What Is FedRAMP? Impact Levels, Certification Classes, and What 20x Changes
FedRAMP (the Federal Risk and Authorization Management Program) is the U.S. government’s standardized program for assessing, certifying, and continuously monitoring the security of cloud services used by federal agencies. A cloud provider gets certified once, and any agency can reuse that assessment package instead of running its own review.
- FedRAMP is law, not guidance: the FedRAMP Authorization Act established the program on December 23, 2022 (44 U.S.C. 3607-3616), and agencies must presume a FedRAMP certification package is adequate at or below its impact level.
- The traditional Rev5 baselines are 156 controls at Low, 323 at Moderate, and 410 at High, counted directly from FedRAMP’s official baseline workbook. Moderate covers roughly 80% of authorized services.
- The Consolidated Rules for 2026 (CR26) launched June 24-25, 2026 and replace impact-level branding with Certification Classes A, B, C, and D, which describe assurance rather than security level.
- FedRAMP 20x is no longer a pilot. The Class A pipeline opened August 3, 2026 and Classes B and C open August 31, 2026, all via Program Certification, which needs no agency sponsor.
- Key dates ahead: January 1, 2027 (CR26 becomes mandatory for everyone) and June 11, 2027 (last day FedRAMP accepts new Rev5 applications).
What Is FedRAMP and Why Does It Exist?
FedRAMP is a governmentwide program run by GSA that standardizes how federal agencies assess the security of cloud products and services. The model is “do once, use many times”: one provider is assessed once, and every agency reuses that package instead of duplicating the work.
It is statutory. The FedRAMP Authorization Act established the program on December 23, 2022, and OMB Memorandum M-24-15, issued July 25, 2024, rescinded the original 2011 policy. That memo states that when a cloud service holds a FedRAMP authorization at a given FIPS 199 impact level, “the Act requires that agencies must presume the security assessment documented in the authorization package is adequate for their use” at or below that level, under 44 U.S.C. 3613(e)(1).
Scope is broad but bounded: FedRAMP covers IaaS, PaaS, and SaaS that “create, collect, process, store, or maintain Federal information on behalf of a Federal agency.” National security systems are excluded.
The practical effect is commercial. If your product cannot show a FedRAMP designation on the Marketplace, most federal buying conversations stop early. As of August 11, 2026, FedRAMP.gov listed 529 total FedRAMP Certified services, 28 of which were certified through FedRAMP 20x.
What Are the FedRAMP Impact Levels and Certification Classes?
Impact levels come from FIPS 199 and describe how bad it would be if confidentiality, integrity, or availability were lost. Low means limited adverse effect, Moderate means serious adverse effect, and High means severe or catastrophic effect. Crucially, FedRAMP’s guidance for cloud service providers notes that the impact level “is determined by the federal agency customer,” not by the vendor, and that Moderate accounts for nearly 80% of cloud service offerings.
Each level maps to a control baseline drawn from NIST SP 800-53 Rev. 5. Counting the control IDs in FedRAMP’s official Security Controls Baseline workbook gives 156 controls at Low, 323 at Moderate, and 410 at High. The Tailored LI-SaaS baseline carries the same 156 Low controls but lets providers attest to most of them, with roughly 45 fully documented and assessed.
The 2026 rules add a second axis: authorizations are now described as Certification Classes A through D rather than levels, partly to avoid confusion with DoD Impact Levels.
| Certification Class | Roughly aligns with | Rev5 baseline controls | Example federal data |
|---|---|---|---|
| Class A | Pilot and negligible-risk use | No Rev5 baseline; 7 Key Security Indicators | Configuration, testing, and evaluation use cases |
| Class B | Low (including LI-SaaS) | 156 | Public-facing content and SaaS holding no PII beyond username, password, and email |
| Class C | Moderate | 323 | Most controlled unclassified information: PII, procurement, financial and operational records |
| Class D | High | 410 | Law enforcement, emergency services, financial, and health systems |
Read the mapping loosely. FedRAMP’s guidance for agencies is blunt: “Certification Classes indicate the level of assurance provided, not the level of security or protection provided,” and agencies “should not treat Certification Classes as one-for-one replacements for Low, Moderate, or High impact levels.” A Class C service is presumed adequate for most Low or Moderate systems, and some High systems with compensating controls.
