FedRAMP 20x
The automation-first path built on Key Security Indicators and machine-readable validation. Now widely available for Low and Moderate after the Phase One and Phase Two pilots.
Compliance readiness
Preparing cloud service providers to sell to federal agencies, across both the 20x path and the closing Rev5 window.
Terminology changed July 4, 2026
Under the 2026 Consolidated Rules, “FedRAMP Authorization” and “FedRAMP Authorized” are retired in favor of “FedRAMP Certification” and “FedRAMP Certified” across every path. Existing Marketplace listings keep the same controls and authorization boundary.
Two paths
The automation-first path built on Key Security Indicators and machine-readable validation. Now widely available for Low and Moderate after the Phase One and Phase Two pilots.
The traditional documentation-driven path. Remains available, but FedRAMP stops accepting new Rev5 applications on June 11, 2027.
Reviewed July 31, 2026. FedRAMP has changed substantially over the past year; confirm current requirements before making a commitment on the basis of any third-party summary, this one included. Primary sources: FedRAMP Consolidated Rules for 2026 , FedRAMP 2026 important deadlines , FedRAMP Certification terminology .
Process
Establish the authorization boundary: what is inside the offering, what is inherited from your underlying provider, and what sits outside. This determines the size of everything that follows.
Measure the environment against the applicable baseline and produce a scored register of what is missing, what is partial, and what is already defensible.
Close gaps in priority order, with particular attention to controls that require a period of operating evidence rather than a configuration change.
Instrument continuous evidence collection. Under 20x this is the core of the work rather than an optimization.
Prepare the package and support you through third-party assessment, which is performed by an accredited assessor rather than by us.
FAQ
No. Under the 2026 Consolidated Rules, “FedRAMP Authorization” and “FedRAMP Authorized” are retired in favor of “FedRAMP Certification” and “FedRAMP Certified” across every path. Existing Marketplace listings keep the same controls and authorization boundary.
If a vendor is still marketing itself as "FedRAMP Authorized" or promising to get you "authorized", that is a reasonable signal about how current their information is.
For most organizations starting now, 20x. It is the direction the program is moving, the validation is automated rather than document-driven, and Rev5 has a closing window: FedRAMP stops accepting new Rev5 applications on June 11, 2027.
Rev5 still makes sense in specific cases, primarily where an agency sponsor has a strong preference or where an existing package is already substantially complete.
The traditional path was built around producing a very large body of documentation for human review. 20x is built around Key Security Indicators validated continuously and machine-readably.
The practical consequence is that engineering effort shifts earlier and documentation effort shifts later. Organizations that have automated their evidence collection find it substantially less painful; organizations relying on manual screenshots find the opposite.
This is one of the areas the program has been actively reworking, and the answer depends on which path and which impact level you are pursuing. It is worth confirming current requirements directly with FedRAMP rather than relying on guidance written before the 2026 Consolidated Rules took effect, including this page.
No. We provide readiness services only. Assessment is performed by an accredited third-party assessment organization, which is a separate role we do not occupy.
The boundary conversation is the one worth having first.