FedRAMP 20x Compliance, Start to Finish: KSIs, Machine-Readable Evidence, and What Changed From Rev 5
FedRAMP 20x is the cloud-native way to earn a FedRAMP Certification under the Consolidated Rules for 2026, which took effect on July 4, 2026. Instead of a System Security Plan narrating hundreds of NIST SP 800-53 controls, you prove Key Security Indicators with automated, repeatable measurements, publish a Certification Package Overview and a Security Decision Record in JSON through a FedRAMP-compatible trust center, and apply directly to FedRAMP without an agency sponsor. Class A requires 7 of the 46 indicators plus a SOC 2 Type II, GovRAMP, or Rev5 assessment completed within the past 12 months. Class B requires 41 of them, with the other 5 optional, and Class C requires all 46. Both need an independent assessment by a FedRAMP Recognized assessor completed in the three months before applying. FedRAMP's goal is an initial decision within 30 days of receiving an application.
This guide follows a 20x project from the first decision to the first Ongoing Certification Report: the rule IDs FedRAMP uses, the machine-readable formats it expects, the full list of Key Security Indicators, what changed from Rev 5, what the work costs, and who should assess it. Every requirement cited here comes from FedRAMP's machine-readable rules dataset (version 2026.09.13.02, updated September 13, 2026) and the Consolidated Rules site. If you already hold a Rev 5 certification, skip to the section on moving from Rev 5, because your next deadline is December 7, 2026. Every acronym in this guide is defined in the acronyms and definitions section near the end.
What FedRAMP 20x is, in FedRAMP's own terms
GSA announced FedRAMP 20x on March 24, 2025, with the stated goal of approving new cloud services “in weeks instead of years” through automation and engineer-friendly requirements. FedRAMP ran it as public pilots. Phase 1 tested Low impact services from April to September 2025 and received 26 complete submissions. Phase 2 tested Moderate impact services from November 2025 through March 2026. FedRAMP's Marketplace data now lists 28 offerings certified at 20x Low or 20x Moderate, 14 of each, including offerings from OpenAI, Google, Perplexity, Confluent, and Vanta. FedRAMP then folded the approach into the Consolidated Rules for 2026 (CR26), launched on June 24, 2026, which now govern both 20x and Rev 5.
The legal footing is the FedRAMP Authorization Act, which Congress enacted on December 23, 2022, and OMB Memorandum M-24-15 of July 25, 2024. M-24-15 rescinded the 2011 policy memo that created the original program and directed FedRAMP to automate intake and review, grow the Marketplace, and stop pushing commercial providers to build separate government-only versions of their products. 20x is the program's answer to that memo.
CR26 also replaced the vocabulary, and FedRAMP treats the old words as a warning sign. Its guidance on choosing an advisor says that one who still offers help obtaining a “FedRAMP Authorization” or talks about Low, Moderate, and High impact levels is showing that it has not followed the changes. These are the terms used throughout this guide.
| Legacy term | CR26 term | What changed |
|---|---|---|
| FedRAMP authorization | FedRAMP Certification | FedRAMP certifies the cloud service. Each agency still issues its own Authorization to Operate for the federal system that uses it. |
| Low, Moderate, and High impact levels | Certification Class A, B, C, or D | A class describes how much assurance information you commit to supply. It is a separate question from how sensitive an agency's data is. |
| System Security Plan and appendices | Certification Package Overview and Security Decision Record | A verified record of the security decisions you made, and how you measure them, replaces a plan. |
| Continuous monitoring | Ongoing Certification | The recurring obligations are broader than scanning, and failing them costs you the certification. |
| 3PAO | FedRAMP Recognized independent assessment service (assessor) | The term follows the FedRAMP Authorization Act. A2LA accreditation is still required for recognition. |
| Plan of Action and Milestones (POA&M) | Accepted vulnerabilities | Any vulnerability not fully mitigated or remediated within 192 days of evaluation is categorized as accepted. |
| FedRAMP Ready | 20x Class A | FedRAMP stopped accepting Ready submissions after July 28, 2026 and points new entrants to Class A. |
Choose your certification profile before you build anything
A Certification Profile is three choices: type, path, and class. Rule FRC-CSO-FCP requires you to name a target profile and apply every FedRAMP Practice that goes with it, so this decision sets the scope of the whole project.
Type: 20x or Rev5
FedRAMP says cloud services built on FedRAMP Certified infrastructure or platforms should choose 20x, and calls it “the fastest, cheapest, and best way to bring an existing commercial cloud service into the federal market.” Rev5 remains the only option for services that run their own infrastructure or need a Class D certification today. FedRAMP stops accepting new Rev5 applications on June 11, 2027, and describes Rev5 as a legacy type it is working to retire.
Path: Program or Agency
Program Certification comes directly from FedRAMP and needs no agency sponsor, and it is the path for every 20x certification. Agency Certification is the legacy route in which an agency completes an ATO first and then sponsors the service to FedRAMP, and it applies only to Rev5. You cannot seek Rev5 and 20x Program Certifications for the same offering (FRC-CSO-POP).
Class: A, B, or C
Classes rise in the assurance you commit to supply to agencies, and in cost. FedRAMP's advice is to start with Class A in most cases, to go straight to Class C only when an existing agency contract requires it, and never to plan a first certification at Class D. Treat Class A as a first step: FedRAMP says agencies should not authorize a Class A service for more than 12 months unless the provider is actively seeking Class B, C, or D (AGU-USE-CLA). Class D is not yet available under 20x. FedRAMP says it anticipates piloting 20x Class D in late 2026 and making it a formal option in early 2027. The table below shows what each available class requires, with the rule behind each line.
| Requirement | Class A | Class B | Class C |
|---|---|---|---|
| What FedRAMP says agencies can use it for | Pilots, configuration and testing, public or negligible-risk data | Most Low impact systems | Most Low and Moderate impact systems |
| Prerequisite (FRC-CLA-ASF, FRC-APP-MLF) | SOC 2 Type II, GovRAMP, or FedRAMP Rev5 (including Ready) completed in the past 12 months, plus a Marketplace listing | Marketplace listing | Marketplace listing |
| Key Security Indicators (FRC-CLA-MFR for Class A; each KSI's class requirements for B and C) | 7 required | 41 required, 5 optional | All 46 required |
| Independent assessment before applying (FRC-APP-FIA) | Optional | Required, completed in the prior 3 months | Required, completed in the prior 3 months |
| Automated methods per KSI (FRC-CSX-VVK) | Optional | At least 1 (recommended) | At least 2 (required) |
| Historical KSI metrics (FRC-CSX-MOT, SDR-CSX-KMT) | Optional | Recommended at application, required once certified | At least 6 months (required) |
| Package kept current (CPO-CSX-CPM) | Every 3 months (recommended) | Monthly | Every 2 weeks |
| Machine-based resources verified and validated (VDR-TFR-MVX) | Monthly (recommended) | Every 7 days | Every 3 days |
| Annual independent assessment (IVV-CSX-AIA) | Must meet the underlying framework's expectations | All KSIs every year | All KSIs every year |
| Quarterly Review with agencies (CCM-QTR-MTG) | Optional | Recommended | Required |
| NIST-validated cryptographic modules (CMU-CSO-UVM) | Optional | Optional | Recommended |
| Default time to answer a FedRAMP Emergency message with a resolution estimate (AFC-FRP-ERT) | 3 p.m. ET, 5th business day | 3 p.m. ET, 3rd business day | 3 p.m. ET, 2nd business day |
If a contract still says Low or Moderate, FedRAMP's own 20x program page says that in the current phase, 20x “will initially support Class A (Pilot), Class B (Low), and Class C (Moderate) Certifications,” which is the practical translation. Expect the agency to do its own categorization anyway. FedRAMP's agency guidance says a class indicates the level of assurance a provider supplies, warns agencies against reading it as a measure of how secure the service is, and leaves the agency to decide whether the service fits its system, data, and risk tolerance.
