
A threat intelligence SaaS provider, acquired by a global payments company, wanted its platform certified for federal agencies. It already had a gap assessment from an earlier FedRAMP effort, with 46 findings scored against the Rev 5 Moderate baseline, and a remediation tracker from its new parent's security maturity program. Its compliance team was small, and its engineers worked across the United States and Europe. Then the FedRAMP Consolidated Rules for 2026 took effect in July 2026, and the company had to decide which path to take, which certification class to target, and what its existing findings still meant under the new rules.
We worked the decision through the rules. Under CR26, Rev 5 and FedRAMP 20x both produce a Certification Package Overview and a Security Decision Record, and the System Security Plan that drove most Rev 5 documentation cost no longer exists on either path. The documentation effort came out close on both paths, so price did not decide the question. Sponsorship and longevity did. Every 20x certification comes directly from FedRAMP without an agency sponsor, while Rev 5 eligibility without a sponsor depended on how the earlier assessment had been delivered, and FedRAMP stops accepting new Rev 5 applications on June 11, 2027. We recommended 20x at Class C, which covers most Low and Moderate impact systems and requires all 46 Key Security Indicators. Class A, which FedRAMP intends for pilots, testing, and negligible-risk data, would not carry the federal work the company wanted.
The earlier gap assessment was scored against rules that have since changed. We are re-scoring its 46 findings under CR26 so the company can see which ones still carry weight on the 20x path. We are also mapping the parent company's security maturity program against FedRAMP requirements, so evidence the company already produces for its parent counts toward certification instead of being collected twice. Several open items in that program are logging and monitoring gaps, and those have to close before any KSI measurement can produce history worth submitting.
Class C sets the engineering bar. Each of the 46 indicators needs at least two automated methods that verify and validate it, and the company has to supply at least six months of historical KSI metrics. For an independent assessment in the third quarter of 2027, the automated measurements have to be running by the end of the first quarter of 2027. That date sets everything upstream: the telemetry fixes, the automated checks, and an enclave design that keeps research infrastructure, which cannot sit inside a federal boundary, outside the certified offering.
The company's leadership has a recommendation it can defend to its parent: one path, one class, a target date, and the dependencies that set it. The program is modular, so the company stays inside its budget and keeps its existing vendors, and its parent's security program and the FedRAMP program draw on the same evidence. BD Emerson prepares companies for FedRAMP and does not perform the assessment. An independent FedRAMP Recognized assessor does.
Client details in this case study are generalized, and in places combined across engagements, to protect confidentiality. The program runs through our FedRAMP 20x readiness and FedRAMP compliance consulting practices, and our FedRAMP 20x guide covers the Key Security Indicators, the classes, and what changed from Rev 5. We are glad to walk through comparable work under NDA.