Program · US government cloud · GSA

FedRAMP compliance in 2026: 20x, certification classes and Rev5

FedRAMP compliance means meeting the US government's security requirements for cloud services sold to federal agencies. The Consolidated Rules for 2026 bring FedRAMP 20x into one ruleset, replace Low, Moderate and High with certification classes A to D, and become mandatory for all providers on 1 January 2027.

Key takeaways

What you need to know about FedRAMP

Classes, not levelsCertification classes A to D replace the Low, Moderate and High labels.
Automation first20x relies on Key Security Indicators and machine-readable evidence.
Rev5 in transitionExisting Rev5 holders move to the new rules; new Rev5 applications are being phased out.
Agencies still decideEach agency issues its own ATO for its system.
Continuous monitoringCertification depends on ongoing scanning and reporting.

Who needs FedRAMP?

Cloud service providers whose services are used by US federal agencies.

SaaS providersSelling software to federal agencies.
IaaS and PaaS providersHosting federal workloads.
Defense suppliers' cloud providersCloud handling CUI must be FedRAMP Moderate (Class C) or equivalent.
State and local suppliersMany states reuse FedRAMP evidence.
3PAOs and advisorsAssessors and consultants serving providers.

QULDEX helps here first: the readiness check shows where you stand before you commit budget.

What the program requires

What does FedRAMP require?

FedRAMP requires cloud providers to meet the security requirements for their certification class, have them independently assessed, and keep them current through continuous monitoring, under the Consolidated Rules for 2026.

Classes A–D

Certification class

Pick the class that matches the assurance agencies need.

In QULDEX: Class checklist per offering
KSIs 20x

Key Security Indicators

Outcome-based, automatically validated indicators.

In QULDEX: KSIs mapped to 800-53
3PAO Assess

Independent assessment

Accredited assessor validates evidence.

In QULDEX: Assessor access, logged
ATO Agency

Agency use

Agencies decide and issue their own ATO.

In QULDEX: Evidence package for agencies
ConMon Monitor

Continuous monitoring

Scans, POA&M and reporting.

In QULDEX: Monthly reporting from live data
Rev5 Legacy

Rev5 transition

Existing holders adopt the new rules.

In QULDEX: Both paths mapped
Program explorer

What are the FedRAMP 2026 rules and classes?

These 15 elements explain how FedRAMP works under the Consolidated Rules for 2026. Select any one to see the detail and how QULDEX handles it.

Jul 2024OMB M-24-15
Mar 202520x announced
Jun 2026Consolidated Rules
Jan 2027rules mandatory

Showing up to 6 per group. Search, filter, or open a group to see all 15.

Certification classes 4

  1. Class ACertification Class ANew in 2026

    Adequate for pilots, configuration and testing, or extremely low-risk use cases; a new entry path.

    In QULDEXClass requirements are a checklist per offering.

  2. Class BCertification Class BNew in 2026

    Adequate for most Low-impact agency systems and some Moderate or High systems with compensating controls; replaces "Low".

    In QULDEXQULDEX tracks this requirement with an owner, evidence and a due date, and reuses NIST 800-53 and SOC 2 evidence where it fits.

  3. Class CCertification Class CNew in 2026

    Adequate for most Low or Moderate-impact systems and some High systems with compensating controls; replaces "Moderate".

    In QULDEXQULDEX tracks this requirement with an owner, evidence and a due date, and reuses NIST 800-53 and SOC 2 evidence where it fits.

  4. Class DCertification Class DNew in 2026

    Adequate for most agency systems regardless of impact level, with compensating controls where needed; replaces "High".

    In QULDEXQULDEX tracks this requirement with an owner, evidence and a due date, and reuses NIST 800-53 and SOC 2 evidence where it fits.

Rules and approach 5

  1. CR26Consolidated Rules for 2026

    One stable ruleset for FedRAMP 20x submissions, published 25 June 2026 and mandatory for all stakeholders from 1 January 2027.

    In QULDEXRules are tracked as requirements with effective dates.

  2. 20xFedRAMP 20x

    The automation-first approach announced in March 2025: machine-readable evidence, Key Security Indicators and faster reviews.

    In QULDEXEvidence is collected in machine-readable form where tools allow.

  3. KSIKey Security Indicators

    Outcome-based indicators that replace much of the narrative control documentation in 20x, validated with automated evidence.

    In QULDEXKSIs map to the NIST 800-53 controls they cover.

    Typical evidence
    Automated validation output
    Maps to
    NIST 800-53

  4. Rev5Legacy Rev5 path

    The traditional NIST 800-53 Rev 5 baseline path remains during the transition, with Balance Improvement Releases bringing Rev5 holders closer to 20x.