One boundary to settle early if you sell to defense: FedRAMP states that it “does not support or provide 'equivalency.'” If a DFARS 252.204-7012 contract calls for FedRAMP Moderate equivalency for a cloud service that stores, processes, or transmits covered defense information, FedRAMP directs those questions to the Department of War, and the question belongs to your CMMC program. Our CMMC consulting team scopes that side.
The FedRAMP 20x project, start to finish
FedRAMP organizes the journey into three phases: Preparation, Initial Implementation, and Ongoing Certification. Its sequencing advice is to build the Certification Package Overview first, then the Security Decision Record, then the assurance capabilities you will operate for as long as you hold the certification. The steps below follow that sequence.
1. Staff it as an engineering project
The strongest signal from the pilots is organizational. FedRAMP's KSI guidance notes that the most successful pilot organizations were led entirely by experienced engineering and product teams that treated certification like any other product, and its implementation guidance calls a separate compliance team without access to engineering resources “a guaranteed way” to make certification harder. Name an executive owner, give the program a product manager, and put platform, security, and site reliability engineers on it from the first week. Compliance staff own the rule mapping and the package. Engineers own the measurements.
2. Get listed in the Marketplace
Since July 6, 2026, providers early in the process can appear in the FedRAMP Marketplace in the Initial Implementation Phase, and you must be listed before you apply (FRC-APP-MLF). The listing is the first real test of the rules. You publish the public information in CDS-CSO-PUB on your website in human-readable and JSON form, including service and deployment model, UEI number, sales and security contacts, a service list with security categories, links to your secure configuration guidance and trust center, and your current assessor. You demonstrate a government-wide use case (MKT-IIP-AGU), stand up a basic FedRAMP-compatible trust center, post progress against your own milestones at least quarterly (MKT-IIP-DCP), and show that a Class B, C, or D assessment is scheduled within two years of listing, or FedRAMP removes the listing (MKT-IIP-DLA). FedRAMP rejects incomplete listing requests with only the minimum explanation, so validate the JSON against FedRAMP's schema before you submit.
3. Draw the Minimum Assessment Scope
The Minimum Assessment Scope replaces the legacy authorization boundary for both 20x and Rev 5. MAS-CSO-IIR puts in scope every information resource likely to handle federal customer data or affect its confidentiality, integrity, or availability, and that set is, by definition, your cloud service offering. You document information flows and security categories for all of it (MAS-CSO-FLO), include metadata about federal customer data (MAS-CSO-MDI), and explain each third-party resource the offering depends on: how you use and configure it, why, and the mitigations and compensating controls around it (MAS-CSO-TPR). Products outside the scope can go in a separate, marked supplement, and they are not certified. Your public service list (CDS-CSO-SVC) must be specific enough that a buyer can tell which features are in scope without asking you.
4. Build the Certification Package Overview
The Certification Package Overview is a short, structured summary of the offering, supplied in human-readable and JSON formats (CPO-CSO-OVR), and together with the Security Decision Record it takes the place of the System Security Plan. It carries your public information and service list, an inventory of every relevant policy and procedure with its summary, word count, version, and date, the assessment scope and third-party resources, your cryptographic module documentation, the assessor's overall summary for Class B and C, and the name and contact of the official accountable for the package. FedRAMP tells providers to build this first, and warns that a provider who finds the overview hard should expect a long road through the rest.
5. Design the measures and build the Security Decision Record
The Security Decision Record is where most of the time goes. For every applicable rule, SDR-CSO-FRR asks for how you follow it (or why you do not, and the resulting risk to customers), verification that the implementation fits the rule, validation that it works, the independent verification and validation, and any rule-specific artifacts. For every applicable KSI, SDR-CSX-KSI asks for the measures that demonstrate it and their objectives, the cycle each persistent measure runs on, verification that the measures and the automation behind them are accurate and sufficient, and validation that they work as intended. Class B and C providers also keep historical metrics for every KSI in the record (SDR-CSX-KMT).
Two class rules set the engineering bar. Class C must run at least two automated methods per KSI to verify and validate its accuracy and completeness, where Class B should run at least one (FRC-CSX-VVK). Class C must supply at least six months of historical KSI metrics, and a new service without that history can apply with the mechanisms in place and an agreement to meet the requirement (FRC-CSX-MOT). FedRAMP also says providers should apply every KSI to every part of the offering inside the assessment scope (FRC-CSX-MAS), so a measure that checks only your primary cloud account falls short.
6. Prove the assurance machinery before you apply
FedRAMP will not certify a service that can only describe how it will operate. Its implementation guidance says you must prove you are ready to meet every Ongoing Certification requirement in order to obtain the initial certification, and for most providers these are new capabilities:
- A monitored FedRAMP Security Inbox that receives FedRAMP email without disruption and routes Emergency messages to a senior security official (AFC-CSO-INB, AFC-CSO-RCV, AFC-CSO-EMR).
- Vulnerability detection that runs persistently and treats a failure in the detection or response process as a vulnerability (VDR-CSO-DET, VDR-CSO-FAV).
- Vulnerability evaluation that rates every finding for exploitability, internet reachability, and a Potential Agency Impact N-rating from N1 to N5, with a monthly human-readable activity report (VER-EVA-ELX, VER-EVA-EIR, VER-EVA-EPA, VER-TFR-MHR).
- A significant change process that sorts each change into routine recurring, adaptive, or transformative, with notices sent on FedRAMP's timelines (SCN-CSO-EVA).
- Incident reporting to fedramp_security@fedramp.gov and affected agencies, from the initial report through the final report (IEC-CSO-IIR, IEC-CSO-FIR).
- A Secure Configuration Guide for top-level administrative accounts, and an Ongoing Certification Report your team can produce every three months (SCG-CSO-RSC, CCM-OCR-AVL).
The package must include a real or example Ongoing Certification Report (FRC-CSO-PKG), and incident reports used as evidence can come from real or simulated incidents.
7. Commission the independent assessment
Class B and C require a FedRAMP Recognized assessor, and the assessment must be completed within three months before you apply (FRC-APP-FIA). If it goes stale, the assessor can review what changed in place of a full reassessment, unless the original is more than nine months old (FRC-APP-USA). Expect a different engagement from a Rev 5 audit. FedRAMP's guidance to assessors tells them to trace each important validation from its source data through the code, queries, and thresholds that produce the result, down to what counts as failure, and warns that “a green status can hide missing accounts, incomplete inventory, faulty integrations, or a manual step that never happened.” That work can include code review, API testing, and cloud architecture analysis. FedRAMP encourages early and frequent contact so you can explain your validation design and the assessor can test it while unclear evidence can still be fixed. The section on choosing an assessor below covers who we recommend.
8. Apply and get through review
You apply through FedRAMP's Certification Application Form yourself (FRC-APP-AFC), because FedRAMP no longer accepts applications submitted by assessors or any other third party (FRC-APP-NTP). The package must show the offering as you verified and validated it within the previous seven days (FRC-APP-FCP). FedRAMP scans the submission for completeness, assigns a Review Team that requests access to your trust center, reviews the Certification Package Overview, and for 20x usually schedules a Deep Dive on the overview and the Security Decision Record. FedRAMP's internal goal is an initial decision within 30 days, and the clock stops whenever it is waiting on you. The first two 20x Class A Certifications, Bland AI and Files.com, moved from In Process to Certified in 19 and 17 days in August 2026, according to FedRAMP's Marketplace status data.
