FedRAMP 20x Class A Pipeline: What Opens August 3 and Who Qualifies

Last updated #fedramp #compliance #saas #cloud-security

By — founder of GovExpress; prior domain experience at Bloomberg Government and GovWin IQ.

FedRAMP 20x Class A is a transitory FedRAMP certification for cloud services with mature security and compliance programs entering the federal marketplace — and its submission pipeline opens on August 3, 2026, per FedRAMP’s June 25, 2026 announcement of the Consolidated Rules for 2026. For a SaaS company that has been circling the federal market, Class A is the first FedRAMP pathway that accepts an existing commercial assessment — a SOC 2 Type II completed within the past 12 months — as the entry ticket, and the first that requires no agency sponsor at all.

This explainer is built exclusively from FedRAMP’s primary sources: the Consolidated Rules announcement, the Class A rulesets, the RFC outcomes, and the machine-readable rules on GitHub. Every date and requirement below links to where FedRAMP says it.

What actually opens on August 3

FedRAMP launched its Consolidated Rules for 2026 on June 24–25, 2026, and published a rollout calendar alongside them. Three dates matter for new entrants (FedRAMP, June 25, 2026):

  • July 6, 2026 — Marketplace listings open (initial implementation phase)
  • August 3, 2026 — the Class A submission pipeline opens
  • August 31, 2026 — the Class B and Class C pipelines open

August 3 is not “FedRAMP 20x launches” — the program has been running phased pilots since March 2025, with Phase 1 completed in September 2025 and Phase 2 completed March 31, 2026. August 3 is the day the fast on-ramp opens to the public: the first date any cloud provider can submit a Class A certification package under the new rules.

Class A, B, C, and D — the new taxonomy

The class taxonomy came out of RFC-0020, and FedRAMP’s initial outcome notice (February 25, 2026) maps the four classes onto the legacy baselines:

  • Class A — “a new pilot baseline”: the transitory on-ramp described in this article
  • Class B — the current Li-SaaS and Low baselines
  • Class C — the current Moderate baseline
  • Class D — the current High baseline, to be developed in Phase 4, estimated FY27

The 20x program page adds the qualitative framing: Class A is “for cloud services with mature security and compliance programs that are looking to enter the federal marketplace”; Class B is for “fairly common small-scale or light use services”; Class C is for “common enterprise services that are likely to be used in systems across an entire agency or that provide important government services.” Per the RFC-0020 outcome, the classes differ by “the depth and complexity of the information provided by the cloud service provider” — the label identifies the scope of FedRAMP’s assessment, “not the total quality or security of the cloud service.”

Class A vs. Class B vs. Class C

Class AClass BClass C
Pipeline opensAugust 3, 2026August 31, 2026August 31, 2026
Legacy equivalentNew pilot baselineLi-SaaS / LowModerate
Intended forMature commercial programs entering federalSmall-scale or light-use servicesEnterprise services used agency-wide
Key Security Indicators7 KSIs across 6 familiesFull set — 46 KSIs across 10 familiesFull set — 46 KSIs across 10 families
External-framework entry (SOC 2 Type II, GovRAMP, prior Rev5)Yes — required, completed within past 12 monthsNo — assessed against full KSI setNo — assessed against full KSI set
Independent assessmentOptional (MAY)RequiredRequired
PermanenceTransitory — Class B/C/D assessment must be scheduled within 2 yearsPermanent certificationPermanent certification

Class D (High baseline) arrives with Phase 4, which FedRAMP estimates for FY27 — sources: Class A certification ruleset, key security indicators reference, RFC-0020 outcome, 20x program page.

Who qualifies for the Class A pipeline

The eligibility rule is FRC-CLA-ASF: providers “MUST have completed a certification or equivalent process, including an independent assessment if applicable, from one of the following alternative security frameworks within the past 12 months”:

  1. FedRAMP Rev5 (including FedRAMP Ready) at any historical impact level
  2. SOC 2 Type II
  3. GovRAMP at any impact level

That second line is the headline for commercial SaaS. RFC-0022’s outcome (March 3, 2026) describes Class A as a “temporary high speed path to FedRAMP authorization for cloud services with existing security assessments from external security frameworks” and names SOC 2 Type II as “the initial test case.” If your SOC 2 Type II report is older than 12 months, renewing it is now a federal-market prerequisite, not just a commercial-sales one.

Two things Class A does not require:

  • An agency sponsor. The Class A rulesets contain no sponsorship requirement. Under the legacy agency-authorization path, finding a federal customer willing to act as authorizing official was the bottleneck that kept most new entrants out.
  • A mandatory independent assessment. Rule FRC-CLA-IVV says providers “MAY have the FedRAMP Certification Package independently verified and validated by a FedRAMP Recognized assessor before submission” — optional at this stage.

The seven Key Security Indicators

Key Security Indicators are FedRAMP 20x’s replacement for narrative, control-by-control documentation: machine-validated indicators, each mapped to specific NIST SP 800-53 controls. The full set spans 46 KSIs across 10 families — from Cloud Native Architecture to Supply Chain Risk. Class A requires a reduced set of 7 KSIs across 6 families:

  1. KSI-CMT-LMC — Logging Changes (Change Management)
  2. KSI-CNA-RNT — Restricting Network Traffic (Cloud Native Architecture)
  3. KSI-CED-RAT — Reviewing All Training (Cybersecurity Education)
  4. KSI-IAM-AAM — Automating Account Management (Identity and Access Management)
  5. KSI-IAM-APM — Adopting Passwordless Methods (Identity and Access Management)
  6. KSI-INR-RIR — Reviewing Incident Response Procedures (Incident Response)
  7. KSI-SVC-SIN — Securing Information (Service Configuration)

Note item 5: passwordless authentication is a named, mandatory indicator. If your product or your internal corporate access still depends on passwords alone, that is a concrete engineering work item between now and submission.

