In this article:

FedRAMP 20x Compliance, Start to Finish: KSIs, Machine-Readable Evidence, and What Changed From Rev 5

Compliance
/
September 23, 2026
FedRAMP 20x Compliance, Start to Finish: KSIs, Machine-Readable Evidence, and What Changed From Rev 5

FedRAMP 20x is the cloud-native way to earn a FedRAMP Certification under the Consolidated Rules for 2026, which took effect on July 4, 2026. Instead of a System Security Plan narrating hundreds of NIST SP 800-53 controls, you prove Key Security Indicators with automated, repeatable measurements, publish a Certification Package Overview and a Security Decision Record in JSON through a FedRAMP-compatible trust center, and apply directly to FedRAMP without an agency sponsor. Class A requires 7 of the 46 indicators plus a SOC 2 Type II, GovRAMP, or Rev5 assessment completed within the past 12 months. Class B requires 41 of them, with the other 5 optional, and Class C requires all 46. Both need an independent assessment by a FedRAMP Recognized assessor completed in the three months before applying. FedRAMP's goal is an initial decision within 30 days of receiving an application.

This guide follows a 20x project from the first decision to the first Ongoing Certification Report: the rule IDs FedRAMP uses, the machine-readable formats it expects, the full list of Key Security Indicators, what changed from Rev 5, what the work costs, and who should assess it. Every requirement cited here comes from FedRAMP's machine-readable rules dataset (version 2026.09.13.02, updated September 13, 2026) and the Consolidated Rules site. If you already hold a Rev 5 certification, skip to the section on moving from Rev 5, because your next deadline is December 7, 2026. Every acronym in this guide is defined in the acronyms and definitions section near the end.

What FedRAMP 20x is, in FedRAMP's own terms

GSA announced FedRAMP 20x on March 24, 2025, with the stated goal of approving new cloud services “in weeks instead of years” through automation and engineer-friendly requirements. FedRAMP ran it as public pilots. Phase 1 tested Low impact services from April to September 2025 and received 26 complete submissions. Phase 2 tested Moderate impact services from November 2025 through March 2026. FedRAMP's Marketplace data now lists 28 offerings certified at 20x Low or 20x Moderate, 14 of each, including offerings from OpenAI, Google, Perplexity, Confluent, and Vanta. FedRAMP then folded the approach into the Consolidated Rules for 2026 (CR26), launched on June 24, 2026, which now govern both 20x and Rev 5.

The legal footing is the FedRAMP Authorization Act, which Congress enacted on December 23, 2022, and OMB Memorandum M-24-15 of July 25, 2024. M-24-15 rescinded the 2011 policy memo that created the original program and directed FedRAMP to automate intake and review, grow the Marketplace, and stop pushing commercial providers to build separate government-only versions of their products. 20x is the program's answer to that memo.

CR26 also replaced the vocabulary, and FedRAMP treats the old words as a warning sign. Its guidance on choosing an advisor says that one who still offers help obtaining a “FedRAMP Authorization” or talks about Low, Moderate, and High impact levels is showing that it has not followed the changes. These are the terms used throughout this guide.

Legacy termCR26 termWhat changed
FedRAMP authorizationFedRAMP CertificationFedRAMP certifies the cloud service. Each agency still issues its own Authorization to Operate for the federal system that uses it.
Low, Moderate, and High impact levelsCertification Class A, B, C, or DA class describes how much assurance information you commit to supply. It is a separate question from how sensitive an agency's data is.
System Security Plan and appendicesCertification Package Overview and Security Decision RecordA verified record of the security decisions you made, and how you measure them, replaces a plan.
Continuous monitoringOngoing CertificationThe recurring obligations are broader than scanning, and failing them costs you the certification.
3PAOFedRAMP Recognized independent assessment service (assessor)The term follows the FedRAMP Authorization Act. A2LA accreditation is still required for recognition.
Plan of Action and Milestones (POA&M)Accepted vulnerabilitiesAny vulnerability not fully mitigated or remediated within 192 days of evaluation is categorized as accepted.
FedRAMP Ready20x Class AFedRAMP stopped accepting Ready submissions after July 28, 2026 and points new entrants to Class A.

Choose your certification profile before you build anything

A Certification Profile is three choices: type, path, and class. Rule FRC-CSO-FCP requires you to name a target profile and apply every FedRAMP Practice that goes with it, so this decision sets the scope of the whole project.

Type: 20x or Rev5

FedRAMP says cloud services built on FedRAMP Certified infrastructure or platforms should choose 20x, and calls it “the fastest, cheapest, and best way to bring an existing commercial cloud service into the federal market.” Rev5 remains the only option for services that run their own infrastructure or need a Class D certification today. FedRAMP stops accepting new Rev5 applications on June 11, 2027, and describes Rev5 as a legacy type it is working to retire.

Path: Program or Agency

Program Certification comes directly from FedRAMP and needs no agency sponsor, and it is the path for every 20x certification. Agency Certification is the legacy route in which an agency completes an ATO first and then sponsors the service to FedRAMP, and it applies only to Rev5. You cannot seek Rev5 and 20x Program Certifications for the same offering (FRC-CSO-POP).

Class: A, B, or C

Classes rise in the assurance you commit to supply to agencies, and in cost. FedRAMP's advice is to start with Class A in most cases, to go straight to Class C only when an existing agency contract requires it, and never to plan a first certification at Class D. Treat Class A as a first step: FedRAMP says agencies should not authorize a Class A service for more than 12 months unless the provider is actively seeking Class B, C, or D (AGU-USE-CLA). Class D is not yet available under 20x. FedRAMP says it anticipates piloting 20x Class D in late 2026 and making it a formal option in early 2027. The table below shows what each available class requires, with the rule behind each line.

RequirementClass AClass BClass C
What FedRAMP says agencies can use it forPilots, configuration and testing, public or negligible-risk dataMost Low impact systemsMost Low and Moderate impact systems
Prerequisite (FRC-CLA-ASF, FRC-APP-MLF)SOC 2 Type II, GovRAMP, or FedRAMP Rev5 (including Ready) completed in the past 12 months, plus a Marketplace listingMarketplace listingMarketplace listing
Key Security Indicators (FRC-CLA-MFR for Class A; each KSI's class requirements for B and C)7 required41 required, 5 optionalAll 46 required
Independent assessment before applying (FRC-APP-FIA)OptionalRequired, completed in the prior 3 monthsRequired, completed in the prior 3 months
Automated methods per KSI (FRC-CSX-VVK)OptionalAt least 1 (recommended)At least 2 (required)
Historical KSI metrics (FRC-CSX-MOT, SDR-CSX-KMT)OptionalRecommended at application, required once certifiedAt least 6 months (required)
Package kept current (CPO-CSX-CPM)Every 3 months (recommended)MonthlyEvery 2 weeks
Machine-based resources verified and validated (VDR-TFR-MVX)Monthly (recommended)Every 7 daysEvery 3 days
Annual independent assessment (IVV-CSX-AIA)Must meet the underlying framework's expectationsAll KSIs every yearAll KSIs every year
Quarterly Review with agencies (CCM-QTR-MTG)OptionalRecommendedRequired
NIST-validated cryptographic modules (CMU-CSO-UVM)OptionalOptionalRecommended
Default time to answer a FedRAMP Emergency message with a resolution estimate (AFC-FRP-ERT)3 p.m. ET, 5th business day3 p.m. ET, 3rd business day3 p.m. ET, 2nd business day

If a contract still says Low or Moderate, FedRAMP's own 20x program page says that in the current phase, 20x “will initially support Class A (Pilot), Class B (Low), and Class C (Moderate) Certifications,” which is the practical translation. Expect the agency to do its own categorization anyway. FedRAMP's agency guidance says a class indicates the level of assurance a provider supplies, warns agencies against reading it as a measure of how secure the service is, and leaves the agency to decide whether the service fits its system, data, and risk tolerance.