    In QULDEXRev5 baselines stay mapped in the control library.

    Typical evidence
    SSP, SAR, POA&M
    Maps to
    NIST 800-53 Rev 5

  5. M-24-15OMB memo M-24-15

    The July 2024 OMB policy that modernised FedRAMP toward automation and multiple paths to authorization.

    In QULDEXQULDEX tracks this requirement with an owner, evidence and a due date, and reuses NIST 800-53 and SOC 2 evidence where it fits.

Process 6

  1. 3PAOIndependent assessment

    An accredited Third Party Assessment Organization assesses the cloud service and validates evidence.

    In QULDEXAssessors get view-only, logged access to evidence.

    Typical evidence
    Assessment report

  2. Agency useAgency authorization to operate

    Each agency still decides whether a certified service is appropriate for its system and issues its own ATO.

    In QULDEXQULDEX tracks this requirement with an owner, evidence and a due date, and reuses NIST 800-53 and SOC 2 evidence where it fits.

    Typical evidence
    Agency ATO letter

  3. MarketplaceFedRAMP Marketplace

    Certified and in-process services are listed so agencies can find and reuse them.

    In QULDEXQULDEX tracks this requirement with an owner, evidence and a due date, and reuses NIST 800-53 and SOC 2 evidence where it fits.

  4. ConMonContinuous monitoring

    Ongoing vulnerability scanning, POA&M updates and reporting to keep certification current.

    In QULDEXScans and POA&M items feed monthly reporting automatically.

    Typical evidence
    Monthly scan results, POA&M
    Maps to
    NIST 800-53 CA-7

  5. ChangeSignificant change requests

    Material changes to the service are reviewed before they go live.

    In QULDEXChanges are logged with impact assessments.

    Typical evidence
    Change request

  6. IncidentsIncident reporting

    Security incidents are reported to agency customers and CISA on short, defined timelines.

    In QULDEXIncidents run with reporting timers.

    Typical evidence
    Incident reports
    Maps to
    NIST 800-53 IR-6

Based on fedramp.gov and the FedRAMP Consolidated Rules for 2026. Class descriptions follow FedRAMP's own wording. Summaries are QULDEX paraphrases.

Certification path

How do you get FedRAMP certified?

Choose a class, meet its requirements with automated evidence where you can, have a 3PAO assess you and keep monitoring. Expect 6 to 18 months depending on class and starting point.

  1. Choose the class and the path

    Match the class to the agency data you will handle and decide between 20x and the legacy path.

  2. Define the boundary and inventory

    Document the service boundary, components and data flows.

  3. Meet the requirements

    Implement and automate validation of the Key Security Indicators or the Rev5 baseline.

  4. Independent assessment

    An accredited 3PAO assesses and validates the evidence.

  5. FedRAMP review and Marketplace listing

    FedRAMP reviews the package; agencies can then issue ATOs.

  6. Continuous monitoring

    MonthlyScans and POA&M updates
    On changeSignificant change review
    YearlyAnnual assessment

Pipeline dates follow fedramp.gov announcements. Durations are QULDEX planning ranges.

Records to keep

Which documents does FedRAMP need?

The 20x path favours machine-readable evidence over long narratives, but these records remain the core of a package.

DocumentPurposeWhere it lives in QULDEX
Service boundary and inventoryDefines what is certifiedRisk register
Key Security Indicator evidence (20x)Shows outcomes are metEvidence vault
System Security Plan (Rev5)Describes control implementationPolicy library
Security Assessment Report3PAO resultsAudit workspace
Plan of Action and MilestonesTracks open findingsCAPA automation
Continuous monitoring reportsMonthly scans and statusEvidence vault
Incident response planDefines reportingPolicy library
Customer responsibility matrixShared responsibilities with agenciesEvidence vault

Document names follow FedRAMP guidance; storage locations are QULDEX recommendations.

Time and cost

How long does FedRAMP take and what drives the effort?

Expect 6 to 18 months. The class you target, how much evidence you can automate and whether you already meet NIST 800-53 drive the effort.

Where the time goes

Class and boundary1–2 mo
Meeting requirements3–9 mo
3PAO assessment1–3 mo
FedRAMP review1–3 mo
Monitoring set-up1–2 mo

Bars show the upper end of each range on one scale (18 months = full width).

What changes the effort

  • Class: Class D (High) carries the most requirements
  • Automation: machine-readable evidence speeds 20x review
  • Architecture: cloud-native services fit 20x more easily
  • Existing SOC 2 or ISO 27001: covers part of the evidence
  • Agency sponsor: helps for legacy Rev5 paths
Readiness check · 2 minutes

How ready are you for FedRAMP?

