FedRAMP 20x Reshapes Federal Cloud Certification
Updated:
August 22, 2026
FedRAMP’s Consolidated Rules for 2026 have moved FedRAMP 20x from a pilot into a government-wide certification path built around persistent security evidence, automation, machine-readable data, and new certification classes. FedRAMP released the Consolidated Rules on June 24, 2026, opened the Class A submission pipeline on August 3, 2026, and plans to open Class B and Class C submissions on August 31, 2026.
The changes represent one of the largest revisions to FedRAMP since the program began. The traditional impact-level terminology is being replaced with certification Classes A, B, C, and eventually D. FedRAMP 20x introduces a Program Certification path that does not require an agency sponsor. Existing Rev5 providers remain supported during the transition, but new Rev5 certification applications are scheduled to end on June 11, 2027.
Organizations working across federal security requirements can compare the underlying framework differences in Bright Defense’s FedRAMP vs CMMC compliance guide.
What Changed With FedRAMP 20x In 2026
FedRAMP 20x replaces much of the traditional document-heavy certification model with measurable security outcomes and persistent evidence. The Consolidated Rules for 2026, often shortened to CR26, now act as the central public reference for FedRAMP rules, definitions, deadlines, certification requirements, agency guidance, and machine-readable source data.
Traditional FedRAMP packages commonly centered on large collections of point-in-time documents. A 20x package instead operates as a continuously maintained set of FedRAMP Certification Data. Providers can make this information available through trust centers, documentation portals, files, APIs, or combinations of these methods. Required information must remain current and must be available in human-readable and machine-readable formats where the rules require them.
The change closely resembles the model explained in Bright Defense’s continuous compliance guide, where control evidence and compliance status are maintained throughout the operating period rather than assembled only around an assessment.
Timeline: From FedRAMP 20x Pilots To The 2026 Rules
The current FedRAMP transition developed through several policy, pilot, and implementation milestones.
- December 2022: The FedRAMP Authorization Act placed FedRAMP into federal law and reinforced its government-wide role for reusable cloud security assessments.
- July 2024: OMB Memorandum M-24-15 replaced earlier FedRAMP policy and called for new authorization paths, greater automation, and broader reuse across federal agencies.
- March 2025: GSA announced FedRAMP 20x as a public modernization initiative.
- September 2025: Phase 1 ended after the Low pilot received 26 submissions and tested automation-centered validation.
- March 2026: Phase 2, focused on Moderate systems, concluded and supplied lessons for the final Consolidated Rules.
- May 4, 2026: FedRAMP formally changed terminology from “authorization” to “certification” and replaced impact-level labels with Classes A, B, C, and D.
- June 24, 2026: FedRAMP released the Consolidated Rules for 2026 and associated JSON schemas.
- July 4, 2026: Optional early adoption began.
- July 28, 2026: FedRAMP Ready became a legacy designation, and new FedRAMP Ready submissions stopped.
- August 3, 2026: The FedRAMP 20x Class A pipeline opened.
- August 10, 2026: Temporary Rev5 Class B and C Program Certification pipelines opened for eligible Ready Conversion and Lost Sponsor applicants.
- August 31, 2026: FedRAMP plans to open the 20x Class B and C pipelines.
- January 1, 2027: CR26 becomes mandatory for all stakeholders, subject to individual rule effective dates and grace periods.
- June 11, 2027: FedRAMP plans to stop accepting applications for new Rev5 Certifications.
How The New FedRAMP Certification Classes Work
FedRAMP 20x initially supports Class A, Class B, and Class C certifications. Class D is expected to enter a pilot during fiscal 2027.
Class A offers an entry path based partly on an existing independent security framework. A provider seeking Class A must have completed an approved framework within the previous 12 months. FedRAMP currently recognizes Rev5, including historical FedRAMP Ready assessments, SOC 2 Type II, and GovRAMP for this purpose.
Class B maps broadly to the historical FedRAMP Low category, while Class C corresponds broadly to Moderate. Class D is intended to address High systems when its future pilot is completed.
The new classes do more than rename the old impact levels. Higher classes carry stronger evidence, automation, historical metrics, and assessment requirements.
How Security Evidence Changes Under FedRAMP 20x
One major change is the Security Decision Record. For applicable 20x certifications, the Security Decision Record replaces the traditional System Security Plan model with a persistent record of security decisions, implementations, validation, and verification.
Providers must explain how applicable rules are met and document verification and validation of those security measures. Information is supplied in human-readable and JSON formats.
Key Security Indicators, or KSIs, form another central part of 20x. Providers record measures showing how each relevant KSI is met and document whether automation accurately verifies those measures.
Class B providers should use at least 1 automated verification method for each applicable KSI. Class C providers must implement at least 2 automated methods for each KSI. Class C applicants must supply at least 6 months of historical persistent-validation metrics during certification.
How Continuous Certification Changes FedRAMP Compliance
FedRAMP 20x treats certification data as something that remains current throughout the service lifecycle.
Class A providers should update their certification package at least every 3 months. Class B providers must maintain packages at least monthly. Class C providers must maintain them at least every 2 weeks. Future Class D certifications are expected to require at least weekly maintenance under the current rules.