These control families come from the same catalog behind most federal security work. Our guide to NIST compliance covers the underlying structure, and the NIST SP 800-53 pre-implementation checklist is a reasonable warm-up before a Rev5 baseline.
How Do You Get FedRAMP Certified in 2026?
The single biggest change is that you no longer need to find an agency willing to sponsor you. FedRAMP’s certification path guidance describes two routes: Program Certification, which “operates independently without requiring federal agency sponsorship,” and Agency Certification, which requires an agency to authorize the service in advance. All FedRAMP 20x classes use Program Certification. Rev5 still generally requires a sponsor, with a small number of temporary Program Certification slots.
The pipelines opened on a fixed schedule published in FedRAMP’s 2026 important dates:
- July 6, 2026 – Marketplace listings opened for providers in the Initial Implementation phase.
- July 28, 2026 – FedRAMP Ready went legacy; no new Ready submissions are accepted, and providers are directed to 20x Class A instead.
- August 3, 2026 – The 20x Class A pipeline opened.
- August 10, 2026 – Temporary Rev5 pipelines opened for Ready Conversion and Lost Sponsor cases.
- August 31, 2026 – The 20x Class B and C pipelines open.
Submissions are now machine-readable. Per the 20x certification rules, a package includes the service overview, implementation and validation detail for every applicable requirement or Key Security Indicator, an Ongoing Certification Report, and JSON documents validated against FedRAMP schemas. Classes B, C, and D require a fresh independent assessment by a FedRAMP Recognized assessor completed within the previous three months; for Class A it is optional. Providers submit their own applications – assessors and advisors cannot submit on their behalf.
On timing, FedRAMP has committed to a target of making “an initial decision within 30 days of receiving any FedRAMP Certification application,” according to its getting certified guidance, with the clock pausing while FedRAMP waits on you. That is the review window only, not the months of engineering work that precede it.
What Is FedRAMP 20x and Where Does It Stand in August 2026?
FedRAMP 20x replaces narrative control write-ups with automated, continuously validated evidence. Instead of proving 323 controls in a document, providers demonstrate Key Security Indicators (KSIs) – outcome statements such as “Adopting Passwordless Methods” or “Testing Recovery Capabilities” – and back each one with machine-generated validation.
The rollout ran in phases. Per FedRAMP’s 20x program page, Phase One ran April through September 2025 at Low impact and drew 26 complete submissions; Phase Two ran from November 18, 2025 into March 2026 at Moderate, with first authorizations on March 6, 2026. Phase Three, the phase now underway, is about wide-scale adoption.
That arrived on June 25, 2026 with the Consolidated Rules for 2026. The announcement is unambiguous: “FedRAMP 20x is no longer just a pilot. It is now a widely available FedRAMP Certification path,” per FedRAMP’s June 2026 launch post. In its July 30, 2026 update, FedRAMP reported receiving nearly 30 Marketplace Provider Listing Forms in under 30 days, and placed the Class D (High) pilot in late 2026 with general availability expected in early 2027.
Under CR26, Class A providers must address seven KSIs, while Classes B and C are assessed against all 46 KSIs across 10 families listed in the CR26 Key Security Indicators reference. Validation rigor scales with class: Class B needs one automated validation method per KSI, Class C needs two, and Class D needs four, with Class C requiring six months of persistent validation history and Class D requiring 18 months.
Two deadlines matter more than the rest. CR26 takes mandatory effect for all stakeholders on January 1, 2027, including existing Rev5 certifications, and FedRAMP stops accepting new Rev5 applications on June 11, 2027. Providers that do not adjust lose their certification. The continuous-evidence model also makes compliance automation a prerequisite rather than a nice-to-have: 18 months of validation history cannot be reconstructed the week before an assessment.
How Much Does FedRAMP Cost and How Long Does It Take?