9. Run Ongoing Certification
Certification starts the recurring work, and the cadence depends on class.
| Obligation | Rule | Class B | Class C |
|---|---|---|---|
| Verify and validate machine-based resources | VDR-TFR-MVX | Every 7 days | Every 3 days |
| Verify and validate policies, procedures, and other non-machine resources | VDR-TFR-NMV | Every 3 months | Every 3 months |
| Keep the Certification Package current | CPO-CSX-CPM | Monthly | Every 2 weeks |
| Vulnerability detection and response activity report | VER-TFR-MHR | At least monthly | At least monthly |
| Historical vulnerability activity in JSON for automated retrieval | VER-TFR-MRH | Monthly (recommended) | Every 14 days (recommended) |
| Ongoing Certification Report to agencies and FedRAMP | CCM-OCR-AVL | Every 3 months | Every 3 months |
| Quarterly Review meeting | CCM-QTR-MTG | Recommended | Required; FedRAMP recommends holding it 3 to 10 business days after each report |
| Availability status service for FedRAMP and agency customers, with 30 days of history, reachable when the offering is down | CDS-CSO-AVR | Required | Required |
| Independent assessment of all KSIs | IVV-CSX-AIA | Every year | Every year |
| Transformative change notices | SCN-TRF | 30 and 10 business days before, 5 after | 30 and 10 business days before, 5 after |
Rev 5 providers will recognize the monthly vulnerability reporting and the annual assessment. The three-day and seven-day resource validation cycles, the quarterly reports and reviews, and the availability status service are new.
Machine-readable controls: what FedRAMP means and what to build
Machine-readable has a legal definition in the rules. FedRAMP adopts 44 U.S.C. § 3502(18): data “in a format that can be easily processed by a computer without human intervention while ensuring no semantic meaning is lost.” Four rules turn that definition into engineering work. FRC-CSO-JSN applies to every class and requires JSON documents that validate against the matching FedRAMP schema whenever a rule names one, unless that rule says otherwise. CDS-CSO-CBF requires automation to keep the human-readable and machine-readable versions of your certification data consistent, so a PDF your team edits by hand next to a JSON file generated from a different source will not pass. CDS-TRC-PAC requires your trust center to give documented programmatic access to all certification data, including the human-readable materials, and CDS-TRC-ACL requires it to log all access to certification data and keep access summaries for at least six months. Those three data-sharing rules apply to Classes B, C, and D.
FedRAMP publishes the schemas at fedramp.gov/schemas and in the FedRAMP/schemas repository: the Certification Package Overview, Security Decision Record, Ongoing Certification Report, incident report, significant change notification, vulnerability detail report, accepted vulnerability information, historical vulnerability activity, advisor information, and assessor information, plus shared definitions. The repository labels them drafts, and each schema carries its own version number, so pin the versions you build against. FedRAMP calls the schemas “lightweight and flexible” minimums that providers can extend. For provider packages, OSCAL is now optional. CR26 moves Rev 5 packages from Word and Excel templates to “simplified JSON documents or (in some cases) optional OSCAL,” and 20x packages use FedRAMP's JSON schemas. Agencies still need governance, risk, and compliance tools that can produce and ingest both OSCAL and JSON (AGU-AGC-GRC).
FedRAMP publishes its own rules the same way. The fedramp-consolidated-rules.json file in the FedRAMP/rules repository holds every definition, rule, and KSI by ID, with class variants where they apply, ruleset effective dates, and each KSI's related NIST SP 800-53 controls. FedRAMP tells automation services and AI agents to skip its website and process the source data directly, and it names this repository the source of truth for structured rules. Build your rule mapping from the file, pin the version you mapped against, and diff it when FedRAMP ships an update, because FedRAMP has revised the rules several times since launch, most recently on September 13, 2026.
What a KSI validation looks like
A KSI is an outcome claim, and at Class C the measurement behind it is code with a data source, a cadence, and a failure condition. Take KSI-IAM-APM, which requires passwordless authentication where feasible and otherwise strong passwords with phishing-resistant MFA. A Class C implementation needs at least two automated methods (FRC-CSX-VVK). The first is a daily query of the identity provider confirming that every active human account is bound to a FIDO2 or passkey authentication policy, failing on any exception. The second is a daily query of authentication logs for any successful sign-in completed without a phishing-resistant factor, failing on any match. Each run writes a timestamped result to the evidence store, a failure opens a ticket and pages the identity team, and the pass rate over time becomes the historical metric. The Security Decision Record entry for that KSI then looks like the example below, which validates against FedRAMP's Security Decision Record schema, version 1.1.1.
The schema requires, for each indicator, the KSI ID and arrays for implementation, validation, assessment, tests, and evidence. An optional implementation status accepts Implemented, Partially Implemented, or Not Implemented. Each evidence entry can carry a type (log, report, screenshot, configuration, policy, procedure, or audit record), a description, a location URI, inline text, and a last-updated date, and the schema requires none of those fields, so decide your own minimum and hold every entry to it. The assessment statements come from your assessor and stay theirs, because FedRAMP requires assessment results in the package “without inappropriate modification” (IVV-CSO-ICP). The same record also holds a fedRampRequirements array with an entry for each of the more than 150 provider rules that apply to Class B and C.
How to produce the records: the technical build
Producing FedRAMP's machine-readable records is a data pipeline. You pull facts from the systems that run the service, test them in code on a schedule, keep every result with a timestamp, generate the JSON documents from those stored results, validate each document against FedRAMP's schema, and publish the documents through a trust center that agencies and FedRAMP can query. FedRAMP does not prescribe tools. You can build the pipeline from your cloud provider's APIs, the security tools you already run, and a GRC platform, your own code, or both.
Start with FedRAMP's source files. Clone the FedRAMP/schemas repository, or download each schema from the fedramp.gov/schemas address in its $id field, which is the schema's official identifier, and keep the copies you build against in your own version control. The date in each file name identifies the CR26 ruleset and stays fixed, while the $schemaVersion field inside the file changes when FedRAMP edits the schema. FedRAMP moved the Security Decision Record schema to version 1.1.1 on September 1, 2026, and it issued new major versions of the assessor and advisor schemas on September 23, 2026, so record the version you build against and rerun your validation when it changes. The rules dataset tells you which schema each rule expects: 24 rules carry a schema field with the schema's name and address. Generate the fedRampRequirements list in your Security Decision Record from the same file by filtering rules on the type, path, class, and affected party in each subset's applicability block and writing one entry per applicable rule, keyed by its rule ID.
Validate every document before it leaves your pipeline. All eleven schemas use JSON Schema draft 2020-12, so use a validator that supports that draft, such as the jsonschema library for Python or Ajv for JavaScript, and run it as a build step that blocks publication on any error. Nine of the ten document schemas reuse shared definitions from the common-definitions schema and reference it by its fedramp.gov address. Load that file into the validator next to the schema you are checking, because a validator that cannot resolve the reference stops with an error instead of validating. The Security Decision Record and every report also require a certificationPackageOverviewUri field that points back to your Certification Package Overview, so publish that document first at a stable address.
| Stage | What you build | Example technology | Rules it serves |
|---|---|---|---|
| Collect | Read-only integrations that pull configuration, inventory, identity, log, and vulnerability data from every resource in the Minimum Assessment Scope | Cloud provider APIs such as AWS Config, Azure Resource Graph, and Google Cloud Asset Inventory; identity provider APIs such as Okta and Microsoft Graph for Entra ID; scanner, code repository, and ticketing APIs | MAS-CSO-IIR, VDR-CSO-DET |
| Evaluate | Validation code for each KSI measure, with a data source, a cadence, a threshold, and a failure condition | Policy-as-code engines such as Open Policy Agent, scheduled queries, or scripts in your build pipeline | FRC-CSX-VVK, VDR-TFR-MVX |
| Store | An evidence store that keeps every result with its timestamp, inputs, and outcome, long enough to report history | Versioned object storage or a database with write-once retention | FRC-CSX-MOT, SDR-CSX-KMT |
| Generate | Code that builds each JSON document from the stored results and renders the human-readable version from the same data | Templates in your build pipeline or the export from your GRC platform | SDR-CSO-FRR, CPO-CSO-OVR, CDS-CSO-CBF |
| Validate | A build step that checks every document against its FedRAMP schema and blocks publication on any error | A validator that supports JSON Schema draft 2020-12 | FRC-CSO-JSN |
| Publish | A FedRAMP-compatible trust center with documented API access, access logging, and an inventory of agency users and systems | A trust center product or your own authenticated API | CDS-CSO-UTC, CDS-TRC-PAC, CDS-TRC-ACL, CDS-TRC-AAI |
| Report | Scheduled jobs for the monthly vulnerability activity report, the Vulnerability Detail Report, historical vulnerability data, and the Ongoing Certification Report | The same pipeline, run on the cadence your class requires | VER-TFR-MHR, VER-RPT-VDT, VER-TFR-MRH, CCM-OCR-AVL |
Here is how the KSI-IAM-APM example above moves through that pipeline. A scheduled job calls the identity provider's API with a read-only credential and saves the raw response. The validation code checks each active account's authentication policy and writes a pass or fail result with a timestamp to the evidence store. The generator reads the latest result and the 30-day and one-year metric summaries that SDR-CSX-KMT requires, writes them into that KSI's Security Decision Record entry with an evidence location pointing to the stored result, renders the human-readable page from the same data, validates the JSON, and publishes both versions to the trust center.