One boundary to settle early if you sell to defense: FedRAMP states that it “does not support or provide 'equivalency.'” If a DFARS 252.204-7012 contract calls for FedRAMP Moderate equivalency for a cloud service that stores, processes, or transmits covered defense information, FedRAMP directs those questions to the Department of War, and the question belongs to your CMMC program. Our CMMC consulting team scopes that side.

The FedRAMP 20x project, start to finish

FedRAMP organizes the journey into three phases: Preparation, Initial Implementation, and Ongoing Certification. Its sequencing advice is to build the Certification Package Overview first, then the Security Decision Record, then the assurance capabilities you will operate for as long as you hold the certification. The steps below follow that sequence.

Six-stage FedRAMP 20x project lifecycle across preparation, initial implementation, and ongoing certification, with the governing rule IDs for each stage
The six stages of a FedRAMP 20x project and the rules that govern each. Source: FedRAMP Consolidated Rules for 2026.

1. Staff it as an engineering project

The strongest signal from the pilots is organizational. FedRAMP's KSI guidance notes that the most successful pilot organizations were led entirely by experienced engineering and product teams that treated certification like any other product, and its implementation guidance calls a separate compliance team without access to engineering resources “a guaranteed way” to make certification harder. Name an executive owner, give the program a product manager, and put platform, security, and site reliability engineers on it from the first week. Compliance staff own the rule mapping and the package. Engineers own the measurements.

2. Get listed in the Marketplace

Since July 6, 2026, providers early in the process can appear in the FedRAMP Marketplace in the Initial Implementation Phase, and you must be listed before you apply (FRC-APP-MLF). The listing is the first real test of the rules. You publish the public information in CDS-CSO-PUB on your website in human-readable and JSON form, including service and deployment model, UEI number, sales and security contacts, a service list with security categories, links to your secure configuration guidance and trust center, and your current assessor. You demonstrate a government-wide use case (MKT-IIP-AGU), stand up a basic FedRAMP-compatible trust center, post progress against your own milestones at least quarterly (MKT-IIP-DCP), and show that a Class B, C, or D assessment is scheduled within two years of listing, or FedRAMP removes the listing (MKT-IIP-DLA). FedRAMP rejects incomplete listing requests with only the minimum explanation, so validate the JSON against FedRAMP's schema before you submit.

3. Draw the Minimum Assessment Scope

The Minimum Assessment Scope replaces the legacy authorization boundary for both 20x and Rev 5. MAS-CSO-IIR puts in scope every information resource likely to handle federal customer data or affect its confidentiality, integrity, or availability, and that set is, by definition, your cloud service offering. You document information flows and security categories for all of it (MAS-CSO-FLO), include metadata about federal customer data (MAS-CSO-MDI), and explain each third-party resource the offering depends on: how you use and configure it, why, and the mitigations and compensating controls around it (MAS-CSO-TPR). Products outside the scope can go in a separate, marked supplement, and they are not certified. Your public service list (CDS-CSO-SVC) must be specific enough that a buyer can tell which features are in scope without asking you.

4. Build the Certification Package Overview

The Certification Package Overview is a short, structured summary of the offering, supplied in human-readable and JSON formats (CPO-CSO-OVR), and together with the Security Decision Record it takes the place of the System Security Plan. It carries your public information and service list, an inventory of every relevant policy and procedure with its summary, word count, version, and date, the assessment scope and third-party resources, your cryptographic module documentation, the assessor's overall summary for Class B and C, and the name and contact of the official accountable for the package. FedRAMP tells providers to build this first, and warns that a provider who finds the overview hard should expect a long road through the rest.

5. Design the measures and build the Security Decision Record

The Security Decision Record is where most of the time goes. For every applicable rule, SDR-CSO-FRR asks for how you follow it (or why you do not, and the resulting risk to customers), verification that the implementation fits the rule, validation that it works, the independent verification and validation, and any rule-specific artifacts. For every applicable KSI, SDR-CSX-KSI asks for the measures that demonstrate it and their objectives, the cycle each persistent measure runs on, verification that the measures and the automation behind them are accurate and sufficient, and validation that they work as intended. Class B and C providers also keep historical metrics for every KSI in the record (SDR-CSX-KMT).

Two class rules set the engineering bar. Class C must run at least two automated methods per KSI to verify and validate its accuracy and completeness, where Class B should run at least one (FRC-CSX-VVK). Class C must supply at least six months of historical KSI metrics, and a new service without that history can apply with the mechanisms in place and an agreement to meet the requirement (FRC-CSX-MOT). FedRAMP also says providers should apply every KSI to every part of the offering inside the assessment scope (FRC-CSX-MAS), so a measure that checks only your primary cloud account falls short.

6. Prove the assurance machinery before you apply

FedRAMP will not certify a service that can only describe how it will operate. Its implementation guidance says you must prove you are ready to meet every Ongoing Certification requirement in order to obtain the initial certification, and for most providers these are new capabilities:

  • A monitored FedRAMP Security Inbox that receives FedRAMP email without disruption and routes Emergency messages to a senior security official (AFC-CSO-INB, AFC-CSO-RCV, AFC-CSO-EMR).
  • Vulnerability detection that runs persistently and treats a failure in the detection or response process as a vulnerability (VDR-CSO-DET, VDR-CSO-FAV).
  • Vulnerability evaluation that rates every finding for exploitability, internet reachability, and a Potential Agency Impact N-rating from N1 to N5, with a monthly human-readable activity report (VER-EVA-ELX, VER-EVA-EIR, VER-EVA-EPA, VER-TFR-MHR).
  • A significant change process that sorts each change into routine recurring, adaptive, or transformative, with notices sent on FedRAMP's timelines (SCN-CSO-EVA).
  • Incident reporting to fedramp_security@fedramp.gov and affected agencies, from the initial report through the final report (IEC-CSO-IIR, IEC-CSO-FIR).
  • A Secure Configuration Guide for top-level administrative accounts, and an Ongoing Certification Report your team can produce every three months (SCG-CSO-RSC, CCM-OCR-AVL).

The package must include a real or example Ongoing Certification Report (FRC-CSO-PKG), and incident reports used as evidence can come from real or simulated incidents.

7. Commission the independent assessment

Class B and C require a FedRAMP Recognized assessor, and the assessment must be completed within three months before you apply (FRC-APP-FIA). If it goes stale, the assessor can review what changed in place of a full reassessment, unless the original is more than nine months old (FRC-APP-USA). Expect a different engagement from a Rev 5 audit. FedRAMP's guidance to assessors tells them to trace each important validation from its source data through the code, queries, and thresholds that produce the result, down to what counts as failure, and warns that “a green status can hide missing accounts, incomplete inventory, faulty integrations, or a manual step that never happened.” That work can include code review, API testing, and cloud architecture analysis. FedRAMP encourages early and frequent contact so you can explain your validation design and the assessor can test it while unclear evidence can still be fixed. The section on choosing an assessor below covers who we recommend.

8. Apply and get through review

You apply through FedRAMP's Certification Application Form yourself (FRC-APP-AFC), because FedRAMP no longer accepts applications submitted by assessors or any other third party (FRC-APP-NTP). The package must show the offering as you verified and validated it within the previous seven days (FRC-APP-FCP). FedRAMP scans the submission for completeness, assigns a Review Team that requests access to your trust center, reviews the Certification Package Overview, and for 20x usually schedules a Deep Dive on the overview and the Security Decision Record. FedRAMP's internal goal is an initial decision within 30 days, and the clock stops whenever it is waiting on you. The first two 20x Class A Certifications, Bland AI and Files.com, moved from In Process to Certified in 19 and 17 days in August 2026, according to FedRAMP's Marketplace status data.

9. Run Ongoing Certification

Certification starts the recurring work, and the cadence depends on class.