There is no official price list, and the government does not track it consistently. GAO reported in its January 2024 review of the program that estimated costs of pursuing FedRAMP authorization “varied widely and ranged anywhere from tens of thousands to millions of dollars,” and that data on actual costs were limited because agencies and providers calculated them differently.
The friction persists. In GAO’s June 23, 2026 report on federal cloud procurement, 15 of the 24 surveyed agencies named difficulty obtaining FedRAMP-authorized cloud solutions as one of the six most common procurement obstacles.
Budget in four buckets rather than one number: engineering work to close control or KSI gaps (usually the largest line), the independent assessment, documentation and automation tooling, and continuous monitoring once certified. The 20x path compresses the review window and removes sponsor-hunting, but front-loads engineering: you cannot fake automated, continuously collected evidence.
How Should You Prepare for FedRAMP Right Now?
If federal revenue is on your roadmap for the next 18 months, this sequence reflects how the 2026 rules actually work.
- Pick the lowest viable class. FedRAMP’s own advice is to “invest in the lowest starting class that meets the agency requirements and your business fit,” and to start at Class A if you have no agency customer yet. It explicitly warns against jumping to Class C or D without an existing contract that demands it.
- Define the authorization boundary. Decide exactly which services, accounts, and data flows are in scope before you spend money on assessment. Boundary churn is the most expensive rework there is.
- Map what you already have. A mature SOC 2 Type II program covers meaningful ground toward Class A, but FedRAMP is clear that it does not support “equivalency” – existing certifications reduce effort, they do not substitute for it. Our frameworks library shows where common controls overlap.
- Automate evidence before you apply. Under 20x, KSIs must be validated by automated methods with months of history. Start collecting now.
- Plan for continuous certification. Ongoing reporting, not the initial package, is where most programs quietly fall out of compliance.
FedRAMP in 2026 rewards teams that treat compliance as a live system rather than an annual document exercise. That is the whole point of 20x.
Frequently asked questions
Is FedRAMP mandatory?
How many controls are in each FedRAMP baseline?
Do you still need an agency sponsor for FedRAMP?
What is the difference between FedRAMP 20x and Rev5?
When do the Consolidated Rules for 2026 become mandatory?
How long does FedRAMP certification take?
- FedRAMP.gov – Marketplace statistics and latest updates (accessed August 11, 2026)
- OMB Memorandum M-24-15, Modernizing the Federal Risk and Authorization Management Program (July 25, 2024)
- FedRAMP – OMB Memorandum M-24-15 authority reference
- FedRAMP Rev5 Security Controls Baseline workbook (Low, Moderate, High, LI-SaaS)
- FedRAMP Documentation – Important Considerations for Cloud Service Providers
- FedRAMP Consolidated Rules for 2026 – Certification Classes for Agencies
- FedRAMP Consolidated Rules for 2026 – Important Dates
- FedRAMP Consolidated Rules for 2026 – Choosing a Certification Path
- FedRAMP Consolidated Rules for 2026 – FedRAMP 20x Certification Rules
- FedRAMP Consolidated Rules for 2026 – Getting Certified
- FedRAMP Consolidated Rules for 2026 – Key Security Indicators reference
- FedRAMP – Propelling Change: FedRAMP Launches Consolidated Rules for 2026 (June 25, 2026)
- FedRAMP – FedRAMP Certification Paths are Heating Up (July 30, 2026)
- FedRAMP 20x program page – phases and status
- FedRAMP – Initial Outcome from RFC-0020 FedRAMP Authorization Designations
- GAO-24-106591, Cloud Security: Federal Authorization Program Usage Increasing, but Challenges Need to Be Fully Addressed (January 18, 2024)
- GAO-26-107530, Cloud Computing: Federal Government Needs to Address Procurement Challenges (June 23, 2026)
Get FedRAMP-Ready Faster With Compyl
Compyl’s agentic GRC platform maps your existing SOC 2 and NIST work to FedRAMP baselines and 20x Key Security Indicators, then collects the automated, continuous evidence that Classes B, C, and D now demand. Build the validation history before you enter the pipeline, not after.
About this article. By Compyl Research. Last updated August 11, 2026. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.