FedRAMP 20x Knowledge Authority
FedRAMP 20x is the U.S. government's modernized approach to authorizing cloud services for federal use, introduced under the FedRAMP Consolidated Rules for 2026 (CR26). It emphasizes automation, machine-readable evidence, and continuous validation in place of document-heavy, point-in-time review.
Educational resource only. scm.cc is not a FedRAMP Recognized Independent Assessor (3PAO) and is not FedRAMP-authorized; it grants no authorization, certification, or assessment outcome. FedRAMP.gov is the authoritative source. This is not legal advice.
What changed from Rev5
FedRAMP 20x keeps the underlying security expectations but changes how a cloud service demonstrates them:
- The Security Decision Record (SDR) is the core package artifact under 20x, in place of the traditional System Security Plan (SSP).
- Key Security Indicators (KSIs) — 10 families and 46 indicators under CR26 — express measurable security capabilities that are validated by automated methods.
- Authorization status is expressed through Certification and Classes A-D.
- Monitoring is collaborative and continuous, rather than only a monthly document delivery.
Certification classes at a glance
FedRAMP uses Certification and Classes A-D for package baselines. During the transition through December 31, 2026, Class B (Low), Class C (Moderate) and Class D (High) pair the new class with the earlier impact label; Class A is a pilot. Certification does not replace an agency's own authorization to operate (ATO). Class A and Class D specifics continue to evolve — confirm the current class definitions on FedRAMP.gov before relying on them.
How certification works
The path runs from determining applicability and the right class, to implementing requirements and KSIs, establishing the SDR and persistent validation, gathering evidence, an independent assessment by a FedRAMP Recognized Independent Assessor (the role formerly called a 3PAO) where required, resolving findings, and the certification decision. Each stage is covered in the Get Certified guides.
Explore the knowledge hub
Learn
Get Certified
Stay Certified
Implementation
Marketplace
Intelligence
Free Tools
Primary sources
- FedRAMP 20x overview & Core Principles
- FedRAMP Consolidated Rules for 2026 (CR26)
- FedRAMP Certification reference
- Security Decision Record
- Key Security Indicators
Reviewed against official sources as of 2026-09-27. FedRAMP.gov is the authoritative source; verify current rules before relying on a date or requirement.