Vulnerability records follow the same pattern with one extra step. Each finding becomes a vulnerabilityDetail entry that requires your tracking ID, the detection time and source, and a description, and that carries the VER evaluation: whether the vulnerability is internet-reachable and likely exploitable, its current PAIN rating as an integer from 1 to 5, the time the evaluation finished, which starts the 192-day clock for accepted vulnerabilities, and its final disposition. Scanners do not produce PAIN ratings or FedRAMP's reachability and exploitability judgments, so the generator has to join each scanner finding with your team's evaluation record before it writes the Vulnerability Detail Report.
Agencies and FedRAMP pull data from you as well. CDS-TRC-PAC requires documented programmatic access to all certification data, so publish an API reference for the trust center, issue a credential to each agency user or system, and log every request: CDS-TRC-ACL requires access summaries kept for at least six months, and CDS-TRC-AAI requires an inventory and history of the agency users and systems with access. VER-TFR-MRH asks Class B providers to keep recent vulnerability history available in JSON for automated retrieval, updated at least monthly, and asks Class C providers to update it at least every 14 days. Separately, CDS-CSO-AVR requires Class B, C, and D providers to run a web service that shows current availability and the past 30 days of availability for core services, in human-readable and machine-readable form, and that stays up when the offering itself is down.
Build the pipeline so an assessor can test it. FedRAMP tells assessors to trace validations end to end, from the source data through collection, transformation, and the code, queries, or thresholds that produce each result, and to review code, test APIs, and analyze cloud architecture instead of stopping at a dashboard. Keep collectors and validation code in source control with peer review, keep the pipeline's own run logs, and make every result reproducible from its stored inputs. If a GRC platform supplies part of the pipeline, confirm that its JSON export validates against the current FedRAMP schemas and that it keeps your assessor's statements separate from yours, because IVV-CSO-ICP requires assessment results in the package without inappropriate modification.
The 46 Key Security Indicators
CR26 organizes the indicators into 10 themes. Class A requires the 7 marked below. Class B requires 41 and makes the other 5 optional, and Class C requires all 46. FedRAMP's dataset maps 44 of the 46 KSIs to related NIST SP 800-53 controls, and some summarize a lot of ground: KSI-IAM-JIT maps to 38 controls and KSI-IAM-ELP to 34. Thirty-five of the 46 statements use FedRAMP's defined term “persistently” or its form “persistent.” FedRAMP defines it as activity repeated in cycles over a long period, where any irregularity or gap between cycles is intentional, understood, and documented, and the status is always known. A measure that runs when someone remembers to run it does not meet that definition.
The statements below are FedRAMP's official wording from the rules dataset, also published on the Key Security Indicators pages. The KSI workbook carries the same statements with their control mappings and columns for planning each measure.
| Theme | Indicator | Official statement | Class A | Class B |
|---|---|---|---|---|
| Cybersecurity Education | KSI-CED-RAT Reviewing All Training | The effectiveness of relevant cybersecurity education and training is persistently reviewed, including at least general training for all employees, role-specific training for employees in high risk roles, training for development and engineering staff on secure software delivery, and training for staff involved with incident response or disaster recovery. | Yes | Required |
| Change Management | KSI-CMT-LMC Logging Changes | Modifications to the cloud service offering are logged and monitored. | Yes | Required |
| Change Management | KSI-CMT-RMV Redeploying vs Modifying | Changes to machine-based information resources are executed through the redeployment of version controlled resources rather than direct modification wherever reasonable. | No | Required |
| Change Management | KSI-CMT-RVP Reviewing Change Procedures | The effectiveness of documented change management procedures is persistently reviewed. | No | Required |
| Change Management | KSI-CMT-VTD Validating Throughout Deployment | Persistent testing and validation of changes throughout deployment is automated. | No | Required |
| Cloud Native Architecture | KSI-CNA-DFP Defining Functionality and Privileges | The functionality and privileges for infrastructure and services are strictly defined. | No | Required |
| Cloud Native Architecture | KSI-CNA-EIS Enforcing Intended State | Automated services are used to persistently assess the security of all machine-based information resources and automatically enforce their intended operational state. | No | Optional |
| Cloud Native Architecture | KSI-CNA-IBP Implementing Best Practices | The use and configuration of third-party machine-based information resources is persistently compared against the original provider's best practices and guidance. | No | Required |
| Cloud Native Architecture | KSI-CNA-MAT Minimizing Attack Surface | Machine-based information resources are persistently reviewed to ensure they have a minimal attack surface and that lateral movement is minimized if compromised. | No | Required |
| Cloud Native Architecture | KSI-CNA-OFA Optimizing for Availability | Machine-based information resources are persistently reviewed to ensure they are appropriately optimized for high availability and rapid recovery. | No | Required |
| Cloud Native Architecture | KSI-CNA-RNT Restricting Network Traffic | Machine-based information resources are persistently reviewed to ensure they are appropriately configured to limit inbound and outbound network traffic. | Yes | Required |
| Cloud Native Architecture | KSI-CNA-RVP Reviewing Protections | The effectiveness of protection against denial of service attacks and other unwanted activity for machine-based information resources is persistently reviewed. | No | Required |
| Cloud Native Architecture | KSI-CNA-ULN Using Logical Networking | Logical networking and related capabilities are used and persistently reviewed to enforce traffic flow controls. | No | Required |
| Identity and Access Management | KSI-IAM-AAM Automating Account Management | The lifecycle and privileges of all accounts, roles, and groups are securely managed using automation. | Yes | Required |
| Identity and Access Management | KSI-IAM-APM Adopting Passwordless Methods | Secure passwordless methods are used for user authentication and authorization when feasible, otherwise strong passwords with phishing-resistant MFA is used. | Yes | Required |
| Identity and Access Management | KSI-IAM-ELP Ensuring Least Privilege | Identity and access management measures are used and persistently reviewed to ensure each user or device can only access the resources they need. | No | Required |
| Identity and Access Management | KSI-IAM-JIT Authorizing Just-in-Time | A least-privileged, role and attribute-based, and just-in-time security authorization model is used and persistently reviewed for all user and non-user accounts and services. | No | Required |
| Identity and Access Management | KSI-IAM-SNU Securing Non-User Authentication | Appropriately secure authentication methods are used and persistently reviewed for non-user accounts and services. | No | Required |
| Identity and Access Management | KSI-IAM-SUS Responding to Suspicious Activity | Accounts with privileged access are disabled or otherwise secured in response to suspicious activity. | No | Required |
| Incident Response | KSI-INR-AAR Generating After Action Reports | Incident after action reports are generated and lessons learned are persistently incorporated. | No | Required |
| Incident Response | KSI-INR-RIR Reviewing Incident Response Procedures | The effectiveness of documented incident response procedures is persistently reviewed. | Yes | Required |
| Incident Response | KSI-INR-RPI Reviewing Past Incidents | Past incidents are persistently reviewed for patterns or vulnerabilities that were not previously apparent or identified. | No | Required |
