What’s New with FedRAMP 20x? Your Guide to FedRAMP 20x in 2026

September 15, 2026 | FedRAMP

By: Aaron Hamlin

 

FedRAMP 20x is moving beyond its initial pilots and into broader adoption. As of September 2026, cloud service providers (CSPs) can apply for Class A, B, and C certifications through 20x, while development of the 20x Class D option continues.

For CSPs entering the federal market or planning their next steps, three developments stand out:

  • Broader access: The 20x Program Certification path allows providers to pursue certification without an agency sponsor.
  • A new class structure: FedRAMP’s new certification classes apply across the program—not just to 20x—and describe different levels of assurance available to agencies.
  • Greater operational emphasis: Security Decision Records, Key Security Indicators, machine-readable evidence, and automation are changing how providers demonstrate and sustain security.

Even with all the new and impending changes, CSPs remain accountable for protecting federal information. The opportunity here is to connect security decisions, engineering practices, and reliable evidence—not to simply produce fewer documents.

What is FedRAMP 20x?

The traditional FedRAMP agency authorization process has been documentation-intensive. Service providers developed extensive security materials, underwent an assessment by a Third-Party Assessment Organization (3PAO), and were required to secure an agency sponsor prior to certification.

FedRAMP 20x takes a different approach. It emphasizes demonstrable security capabilities and measurable outcomes, supported by automation and structured evidence. Rather than simply reproducing a traditional control-by-control package, CSPs must explain their security decisions and demonstrate that the measures they have implemented are effective.

CSPs can pursue 20x Program Certification directly through FedRAMP without an agency sponsor. This removes a significant dependency from the certification process. However, it does not eliminate the agency’s role in deciding whether to use a service.

FedRAMP certification is not an agency authorization to operate. Each agency remains responsible for evaluating the offering and authorizing its use within the agency’s information system, including the relevant configuration, integrations, and risks. Certification applies to the specified cloud service offering—not every product or operation of the provider.

What’s Changed?

Since FedRAMP 20x was introduced, the program has moved through several pilot phases designed to test new approaches to assessing and certifying organizations’ security postures. The results of those pilots have helped shape the current 20x requirements, which are now incorporated into the FedRAMP Consolidated Rules for 2026.

New Certification Classes

FedRAMP’s class structure includes Classes A, B, C, and D. Class A provides an entry point for providers entering the federal market. Classes B, C, and D broadly align with the former Low, Moderate, and High baselines, respectively. 

Notably, these are not one-for-one replacements for agency impact-level determinations. Classes describe the depth, frequency, and quality of assurance information, while agencies retain responsibility for security categorization and risk decisions.

Class A takes the place of the former “FedRAMP Ready” designation, but it is a certification route—not an automatic conversion of readiness status. CSPs can build on a SOC 2 Type 2 or another approved assessment completed within the previous 12 months, but they must also address the FedRAMP requirements applicable to Class A. (An existing assessment supports the application; it does not automatically establish certification.)

Class A should also be viewed in the context of longer-term customer needs. FedRAMP’s agency guidance advises against authorizing use of a Class A service for more than 12 months unless the provider is actively seeking Class B, C, or D certification.

Class A, B, and C applications are now open through 20x. Rev5 Class D remains available while the 20x option is developed. Under the current plan, FedRAMP anticipates a 20x Class D pilot to launch in late 2026 and a formal certification option to become available in early 2027.

Security Decision Record & Machine-Readable Evidence

The traditional System Security Plan (SSP) and its appendices are giving way to a more structured certification package. Under 20x, two central components are the Certification Package Overview (CPO) and the Security Decision Record (SDR).

The CPO summarizes the cloud service offering, its scope, and the information included in the package. The SDR maintains a record of security decisions made throughout the offering’s lifecycle, including how applicable requirements are addressed, how implementations are verified and validated, and relevant supporting evidence and assessment information.

Required package components must be supplied in human-readable and structured JSON formats according to the applicable FedRAMP rules and schemas. Although this does not eliminate written explanations, relevant policies, configuration guidance, or assessment information, it does reduce dependence on static templates.

