Program · US government cloud · GSA
FedRAMP compliance means meeting the US government's security requirements for cloud services sold to federal agencies. The Consolidated Rules for 2026 bring FedRAMP 20x into one ruleset, replace Low, Moderate and High with certification classes A to D, and become mandatory for all providers on 1 January 2027.
Cloud service providers whose services are used by US federal agencies.
QULDEX helps here first: the readiness check shows where you stand before you commit budget.
FedRAMP requires cloud providers to meet the security requirements for their certification class, have them independently assessed, and keep them current through continuous monitoring, under the Consolidated Rules for 2026.
Pick the class that matches the assurance agencies need.
In QULDEX: Class checklist per offeringOutcome-based, automatically validated indicators.
In QULDEX: KSIs mapped to 800-53Accredited assessor validates evidence.
In QULDEX: Assessor access, loggedAgencies decide and issue their own ATO.
In QULDEX: Evidence package for agenciesScans, POA&M and reporting.
In QULDEX: Monthly reporting from live dataExisting holders adopt the new rules.
In QULDEX: Both paths mappedThese 15 elements explain how FedRAMP works under the Consolidated Rules for 2026. Select any one to see the detail and how QULDEX handles it.
Showing up to 6 per group. Search, filter, or open a group to see all 15.
Class ACertification Class ANew in 2026Adequate for pilots, configuration and testing, or extremely low-risk use cases; a new entry path.
In QULDEXClass requirements are a checklist per offering.
Class BCertification Class BNew in 2026Adequate for most Low-impact agency systems and some Moderate or High systems with compensating controls; replaces "Low".
In QULDEXQULDEX tracks this requirement with an owner, evidence and a due date, and reuses NIST 800-53 and SOC 2 evidence where it fits.
Class CCertification Class CNew in 2026Adequate for most Low or Moderate-impact systems and some High systems with compensating controls; replaces "Moderate".
In QULDEXQULDEX tracks this requirement with an owner, evidence and a due date, and reuses NIST 800-53 and SOC 2 evidence where it fits.
Class DCertification Class DNew in 2026Adequate for most agency systems regardless of impact level, with compensating controls where needed; replaces "High".
In QULDEXQULDEX tracks this requirement with an owner, evidence and a due date, and reuses NIST 800-53 and SOC 2 evidence where it fits.
CR26Consolidated Rules for 2026One stable ruleset for FedRAMP 20x submissions, published 25 June 2026 and mandatory for all stakeholders from 1 January 2027.
In QULDEXRules are tracked as requirements with effective dates.
20xFedRAMP 20xThe automation-first approach announced in March 2025: machine-readable evidence, Key Security Indicators and faster reviews.
In QULDEXEvidence is collected in machine-readable form where tools allow.
KSIKey Security IndicatorsOutcome-based indicators that replace much of the narrative control documentation in 20x, validated with automated evidence.
In QULDEXKSIs map to the NIST 800-53 controls they cover.
Rev5Legacy Rev5 pathThe traditional NIST 800-53 Rev 5 baseline path remains during the transition, with Balance Improvement Releases bringing Rev5 holders closer to 20x.
In QULDEXRev5 baselines stay mapped in the control library.
M-24-15OMB memo M-24-15The July 2024 OMB policy that modernised FedRAMP toward automation and multiple paths to authorization.
In QULDEXQULDEX tracks this requirement with an owner, evidence and a due date, and reuses NIST 800-53 and SOC 2 evidence where it fits.
3PAOIndependent assessmentAn accredited Third Party Assessment Organization assesses the cloud service and validates evidence.
In QULDEXAssessors get view-only, logged access to evidence.
Agency useAgency authorization to operateEach agency still decides whether a certified service is appropriate for its system and issues its own ATO.
In QULDEXQULDEX tracks this requirement with an owner, evidence and a due date, and reuses NIST 800-53 and SOC 2 evidence where it fits.
MarketplaceFedRAMP MarketplaceCertified and in-process services are listed so agencies can find and reuse them.
In QULDEXQULDEX tracks this requirement with an owner, evidence and a due date, and reuses NIST 800-53 and SOC 2 evidence where it fits.
ConMonContinuous monitoringOngoing vulnerability scanning, POA&M updates and reporting to keep certification current.
In QULDEXScans and POA&M items feed monthly reporting automatically.
ChangeSignificant change requestsMaterial changes to the service are reviewed before they go live.
In QULDEXChanges are logged with impact assessments.
IncidentsIncident reportingSecurity incidents are reported to agency customers and CISA on short, defined timelines.
In QULDEXIncidents run with reporting timers.
Nothing matches that search.