| Monitoring, Logging, and Auditing | KSI-MLA-ALA Authorizing Log Access | A least-privileged, role and attribute-based, and just-in-time access authorization model is used and persistently reviewed for access to log data based on organizationally defined data sensitivity. | No | Optional |
| Monitoring, Logging, and Auditing | KSI-MLA-EVC Evaluating Configurations | The configuration of machine-based information resources, especially infrastructure as code, is persistently evaluated and tested. | No | Required |
| Monitoring, Logging, and Auditing | KSI-MLA-LET Logging Event Types | A list of information resources and event types that will be logged, monitored, and audited is maintained and persistently reviewed to ensure these activities occur. | No | Required |
| Monitoring, Logging, and Auditing | KSI-MLA-OSM Operating SIEM Capability | A Security Information and Event Management (SIEM) or similar system(s) is used and persistently reviewed for centralized, tamper-resistant logging of events, activities, and changes. | No | Required |
| Monitoring, Logging, and Auditing | KSI-MLA-RVL Reviewing Logs | Logs are persistently reviewed and audited. | No | Required |
| Policy and Inventory | KSI-PIY-GIV Generating Inventories | Authoritative sources are used to automatically generate real-time inventories of all information resources when needed. | No | Required |
| Policy and Inventory | KSI-PIY-RES Reviewing Executive Support | Executive support for achieving the provider's security goals is persistently reviewed and demonstrated. | No | Required |
| Policy and Inventory | KSI-PIY-RIS Reviewing Investments in Security | The effectiveness of the provider's investments in achieving security goals is persistently reviewed. | No | Required |
| Policy and Inventory | KSI-PIY-RSD Reviewing Security in the SDLC | The effectiveness of building security and privacy considerations into the Software Development Lifecycle and aligning with CISA Secure By Design principles is persistently reviewed. | No | Required |
| Policy and Inventory | KSI-PIY-RVD Reviewing Vulnerability Disclosures | The effectiveness of the provider's vulnerability disclosure program is persistently reviewed. | No | Required |
| Recovery Planning | KSI-RPL-ABO Aligning Backups with Objectives | The alignment of machine-based information resource backups with defined recovery objectives is persistently reviewed. | No | Required |
| Recovery Planning | KSI-RPL-ARP Aligning Recovery Plan | The alignment of recovery plans with defined recovery objectives is persistently reviewed. | No | Required |
| Recovery Planning | KSI-RPL-RRO Reviewing Recovery Objectives | The desired Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are defined and persistently reviewed for alignment with the provider's business needs and capabilities. | No | Required |
| Recovery Planning | KSI-RPL-TRC Testing Recovery Capabilities | The capability to recover from incidents and contingencies aligned with defined recovery objectives is persistently tested. | No | Required |
| Supply Chain Risk | KSI-SCR-MIT Mitigating Supply Chain Risk | Persistently identify, review, and mitigate potential supply chain risks. | No | Required |
| Supply Chain Risk | KSI-SCR-MON Monitoring Supply Chain Risk | Third party software information resources are automatically monitored for upstream vulnerabilities using mechanisms that may include contractual notification requirements or active monitoring services. | No | Required |
| Service Configuration | KSI-SVC-ACM Automating Configuration Management | The configuration of machine-based information resources is managed using automation and persistently reviewed for drift. | No | Required |
| Service Configuration | KSI-SVC-ASM Automating Secret Management | Management, protection, and regular rotation of digital keys, certificates, and other secrets is automated and persistently reviewed. | No | Required |
| Service Configuration | KSI-SVC-EIS Evaluating and Improving Security | Information resources are persistently evaluated for opportunities to improve security and those improvements are persistently made. | No | Required |
| Service Configuration | KSI-SVC-PRR Preventing Residual Risk | Plans, procedures, and the state of information resources are persistently reviewed after making changes to limit and remove unwanted residual elements that would likely negatively affect the confidentiality, integrity, or availability of federal customer data. | No | Optional |
| Service Configuration | KSI-SVC-RUD Removing Unwanted Data | Unwanted federal customer data is removed promptly when requested by an agency in alignment with customer agreements, including from backups if appropriate; this typically applies when a customer spills information or when a customer seeks to remove information from a service due to a change in usage. | No | Optional |
| Service Configuration | KSI-SVC-SIN Securing Information | Information is encrypted or otherwise secured from unwanted access or modification. | Yes | Required |
| Service Configuration | KSI-SVC-VCM Validating Communications | The authenticity and integrity of communications between machine-based information resources is persistently validated using automation. | No | Optional |
| Service Configuration | KSI-SVC-VRI Validating Resource Integrity | Use cryptographic methods to validate the integrity of machine-based information resources. | No | Required |
What changes from Rev 5
Rev 5 and 20x expect similar security. They differ in what counts as proof, who reviews it, and how often it moves. The table compares the legacy Rev 5 process most current providers went through with 20x under CR26.
| Area | Legacy Rev 5 | FedRAMP 20x under CR26 |
|---|---|---|
| Basis | NIST SP 800-53 Rev 5 baselines of 156 controls at Low, 323 at Moderate, and 410 at High | 46 KSIs (7 for Class A) plus more than 150 provider rules for Class B and C, with 800-53 mappings kept for reference |
| Core document | System Security Plan and appendices in Word and Excel templates | Certification Package Overview and Security Decision Record, human-readable and JSON |
| Evidence | Narratives and screenshots gathered for a point-in-time test | Automated measurements with history, and an assessor who tests the code producing them |
| Sponsor | Agency sponsor completing an ATO first | None; FedRAMP issues a Program Certification |
| Assessor | Independent assessment required, usually by a 3PAO | FedRAMP Recognized assessor required for Class B and C, optional for Class A |
| Where the package lives | USDA Connect for Low and Moderate packages; the provider's own repository for High | Your FedRAMP-compatible trust center with programmatic access |
| Monitoring | Monthly continuous monitoring uploads of scans, POA&M, and inventory | Ongoing Certification: machine-based resources validated every 7 days (Class B) or 3 days (Class C), monthly vulnerability reports, quarterly reports and reviews |
| Weaknesses | POA&M items with remediation deadlines by severity | Remediation expectations by PAIN rating, reachability, and exploitability; accepted vulnerabilities after 192 days |
| Changes | Significant change requests approved in advance | Notification framework for routine recurring, adaptive, and transformative changes |
| Encryption | FIPS 140 validated modules assumed for federal data | Modules documented per service; validated modules optional for Class B and recommended for Class C |
| FedRAMP review time | Could take a year or more, as FedRAMP acknowledges | 30-day goal for an initial decision |
| Open to new applicants | Until June 11, 2027 | Class A since August 3, 2026; Class B and C since August 31, 2026 |
Rev 5 does not stand still under CR26. FedRAMP calls it a legacy type that “will be retired,” and it applies the same modernization to it: JSON packages in place of Word and Excel templates, most FedRAMP-defined organizational parameters removed so providers set their own values, FIPS 140 expected only where data is sensitive, vulnerability detection “scaled widely beyond traditional monthly vulnerability scanning,” and POA&Ms eliminated in favor of a list of accepted weaknesses. The CR26 Rev5 baselines list 155 controls for Class B, 322 for Class C, and 409 for Class D, each documented in a Security Decision Record.
