- Choose your Certification Class (A–D).
- Map the Key Security Indicators (KSIs) to your service.
- Automate evidence collection into a machine-readable record.
- Get listed on the FedRAMP Marketplace and line up a recognized assessor.
- Build and submit your certification package.
- Maintain certification through continuous validation.
Unlike the legacy route, getting FedRAMP 20x certified is handled directly by the program, so there is no need to find a federal agency to sponsor you first.
What you will learn
- The six steps of the FedRAMP 20x certification process, in the order the work actually happens.
- How the Certification Classes A–D differ, and what the shorthand "Class C equals Moderate" gets right and wrong.
- What the Key Security Indicators are, including the seven mandatory for Class A, and what replaced the System Security Plan.
- Where the real time goes, how long the process takes by third-party estimates, and how continuous validation keeps a certification current.
What FedRAMP 20x Changes
If you already know FedRAMP, the fastest way to understand FedRAMP 20x is by what it removes. The long written control narratives are gone. In their place sit measurable Key Security Indicators (KSIs): outcomes you demonstrate with evidence rather than describe in prose. The rules that govern the FedRAMP 20x certification process are the FedRAMP Consolidated Rules for 2026, and they are already in force for new work: every new 20x application has had to follow them since July 4, 2026, and on January 1, 2027 they become mandatory across FedRAMP.
There are two ways into FedRAMP, and 20x is the one that changes the economics. Under Program Certification, FedRAMP certifies your service directly, with no agency sponsor required. Under Agency Certification (the legacy Rev5 route), a federal agency has to authorize and sponsor the service first. That route is being retired: FedRAMP will stop accepting new Rev5 Certifications on June 11, 2027.
20x is not a lighter version of the old process, it is a completely different approach, built around living, machine-readable proof instead of a point-in-time document. If you want the model before the path, our explainer of what FedRAMP 20x is covers the classes, the KSI validation model, and how 20x compares with Rev5. The rest of this guide walks the path in the order the work actually happens.
{{ banner-image }}
Step 1: Choose Your Certification Class (A–D)
FedRAMP 20x sorts services into Certification Classes by the kind of government use they are built for.
- Class A is the light entry tier: for cloud services with mature security and compliance programs entering the federal marketplace, and on the agency side adequate for pilots and negligible-risk use cases. It asks for a small amount of information up front.
- Class B is for common small-scale or light-use services that a whole agency is unlikely to lean on for important work.
- Class C is for common enterprise services likely to be used across an entire agency, or that provide important government services.
- Class D is not available yet. FedRAMP is developing it in Phase 4, with a Class D (High) pilot estimated for late 2026 into early 2027, timing FedRAMP itself flags as an estimate rather than a commitment.
One point is worth getting right. The classes are not renamed impact levels: FedRAMP warns that they signal the level of assurance provided and are not one-for-one replacements for Low, Moderate, or High. The lineage is real, though. Class B is the closest heir of the old Low baseline, Class C of Moderate; and Class A inherits nothing, a new tier rather than the old "FedRAMP Ready."
Where to start is the next call. Most providers entering the federal market should start at Class A and climb: Class A requires only a small amount of information in advance, FedRAMP's own classes page notes that many services with world-class security programs choose Class A or B, and the classes are designed to be climbed. Most enterprise SaaS providers ultimately need Class C, but unless an agency contract already requires that level of commitment, entering at Class A (or B) and climbing is the normal path.
The requirements themselves form a ladder, and the ladder is what makes the classes concrete:
{{travel-table-12="/guides-comp"}}
In development (Phase 4); High pilot estimated late 2026–early 2027
Source: FedRAMP Consolidated Rules for 2026. For the class-by-class detail, see FedRAMP's own guidance on choosing a Certification Class.
The table carries one practical implication. Because Class C requires at least six months of historical metrics, the clock on your evidence starts long before your application does. If Class C is the goal, the pipelines that produce that history need to be running well ahead of the submission.
Step 2: Map the Key Security Indicators (KSIs)
A Key Security Indicator is a measurable statement of a security outcome: something you demonstrate is working, backed by evidence, rather than a paragraph describing a control. In FedRAMP's framing, security controls define the protection required, and KSIs provide measurable validation that the protection is actually functioning in your live environment.