Based on fedramp.gov and the FedRAMP Consolidated Rules for 2026. Class descriptions follow FedRAMP's own wording. Summaries are QULDEX paraphrases.
Choose a class, meet its requirements with automated evidence where you can, have a 3PAO assess you and keep monitoring. Expect 6 to 18 months depending on class and starting point.
Match the class to the agency data you will handle and decide between 20x and the legacy path.
Document the service boundary, components and data flows.
Implement and automate validation of the Key Security Indicators or the Rev5 baseline.
An accredited 3PAO assesses and validates the evidence.
FedRAMP reviews the package; agencies can then issue ATOs.
Pipeline dates follow fedramp.gov announcements. Durations are QULDEX planning ranges.
The 20x path favours machine-readable evidence over long narratives, but these records remain the core of a package.
| Document | Purpose | Where it lives in QULDEX |
|---|---|---|
| Service boundary and inventory | Defines what is certified | Risk register |
| Key Security Indicator evidence (20x) | Shows outcomes are met | Evidence vault |
| System Security Plan (Rev5) | Describes control implementation | Policy library |
| Security Assessment Report | 3PAO results | Audit workspace |
| Plan of Action and Milestones | Tracks open findings | CAPA automation |
| Continuous monitoring reports | Monthly scans and status | Evidence vault |
| Incident response plan | Defines reporting | Policy library |
| Customer responsibility matrix | Shared responsibilities with agencies | Evidence vault |
Document names follow FedRAMP guidance; storage locations are QULDEX recommendations.
Expect 6 to 18 months. The class you target, how much evidence you can automate and whether you already meet NIST 800-53 drive the effort.
Bars show the upper end of each range on one scale (18 months = full width).
Check these eight things first. Nothing you enter leaves this page.
FedRAMP baselines come from NIST SP 800-53 Rev 5. SOC 2 and ISO 27001 evidence covers part of them, but FedRAMP adds federal-specific requirements.
| FedRAMP area | NIST 800-53 Rev 5 | SOC 2 | ISO 27001:2022 | Shared evidence |
|---|---|---|---|---|
| Identity and access | AC, IA | CC6.1–CC6.3 | A.5.15–A.5.18, A.8.5 | Access reviews, MFA |
| Change management | CM | CC8.1 | A.8.32 | Change records |
| Monitoring and logging | AU, SI-4 | CC7.2 | A.8.15–A.8.16 | Log samples |
| Vulnerability management | RA-5, SI-2 | CC7.1 | A.8.8 | Scan results |
| Incident response | IR | CC7.3–CC7.5 | A.5.24–A.5.26 | Incident reports |
| Recovery | CP | A1.2–A1.3 | A.5.30, A.8.13 | Backup and DR tests |
| Supply chain | SR | CC9.2 | A.5.19–A.5.22 | Vendor assessments |
Indicative mapping for planning. FedRAMP 20x vs Rev5 is compared in full on the blog.
QULDEX is FedRAMP compliance and audit management software built from EGV Group's audit delivery, used by cloud providers, their advisors and the 3PAOs who assess them. Pick your role to see who does what.
For SaaS, PaaS and IaaS providers selling to agencies.
For FedRAMP advisors and internal audit.
For accredited third-party assessors.
Requirements with owners, test steps and the crosswalk to 50+ frameworks.
Explore →EvidenceEvidence linked to controls and findings, with upload, review and approval history.
Explore →RiskRisk assessment and treatment, with decisions traced to the controls they drive.
Explore →FindingsFindings from internal and external audits tracked to closure with due dates.
Explore →FedRAMP published the Consolidated Rules for 2026 on 25 June 2026. They bring FedRAMP 20x into one ruleset, introduce certification classes A to D, opened new pipelines in August 2026, and become mandatory for all stakeholders on 1 January 2027.
Class A is for pilots and very low-risk uses; Class B replaces Low; Class C replaces Moderate; and Class D replaces High. Agencies still decide whether a service fits their own system.
Rev5 remains during the transition for providers already in the legacy process, and existing Rev5 holders must adopt the new rules. FedRAMP is phasing out new Rev5 applications; check fedramp.gov for the current cut-off date.
Typically 6 to 18 months, depending on the class, how much evidence you can automate and your existing NIST 800-53, SOC 2 or ISO 27001 controls.
A Third Party Assessment Organization accredited to assess cloud services for FedRAMP and validate their evidence.
NIST CSF, 800-53 and CIS Controls articles.
blog.quldex.comA file-naming scheme assessors can follow.
blog.quldex.comHow many samples assessors look at.
blog.quldex.comGovernance outcomes that support a FedRAMP programme.
Reviewed by
Answer a short readiness check and get a gap summary by area. No sales call needed to see the result.