by choosing the right Certification Profile for your product, architecture, customers, and investment level. If you already hold a Rev 5 Certification, keep the long-term 20x transition in view, but focus first on the rules and deadlines that apply to your current offering, especially VDR and VER.
The question is no longer whether FedRAMP will move toward continuous validation, structured information, and ongoing assurance. The question for each cloud provider is how to build an operating model that can support it.
Source note: This article reflects the FedRAMP Consolidated Rules for 2026, official timeline, provider deadline pages, and changelog available as of July 31, 2026.
Table Of Contents
-
What has happened since CR26 was released
-
The first thing to understand: type, path, and class are different decisions
-
FedRAMP certifies. Agencies authorize.
-
If you are entering the federal market now
-
What FedRAMP 20x changes in practice
-
What belongs in the Certification package
-
If you already have a Rev 5 Certification
-
CR26 reaches well beyond the compliance team
-
The bottom line