Historical security metrics become more detailed at higher classes. Class B requires a summary covering the previous 30 days and historical summaries extending up to 1 year when available. Class C adds daily metric data extending up to 1 year where available.
The model places more emphasis on continuous control evidence, configuration state, vulnerability status, and assessment data. Bright Defense’s guide to compliance monitoring explains the same underlying operational shift from periodic checks toward ongoing control verification.
What Independent Assessors Must Do
Independent assessments remain part of FedRAMP rather than disappearing under the automation-centered model.
Cloud providers seeking Class B, C, or D certification need a FedRAMP Recognized independent assessment service. Independent assessors perform initial assessment work and participate in ongoing certification activities.
Class B and Class C providers must include all applicable Key Security Indicators in a FedRAMP independent assessment at least once each year. Class A instead follows the independent assessment requirements of its underlying approved security framework.
The rules therefore combine automated evidence with independent human assessment rather than replacing one with the other.
What Happens To FedRAMP Rev5
Rev5 remains available during the transition, but it is now the legacy certification type.
Existing Rev5 providers must begin moving toward applicable CR26 requirements. Mandatory adoption begins on January 1, 2027. FedRAMP states that cloud providers that fail to adjust to the new rules can lose their FedRAMP Certification.
Two temporary Rev5 Program Certification pipelines opened on August 10, 2026 for qualifying Class B and Class C providers. These routes target organizations that lost agency sponsorship or had already invested substantially in FedRAMP Ready or traditional Rev5 work.
The temporary pipelines close when new Rev5 certification applications end on June 11, 2027.
How Agencies Will Use FedRAMP 20x Packages
A FedRAMP Certification does not automatically give a cloud service an Authorization to Operate at every federal agency.
Agencies remain responsible for reviewing security information and deciding whether a service presents an acceptable risk for their systems. FedRAMP’s goal is to make that review faster through reusable, current certification evidence.
The new package model gives agencies continuing access to security data rather than a single static document set. Providers can use trust centers and machine-readable interfaces to supply authorized parties with current information.
How Bright Defense Can Support FedRAMP 20x Security Readiness
Bright Defense can support the technical control and evidence work surrounding a FedRAMP 20x program, particularly cloud security testing, vulnerability management, NIST-oriented control work, and continuous compliance. Internal Bright Defense documentation lists cloud penetration testing across AWS, Azure, and Google Cloud alongside vulnerability management and continuous compliance capabilities.
Cloud security verification has greater weight under a model built around persistent technical evidence. Bright Defense’s cloud penetration testing guide explains how testing can expose cloud configuration weaknesses, excessive IAM permissions, exposed APIs, and insecure storage before those weaknesses become larger security problems.
Continuous evidence work can support teams preparing for recurring security verification. The Bright Defense continuous compliance guide covers automated evidence collection, control testing, configuration drift detection, remediation tracking, and recurring reporting.
Bright Defense should not be presented as the entity issuing a FedRAMP Certification unless that role is independently confirmed. FedRAMP itself and FedRAMP Recognized assessors retain defined responsibilities under the federal certification process.
What Remains Unclear About FedRAMP 20x
Several pieces of the transition are still developing.
Class D remains a future 20x certification type. FedRAMP currently estimates a Class D pilot during fiscal 2027. The exact final requirements may change following that pilot.
FedRAMP can still make targeted corrections to CR26. The official Consolidated Rules changelog lists July 14, 2026 as the latest published CR26 rules revision available in the current record, with clarifications to requirements and JSON schemas. Later program activity includes an August 6, 2026 Request for Comment concerning Offerings By Government.
Providers therefore need to track the rule-level effective dates rather than treating January 1, 2027 as the only deadline.
Why The FedRAMP 20x Consolidated Rules Are Significant
FedRAMP 20x changes federal cloud certification from a largely document-centered process into a system centered on persistent security evidence, machine-readable data, automation, recurring assessments, and reusable certification information.
The transition is already underway. Class A applications are open as of August 20, 2026. Class B and C pipelines are scheduled to open on August 31, 2026. CR26 becomes mandatory across the program on January 1, 2027, and the intake of new Rev5 certification applications ends on June 11, 2027.
For cloud providers selling to federal agencies, the central change is operational. FedRAMP compliance increasingly requires security controls and evidence that remain current throughout the certification lifecycle rather than documentation prepared primarily around a single assessment.
Sources
FedRAMP – FedRAMP Consolidated Rules for 2026
FedRAMP – Propelling Change: FedRAMP Launches Consolidated Rules for 2026 (June 25, 2026)
FedRAMP – Important Dates for the Consolidated Rules for 2026
FedRAMP – FedRAMP 20x Program Overview
FedRAMP – Updating to 2026 Rules
FedRAMP – Choosing a Certification Path
FedRAMP – Security Decision Record Rules
FedRAMP – FedRAMP Certification Rules
FedRAMP – Certification Package Overview
FedRAMP – Independent Verification and Validation Rules
FedRAMP – Certification Data Sharing Rules
FedRAMP – Vulnerability Detection and Response Rules
FedRAMP – Consolidated Rules for 2026 Changelog
FedRAMP – Program Changelog
FedScoop – FedRAMP 20x Widely Available to Cloud Services With Release of 2026 Consolidated Rules (June 29, 2026)


