For modern cloud services supporting U.S. government missions, FedRAMP compliance is non-negotiable. This guide demystifies FedRAMP requirements, the certification journey, and what federal agencies expect from a cloud service provider seeking an Authorization to Operate (ATO).
You’ll learn how the federal risk and authorization management framework aligns with NIST 800-53 controls, what documentation and testing are required, and how to streamline the compliance process without compromising cloud security.
What Is FedRAMP? And Why Does It Matter?

FedRAMP, short for the Federal Risk and Authorization Management Program, standardizes information security for cloud computing across federal agencies. Established in law by the FedRAMP Authorization Act and overseen by the General Services Administration (GSA), the program establishes baseline security controls and an independent security assessment process to protect federal information at each impact level.
For cloud providers, achieving FedRAMP Certification opens the door to the FedRAMP Marketplace and agency adoption opportunities.
The Certification Landscape: FedRAMP 20x

The FedRAMP certification landscape has changed significantly in the past year. The legacy dual-path model, JAB Authorization and Agency Authorization, is no longer the framework you need to plan around.
The JAB has been rescinded. As directed by OMB Memorandum M-24-15, the Joint Authorization Board was eliminated, and all cloud services were consolidated under a single FedRAMP Authorized designation. As of July 2026, the verbiage changed from FedRAMP Authorized to FedRAMP Certified.
FedRAMP 20x is now the program’s official certification path. FedRAMP launched the Consolidated Rules for 2026 (CR26) on June 25, 2026, consolidating every 20x requirement into a single ruleset that becomes mandatory for all stakeholders on January 1, 2027.
Key differences from the legacy process:
- No agency sponsorship required. FedRAMP 20x does not require agency sponsorship and relies heavily on automated validation of security controls rather than manual documentation review.
- Key Security Indicators (KSIs) replace traditional control checklists, streamlining how compliance is demonstrated and assessed.
- Rev5 set to retire in June 2027. Rev5 is on a published retirement schedule. FedRAMP stops accepting new Rev5 applications on June 11, 2027, and existing Rev5 certifications sunset December 31, 2028 unless otherwise directed. Current Rev5 holders must adopt CR26 rules by January 1, 2027.
Where Things Stand Today (As of August 2026)
FedRAMP 20x is no longer a pilot program. In FedRAMP’s own words, it is now a widely available Certification path.
Here is the current state of each phase:
- Phase 1 (complete): The Low pilot ran April through September 2025. FedRAMP received 26 complete packages and completed 13 reviews during Phase 1, with the remaining reviews carrying into Phase 2 after the fall 2025 government shutdown.
- Phase 2 (complete): The Moderate pilot ran November 18, 2025 through March 2026, with 14 qualifying submissions. The first cohort received pilot certifications on March 6, 2026, and six additional providers had received them as of April 27, 2026.
- Phase 3 (active): Wide-scale adoption. CR26 published June 25, 2026. Marketplace listings for the Initial Implementation phase opened July 6. The Class A pipeline opened August 3, 2026. Class B and Class C pipelines open August 31, 2026.
- Phase 4 (next): The Class D pilot. FedRAMP’s July 30, 2026 update anticipates piloting Class D in late 2026 and making it a formal Certification option in early 2027. The published 20x roadmap still shows Phase 4 as FY27 Q1 to Q2. FedRAMP states that all future phase dates are estimates for public awareness, not firm commitments.
- Phase 5 (estimated FY27 Q3 to Q4): FedRAMP stops accepting new Rev5 Certifications on June 11, 2027 and publishes a transition path for existing Rev5 offerings.
Both Rev5 and 20x paths require accredited third-party assessment organizations (3PAOs) and rigorous evidence, but 20x is designed to compress timelines dramatically. Some participating providers achieved authorization in roughly three months during Phase 1, a meaningful shift compared to the 18+ months typical under legacy processes.
Don’t Wait for FedRAMP 20x If You Need FedRAMP High or DoD Impact Levels