For security and compliance teams, the practical takeaway from this shift is that it’s best to maintain a log of decisions and evidence as part of your normal operations, rather than assemble them primarily for a point-in-time review.

Key Security Indicators

Key Security Indicators, or KSIs, help service providers demonstrate the effectiveness of their security capabilities through meaningful measures and supporting evidence. They focus attention on security outcomes within the operating environment, rather than documentation alone.

For example, a vulnerability management policy can explain how weaknesses should be addressed. Technical evidence shows whether the process is working—i.e., whether detection covers the intended environment, whether findings are evaluated, and whether remediation actually resolves the issue. That distinction between describing a process and demonstrating its effectiveness is central to the 20x approach.

CSPs must also explain the measures supporting their applicable KSIs and how those measures are verified and validated. They also need to account for class-specific historical metrics requirements, rather than assuming that a current dashboard alone provides sufficient evidence.

This does not make formal reporting disappear. The rules require Ongoing Certification Reports every three months, alongside applicable package-maintenance, review, and assessment obligations. Continuously maintained evidence supports these responsibilities; it does not replace them.

The Role of Automation

Automation can make evidence collection and validation more repeatable, but its role varies by certification class. For Class C, automated KSI verification and validation are mandatory, with at least two automated methods per KSI. The rules also require at least six months of historical KSI metrics. Providers applying before that history is available must have mechanisms in place and agree to meet the requirement.

Automation does not eliminate independent assessment or professional judgment. Classes B and C require FedRAMP independent assessments, including coverage of all KSIs, at least once per year. (Class A follows the assurance expectations of its approved underlying framework; a separate FedRAMP-specific independent assessment is optional.)

Preparing for these requirements calls for more than purchasing an evidence-collection tool. FedRAMP’s KSI guidance explicitly calls for hands-on involvement from software, infrastructure, and security engineers. Security, engineering, and compliance teams should work together to connect reliable data sources, validate their outputs, and respond when evidence reveals a security issue.

What is Happening to Traditional FedRAMP?

The traditional Rev5 path to FedRAMP is still available during the transition to 20x, but its requirements are also changing. Mandatory adoption of Rev5 begins Jan. 1, 2027, subject to rule-specific effective dates and transition provisions. Some requirements already apply. 

FedRAMP will stop accepting applications for new Rev5 certifications on June 11, 2027. That is an application cutoff—not a date on which existing certifications automatically terminate.

Current guidance states that existing Rev5 certifications will remain active until at least Dec. 31, 2028, unless FedRAMP is otherwise directed. However, the end-of-2028 deadline should not be treated as a confirmed expiration date or permission to defer modernization—CSPs must continue meeting the applicable requirements to maintain their status.

Providers already pursuing Rev5 should evaluate the work completed, their agency relationships, customer requirements, and the readiness of their engineering and security programs before changing direction. The right decision is not necessarily to abandon an in-progress effort, but it should include a deliberate plan for adopting the updated rules and transitioning to 20x.

The Bottom Line

FedRAMP 20x offers a more accessible, outcome-focused route to federal cloud certification. Success depends on more than a different documentation format: providers need security practices that can consistently substantiate their decisions and support ongoing assurance.

Start with the intended federal use of the offering, select an appropriate certification class, and assess the gaps across security, engineering, and compliance. FedRAMP encourages progressive investment based on agency needs, rather than pursuing the highest class without a clear business reason.

At BARR Advisory, we help cloud service providers develop a FedRAMP strategy aligned with their federal customers, assess technical and operational readiness, and build the security processes and evidence capabilities needed to support initial and ongoing certification. Our advisory and security engineering teams translate evolving requirements into a practical roadmap—from identifying gaps to integrating automation and sustaining assurance over time.

Contact us today to discuss the right next step for your team.

 

About the Author

 

Aaron Hamlin serves as practice leader of cybersecurity consulting at BARR Advisory, where he leads initiatives in cybersecurity compliance and risk management, specializing in federal and government-focused frameworks such as FedRAMP, FISMA, CMMC, NIST 800-171, ISO, SOC, and HITRUST. Throughout his career, he has successfully supported dozens of organizations in achieving their compliance goals while fostering innovation and building robust security programs.

Let's Talk