FedRAMP 20x Fundamentals

Four building blocks show up on almost every 20x path: Key Security Indicators, the Security Decision Record, Collaborative Continuous Monitoring, and Certification Classes A–D. Each is defined by FedRAMP.gov; this page is a map, not a substitute.

Educational resource only. scm.cc is not a FedRAMP Recognized Independent Assessor (3PAO) and is not FedRAMP-authorized; it grants no authorization, certification, or assessment outcome. FedRAMP.gov is the authoritative source. This is not legal advice.

Technical detail

KSIs are 10 families and 46 indicators under CR26, with measurable statements and Class C markers where FedRAMP published them. The SDR is the core package artifact under 20x and replaces the traditional SSP. CCM is ongoing, collaborative monitoring rather than only a monthly document drop. Classes B, C, and D pair with Low, Moderate, and High during the transition through 31 December 2026; Class A is a pilot.

How to implement

Read the KSI catalog, the SDR schema, and the CCM / certification references on FedRAMP.gov. Then use the hub's KSI, SDR, evidence, and continuous-monitoring pages for implementation detail. Missing or unverified facts stay missing.

Questions teams ask

What are KSIs?
Key Security Indicators: 10 families and 46 indicators under the CR26 catalog. Each has a verbatim official statement. The hub renders them from that catalog.
What is the Security Decision Record?
The SDR is the core 20x package artifact in place of a traditional System Security Plan. FedRAMP publishes the schema; scm.cc validates against it and does not invent fields.
What is Collaborative Continuous Monitoring?
CCM is ongoing, collaborative monitoring (including the Ongoing Certification Report), not only a monthly document delivery. See the FedRAMP CCM reference.

Related hub pages

Primary sources

Last verified 2026-09-27. FedRAMP.gov is authoritative.

Explore the knowledge hub