ObligationRuleClass BClass C
Verify and validate machine-based resourcesVDR-TFR-MVXEvery 7 daysEvery 3 days
Verify and validate policies, procedures, and other non-machine resourcesVDR-TFR-NMVEvery 3 monthsEvery 3 months
Keep the Certification Package currentCPO-CSX-CPMMonthlyEvery 2 weeks
Vulnerability detection and response activity reportVER-TFR-MHRAt least monthlyAt least monthly
Historical vulnerability activity in JSON for automated retrievalVER-TFR-MRHMonthly (recommended)Every 14 days (recommended)
Ongoing Certification Report to agencies and FedRAMPCCM-OCR-AVLEvery 3 monthsEvery 3 months
Quarterly Review meetingCCM-QTR-MTGRecommendedRequired; FedRAMP recommends holding it 3 to 10 business days after each report
Availability status service for FedRAMP and agency customers, with 30 days of history, reachable when the offering is downCDS-CSO-AVRRequiredRequired
Independent assessment of all KSIsIVV-CSX-AIAEvery yearEvery year
Transformative change noticesSCN-TRF30 and 10 business days before, 5 after30 and 10 business days before, 5 after

Rev 5 providers will recognize the monthly vulnerability reporting and the annual assessment. The three-day and seven-day resource validation cycles, the quarterly reports and reviews, and the availability status service are new.

Machine-readable controls: what FedRAMP means and what to build

Machine-readable has a legal definition in the rules. FedRAMP adopts 44 U.S.C. § 3502(18): data “in a format that can be easily processed by a computer without human intervention while ensuring no semantic meaning is lost.” Four rules turn that definition into engineering work. FRC-CSO-JSN applies to every class and requires JSON documents that validate against the matching FedRAMP schema whenever a rule names one, unless that rule says otherwise. CDS-CSO-CBF requires automation to keep the human-readable and machine-readable versions of your certification data consistent, so a PDF your team edits by hand next to a JSON file generated from a different source will not pass. CDS-TRC-PAC requires your trust center to give documented programmatic access to all certification data, including the human-readable materials, and CDS-TRC-ACL requires it to log all access to certification data and keep access summaries for at least six months. Those three data-sharing rules apply to Classes B, C, and D.

FedRAMP publishes the schemas at fedramp.gov/schemas and in the FedRAMP/schemas repository: the Certification Package Overview, Security Decision Record, Ongoing Certification Report, incident report, significant change notification, vulnerability detail report, accepted vulnerability information, historical vulnerability activity, advisor information, and assessor information, plus shared definitions. The repository labels them drafts, and each schema carries its own version number, so pin the versions you build against. FedRAMP calls the schemas “lightweight and flexible” minimums that providers can extend. For provider packages, OSCAL is now optional. CR26 moves Rev 5 packages from Word and Excel templates to “simplified JSON documents or (in some cases) optional OSCAL,” and 20x packages use FedRAMP's JSON schemas. Agencies still need governance, risk, and compliance tools that can produce and ingest both OSCAL and JSON (AGU-AGC-GRC).

FedRAMP publishes its own rules the same way. The fedramp-consolidated-rules.json file in the FedRAMP/rules repository holds every definition, rule, and KSI by ID, with class variants where they apply, ruleset effective dates, and each KSI's related NIST SP 800-53 controls. FedRAMP tells automation services and AI agents to skip its website and process the source data directly, and it names this repository the source of truth for structured rules. Build your rule mapping from the file, pin the version you mapped against, and diff it when FedRAMP ships an update, because FedRAMP has revised the rules several times since launch, most recently on September 13, 2026.

Comparison of Rev 5 document-based evidence with FedRAMP 20x machine-readable evidence flowing from source systems through automated validations to a trust center
Rev 5 assembles evidence as documents for review. 20x produces it as data at the source and shares it through the trust center.

What a KSI validation looks like

A KSI is an outcome claim, and at Class C the measurement behind it is code with a data source, a cadence, and a failure condition. Take KSI-IAM-APM, which requires passwordless authentication where feasible and otherwise strong passwords with phishing-resistant MFA. A Class C implementation needs at least two automated methods (FRC-CSX-VVK). The first is a daily query of the identity provider confirming that every active human account is bound to a FIDO2 or passkey authentication policy, failing on any exception. The second is a daily query of authentication logs for any successful sign-in completed without a phishing-resistant factor, failing on any match. Each run writes a timestamped result to the evidence store, a failure opens a ticket and pages the identity team, and the pass rate over time becomes the historical metric. The Security Decision Record entry for that KSI then looks like the example below, which validates against FedRAMP's Security Decision Record schema, version 1.1.1.

Abridged Security Decision Record JSON entry for KSI-IAM-APM with numbered callouts for metadata, implementation, validation, assessment, and evidence
An abridged Security Decision Record entry for KSI-IAM-APM. The full, schema-valid sample is in the KSI workbook.

The schema requires, for each indicator, the KSI ID and arrays for implementation, validation, assessment, tests, and evidence. An optional implementation status accepts Implemented, Partially Implemented, or Not Implemented. Each evidence entry can carry a type (log, report, screenshot, configuration, policy, procedure, or audit record), a description, a location URI, inline text, and a last-updated date, and the schema requires none of those fields, so decide your own minimum and hold every entry to it. The assessment statements come from your assessor and stay theirs, because FedRAMP requires assessment results in the package “without inappropriate modification” (IVV-CSO-ICP). The same record also holds a fedRampRequirements array with an entry for each of the more than 150 provider rules that apply to Class B and C.

How to produce the records: the technical build

Producing FedRAMP's machine-readable records is a data pipeline. You pull facts from the systems that run the service, test them in code on a schedule, keep every result with a timestamp, generate the JSON documents from those stored results, validate each document against FedRAMP's schema, and publish the documents through a trust center that agencies and FedRAMP can query. FedRAMP does not prescribe tools. You can build the pipeline from your cloud provider's APIs, the security tools you already run, and a GRC platform, your own code, or both.

Start with FedRAMP's source files. Clone the FedRAMP/schemas repository, or download each schema from the fedramp.gov/schemas address in its $id field, which is the schema's official identifier, and keep the copies you build against in your own version control. The date in each file name identifies the CR26 ruleset and stays fixed, while the $schemaVersion field inside the file changes when FedRAMP edits the schema. FedRAMP moved the Security Decision Record schema to version 1.1.1 on September 1, 2026, and it issued new major versions of the assessor and advisor schemas on September 23, 2026, so record the version you build against and rerun your validation when it changes. The rules dataset tells you which schema each rule expects: 24 rules carry a schema field with the schema's name and address. Generate the fedRampRequirements list in your Security Decision Record from the same file by filtering rules on the type, path, class, and affected party in each subset's applicability block and writing one entry per applicable rule, keyed by its rule ID.

Validate every document before it leaves your pipeline. All eleven schemas use JSON Schema draft 2020-12, so use a validator that supports that draft, such as the jsonschema library for Python or Ajv for JavaScript, and run it as a build step that blocks publication on any error. Nine of the ten document schemas reuse shared definitions from the common-definitions schema and reference it by its fedramp.gov address. Load that file into the validator next to the schema you are checking, because a validator that cannot resolve the reference stops with an error instead of validating. The Security Decision Record and every report also require a certificationPackageOverviewUri field that points back to your Certification Package Overview, so publish that document first at a stable address.