The reporting model is machine-readable and continuous. Per the Class A certification package overview, the package “serves as a replacement for the historical System Security Plan”; providers submit a JSON-schema-compliant Ongoing Certification Report, “are expected to maintain their FedRAMP Certification Package using automation as changes occur,” and must refresh it at least once every 3 months.

The 2-year clock: Class A is an on-ramp, not a destination

FedRAMP is explicit that Class A is transitory. RFC-0022 says Class A certifications are “intended to be transitory and replaced by a Class B, C, or D FedRAMP Certification,” and the Class A marketplace listing ruleset requires providers to “demonstrate that an assessment for a FedRAMP Certification Class B, C, or D has been scheduled within 2 years of initial listing.”

Plan for Class A the way you would plan a bridge loan: it gets you listed in the FedRAMP Marketplace years earlier than the legacy path would, but the full-set assessment (46 KSIs, independent assessor) is still coming — you choose when in a 2-year window, rather than before you can sell at all.

The speed claim is FedRAMP’s own. Three months into the 20x pilot, the program reported that “the authorization life cycle is coming in at 30 days or less from submission to authorization,” alongside 104 products authorized in FY2025 and 4 complete 20x pilot submissions in the pilot’s first month. The Phase 2 pilot that shaped the current rules ran with 3 cloud services in Cohort 1 and up to 7 in Cohort 2. The ruleset itself was developed in the open across 31 public RFCs.

Meanwhile, Rev5 is winding down

The same June 25 announcement that opened the Class A pipeline scheduled the legacy program’s exit (FedRAMP, June 25, 2026):

  • July 28, 2026 — FedRAMP Ready becomes Legacy
  • August 10, 2026 — temporary Rev5 Program Certification pipelines open
  • January 1, 2027 — the new rules become mandatory for all stakeholders
  • June 11, 2027 — no new Rev5 certification applications accepted

If you were partway down the Rev5 path, the window to finish under the old rules closes in under a year. For everyone else, the strategic read is simple: there is no reason to start a legacy authorization now.

What a SaaS ISV should do before August 3

From the Class A rulesets and RFC-0022, in priority order:

  1. Confirm your entry ticket. A SOC 2 Type II (or prior Rev5/Ready, or GovRAMP certification) completed within the past 12 months is mandatory. If yours is stale or in progress, that is the critical path.
  2. Gap-check the 7 Class A KSIs. Passwordless authentication and automated account management are the two that most often require real engineering, not paperwork.
  3. Stand up machine-readable reporting. You will need to produce a JSON Ongoing Certification Report and keep the package current via automation, refreshed at least every 3 months.
  4. Decide your Class B or C target now. The 2-year advancement clock starts at your initial listing; knowing whether you are heading to Class B (Low-equivalent) or Class C (Moderate-equivalent) determines how much of the full 46-KSI set to start building toward.
  5. Skip the sponsor hunt. The energy that used to go into finding an authorizing agency can go into the KSIs — Class A does not require a sponsor.

This article summarizes FedRAMP’s published rules for general information; it is not legal or compliance advice. All sources accessed July 19, 2026.

Frequently Asked Questions

What is a FedRAMP 20x Class A certification?

Class A is a FedRAMP 20x certification for cloud services with mature security and compliance programs entering the federal marketplace. It is a transitory fast on-ramp introduced in RFC-0020 as a new pilot baseline: it lets a provider list in the FedRAMP Marketplace by leveraging an existing external assessment such as SOC 2 Type II, but the provider must schedule an assessment for a permanent Class B, C, or D certification within 2 years of the initial listing.

When does the FedRAMP 20x Class A pipeline open?

August 3, 2026, per FedRAMP's June 25, 2026 announcement of the Consolidated Rules for 2026. Marketplace listings opened July 6, 2026, and the Class B and Class C pipelines open August 31, 2026.

Do I need an agency sponsor for a Class A certification?

No. The Class A rulesets contain no agency-sponsor requirement. This is the major change from the legacy Rev5 agency-authorization path, where finding a sponsoring agency was the practical bottleneck for companies new to the federal market.

Does SOC 2 Type II count toward FedRAMP under 20x?

Yes, for Class A. Rule FRC-CLA-ASF requires a completed certification from one of three alternative security frameworks within the past 12 months: FedRAMP Rev5 (including FedRAMP Ready) at any historical impact level, SOC 2 Type II, or GovRAMP at any impact level. RFC-0022 names SOC 2 Type II as the initial test case for Class A certifications.

How many Key Security Indicators does Class A require?

Seven KSIs across six families, versus 46 KSIs across 10 families in the full FedRAMP 20x set that applies at Class B and Class C. The seven are: Logging Changes, Restricting Network Traffic, Reviewing All Training, Automating Account Management, Adopting Passwordless Methods, Reviewing Incident Response Procedures, and Securing Information.

Is a 3PAO or independent assessor required for Class A?

No — it is optional at the Class A stage. Rule FRC-CLA-IVV says providers MAY have the certification package independently verified and validated by a FedRAMP Recognized assessor before submission. An independent assessment becomes unavoidable on the path to Class B, C, or D, which must be scheduled within 2 years of the initial Class A listing.

What happens to FedRAMP Rev5?

It winds down on a published schedule: FedRAMP Ready became Legacy on July 28, 2026; temporary Rev5 Program Certification pipelines open August 10, 2026; the new consolidated rules become mandatory for all stakeholders January 1, 2027; and no new Rev5 certification applications are accepted after June 11, 2027.