FedRAMP 20x is a meaningful leap forward, but waiting for it could cost you deals today.
FedRAMP Class D (High) is not part of 20x’s immediate future. The current 20x phases cover Class A, B, and C impact levels only. A 20x Class D pilot is planned for Phase 4, estimated for FY27 Q1–Q2, and is specifically scoped to hyperscale IaaS and PaaS providers, not general availability for all cloud service offerings.
DoD Impact Levels run through DISA, not FedRAMP 20x. If your target customers include Department of Defense entities operating at IL2, IL4, IL5, or IL6, those authorizations are governed by the Defense Information Systems Agency (DISA) under the DoD Cloud Computing Security Requirements Guide (CC SRG), a separate framework from FedRAMP 20x entirely. Waiting for 20x to mature will not unlock DoD Impact Level opportunities.
The cost of waiting is real. We are hearing directly from prospects who are hesitant to move forward, assuming FedRAMP 20x will simplify or replace the work ahead. For High and DoD IL environments, that assumption is wrong, and every quarter spent waiting is a quarter your competitors are spending winning those contracts.
Core FedRAMP Requirements and Impact Levels
FedRAMP requirements map to NIST SP 800-53 Rev. 5 controls and scale by classes: Class A, B, C, and C. Class A is a new addition, while FedRAMP Classes B-D map to former FedRAMP levels Low through High.
Key artifacts continue to include:
- System Security Plan (SSP) and authorization package
- Control implementation details and security assessment evidence
- Plan of Actions and Milestones (POA&M)
- Continuous monitoring deliverables, including vulnerability management reporting
Under FedRAMP 20x, authorization packages are increasingly expected to be machine-readable. FedRAMP Rev5 providers will be required to produce machine-readable authorization packages, with an initial compliance deadline of September 30, 2026, and a hard final deadline of September 30, 2027, after which non-compliant Rev5 authorizations will be revoked, requiring providers to go through a completely new initial authorization process. This is not a soft deadline. Cloud providers should be actively planning for this requirement now.
The FedRAMP Certification Process in 2026
For Rev5 (Legacy Path):
- Scoping and categorization: Define the cloud service offering boundary, data types, and impact level, leveraging the new Minimum Assessment Scope (MAS) standard to simplify boundary guidance.
- Gap analysis: Map current security controls against FedRAMP Rev5 controls to identify gaps.
- Documentation and readiness: Develop the SSP and supporting documentation for 3PAO review.
- Independent testing: Undergo a 3PAO security assessment; results compiled into an assessment report and authorization package.
- Agency authorization: A sponsoring agency reviews and issues the ATO. (Note: JAB authorization no longer exists.)
- Continuous monitoring: Maintain compliance through monthly reporting, vulnerability remediation, and change management.
For FedRAMP 20x:
- Eligibility and scoping: Determine your target Certification Class and get a Marketplace listing, which CR26 requires before you can apply for certification.
- Key Security Indicator (KSI) mapping: Demonstrate compliance through automated, measurable security indicators rather than manual documentation.
- Automated validation: Security posture is validated continuously through automation rather than point-in-time assessment.
- Independent assessment: A FedRAMP Recognized independent assessment service validates your approach. Class B, C, and D require it; Class A may supply one.
- Certification: No agency sponsor required; FedRAMP issues certification directly based on validated KSIs.
- Persistent validation: Ongoing compliance is maintained through continuous automated monitoring rather than traditional periodic reporting cycles.
Tips for Meeting FedRAMP Requirements in 2026