StageWhat you buildExample technologyRules it serves
CollectRead-only integrations that pull configuration, inventory, identity, log, and vulnerability data from every resource in the Minimum Assessment ScopeCloud provider APIs such as AWS Config, Azure Resource Graph, and Google Cloud Asset Inventory; identity provider APIs such as Okta and Microsoft Graph for Entra ID; scanner, code repository, and ticketing APIsMAS-CSO-IIR, VDR-CSO-DET
EvaluateValidation code for each KSI measure, with a data source, a cadence, a threshold, and a failure conditionPolicy-as-code engines such as Open Policy Agent, scheduled queries, or scripts in your build pipelineFRC-CSX-VVK, VDR-TFR-MVX
StoreAn evidence store that keeps every result with its timestamp, inputs, and outcome, long enough to report historyVersioned object storage or a database with write-once retentionFRC-CSX-MOT, SDR-CSX-KMT
GenerateCode that builds each JSON document from the stored results and renders the human-readable version from the same dataTemplates in your build pipeline or the export from your GRC platformSDR-CSO-FRR, CPO-CSO-OVR, CDS-CSO-CBF
ValidateA build step that checks every document against its FedRAMP schema and blocks publication on any errorA validator that supports JSON Schema draft 2020-12FRC-CSO-JSN
PublishA FedRAMP-compatible trust center with documented API access, access logging, and an inventory of agency users and systemsA trust center product or your own authenticated APICDS-CSO-UTC, CDS-TRC-PAC, CDS-TRC-ACL, CDS-TRC-AAI
ReportScheduled jobs for the monthly vulnerability activity report, the Vulnerability Detail Report, historical vulnerability data, and the Ongoing Certification ReportThe same pipeline, run on the cadence your class requiresVER-TFR-MHR, VER-RPT-VDT, VER-TFR-MRH, CCM-OCR-AVL

Here is how the KSI-IAM-APM example above moves through that pipeline. A scheduled job calls the identity provider's API with a read-only credential and saves the raw response. The validation code checks each active account's authentication policy and writes a pass or fail result with a timestamp to the evidence store. The generator reads the latest result and the 30-day and one-year metric summaries that SDR-CSX-KMT requires, writes them into that KSI's Security Decision Record entry with an evidence location pointing to the stored result, renders the human-readable page from the same data, validates the JSON, and publishes both versions to the trust center.

Vulnerability records follow the same pattern with one extra step. Each finding becomes a vulnerabilityDetail entry that requires your tracking ID, the detection time and source, and a description, and that carries the VER evaluation: whether the vulnerability is internet-reachable and likely exploitable, its current PAIN rating as an integer from 1 to 5, the time the evaluation finished, which starts the 192-day clock for accepted vulnerabilities, and its final disposition. Scanners do not produce PAIN ratings or FedRAMP's reachability and exploitability judgments, so the generator has to join each scanner finding with your team's evaluation record before it writes the Vulnerability Detail Report.

Agencies and FedRAMP pull data from you as well. CDS-TRC-PAC requires documented programmatic access to all certification data, so publish an API reference for the trust center, issue a credential to each agency user or system, and log every request: CDS-TRC-ACL requires access summaries kept for at least six months, and CDS-TRC-AAI requires an inventory and history of the agency users and systems with access. VER-TFR-MRH asks Class B providers to keep recent vulnerability history available in JSON for automated retrieval, updated at least monthly, and asks Class C providers to update it at least every 14 days. Separately, CDS-CSO-AVR requires Class B, C, and D providers to run a web service that shows current availability and the past 30 days of availability for core services, in human-readable and machine-readable form, and that stays up when the offering itself is down.

Build the pipeline so an assessor can test it. FedRAMP tells assessors to trace validations end to end, from the source data through collection, transformation, and the code, queries, or thresholds that produce each result, and to review code, test APIs, and analyze cloud architecture instead of stopping at a dashboard. Keep collectors and validation code in source control with peer review, keep the pipeline's own run logs, and make every result reproducible from its stored inputs. If a GRC platform supplies part of the pipeline, confirm that its JSON export validates against the current FedRAMP schemas and that it keeps your assessor's statements separate from yours, because IVV-CSO-ICP requires assessment results in the package without inappropriate modification.

The 46 Key Security Indicators

CR26 organizes the indicators into 10 themes. Class A requires the 7 marked below. Class B requires 41 and makes the other 5 optional, and Class C requires all 46. FedRAMP's dataset maps 44 of the 46 KSIs to related NIST SP 800-53 controls, and some summarize a lot of ground: KSI-IAM-JIT maps to 38 controls and KSI-IAM-ELP to 34. Thirty-five of the 46 statements use FedRAMP's defined term “persistently” or its form “persistent.” FedRAMP defines it as activity repeated in cycles over a long period, where any irregularity or gap between cycles is intentional, understood, and documented, and the status is always known. A measure that runs when someone remembers to run it does not meet that definition.

The 46 FedRAMP 20x Key Security Indicators in 10 themes, marking the 7 required for Class A and the 5 optional in Class B
The 46 Key Security Indicators by theme, with the Class A and Class B requirements marked.

The statements below are FedRAMP's official wording from the rules dataset, also published on the Key Security Indicators pages. The KSI workbook carries the same statements with their control mappings and columns for planning each measure.

