COMPLIANCE POSTURE

FedRAMP 20x

The modernized FedRAMP authorization path that replaces narrative security packages with machine-readable evidence and a class-based certification model.

Also called 20x, FedRAMP Consolidated Rules

Last reviewed

What is FedRAMP 20x?

FedRAMP 20x is the program’s rebuild of how a cloud service gets authorized. It keeps the goal of the original program — one security assessment that any agency can rely on — and changes almost everything about how that assessment is produced, evidenced, and maintained.

Two shifts matter. The first is technical: instead of a several-hundred-page narrative security package assembled by consultants and read by humans, 20x expresses requirements as Key Security Indicators — discrete, testable statements that can be evidenced automatically from the systems that already produce the evidence. The second is procedural: 20x introduces a class-based certification model with a deliberate on-ramp for companies that have never touched federal before.

For a technology company that has been circling the federal market, the second shift is the one that changes the calculus.

The class model

The four classes describe how deep FedRAMP’s assessment goes, and they map onto the old baselines:

  • Class A — a new pilot baseline. A transitory certification for cloud services with mature commercial security programs entering the federal marketplace.
  • Class B — the former Li-SaaS and Low baselines. Small-scale or light-use services.
  • Class C — the former Moderate baseline. Common enterprise services likely to be used across an agency.
  • Class D — the former High baseline, arriving in a later phase.

The class label identifies the scope of FedRAMP’s assessment, not the total quality or security of the service. A Class A listing does not mean a service is less secure than a Class C one; it means FedRAMP looked at less of it.

Why Class A is the interesting one

Class A is the first FedRAMP pathway that accepts an existing commercial assessment as the entry ticket. A provider qualifies by having completed a certification from one of a small set of alternative security frameworks within the past twelve months — a SOC 2 Type II, a prior FedRAMP Rev5 authorization at any historical impact level, or a GovRAMP certification.

It is also the first with no agency sponsor requirement. Under the legacy agency-authorization path, finding a sponsoring agency was the wall that new entrants hit, and it had nothing to do with how secure the product was. Removing it converts FedRAMP from a relationship problem back into an engineering problem.

The trade is that Class A is transitory. A provider must schedule an assessment for a permanent Class B, C, or D certification within two years of the initial listing. Independent verification is optional at the Class A stage and unavoidable on the path beyond it.

The dates that are actually in force

  • July 6, 2026 — Marketplace listings opened under the new rules.
  • August 3, 2026 — the Class A submission pipeline opened.
  • August 31, 2026 — the Class B and Class C pipelines opened.
  • January 1, 2027 — the consolidated rules become mandatory for all stakeholders.
  • June 11, 2027 — no new Rev5 certification applications accepted.

What this changes about how you plan

Under legacy FedRAMP, the sensible strategy for a small company was usually to wait: build federal pipeline first, find an agency that wanted the product badly enough to sponsor, then start. Under 20x, the sensible strategy inverts. The entry credential — a current SOC 2 Type II — is something a commercial SaaS company plausibly already has or can get on a commercial timeline, and the sponsorship dependency is gone.

That makes readiness a timing question. Pipeline windows open and the companies whose registration, compliance evidence, and contract-vehicle posture are already assembled move through them. The ones still gathering documents watch the window from outside.

COMMON QUESTIONS

What is the difference between FedRAMP 20x and legacy FedRAMP?

Two things. First, the evidence — 20x replaces long narrative documents with machine-readable Key Security Indicators that can be validated automatically. Second, the on-ramp — the Class A certification lets a provider list by leveraging an existing external assessment such as SOC 2 Type II, and requires no agency sponsor — which was the practical bottleneck under the legacy Rev5 agency path.

What are the FedRAMP 20x classes?

Class A is a transitory on-ramp for cloud services with mature commercial security programs entering the federal market. Class B maps to the former Li-SaaS and Low baselines, Class C to Moderate, and Class D to High. The class describes the depth of FedRAMP's assessment, not the quality of the service.

Does a Class A listing last forever?

No — it is explicitly transitory. A provider listing under Class A must schedule an assessment for a permanent Class B, C, or D certification within two years of the initial listing. Treat Class A as a market-entry mechanism with a clock on it, not a destination.

When does legacy Rev5 stop being an option?

On a published schedule. The consolidated rules become mandatory for all stakeholders on January 1, 2027, and no new Rev5 certification applications are accepted after June 11, 2027. Companies still early in a Rev5 effort should be modeling the 20x path in parallel.

HOW GOVEXPRESS SCORES THIS

Compliance Posture

FedRAMP 20x resets what a strong Compliance Posture looks like, because a Class A listing is now reachable by a company with a current SOC 2 Type II and no agency sponsor — a posture the score can observe on the Marketplace the day it appears.

One of the 12 categories in the Federal Readiness Score. The methodology is public — including the things this platform will never claim.

FedRAMP 20x is one signal. See all of them.

Get your free score