What is FedRAMP 20x?
FedRAMP 20x is the program’s rebuild of how a cloud service gets authorized. It keeps the goal of the original program — one security assessment that any agency can rely on — and changes almost everything about how that assessment is produced, evidenced, and maintained.
Two shifts matter. The first is technical: instead of a several-hundred-page narrative security package assembled by consultants and read by humans, 20x expresses requirements as Key Security Indicators — discrete, testable statements that can be evidenced automatically from the systems that already produce the evidence. The second is procedural: 20x introduces a class-based certification model with a deliberate on-ramp for companies that have never touched federal before.
For a technology company that has been circling the federal market, the second shift is the one that changes the calculus.
The class model
The four classes describe how deep FedRAMP’s assessment goes, and they map onto the old baselines:
- Class A — a new pilot baseline. A transitory certification for cloud services with mature commercial security programs entering the federal marketplace.
- Class B — the former Li-SaaS and Low baselines. Small-scale or light-use services.
- Class C — the former Moderate baseline. Common enterprise services likely to be used across an agency.
- Class D — the former High baseline, arriving in a later phase.
The class label identifies the scope of FedRAMP’s assessment, not the total quality or security of the service. A Class A listing does not mean a service is less secure than a Class C one; it means FedRAMP looked at less of it.
Why Class A is the interesting one
Class A is the first FedRAMP pathway that accepts an existing commercial assessment as the entry ticket. A provider qualifies by having completed a certification from one of a small set of alternative security frameworks within the past twelve months — a SOC 2 Type II, a prior FedRAMP Rev5 authorization at any historical impact level, or a GovRAMP certification.
It is also the first with no agency sponsor requirement. Under the legacy agency-authorization path, finding a sponsoring agency was the wall that new entrants hit, and it had nothing to do with how secure the product was. Removing it converts FedRAMP from a relationship problem back into an engineering problem.
The trade is that Class A is transitory. A provider must schedule an assessment for a permanent Class B, C, or D certification within two years of the initial listing. Independent verification is optional at the Class A stage and unavoidable on the path beyond it.
The dates that are actually in force
- July 6, 2026 — Marketplace listings opened under the new rules.
- August 3, 2026 — the Class A submission pipeline opened.
- August 31, 2026 — the Class B and Class C pipelines opened.
- January 1, 2027 — the consolidated rules become mandatory for all stakeholders.
- June 11, 2027 — no new Rev5 certification applications accepted.
What this changes about how you plan
Under legacy FedRAMP, the sensible strategy for a small company was usually to wait: build federal pipeline first, find an agency that wanted the product badly enough to sponsor, then start. Under 20x, the sensible strategy inverts. The entry credential — a current SOC 2 Type II — is something a commercial SaaS company plausibly already has or can get on a commercial timeline, and the sponsorship dependency is gone.
That makes readiness a timing question. Pipeline windows open and the companies whose registration, compliance evidence, and contract-vehicle posture are already assembled move through them. The ones still gathering documents watch the window from outside.