ThemeIndicatorOfficial statementClass AClass B
Cybersecurity EducationKSI-CED-RAT Reviewing All TrainingThe effectiveness of relevant cybersecurity education and training is persistently reviewed, including at least general training for all employees, role-specific training for employees in high risk roles, training for development and engineering staff on secure software delivery, and training for staff involved with incident response or disaster recovery.YesRequired
Change ManagementKSI-CMT-LMC Logging ChangesModifications to the cloud service offering are logged and monitored.YesRequired
Change ManagementKSI-CMT-RMV Redeploying vs ModifyingChanges to machine-based information resources are executed through the redeployment of version controlled resources rather than direct modification wherever reasonable.NoRequired
Change ManagementKSI-CMT-RVP Reviewing Change ProceduresThe effectiveness of documented change management procedures is persistently reviewed.NoRequired
Change ManagementKSI-CMT-VTD Validating Throughout DeploymentPersistent testing and validation of changes throughout deployment is automated.NoRequired
Cloud Native ArchitectureKSI-CNA-DFP Defining Functionality and PrivilegesThe functionality and privileges for infrastructure and services are strictly defined.NoRequired
Cloud Native ArchitectureKSI-CNA-EIS Enforcing Intended StateAutomated services are used to persistently assess the security of all machine-based information resources and automatically enforce their intended operational state.NoOptional
Cloud Native ArchitectureKSI-CNA-IBP Implementing Best PracticesThe use and configuration of third-party machine-based information resources is persistently compared against the original provider's best practices and guidance.NoRequired
Cloud Native ArchitectureKSI-CNA-MAT Minimizing Attack SurfaceMachine-based information resources are persistently reviewed to ensure they have a minimal attack surface and that lateral movement is minimized if compromised.NoRequired
Cloud Native ArchitectureKSI-CNA-OFA Optimizing for AvailabilityMachine-based information resources are persistently reviewed to ensure they are appropriately optimized for high availability and rapid recovery.NoRequired
Cloud Native ArchitectureKSI-CNA-RNT Restricting Network TrafficMachine-based information resources are persistently reviewed to ensure they are appropriately configured to limit inbound and outbound network traffic.YesRequired
Cloud Native ArchitectureKSI-CNA-RVP Reviewing ProtectionsThe effectiveness of protection against denial of service attacks and other unwanted activity for machine-based information resources is persistently reviewed.NoRequired
Cloud Native ArchitectureKSI-CNA-ULN Using Logical NetworkingLogical networking and related capabilities are used and persistently reviewed to enforce traffic flow controls.NoRequired
Identity and Access ManagementKSI-IAM-AAM Automating Account ManagementThe lifecycle and privileges of all accounts, roles, and groups are securely managed using automation.YesRequired
Identity and Access ManagementKSI-IAM-APM Adopting Passwordless MethodsSecure passwordless methods are used for user authentication and authorization when feasible, otherwise strong passwords with phishing-resistant MFA is used.YesRequired
Identity and Access ManagementKSI-IAM-ELP Ensuring Least PrivilegeIdentity and access management measures are used and persistently reviewed to ensure each user or device can only access the resources they need.NoRequired
Identity and Access ManagementKSI-IAM-JIT Authorizing Just-in-TimeA least-privileged, role and attribute-based, and just-in-time security authorization model is used and persistently reviewed for all user and non-user accounts and services.NoRequired
Identity and Access ManagementKSI-IAM-SNU Securing Non-User AuthenticationAppropriately secure authentication methods are used and persistently reviewed for non-user accounts and services.NoRequired
Identity and Access ManagementKSI-IAM-SUS Responding to Suspicious ActivityAccounts with privileged access are disabled or otherwise secured in response to suspicious activity.NoRequired
Incident ResponseKSI-INR-AAR Generating After Action ReportsIncident after action reports are generated and lessons learned are persistently incorporated.NoRequired
Incident ResponseKSI-INR-RIR Reviewing Incident Response ProceduresThe effectiveness of documented incident response procedures is persistently reviewed.YesRequired
Incident ResponseKSI-INR-RPI Reviewing Past IncidentsPast incidents are persistently reviewed for patterns or vulnerabilities that were not previously apparent or identified.NoRequired
Monitoring, Logging, and AuditingKSI-MLA-ALA Authorizing Log AccessA least-privileged, role and attribute-based, and just-in-time access authorization model is used and persistently reviewed for access to log data based on organizationally defined data sensitivity.NoOptional
Monitoring, Logging, and AuditingKSI-MLA-EVC Evaluating ConfigurationsThe configuration of machine-based information resources, especially infrastructure as code, is persistently evaluated and tested.NoRequired
Monitoring, Logging, and AuditingKSI-MLA-LET Logging Event TypesA list of information resources and event types that will be logged, monitored, and audited is maintained and persistently reviewed to ensure these activities occur.NoRequired
Monitoring, Logging, and AuditingKSI-MLA-OSM Operating SIEM CapabilityA Security Information and Event Management (SIEM) or similar system(s) is used and persistently reviewed for centralized, tamper-resistant logging of events, activities, and changes.NoRequired
Monitoring, Logging, and AuditingKSI-MLA-RVL Reviewing LogsLogs are persistently reviewed and audited.NoRequired
Policy and InventoryKSI-PIY-GIV Generating InventoriesAuthoritative sources are used to automatically generate real-time inventories of all information resources when needed.NoRequired
Policy and InventoryKSI-PIY-RES Reviewing Executive SupportExecutive support for achieving the provider's security goals is persistently reviewed and demonstrated.NoRequired
Policy and InventoryKSI-PIY-RIS Reviewing Investments in SecurityThe effectiveness of the provider's investments in achieving security goals is persistently reviewed.NoRequired
Policy and InventoryKSI-PIY-RSD Reviewing Security in the SDLCThe effectiveness of building security and privacy considerations into the Software Development Lifecycle and aligning with CISA Secure By Design principles is persistently reviewed.NoRequired
Policy and InventoryKSI-PIY-RVD Reviewing Vulnerability DisclosuresThe effectiveness of the provider's vulnerability disclosure program is persistently reviewed.NoRequired
Recovery PlanningKSI-RPL-ABO Aligning Backups with ObjectivesThe alignment of machine-based information resource backups with defined recovery objectives is persistently reviewed.NoRequired
Recovery PlanningKSI-RPL-ARP Aligning Recovery PlanThe alignment of recovery plans with defined recovery objectives is persistently reviewed.NoRequired
Recovery PlanningKSI-RPL-RRO Reviewing Recovery ObjectivesThe desired Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are defined and persistently reviewed for alignment with the provider's business needs and capabilities.NoRequired
Recovery PlanningKSI-RPL-TRC Testing Recovery CapabilitiesThe capability to recover from incidents and contingencies aligned with defined recovery objectives is persistently tested.NoRequired
Supply Chain RiskKSI-SCR-MIT Mitigating Supply Chain RiskPersistently identify, review, and mitigate potential supply chain risks.NoRequired
Supply Chain RiskKSI-SCR-MON Monitoring Supply Chain RiskThird party software information resources are automatically monitored for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services.NoRequired
Service ConfigurationKSI-SVC-ACM Automating Configuration ManagementThe configuration of machine-based information resources is managed using automation and persistently reviewed for drift.NoRequired
Service ConfigurationKSI-SVC-ASM Automating Secret ManagementManagement, protection, and regular rotation of digital keys, certificates, and other secrets is automated and persistently reviewed.NoRequired
Service ConfigurationKSI-SVC-EIS Evaluating and Improving SecurityInformation resources are persistently evaluated for opportunities to improve security and those improvements are persistently made.NoRequired
Service ConfigurationKSI-SVC-PRR Preventing Residual RiskPlans, procedures, and the state of information resources are persistently reviewed after making changes to limit and remove unwanted residual elements that would likely negatively affect the confidentiality, integrity, or availability of federal customer data.NoOptional
Service ConfigurationKSI-SVC-RUD Removing Unwanted DataUnwanted federal customer data is removed promptly when requested by an agency in alignment with customer agreements, including from backups if appropriate; this typically applies when a customer spills information or when a customer seeks to remove information from a service due to a change in usage.NoOptional
Service ConfigurationKSI-SVC-SIN Securing InformationInformation is encrypted or otherwise secured from unwanted access or modification.YesRequired
Service ConfigurationKSI-SVC-VCM Validating CommunicationsThe authenticity and integrity of communications between machine-based information resources is persistently validated using automation.NoOptional
Service ConfigurationKSI-SVC-VRI Validating Resource IntegrityUse cryptographic methods to validate the integrity of machine-based information resources.NoRequired

What changes from Rev 5

Rev 5 and 20x expect similar security. They differ in what counts as proof, who reviews it, and how often it moves. The table compares the legacy Rev 5 process most current providers went through with 20x under CR26.

AreaLegacy Rev 5FedRAMP 20x under CR26
BasisNIST SP 800-53 Rev 5 baselines of 156 controls at Low, 323 at Moderate, and 410 at High46 KSIs (7 for Class A) plus more than 150 provider rules for Class B and C, with 800-53 mappings kept for reference
Core documentSystem Security Plan and appendices in Word and Excel templatesCertification Package Overview and Security Decision Record, human-readable and JSON
EvidenceNarratives and screenshots gathered for a point-in-time testAutomated measurements with history, and an assessor who tests the code producing them
SponsorAgency sponsor completing an ATO firstNone; FedRAMP issues a Program Certification
AssessorIndependent assessment required, usually by a 3PAOFedRAMP Recognized assessor required for Class B and C, optional for Class A
Where the package livesUSDA Connect for Low and Moderate packages; the provider's own repository for HighYour FedRAMP-compatible trust center with programmatic access
MonitoringMonthly continuous monitoring uploads of scans, POA&M, and inventoryOngoing Certification: machine-based resources validated every 7 days (Class B) or 3 days (Class C), monthly vulnerability reports, quarterly reports and reviews
WeaknessesPOA&M items with remediation deadlines by severityRemediation expectations by PAIN rating, reachability, and exploitability; accepted vulnerabilities after 192 days
ChangesSignificant change requests approved in advanceNotification framework for routine recurring, adaptive, and transformative changes
EncryptionFIPS 140 validated modules assumed for federal dataModules documented per service; validated modules optional for Class B and recommended for Class C
FedRAMP review timeCould take a year or more, as FedRAMP acknowledges30-day goal for an initial decision
Open to new applicantsUntil June 11, 2027Class A since August 3, 2026; Class B and C since August 31, 2026

Rev 5 does not stand still under CR26. FedRAMP calls it a legacy type that “will be retired,” and it applies the same modernization to it: JSON packages in place of Word and Excel templates, most FedRAMP-defined organizational parameters removed so providers set their own values, FIPS 140 expected only where data is sensitive, vulnerability detection “scaled widely beyond traditional monthly vulnerability scanning,” and POA&Ms eliminated in favor of a list of accepted weaknesses. The CR26 Rev5 baselines list 155 controls for Class B, 322 for Class C, and 409 for Class D, each documented in a Security Decision Record.

