FedRAMP Requirements Explained: What You Actually Have to Do
FedRAMP requirements get described as a control list, which makes the program sound more tractable than it is. The controls are published and knowable. The parts that decide whether you get authorized are the impact level you choose, whether an agency will sponsor you, and whether you can sustain the monthly obligations after the certificate arrives.
Start with the impact level, because it sets everything else
FedRAMP baselines derive from FIPS 199 categorization: Low, Moderate, and High, plus the streamlined LI-SaaS path for low-impact software as a service. The level follows the sensitivity of the federal data your service will hold, and it determines control count, testing obligations, and cost.
Moderate is where the large majority of authorizations sit and where most agency demand is. High is for data whose loss would cause severe or catastrophic harm, and it carries meaningfully heavier ongoing obligations, including semiannual incident response plan testing where Moderate is annual. Choosing High to look impressive is an expensive way to slow yourself down; choosing Low when agencies need Moderate means redoing the work.
The sponsor is the real gate
New authorizations proceed through the Agency Authorization path: an agency sponsor reviews your package and issues the Authority to Operate. No sponsor, no authorization, regardless of how good your documentation is. This is the single most common reason FedRAMP programs stall, and it is a business development problem rather than a compliance one.
Practically, that means the sponsor conversation should start before the compliance spend, not after. Agencies sponsor services they already want to buy, so a warm procurement conversation is worth more to your FedRAMP timeline than another month of documentation.
What FedRAMP 20x changes, and when
FedRAMP 20x is the program's move toward automation, reuse, and continuous validation built on Key Security Indicators rather than static document packages. It is genuinely different in philosophy, and it is also not yet the default path.
As of mid-2026, the second pilot phase closed at the end of March and involved a small group of providers at the Moderate class. A wider launch of the 20x path is expected later in 2026 and is anticipated to cover Low and Moderate only. If you are pursuing High, the agency sponsorship path under Rev 5 remains your route. The sensible posture for most providers starting now is to build against Rev 5 while structuring evidence so it can be automated later, because 20x rewards machine-readable evidence and punishes prose.
The ongoing obligations people underestimate
Authorization is a beginning. Continuous monitoring requires monthly vulnerability scanning and monthly deliverables to your sponsoring agency, plus POA&M management for anything unresolved. Annual activities include a penetration test and, at Moderate and High, a red team exercise under control CA-8(2), along with static code analysis. Incident response plan testing is annual at Moderate and semiannual at High.
The penetration test is prescriptive rather than open-ended: the FedRAMP Penetration Test Guidance defines six mandatory attack vectors covering External to Corporate including a phishing campaign, External to CSP Target System, Tenant to CSP Management System, Tenant to Tenant, Mobile Application to Target System, and Client-side Application or Agents to Target System. The red team exercise is a separate obligation with its own plan and report, and it is enterprise focused rather than confined to the authorization boundary, which we cover in the FedRAMP red team requirement.
Budget for this operating load as a permanent line item. Programs that treat authorization as a project and monitoring as an afterthought are the ones that lose their ATO.
How the moving parts fit together
You categorize the system and define the authorization boundary. You implement the baseline controls and document them in a System Security Plan. A 3PAO independently assesses and produces a Security Assessment Report. Your sponsoring agency reviews the package and issues the ATO. Then continuous monitoring runs indefinitely, with annual testing revalidating what was assessed.
The boundary definition deserves more attention than it usually gets. It determines what gets assessed, what your 3PAO tests, and how much of your infrastructure falls inside scope. Boundaries drawn loosely to avoid hard conversations tend to produce those conversations later, with a reviewer.
Realistic expectations
For most providers, expect the better part of a year for a Moderate authorization once a sponsor is secured, and longer if you are also remediating gaps found in readiness. The compliance work is predictable. The sponsor timeline is not, because it depends on an agency's procurement calendar rather than yours.
Where BD Emerson fits
We run FedRAMP advisory from categorization and boundary definition through SSP development, readiness, and continuous monitoring, and we perform the offensive testing obligations directly through FedRAMP penetration testing and CA-8(2) red team exercises. Because the exercise may be performed by a party other than your attesting 3PAO, using us keeps testing and attestation in separate hands. If NIST 800-171 or CMMC also apply to you, NIST compliance consulting shares much of the same control work.
