FedRAMP 20x Knowledge Authority

FedRAMP 20x is the U.S. government's modernized approach to authorizing cloud services for federal use, introduced under the FedRAMP Consolidated Rules for 2026 (CR26). It emphasizes automation, machine-readable evidence, and continuous validation in place of document-heavy, point-in-time review.

Educational resource only. scm.cc is not a FedRAMP Recognized Independent Assessor (3PAO) and is not FedRAMP-authorized; it grants no authorization, certification, or assessment outcome. FedRAMP.gov is the authoritative source. This is not legal advice.

What changed from Rev5

FedRAMP 20x keeps the underlying security expectations but changes how a cloud service demonstrates them:

Certification classes at a glance

FedRAMP uses Certification and Classes A-D for package baselines. During the transition through December 31, 2026, Class B (Low), Class C (Moderate) and Class D (High) pair the new class with the earlier impact label; Class A is a pilot. Certification does not replace an agency's own authorization to operate (ATO). Class A and Class D specifics continue to evolve — confirm the current class definitions on FedRAMP.gov before relying on them.

How certification works

The path runs from determining applicability and the right class, to implementing requirements and KSIs, establishing the SDR and persistent validation, gathering evidence, an independent assessment by a FedRAMP Recognized Independent Assessor (the role formerly called a 3PAO) where required, resolving findings, and the certification decision. Each stage is covered in the Get Certified guides.

Explore the knowledge hub

Primary sources

Reviewed against official sources as of 2026-09-27. FedRAMP.gov is the authoritative source; verify current rules before relying on a date or requirement.