If you already hold a Rev 5 certification

Existing Rev 5 certifications remain active until at least December 31, 2028, unless FedRAMP is directed otherwise, but the rules under them change on a schedule, and FedRAMP warns that providers who do not adjust “will lose their FedRAMP Certification.” Grace periods are hard deadlines with no extensions. A provider that misses one loses its certification with public notice and can regain it by following the rules.

DateWhat happensWho it affects
July 4, 2026CR26 in effect; new 20x applications must follow it; optional early adoption begins for most Rev5 rulesetsAll providers
July 28, 2026FedRAMP Ready closes to new submissions; FedRAMP points new entrants to 20x Class AReady applicants
August 10, 2026Lost Sponsor and Ready Conversion pipelines open for a Rev5 Class B or C Program CertificationProviders that lost a sponsor, completed a readiness assessment, or reached Ready between January 2025 and March 2026
November 17, 2026FedRAMP Ready listings must convert to a certification, or at annual assessment expiration if that is laterFedRAMP Ready
December 7, 2026VDR and VER rulesets required to obtain a certification, and to keep one without a corrective action plan, under CISA BOD 26-04; grace ends March 7, 2027Class B, C, and D providers, Rev5 and 20x
January 1, 2027CR26 mandatory for new Rev5 applications; most rulesets must be followed or a corrective action plan is requiredAll providers
June 1, 2027Grace ends for the Rev5 cryptography, incident, and significant change rulesetsRev5
June 11, 2027FedRAMP stops accepting new Rev5 applications, and the Lost Sponsor and Ready Conversion pipelines closeNew Rev5 applicants
August 1, 2027Rev5 Certification Data Sharing and Security Decision Record rules required to maintain certificationRev5
October 1, 2027Grace ends for Rev5 Collaborative Continuous MonitoringRev5
December 31, 2027Legacy FedRAMP Ready status removed entirelyFedRAMP Ready
February 1, 2028All CR26 grace periods expireAll providers
December 31, 2028CR26 practices expire and must be replaced by a later release; existing Rev5 certifications active until at least this dateAll providers

The next deadline is December 7, 2026, when the Vulnerability Detection and Response (VDR) and Vulnerability Evaluation and Reporting (VER) rulesets become required for every Class B, C, and D provider, Rev5 and 20x, under CISA Binding Operational Directive 26-04. A certified provider that has not adopted them by then needs a corrective action plan, and FedRAMP revokes certification if they are not in place by March 7, 2027. Class A providers must follow VDR-CSO-DET, and FedRAMP recommends the timeframe rules. Every detected vulnerability needs an evaluation of exploitability and internet reachability and a Potential Agency Impact N-rating (PAIN), from N1, minimal effects on agency customers, to N5, a debilitating effect on more than one agency. FedRAMP's remediation expectations run on those three facts. The table shows the number of days after evaluation within which FedRAMP expects partial mitigation, full mitigation, or remediation to a lower rating (VDR-TFR-PVR), for Class B and Class C.

PAIN ratingInternet-reachable and likely exploitable (B / C)Not internet-reachable, likely exploitable (B / C)Not likely exploitable (B / C)
N54 / 2 days8 / 4 days32 / 16 days
N48 / 4 days32 / 8 days64 / 64 days
N332 / 16 days64 / 32 days192 / 128 days
N296 / 48 days160 / 128 days192 / 192 days

N1 carries no timeframe. FedRAMP expects Known Exploited Vulnerabilities to be remediated by the due dates in CISA's KEV catalog even after full mitigation (VDR-TFR-KEV), and any vulnerability not fully mitigated or remediated within 192 days of evaluation must be categorized as an accepted vulnerability (VER-TFR-MAV).

For a Rev 5 provider, the decision is sequencing. The CR26 changes to Rev 5 are mandatory either way, and several of them are the same capabilities 20x requires: JSON packages, delivery through a trust center, persistent vulnerability detection, accepted-vulnerability reporting, and notification-based change management. Build them once to the 20x standard, and a later move to 20x reuses them. Three details matter. A Rev 5 certification or FedRAMP Ready status completed within the past 12 months satisfies the prerequisite for a 20x Class A Certification (FRC-CLA-ASF), so a Rev 5 Agency Certification holder can pursue Class A without a new independent assessment when an agency wants a Program Certification. You cannot hold Rev 5 and 20x Program Certifications for the same offering, and FedRAMP allows a Rev 5 Agency Certification alongside a 20x Program Certification but strongly discourages it (FRC-CSO-POP). And if the offering runs on your own infrastructure or needs Class D, Rev 5 is currently the only option; FedRAMP expects to offer 20x Class D in early 2027.

What FedRAMP 20x costs and how long it takes

FedRAMP's review is the fast part. Its goal is 30 days, and the first two Class A Certifications moved from In Process to Certified in 19 and 17 days. Preparation sets the calendar and the budget, and three things drive both: how much of your security program already produces measurable, automatable evidence; how many services and third-party resources sit inside the Minimum Assessment Scope; and the class. The largest cost for most providers is internal engineering time to build validations and reporting. Workstreet calls engineering and development “the biggest cost,” and the ranges below cover only external spend on the assessment and readiness work.

We recommend budgeting 1.5 to 2 times the published estimates for this work, and the table applies that multiplier. Where you land within each range depends on the size of the business.

ProfilePreparation timeIndependent assessmentReadiness and advisoryFirst-year external spend
20x Class A90 to 120 days from a SOC 2 baselineOptional; $60,000 to $100,000 when used$75,000 to $100,000$135,000 to $200,000, including an assessment
20x Class BNo estimate in the cited sources; longer than Class A because 41 KSIs are required$75,000 to $120,000$115,000 to $150,000$190,000 to $270,000
20x Class CNo estimate in the cited sources; longer than Class B, with all 46 KSIs and at least 2 automated methods for each$90,000 to $140,000$165,000 to $260,000$255,000 to $400,000
Rev5, legacy Moderate for comparison12 to 18 months$225,000 to $600,000 or more$75,000 to $300,000 for the gap assessment alone$375,000 to $1.5 million, and above $2 million for some large offerings

A provider with one product, a small engineering team, one production environment, and a current SOC 2 Type II report should plan near the low end. Costs rise with the number of people and accounts your identity and access measures have to cover, with the number of services, environments, and third-party resources inside the Minimum Assessment Scope, and with the number of engineering teams whose pipelines have to produce evidence. A company with several product lines or hundreds of engineers should plan at the top of the range, and the largest offerings can exceed it.

The published estimates behind these ranges are Workstreet's August 2026 estimate for the 20x rows, which describes a provider starting from a SOC 2 baseline, and Secureframe, which cites Coalfire and Schellman, together with Workstreet for the Rev 5 row. Workstreet is a FedRAMP Marketplace-listed advisor. Budget for tooling on its own line: a trust center with API access, a GRC platform that can generate JSON, identity and endpoint tiers that expose the data your validations need, and penetration testing, which VDR-CSO-DET names as an example detection technique.

Choosing the independent assessor

We recommend Schellman for the independent assessment, and the public record supports it. In FedRAMP's Marketplace data as of September 23, 2026, Schellman is the independent assessor of record for 144 of the 532 FedRAMP Authorized offerings, about 27 percent and well ahead of Coalfire at 81. Of the 28 20x Low and Moderate authorizations in the same data, Schellman assessed 6, more than any other assessor, including OpenAI's ChatGPT Enterprise and API Platform at 20x Moderate, both of Vanta's 20x offerings, Drata, Spectro Cloud, and Anecdotes. Schellman has been accredited since July 2012, announced in April 2026 that it had become the first assessor to reach 200 assessed offerings on the FedRAMP Marketplace, and states in its Marketplace listing that it “only performs assessment services, and no consulting services.” That last point matters, because the firm testing your KSIs has no stake in how they were built.