If you already hold a Rev 5 certification
Existing Rev 5 certifications remain active until at least December 31, 2028, unless FedRAMP is directed otherwise, but the rules under them change on a schedule, and FedRAMP warns that providers who do not adjust “will lose their FedRAMP Certification.” Grace periods are hard deadlines with no extensions. A provider that misses one loses its certification with public notice and can regain it by following the rules.
| Date | What happens | Who it affects |
|---|---|---|
| July 4, 2026 | CR26 in effect; new 20x applications must follow it; optional early adoption begins for most Rev5 rulesets | All providers |
| July 28, 2026 | FedRAMP Ready closes to new submissions; FedRAMP points new entrants to 20x Class A | Ready applicants |
| August 10, 2026 | Lost Sponsor and Ready Conversion pipelines open for a Rev5 Class B or C Program Certification | Providers that lost a sponsor, completed a readiness assessment, or reached Ready between January 2025 and March 2026 |
| November 17, 2026 | FedRAMP Ready listings must convert to a certification, or at annual assessment expiration if that is later | FedRAMP Ready |
| December 7, 2026 | VDR and VER rulesets required to obtain a certification, and to keep one without a corrective action plan, under CISA BOD 26-04; grace ends March 7, 2027 | Class B, C, and D providers, Rev5 and 20x |
| January 1, 2027 | CR26 mandatory for new Rev5 applications; most rulesets must be followed or a corrective action plan is required | All providers |
| June 1, 2027 | Grace ends for the Rev5 cryptography, incident, and significant change rulesets | Rev5 |
| June 11, 2027 | FedRAMP stops accepting new Rev5 applications, and the Lost Sponsor and Ready Conversion pipelines close | New Rev5 applicants |
| August 1, 2027 | Rev5 Certification Data Sharing and Security Decision Record rules required to maintain certification | Rev5 |
| October 1, 2027 | Grace ends for Rev5 Collaborative Continuous Monitoring | Rev5 |
| December 31, 2027 | Legacy FedRAMP Ready status removed entirely | FedRAMP Ready |
| February 1, 2028 | All CR26 grace periods expire | All providers |
| December 31, 2028 | CR26 practices expire and must be replaced by a later release; existing Rev5 certifications active until at least this date | All providers |
The next deadline is December 7, 2026, when the Vulnerability Detection and Response (VDR) and Vulnerability Evaluation and Reporting (VER) rulesets become required for every Class B, C, and D provider, Rev5 and 20x, under CISA Binding Operational Directive 26-04. A certified provider that has not adopted them by then needs a corrective action plan, and FedRAMP revokes certification if they are not in place by March 7, 2027. Class A providers must follow VDR-CSO-DET, and FedRAMP recommends the timeframe rules. Every detected vulnerability needs an evaluation of exploitability and internet reachability and a Potential Agency Impact N-rating (PAIN), from N1, minimal effects on agency customers, to N5, a debilitating effect on more than one agency. FedRAMP's remediation expectations run on those three facts. The table shows the number of days after evaluation within which FedRAMP expects partial mitigation, full mitigation, or remediation to a lower rating (VDR-TFR-PVR), for Class B and Class C.
| PAIN rating | Internet-reachable and likely exploitable (B / C) | Not internet-reachable, likely exploitable (B / C) | Not likely exploitable (B / C) |
|---|---|---|---|
| N5 | 4 / 2 days | 8 / 4 days | 32 / 16 days |
| N4 | 8 / 4 days | 32 / 8 days | 64 / 64 days |
| N3 | 32 / 16 days | 64 / 32 days | 192 / 128 days |
| N2 | 96 / 48 days | 160 / 128 days | 192 / 192 days |
N1 carries no timeframe. FedRAMP expects Known Exploited Vulnerabilities to be remediated by the due dates in CISA's KEV catalog even after full mitigation (VDR-TFR-KEV), and any vulnerability not fully mitigated or remediated within 192 days of evaluation must be categorized as an accepted vulnerability (VER-TFR-MAV).
For a Rev 5 provider, the decision is sequencing. The CR26 changes to Rev 5 are mandatory either way, and several of them are the same capabilities 20x requires: JSON packages, delivery through a trust center, persistent vulnerability detection, accepted-vulnerability reporting, and notification-based change management. Build them once to the 20x standard, and a later move to 20x reuses them. Three details matter. A Rev 5 certification or FedRAMP Ready status completed within the past 12 months satisfies the prerequisite for a 20x Class A Certification (FRC-CLA-ASF), so a Rev 5 Agency Certification holder can pursue Class A without a new independent assessment when an agency wants a Program Certification. You cannot hold Rev 5 and 20x Program Certifications for the same offering, and FedRAMP allows a Rev 5 Agency Certification alongside a 20x Program Certification but strongly discourages it (FRC-CSO-POP). And if the offering runs on your own infrastructure or needs Class D, Rev 5 is currently the only option; FedRAMP expects to offer 20x Class D in early 2027.
What FedRAMP 20x costs and how long it takes
FedRAMP's review is the fast part. Its goal is 30 days, and the first two Class A Certifications moved from In Process to Certified in 19 and 17 days. Preparation sets the calendar and the budget, and three things drive both: how much of your security program already produces measurable, automatable evidence; how many services and third-party resources sit inside the Minimum Assessment Scope; and the class. The largest cost for most providers is internal engineering time to build validations and reporting. Workstreet calls engineering and development “the biggest cost,” and the ranges below cover only external spend on the assessment and readiness work.
We recommend budgeting 1.5 to 2 times the published estimates for this work, and the table applies that multiplier. Where you land within each range depends on the size of the business.
| Profile | Preparation time | Independent assessment | Readiness and advisory | First-year external spend |
|---|---|---|---|---|
| 20x Class A | 90 to 120 days from a SOC 2 baseline | Optional; $60,000 to $100,000 when used | $75,000 to $100,000 | $135,000 to $200,000, including an assessment |
| 20x Class B | No estimate in the cited sources; longer than Class A because 41 KSIs are required | $75,000 to $120,000 | $115,000 to $150,000 | $190,000 to $270,000 |
| 20x Class C | No estimate in the cited sources; longer than Class B, with all 46 KSIs and at least 2 automated methods for each | $90,000 to $140,000 | $165,000 to $260,000 | $255,000 to $400,000 |
| Rev5, legacy Moderate for comparison | 12 to 18 months | $225,000 to $600,000 or more | $75,000 to $300,000 for the gap assessment alone | $375,000 to $1.5 million, and above $2 million for some large offerings |
A provider with one product, a small engineering team, one production environment, and a current SOC 2 Type II report should plan near the low end. Costs rise with the number of people and accounts your identity and access measures have to cover, with the number of services, environments, and third-party resources inside the Minimum Assessment Scope, and with the number of engineering teams whose pipelines have to produce evidence. A company with several product lines or hundreds of engineers should plan at the top of the range, and the largest offerings can exceed it.
The published estimates behind these ranges are Workstreet's August 2026 estimate for the 20x rows, which describes a provider starting from a SOC 2 baseline, and Secureframe, which cites Coalfire and Schellman, together with Workstreet for the Rev 5 row. Workstreet is a FedRAMP Marketplace-listed advisor. Budget for tooling on its own line: a trust center with API access, a GRC platform that can generate JSON, identity and endpoint tiers that expose the data your validations need, and penetration testing, which VDR-CSO-DET names as an example detection technique.
Choosing the independent assessor
We recommend Schellman for the independent assessment, and the public record supports it. In FedRAMP's Marketplace data as of September 23, 2026, Schellman is the independent assessor of record for 144 of the 532 FedRAMP Authorized offerings, about 27 percent and well ahead of Coalfire at 81. Of the 28 20x Low and Moderate authorizations in the same data, Schellman assessed 6, more than any other assessor, including OpenAI's ChatGPT Enterprise and API Platform at 20x Moderate, both of Vanta's 20x offerings, Drata, Spectro Cloud, and Anecdotes. Schellman has been accredited since July 2012, announced in April 2026 that it had become the first assessor to reach 200 assessed offerings on the FedRAMP Marketplace, and states in its Marketplace listing that it “only performs assessment services, and no consulting services.” That last point matters, because the firm testing your KSIs has no stake in how they were built.