- Understand which class and path apply to you. If you’re early in your FedRAMP journey, 20x is the path, and it is open now for Class A, with Class B and C opening August 31. If you need Class D or a DoD Impact Level authorization, do not wait for 20x. Class D is not yet available on the 20x roadmap, and DoD IL requirements flow through DISA under its own framework, so start on Rev5 now.
- Prepare for machine-readable packages now. Whether on Rev5 or 20x, machine-readable certification data is a core CR26 requirement, and your first independent assessment after January 1, 2027 is when the grace period ends.
- Inherit where possible. Leverage inherited controls from your infrastructure provider. Many cloud platforms provide pre-documented inheritance that reduces your control burden significantly.
- Automate evidence collection. Policy-as-code, CI/CD pipelines, and automated evidence collection reduce audit friction and are foundational to the 20x model.
- Monitor FedRAMP 20x actively. CR26 is the authoritative reference now, and FedRAMP maintains a public changelog, a GitHub discussion forum, and machine-readable rules in JSON. FedRAMP is also shifting intake from its shared inbox to structured forms, so bookmark help.fedramp.gov.
- Build a sustainable continuous monitoring cadence. Whether Rev5 or 20x, ongoing vulnerability management and reporting remain mandatory; 20x raises the bar by expecting persistent, automated validation rather than periodic snapshots.
How UberEther Accelerates ATO
UberEther offers two purpose-built paths to the federal market. ATO Advantage is built for organizations pursuing their own FedRAMP certification: a pre-configured, pre-accredited platform that inherits a significant portion of required controls, with automated documentation and white-glove coordination with 3PAOs and the FedRAMP PMO.
Express Advantage takes a different approach, operating as a FedRAMP as a Service model that lets ISVs leverage UberEther’s existing certifications to start selling to government customers in weeks rather than months, no ATO required.
Whether you need to move fast now or build a long-term federal foundation, UberEther has a path for you. The 20x pipelines are open today, not on the horizon, and we’re already helping clients navigate CR26, the Class A on-ramp, and the machine-readable package requirements that come with them.
Frequently Asked Questions
How long does FedRAMP Certification take in 2026?
It depends on the path. FedRAMP 20x is targeting certification timelines of approximately 4 to 9 months, and 9 to 14 months when starting from scratch.
What are FedRAMP Certification Classes, and how do they map to Low, Moderate, and High?
Certification Classes A through D replaced the Low, Moderate, and High impact level labels for FedRAMP certifications. Class B corresponds broadly to the old Low, Class C to Moderate, and Class D to High, with Class A as a new entry-level tier. But FedRAMP is emphatic that classes are not one-for-one replacements: a class describes how much assurance information a provider has committed to supplying, while an impact level describes the sensitivity of the agency’s own system. Agencies still categorize their systems under FIPS-199 and then decide whether a given offering fits.
Can I still get a Rev5 certification without an agency sponsor?
Temporarily, yes, if you qualify. FedRAMP opened two limited Rev5 Program Certification pipelines on August 10, 2026, Lost Sponsor and Ready Conversion, for eligible Class B and Class C providers. FedRAMP confirms eligibility individually after you submit the appropriate form.
Is the JAB authorization path still available?
No. The JAB was rescinded under OMB M-24-15. All certifications now flow through the Rev5 Agency path, the temporary Rev5 Program pipelines, or the new FedRAMP 20x process.
What happened to FedRAMP Ready?
It went legacy on July 28, 2026. No new submissions are accepted. Existing designations show as “Legacy FedRAMP Ready” on the Marketplace, and a completed Readiness Assessment Report can be submitted toward a 20x Class A Certification, which is the direct replacement.
What is FedRAMP 20x and when can I use it?
FedRAMP 20x is a modernized certification framework that replaces manual documentation reviews with automated validation using Key Security Indicators. It does not require agency sponsorship. It is available now: the Class A pipeline opened August 3, 2026, and Class B and Class C pipelines open August 31, 2026. Class D is still in development under Phase 4.
What ongoing activities are required after certification?
Continuous monitoring remains mandatory: monthly reporting, vulnerability remediation, configuration baselines, and change management. Under FedRAMP 20x, persistent automated validation replaces much of the traditional periodic reporting burden.
Does FedRAMP apply if I only process limited federal information?
Yes. Any federal information processed, stored, or transmitted by your cloud services can trigger FedRAMP applicability. Scope and impact level determine the depth of controls and testing required.
What if my provider already has strong NIST 800-53 controls?
You can inherit many platform-level controls. However, you must still document all cloud products and services used, implement any remaining FedRAMP controls, and provide proof through the assessment process; or, under 20x, through automated KSI validation.
Conclusion

FedRAMP compliance doesn’t have to stall your roadmap, and in 2026, the program has changed more in twelve months than in the previous twelve years. With the JAB gone, FedRAMP CR26 published, the pilots finished, and the 20x Class A pipeline already open with Class B and C days behind it, cloud providers who align now to the automation-first model will have a decisive advantage.
But modernization doesn’t mean everything is available. If your federal opportunities require a High-impact-capable certification or DoD Impact Level authorizations, those paths run through DISA and existing Rev5 frameworks today, and the agencies you’re selling to can’t afford to wait for a Class D pilot that hasn’t started.
By leveraging inherited security controls, automating evidence, and partnering with experts who track the CR26 ruleset and the 20x roadmap in real time, you can reach the FedRAMP Marketplace faster while meeting the evolving needs of federal agencies.
Ready to accelerate your FedRAMP certification? Talk to UberEther about ATO Advantage or Express Advantage today. Our platform and services are built for FedRAMP High and DoD IL5 environments, and we’re ready to help you navigate the transition to FedRAMP 20x so you can win more missions, faster.