Check these eight things first. Nothing you enter leaves this page.

ClassDo you know which certification class your agency customers need?
BoundaryIs your service boundary documented with an inventory?
KSICan you show security outcomes with automated evidence?
IAIs phishing-resistant MFA in place for all users?
RADo you scan continuously and track findings in a POA&M?
IRCan you report incidents to agencies and CISA quickly?
CMAre configuration changes reviewed and logged?
3PAOHave you chosen a 3PAO and planned the assessment?
Crosswalk

How FedRAMP maps to NIST 800-53, SOC 2 and ISO 27001

FedRAMP baselines come from NIST SP 800-53 Rev 5. SOC 2 and ISO 27001 evidence covers part of them, but FedRAMP adds federal-specific requirements.

FedRAMP crosswalk

FedRAMP areaNIST 800-53 Rev 5SOC 2ISO 27001:2022Shared evidence
Identity and accessAC, IACC6.1–CC6.3A.5.15–A.5.18, A.8.5Access reviews, MFA
Change managementCMCC8.1A.8.32Change records
Monitoring and loggingAU, SI-4CC7.2A.8.15–A.8.16Log samples
Vulnerability managementRA-5, SI-2CC7.1A.8.8Scan results
Incident responseIRCC7.3–CC7.5A.5.24–A.5.26Incident reports
RecoveryCPA1.2–A1.3A.5.30, A.8.13Backup and DR tests
Supply chainSRCC9.2A.5.19–A.5.22Vendor assessments

Indicative mapping for planning. FedRAMP 20x vs Rev5 is compared in full on the blog.

Where QULDEX fits

How QULDEX runs FedRAMP from boundary to continuous monitoring

QULDEX is FedRAMP compliance and audit management software built from EGV Group's audit delivery, used by cloud providers, their advisors and the 3PAOs who assess them. Pick your role to see who does what.

For SaaS, PaaS and IaaS providers selling to agencies.

  1. PlanChoose class and pathClass checklist per offering
  2. BoundaryDocument the boundaryInventory linked to evidence
  3. RequirementsMeet KSIs or baselineRequirements mapped to 800-53
  4. AssessHost the 3PAOControlled evidence sharing
  5. ReviewAnswer FedRAMP and agenciesPackage sharing with access logs
  6. MonitorRun ConMonMonthly scans and POA&M
Without one systemWith QULDEX
Narrative SSPs rewritten every yearEvidence linked to live data
Monthly ConMon assembled by handScans and POA&M feed reports
SOC 2 and FedRAMP run separatelyOne control set mapped to both
Agency questions answered by emailPackage sharing with access logs
10+years of audit delivery500+audits deliveredBoth sidesof the audit on one platformRBACand a full audit trail on every action
FAQ

FedRAMP questions people ask

What changed in FedRAMP in 2026?

FedRAMP published the Consolidated Rules for 2026 on 25 June 2026. They bring FedRAMP 20x into one ruleset, introduce certification classes A to D, opened new pipelines in August 2026, and become mandatory for all stakeholders on 1 January 2027.

What are FedRAMP certification classes?

Class A is for pilots and very low-risk uses; Class B replaces Low; Class C replaces Moderate; and Class D replaces High. Agencies still decide whether a service fits their own system.

Is FedRAMP Rev5 being retired?

Rev5 remains during the transition for providers already in the legacy process, and existing Rev5 holders must adopt the new rules. FedRAMP is phasing out new Rev5 applications; check fedramp.gov for the current cut-off date.

How long does FedRAMP take?

Typically 6 to 18 months, depending on the class, how much evidence you can automate and your existing NIST 800-53, SOC 2 or ISO 27001 controls.

What is a 3PAO?

A Third Party Assessment Organization accredited to assess cloud services for FedRAMP and validate their evidence.

Sources

References

  1. FedRAMP Consolidated Rules for 2026 announcement, 25 Jun 2026. fedramp.gov
  2. FedRAMP Certification Classes. fedramp.gov/2026
  3. OMB Memorandum M-24-15, Modernizing FedRAMP, Jul 2024. whitehouse.gov
  4. FedRAMP Authorization Act (FY2023 NDAA). congress.gov
  5. NIST SP 800-53 Rev 5. csrc.nist.gov

Reviewed by

Ankit Tiwari

Framework reviewer · QULDEX

Reviewed this page against fedramp.gov and the Consolidated Rules for 2026: classes, the 20x approach and the Rev5 transition.

Page history
  • : Page first built: certification classes, 2026 rules, process explorer and readiness check

Pick your FedRAMP class and path with confidence

Answer a short readiness check and get a gap summary by area. No sales call needed to see the result.

Schedule
Book a Demo