One rule and one FedRAMP recommendation shape the choice. An assessor may not assess an offering within two years of providing advisory or consulting services for it (REC-IAS-SEP), so your advisor and your assessor should be different firms from the start. FedRAMP also calls it good practice to interview several FedRAMP Recognized assessors and get proposals from at least two or three, and it warns separately that recognition and the A2LA requirements behind it set “a minimum bar” and that neither reviews technical expertise in depth. Ask each firm how it tests automated validations, whether its team can review your validation code and query your APIs, and which 20x assessments it has completed. Schellman answers those questions with a track record. Get the other proposals anyway, as FedRAMP advises.
Frequently asked questions
What is FedRAMP 20x? FedRAMP 20x is the cloud-native FedRAMP Certification type under the Consolidated Rules for 2026. Providers prove Key Security Indicators with automated, machine-readable evidence and receive a Program Certification directly from FedRAMP. It is designed for services built on FedRAMP Certified infrastructure or platforms.
Does FedRAMP 20x require an agency sponsor? No. Every 20x certification is a Program Certification issued by FedRAMP, so no agency sponsor or prior ATO is required. Each agency still issues its own Authorization to Operate before it uses your service.
How long does FedRAMP 20x take? FedRAMP's goal is an initial decision within 30 days of receiving an application, and the first two Class A Certifications moved from In Process to Certified in 19 and 17 days in August 2026. Preparation takes longer: a published estimate puts Class A readiness at 90 to 120 days from a SOC 2 Type II baseline, and Class B and C take longer because 41 or all 46 indicators apply.
What is the difference between FedRAMP 20x and Rev 5? Rev 5 certifies a documented implementation of NIST SP 800-53 baselines and usually requires an agency sponsor. 20x certifies measured outcomes against Key Security Indicators, uses JSON packages shared through a trust center, and requires no sponsor. FedRAMP stops accepting new Rev 5 applications on June 11, 2027.
Do I need a 3PAO for FedRAMP 20x? Class B and Class C require an independent assessment by a FedRAMP Recognized assessor, the current term for a 3PAO, completed within three months before you apply. Class A makes the assessment optional because it relies on a SOC 2 Type II, GovRAMP, or Rev 5 assessment from the past 12 months.
How many Key Security Indicators are there? The Consolidated Rules for 2026 define 46 Key Security Indicators across 10 themes. Class A requires 7, Class B requires 41 and makes 5 optional, and Class C requires all 46.
Is OSCAL required for FedRAMP 20x? No. 20x requires JSON documents that validate against FedRAMP's published schemas, such as the Security Decision Record and Certification Package Overview schemas. FedRAMP describes OSCAL as optional in some Rev 5 cases.
Can a Rev 5 provider move to FedRAMP 20x? Yes, and FedRAMP asks Rev 5 providers to plan the move. A Rev 5 certification assessed in the past 12 months satisfies the prerequisite for 20x Class A, existing Rev 5 certifications stay active until at least December 31, 2028, and many of the CR26 changes Rev 5 providers must make by February 1, 2028 are capabilities 20x also requires.
Where BD Emerson fits
BD Emerson advises cloud service providers on FedRAMP. We are not a FedRAMP Recognized assessor, and we do not perform the assessment that results in your certification. FedRAMP defines an advisor as an entity that helps a provider prepare “without replacing the provider's responsibility or the assessor's independence,” and it warns that an advisor who claims to produce your artifacts and meet ongoing requirements on your behalf misrepresents the program. We work within that line. Our FedRAMP 20x readiness team helps you choose the profile, draws the Minimum Assessment Scope with your architects, designs KSI measures and failure conditions with your engineers, reviews the validation code and the JSON your pipelines generate, and helps your team put VDR and VER reporting in place ahead of December 7, 2026. Your team owns and runs the program, and we test it before the assessor and FedRAMP see it.
If you plan to use a SOC 2 Type II as your Class A prerequisite, our SOC 2 readiness practice can prepare you for the examination. For the testing that feeds vulnerability detection, see FedRAMP penetration testing. The FedRAMP 20x KSI workbook (Excel) lists all 46 indicators with their official statements, class requirements, and control mappings, with columns for owner, data source, automated methods, cadence, and failure condition, plus the ongoing cadence by class and the sample Security Decision Record. For the Rev 5 requirements under the 2026 rules, see FedRAMP requirements explained. When you want a second set of eyes on your profile or your first KSI designs, talk to us.
Acronyms and definitions
This section defines every acronym in this guide. FedRAMP terms follow the definitions in the Consolidated Rules for 2026, and the ruleset names come from FedRAMP's rules dataset.
| Term | Meaning |
|---|---|
| 3PAO | Third Party Assessment Organization. The legacy name for a FedRAMP Recognized assessor, the independent firm that assesses a cloud service for FedRAMP. |
| A2LA | American Association for Laboratory Accreditation. The body that accredits assessment firms; A2LA accreditation is a requirement for FedRAMP Recognition. |
| AFC | Addressing FedRAMP Communication. The ruleset, formerly the FedRAMP Security Inbox, that sets how FedRAMP reaches your security staff and how fast you respond to urgent messages. |
| AGU | Agency Use of FedRAMP Certified Cloud Services. The ruleset that sets agency responsibilities under the FedRAMP Authorization Act and OMB Memorandum M-24-15. |
| AI | Artificial intelligence. |
| API | Application programming interface. A defined way for one system to request data from another, such as an agency tool pulling your certification data from a trust center. |
| ATO | Authorization to Operate. An agency's formal decision to use a system and accept its risk. FedRAMP certifies the cloud service, and each agency still issues its own ATO. |
| AWS | Amazon Web Services. |
| BOD | Binding Operational Directive. A compulsory CISA directive to federal agencies. The VDR and VER rulesets are mandated under BOD 26-04 from December 7, 2026. |
| CCM | Collaborative Continuous Monitoring. The ruleset for Ongoing Certification Reports and Quarterly Reviews, which agencies use in their own continuous monitoring. |
| CDS | Certification Data Sharing. The ruleset for storing and sharing certification data through a FedRAMP-compatible trust center. |
| CISA | Cybersecurity and Infrastructure Security Agency. The Department of Homeland Security agency that issues binding operational directives and maintains the KEV catalog. |
| CMMC | Cybersecurity Maturity Model Certification. The Department of War program that verifies how defense contractors protect sensitive contract information. |
| CMU | Cryptographic Module Use. The ruleset for choosing and documenting cryptographic modules, which encourages validated modules wherever they are feasible. |
| CPO | Certification Package Overview. The human-readable and JSON overview of your offering that, with the Security Decision Record, replaces the System Security Plan. It is also the name of its ruleset. |
| CR26 | Consolidated Rules for 2026. The FedRAMP rules that took effect on July 4, 2026, for both Rev 5 and 20x. |
| DFARS | Defense Federal Acquisition Regulation Supplement. Its clause 252.204-7012 sets cybersecurity requirements for defense contractors, including cloud services that handle covered defense information. |
| ET | Eastern Time. FedRAMP states its default emergency response deadlines in Eastern Time. |
| FedRAMP | Federal Risk and Authorization Management Program. The GSA program that certifies cloud services for use by federal agencies. |
| FIDO2 | An authentication standard from the FIDO (Fast IDentity Online) Alliance for phishing-resistant, passwordless sign-in with security keys and passkeys. |
| FIPS 140 | Federal Information Processing Standard 140. The NIST standard that cryptographic modules are validated against. |
| FRC | FedRAMP Certification. The ruleset that explains how an offering obtains and maintains certification across classes and paths. |
| GovRAMP | A cybersecurity verification program for cloud services used by state and local governments. A GovRAMP verification at any impact level completed in the past 12 months satisfies the 20x Class A prerequisite. |