One rule and one FedRAMP recommendation shape the choice. An assessor may not assess an offering within two years of providing advisory or consulting services for it (REC-IAS-SEP), so your advisor and your assessor should be different firms from the start. FedRAMP also calls it good practice to interview several FedRAMP Recognized assessors and get proposals from at least two or three, and it warns separately that recognition and the A2LA requirements behind it set “a minimum bar” and that neither reviews technical expertise in depth. Ask each firm how it tests automated validations, whether its team can review your validation code and query your APIs, and which 20x assessments it has completed. Schellman answers those questions with a track record. Get the other proposals anyway, as FedRAMP advises.

Frequently asked questions

What is FedRAMP 20x? FedRAMP 20x is the cloud-native FedRAMP Certification type under the Consolidated Rules for 2026. Providers prove Key Security Indicators with automated, machine-readable evidence and receive a Program Certification directly from FedRAMP. It is designed for services built on FedRAMP Certified infrastructure or platforms.

Does FedRAMP 20x require an agency sponsor? No. Every 20x certification is a Program Certification issued by FedRAMP, so no agency sponsor or prior ATO is required. Each agency still issues its own Authorization to Operate before it uses your service.

How long does FedRAMP 20x take? FedRAMP's goal is an initial decision within 30 days of receiving an application, and the first two Class A Certifications moved from In Process to Certified in 19 and 17 days in August 2026. Preparation takes longer: a published estimate puts Class A readiness at 90 to 120 days from a SOC 2 Type II baseline, and Class B and C take longer because 41 or all 46 indicators apply.

What is the difference between FedRAMP 20x and Rev 5? Rev 5 certifies a documented implementation of NIST SP 800-53 baselines and usually requires an agency sponsor. 20x certifies measured outcomes against Key Security Indicators, uses JSON packages shared through a trust center, and requires no sponsor. FedRAMP stops accepting new Rev 5 applications on June 11, 2027.

Do I need a 3PAO for FedRAMP 20x? Class B and Class C require an independent assessment by a FedRAMP Recognized assessor, the current term for a 3PAO, completed within three months before you apply. Class A makes the assessment optional because it relies on a SOC 2 Type II, GovRAMP, or Rev 5 assessment from the past 12 months.

How many Key Security Indicators are there? The Consolidated Rules for 2026 define 46 Key Security Indicators across 10 themes. Class A requires 7, Class B requires 41 and makes 5 optional, and Class C requires all 46.

Is OSCAL required for FedRAMP 20x? No. 20x requires JSON documents that validate against FedRAMP's published schemas, such as the Security Decision Record and Certification Package Overview schemas. FedRAMP describes OSCAL as optional in some Rev 5 cases.

Can a Rev 5 provider move to FedRAMP 20x? Yes, and FedRAMP asks Rev 5 providers to plan the move. A Rev 5 certification assessed in the past 12 months satisfies the prerequisite for 20x Class A, existing Rev 5 certifications stay active until at least December 31, 2028, and many of the CR26 changes Rev 5 providers must make by February 1, 2028 are capabilities 20x also requires.

Where BD Emerson fits

BD Emerson advises cloud service providers on FedRAMP. We are not a FedRAMP Recognized assessor, and we do not perform the assessment that results in your certification. FedRAMP defines an advisor as an entity that helps a provider prepare “without replacing the provider's responsibility or the assessor's independence,” and it warns that an advisor who claims to produce your artifacts and meet ongoing requirements on your behalf misrepresents the program. We work within that line. Our FedRAMP 20x readiness team helps you choose the profile, draws the Minimum Assessment Scope with your architects, designs KSI measures and failure conditions with your engineers, reviews the validation code and the JSON your pipelines generate, and helps your team put VDR and VER reporting in place ahead of December 7, 2026. Your team owns and runs the program, and we test it before the assessor and FedRAMP see it.

If you plan to use a SOC 2 Type II as your Class A prerequisite, our SOC 2 readiness practice can prepare you for the examination. For the testing that feeds vulnerability detection, see FedRAMP penetration testing. The FedRAMP 20x KSI workbook (Excel) lists all 46 indicators with their official statements, class requirements, and control mappings, with columns for owner, data source, automated methods, cadence, and failure condition, plus the ongoing cadence by class and the sample Security Decision Record. For the Rev 5 requirements under the 2026 rules, see FedRAMP requirements explained. When you want a second set of eyes on your profile or your first KSI designs, talk to us.

Acronyms and definitions

This section defines every acronym in this guide. FedRAMP terms follow the definitions in the Consolidated Rules for 2026, and the ruleset names come from FedRAMP's rules dataset.