| GRC | Governance, risk, and compliance. The category of platforms that track controls, evidence, and risks, including tools that generate your JSON package. |
| GSA | General Services Administration. The federal agency that runs FedRAMP. |
| ID | Identifier, as in a rule ID or a KSI ID. |
| IEC | Incident Evaluation and Communication. The ruleset for reporting incidents to FedRAMP and agency customers. |
| IVV | Independent Verification and Validation. The ruleset for independent assessments, including what each class must have assessed and how often. |
| JIT | Just-in-time. Access granted only when it is needed and removed afterward, as KSI-IAM-JIT describes. |
| JSON | JavaScript Object Notation. The machine-readable text format FedRAMP uses for 20x packages, reports, and its published schemas. |
| KEV | Known Exploited Vulnerabilities. CISA's catalog of vulnerabilities with evidence of active exploitation, each with a remediation due date for federal agencies. |
| KSI | Key Security Indicator. One of the 46 security outcomes, grouped in 10 themes, that a 20x provider proves with automated, machine-readable evidence. |
| MAS | Minimum Assessment Scope. Every information resource likely to handle federal customer data or affect its confidentiality, integrity, or availability. It replaces the legacy authorization boundary and is also the name of its ruleset. |
| MFA | Multi-factor authentication. Sign-in that requires more than one kind of proof of identity. KSI-IAM-APM calls for phishing-resistant MFA where passwordless methods are not feasible. |
| MKT | Marketplace Listing. The ruleset that decides which offerings, assessors, and advisors FedRAMP lists in the Marketplace. |
| NIST | National Institute of Standards and Technology. The Commerce Department agency that publishes SP 800-53, FIPS 140, and OSCAL. |
| OCR | Ongoing Certification Report. The report a certified provider supplies to agency customers every 3 months under the CCM rules. |
| OMB | Office of Management and Budget. Its Memorandum M-24-15 of July 25, 2024 sets current federal policy for FedRAMP. |
| OSCAL | Open Security Controls Assessment Language. NIST's machine-readable format for security plans and assessment results. Under CR26 it is optional for provider packages. |
| PAIN | Potential Agency Impact N-rating. The rating from N1 to N5 that VER requires for each vulnerability, estimating the harm to agency customers if it were exploited. |
| Portable Document Format. | |
| POA&M | Plan of Action and Milestones. The Rev 5 list of open weaknesses and remediation dates. CR26 replaces it with accepted-vulnerability reporting. |
| REC | FedRAMP Recognition of Independent Assessment Services. The ruleset assessors follow to earn and keep FedRAMP Recognition. |
| Rev 5 (Rev5) | Revision 5 of NIST SP 800-53. FedRAMP also uses the name for its legacy certification type, which documents SP 800-53 controls in a Security Decision Record. |
| RPO | Recovery Point Objective. The maximum amount of data, measured in time, a service can afford to lose in a disruption. |
| RTO | Recovery Time Objective. The maximum time a service can take to recover from a disruption. |
| SCG | Secure Configuration Guide. The ruleset requiring providers to explain the security impact of common settings so customers can configure the service securely. |
| SCN | Significant Change Notification. The ruleset that sorts changes into routine recurring, adaptive, or transformative and sets when you notify agencies and FedRAMP. |
| SDLC | Software development lifecycle. The stages of planning, building, testing, releasing, and maintaining software. |
| SDR | Security Decision Record. The persistently maintained record of your security decisions, including implementation rationale, customer risk, assessment findings, and supporting artifacts. It replaces the System Security Plan and is also the name of its ruleset. |
| SIEM | Security information and event management. A system that collects and correlates security logs across an environment. |
| SOC 2 | System and Organization Controls 2. An independent auditor's report on a service organization's security controls. A Type II report covers how the controls operated over a review period, and one completed in the past 12 months satisfies the 20x Class A prerequisite. |
| SP | Special Publication. NIST's document series; SP 800-53 is the catalog of security and privacy controls behind the Rev 5 baselines. |
| SSP | System Security Plan. The Rev 5 document that narrated how each control was implemented. CR26 replaces it with the Certification Package Overview and the Security Decision Record. |
| UEI | Unique Entity Identifier. The 12-character identifier the federal government assigns to organizations registered to do business with it. |
| URI | Uniform Resource Identifier. A string that identifies a resource, such as a link to a piece of evidence. |
| USDA | U.S. Department of Agriculture. USDA Connect is the repository that holds legacy Rev 5 Low and Moderate packages. |
| VDR | Vulnerability Detection and Response. The ruleset requiring providers to find, prioritize, mitigate, and remediate vulnerabilities through automated systems on FedRAMP timeframes. |
| VER | Vulnerability Evaluation and Reporting. The ruleset for deciding whether each vulnerability is likely to affect federal customers and reporting its status. |
Codes inside rule IDs and KSI IDs
A FedRAMP rule ID has three parts. The first names the ruleset, the second names the section of that ruleset, and the third is a short label for the individual rule. In VDR-TFR-MVX, VDR is Vulnerability Detection and Response, TFR is its Timeframes section, and MVX is the rule for persistent machine verification and validation on 20x. KSI IDs follow the same pattern: KSI-IAM-JIT is the Authorizing Just-in-Time indicator in the Identity and Access Management theme. The ruleset codes are defined in the table above, and the section and theme codes are below.
| Code | Used in | Meaning |
|---|---|---|
| AGC | AGU-AGC | General Agency Responsibilities |
| APP | FRC-APP | Applying for FedRAMP Certification |
| CED | KSI-CED | Cybersecurity Education theme, 1 indicator |
| CLA | FRC-CLA | FedRAMP Class A Certification Rules |
| CMT | KSI-CMT | Change Management theme, 4 indicators |
| CNA | KSI-CNA | Cloud Native Architecture theme, 8 indicators |
| CSO | For example, FRC-CSO | General Provider Responsibilities, which apply to every provider |
| CSX | For example, FRC-CSX | 20x-Specific Provider Responsibilities |
| EVA | VER-EVA | Evaluation |
| FRP | For example, AFC-FRP | FedRAMP Responsibilities, the rules FedRAMP itself follows |
| IAM | KSI-IAM | Identity and Access Management theme, 6 indicators |
| IAS | REC-IAS | Independent Assessor Responsibilities |
| IIP | MKT-IIP | Initial Implementation Phase listings in the Marketplace |
| INR | KSI-INR | Incident Response theme, 3 indicators |
| MLA | KSI-MLA | Monitoring, Logging, and Auditing theme, 5 indicators |
| OCR | CCM-OCR | Ongoing Certification Reports |
| PIY | KSI-PIY | Policy and Inventory theme, 5 indicators |
| QTR | CCM-QTR | Quarterly Reviews |
| RPL | KSI-RPL | Recovery Planning theme, 4 indicators |
| RPT | VER-RPT | Reporting |
| SCR | KSI-SCR | Supply Chain Risk theme, 2 indicators |
| SVC | KSI-SVC | Service Configuration theme, 8 indicators |
| TFR | VDR-TFR, VER-TFR | Timeframes |
| TRC | CDS-TRC | FedRAMP-Compatible Trust Centers |
| TRF | SCN-TRF | Transformative Changes |
| USE | AGU-USE | Use of FedRAMP Certifications |
FedRAMP primary sources
| Source | What it covers |
|---|---|
| FedRAMP Consolidated Rules for 2026 | The rules, definitions, timelines, and guidance for providers, agencies, assessors, and advisors |
| FedRAMP/rules on GitHub | The machine-readable source of truth for every rule, definition, and KSI |
| FedRAMP/schemas on GitHub | JSON schemas for the Certification Package Overview, Security Decision Record, reports, and notifications |
| Key Security Indicators | Official KSI statements and related controls |
| FedRAMP Certification rules for 20x | Class A requirements, application rules, and KSI automation rules |
| Getting started for providers | Choosing an advisor, path, class, and type |
| Important dates | Adoption, pipeline, and retirement milestones |
| What's changing in 2026 | Terminology shifts and mandatory Rev 5 changes |
| Rev5 deadlines and 20x deadlines | Obtain, maintain, and grace dates for every ruleset |
| Approaching FedRAMP 20x assessments | How assessors are told to test KSIs and automated validations |
| FedRAMP 20x program page | Pilot phases and current status |
| FedRAMP Marketplace data | Certified offerings, assessors, and certification status history |