TermMeaning
3PAOThird Party Assessment Organization. The legacy name for a FedRAMP Recognized assessor, the independent firm that assesses a cloud service for FedRAMP.
A2LAAmerican Association for Laboratory Accreditation. The body that accredits assessment firms; A2LA accreditation is a requirement for FedRAMP Recognition.
AFCAddressing FedRAMP Communication. The ruleset, formerly the FedRAMP Security Inbox, that sets how FedRAMP reaches your security staff and how fast you respond to urgent messages.
AGUAgency Use of FedRAMP Certified Cloud Services. The ruleset that sets agency responsibilities under the FedRAMP Authorization Act and OMB Memorandum M-24-15.
AIArtificial intelligence.
APIApplication programming interface. A defined way for one system to request data from another, such as an agency tool pulling your certification data from a trust center.
ATOAuthorization to Operate. An agency's formal decision to use a system and accept its risk. FedRAMP certifies the cloud service, and each agency still issues its own ATO.
AWSAmazon Web Services.
BODBinding Operational Directive. A compulsory CISA directive to federal agencies. The VDR and VER rulesets are mandated under BOD 26-04 from December 7, 2026.
CCMCollaborative Continuous Monitoring. The ruleset for Ongoing Certification Reports and Quarterly Reviews, which agencies use in their own continuous monitoring.
CDSCertification Data Sharing. The ruleset for storing and sharing certification data through a FedRAMP-compatible trust center.
CISACybersecurity and Infrastructure Security Agency. The Department of Homeland Security agency that issues binding operational directives and maintains the KEV catalog.
CMMCCybersecurity Maturity Model Certification. The Department of War program that verifies how defense contractors protect sensitive contract information.
CMUCryptographic Module Use. The ruleset for choosing and documenting cryptographic modules, which encourages validated modules wherever they are feasible.
CPOCertification Package Overview. The human-readable and JSON overview of your offering that, with the Security Decision Record, replaces the System Security Plan. It is also the name of its ruleset.
CR26Consolidated Rules for 2026. The FedRAMP rules that took effect on July 4, 2026, for both Rev 5 and 20x.
DFARSDefense Federal Acquisition Regulation Supplement. Its clause 252.204-7012 sets cybersecurity requirements for defense contractors, including cloud services that handle covered defense information.
ETEastern Time. FedRAMP states its default emergency response deadlines in Eastern Time.
FedRAMPFederal Risk and Authorization Management Program. The GSA program that certifies cloud services for use by federal agencies.
FIDO2An authentication standard from the FIDO (Fast IDentity Online) Alliance for phishing-resistant, passwordless sign-in with security keys and passkeys.
FIPS 140Federal Information Processing Standard 140. The NIST standard that cryptographic modules are validated against.
FRCFedRAMP Certification. The ruleset that explains how an offering obtains and maintains certification across classes and paths.
GovRAMPA cybersecurity verification program for cloud services used by state and local governments. A GovRAMP verification at any impact level completed in the past 12 months satisfies the 20x Class A prerequisite.
GRCGovernance, risk, and compliance. The category of platforms that track controls, evidence, and risks, including tools that generate your JSON package.
GSAGeneral Services Administration. The federal agency that runs FedRAMP.
IDIdentifier, as in a rule ID or a KSI ID.
IECIncident Evaluation and Communication. The ruleset for reporting incidents to FedRAMP and agency customers.
IVVIndependent Verification and Validation. The ruleset for independent assessments, including what each class must have assessed and how often.
JITJust-in-time. Access granted only when it is needed and removed afterward, as KSI-IAM-JIT describes.
JSONJavaScript Object Notation. The machine-readable text format FedRAMP uses for 20x packages, reports, and its published schemas.
KEVKnown Exploited Vulnerabilities. CISA's catalog of vulnerabilities with evidence of active exploitation, each with a remediation due date for federal agencies.
KSIKey Security Indicator. One of the 46 security outcomes, grouped in 10 themes, that a 20x provider proves with automated, machine-readable evidence.
MASMinimum Assessment Scope. Every information resource likely to handle federal customer data or affect its confidentiality, integrity, or availability. It replaces the legacy authorization boundary and is also the name of its ruleset.
MFAMulti-factor authentication. Sign-in that requires more than one kind of proof of identity. KSI-IAM-APM calls for phishing-resistant MFA where passwordless methods are not feasible.
MKTMarketplace Listing. The ruleset that decides which offerings, assessors, and advisors FedRAMP lists in the Marketplace.
NISTNational Institute of Standards and Technology. The Commerce Department agency that publishes SP 800-53, FIPS 140, and OSCAL.
OCROngoing Certification Report. The report a certified provider supplies to agency customers every 3 months under the CCM rules.
OMBOffice of Management and Budget. Its Memorandum M-24-15 of July 25, 2024 sets current federal policy for FedRAMP.
OSCALOpen Security Controls Assessment Language. NIST's machine-readable format for security plans and assessment results. Under CR26 it is optional for provider packages.
PAINPotential Agency Impact N-rating. The rating from N1 to N5 that VER requires for each vulnerability, estimating the harm to agency customers if it were exploited.
PDFPortable Document Format.
POA&MPlan of Action and Milestones. The Rev 5 list of open weaknesses and remediation dates. CR26 replaces it with accepted-vulnerability reporting.
RECFedRAMP Recognition of Independent Assessment Services. The ruleset assessors follow to earn and keep FedRAMP Recognition.
Rev 5 (Rev5)Revision 5 of NIST SP 800-53. FedRAMP also uses the name for its legacy certification type, which documents SP 800-53 controls in a Security Decision Record.
RPORecovery Point Objective. The maximum amount of data, measured in time, a service can afford to lose in a disruption.
RTORecovery Time Objective. The maximum time a service can take to recover from a disruption.
SCGSecure Configuration Guide. The ruleset requiring providers to explain the security impact of common settings so customers can configure the service securely.
SCNSignificant Change Notification. The ruleset that sorts changes into routine recurring, adaptive, or transformative and sets when you notify agencies and FedRAMP.
SDLCSoftware development lifecycle. The stages of planning, building, testing, releasing, and maintaining software.
SDRSecurity Decision Record. The persistently maintained record of your security decisions, including implementation rationale, customer risk, assessment findings, and supporting artifacts. It replaces the System Security Plan and is also the name of its ruleset.
SIEMSecurity information and event management. A system that collects and correlates security logs across an environment.
SOC 2System and Organization Controls 2. An independent auditor's report on a service organization's security controls. A Type II report covers how the controls operated over a review period, and one completed in the past 12 months satisfies the 20x Class A prerequisite.
SPSpecial Publication. NIST's document series; SP 800-53 is the catalog of security and privacy controls behind the Rev 5 baselines.
SSPSystem Security Plan. The Rev 5 document that narrated how each control was implemented. CR26 replaces it with the Certification Package Overview and the Security Decision Record.
UEIUnique Entity Identifier. The 12-character identifier the federal government assigns to organizations registered to do business with it.
URIUniform Resource Identifier. A string that identifies a resource, such as a link to a piece of evidence.
USDAU.S. Department of Agriculture. USDA Connect is the repository that holds legacy Rev 5 Low and Moderate packages.
VDRVulnerability Detection and Response. The ruleset requiring providers to find, prioritize, mitigate, and remediate vulnerabilities through automated systems on FedRAMP timeframes.
VERVulnerability Evaluation and Reporting. The ruleset for deciding whether each vulnerability is likely to affect federal customers and reporting its status.

Codes inside rule IDs and KSI IDs

A FedRAMP rule ID has three parts. The first names the ruleset, the second names the section of that ruleset, and the third is a short label for the individual rule. In VDR-TFR-MVX, VDR is Vulnerability Detection and Response, TFR is its Timeframes section, and MVX is the rule for persistent machine verification and validation on 20x. KSI IDs follow the same pattern: KSI-IAM-JIT is the Authorizing Just-in-Time indicator in the Identity and Access Management theme. The ruleset codes are defined in the table above, and the section and theme codes are below.

CodeUsed inMeaning
AGCAGU-AGCGeneral Agency Responsibilities
APPFRC-APPApplying for FedRAMP Certification
CEDKSI-CEDCybersecurity Education theme, 1 indicator
CLAFRC-CLAFedRAMP Class A Certification Rules
CMTKSI-CMTChange Management theme, 4 indicators
CNAKSI-CNACloud Native Architecture theme, 8 indicators
CSOFor example, FRC-CSOGeneral Provider Responsibilities, which apply to every provider
CSXFor example, FRC-CSX20x-Specific Provider Responsibilities
EVAVER-EVAEvaluation
FRPFor example, AFC-FRPFedRAMP Responsibilities, the rules FedRAMP itself follows
IAMKSI-IAMIdentity and Access Management theme, 6 indicators
IASREC-IASIndependent Assessor Responsibilities
IIPMKT-IIPInitial Implementation Phase listings in the Marketplace
INRKSI-INRIncident Response theme, 3 indicators
MLAKSI-MLAMonitoring, Logging, and Auditing theme, 5 indicators
OCRCCM-OCROngoing Certification Reports
PIYKSI-PIYPolicy and Inventory theme, 5 indicators
QTRCCM-QTRQuarterly Reviews
RPLKSI-RPLRecovery Planning theme, 4 indicators
RPTVER-RPTReporting
SCRKSI-SCRSupply Chain Risk theme, 2 indicators
SVCKSI-SVCService Configuration theme, 8 indicators
TFRVDR-TFR, VER-TFRTimeframes
TRCCDS-TRCFedRAMP-Compatible Trust Centers
TRFSCN-TRFTransformative Changes
USEAGU-USEUse of FedRAMP Certifications

FedRAMP primary sources

SourceWhat it covers
FedRAMP Consolidated Rules for 2026The rules, definitions, timelines, and guidance for providers, agencies, assessors, and advisors
FedRAMP/rules on GitHubThe machine-readable source of truth for every rule, definition, and KSI
FedRAMP/schemas on GitHubJSON schemas for the Certification Package Overview, Security Decision Record, reports, and notifications
Key Security IndicatorsOfficial KSI statements and related controls
FedRAMP Certification rules for 20xClass A requirements, application rules, and KSI automation rules
Getting started for providersChoosing an advisor, path, class, and type
Important datesAdoption, pipeline, and retirement milestones
What's changing in 2026Terminology shifts and mandatory Rev 5 changes
Rev5 deadlines and 20x deadlinesObtain, maintain, and grace dates for every ruleset
Approaching FedRAMP 20x assessmentsHow assessors are told to test KSIs and automated validations
FedRAMP 20x program pagePilot phases and current status
FedRAMP Marketplace dataCertified offerings, assessors, and certification status history

About the author

Drew Danner is a Managing Director at BD Emerson. He leads engagements across technology strategy, enterprise AI, M&A technology diligence, and the firm's governance, risk, and security practice, advising buyers, operators, and portfolio companies on decisions where the technical call drives the commercial outcome. His work spans build vs buy decisions, platform implementations, and the security and compliance programs that keep them defensible.
Drew Danner
Drew Danner
Managing Director