Under the Consolidated Rules for 2026, the KSI set spans ten themes, from cloud-native architecture and identity and access management to incident response, recovery planning, and change management. FedRAMP's Class B and Class C reference pages list the same 46 indicators: at Class C all 46 apply, while at Class B five of them are optional, leaving 41 required. (Older write-ups still cite the pilot-era counts of 56 KSIs at Low and 61 at Moderate; those are history, not the current ruleset.) For the full set, indicator by indicator with the evidence each one takes, see our FedRAMP 20x KSI checklist.
The shift from Rev5 is easiest to feel through one example. Under Rev5, a control asks you to describe your backup and contingency planning; the matching KSI asks you to prove, with machine-readable evidence, that backups align with your defined recovery objectives and that your ability to recover is persistently tested against them.
Every reader meets the same seven first, because FedRAMP names them as mandatory for a Class A certification. Start your mapping here:
KSI
What it proves (FedRAMP)
Typical evidence (illustrative)
KSI-CNA-RNT: Restricting Network Traffic
Machine-based information resources are persistently reviewed to ensure they are appropriately configured to limit inbound and outbound network traffic.
Security-group, firewall, and WAF configuration pulled from cloud infrastructure.
KSI-IAM-AAM: Automating Account Management
The lifecycle and privileges of all accounts, roles, and groups are securely managed using automation.
Identity-provider account and role data; joiner-mover-leaver automation logs.
KSI-IAM-APM: Adopting Passwordless Methods
Secure passwordless methods are used where feasible; otherwise strong passwords with phishing-resistant MFA.
MFA-enforcement and authentication-policy configuration from the identity provider.
KSI-CMT-LMC: Logging Changes
Modifications to the cloud service offering are logged and monitored.
Change-management tickets tied to audit and deployment logs.
KSI-INR-RIR: Reviewing Incident Response Procedures
The effectiveness of documented incident-response procedures is persistently reviewed.
Incident-response plan reviews, exercise records, and post-incident findings.
KSI-CED-RAT: Reviewing All Training
The effectiveness of cybersecurity education and training is persistently reviewed, including general, role-specific, secure-development, and IR/DR training.
Training-platform completion records mapped to roles.
KSI-SVC-SIN: Securing Information
Information is encrypted or otherwise secured from unwanted access or modification.
Encryption-at-rest and in-transit configuration; key-management settings.
The indicators and the "what it proves" statements are drawn from FedRAMP's Key Security Indicator definitions in the Consolidated Rules for 2026, condensed where needed for length. FedRAMP is deliberately non-prescriptive about the exact evidence for each KSI, so the third column is illustrative of common practice, not a FedRAMP requirement.
And the scope is the whole service: FedRAMP's guidance is that all KSIs should apply to everything inside your Minimum Assessment Scope, not to a convenient subset of it.
Step 3: Automate Evidence Collection
This is the step the whole model turns on, and it starts with a rename. The Security Decision Record (SDR) is what the old System Security Plan becomes. It is not a document you write once and revise occasionally; it is a persistently maintained, verified, and validated record of the security decisions you made and how each applicable FedRAMP rule is addressed.
Machine-readable is a rule here, not a preference. Where a FedRAMP rule ships with a JSON schema, you must supply that information as JSON that validates against the schema, and the SDR itself is supplied in both human-readable and JSON form. The point of 20x is that a reviewer can query your posture, not that they read your prose.
You will see a "70 percent of KSIs must be automated" figure circulating, including in earlier write-ups. Handle it carefully: that number comes from the Phase 2 pilot, where automated validation had to cover at least 70 percent of the Key Security Indicators. It does not appear in the Consolidated Rules for 2026, so treat it as pilot-era context, not a threshold you have to hit today. What the rules do require is that validation runs continuously rather than at a point in time, and that you keep reporting current: Ongoing Certification Reports are supplied every three months.
The time goes where teams least expect it. The hardest part is rarely the technical telemetry; cloud config and access data are usually the easy things to instrument. It is the policy approvals, governance workflows, and training records (the manual processes never designed to run continuously) that take longest. Start those first. They will not compress under deadline.
Step 4: Get Listed on the FedRAMP Marketplace and Engage an Assessor
There is a sequencing rule is often brushed over, but is critical to time. every provider must obtain an Initial Implementation Phase listing on the FedRAMP Marketplace before it can apply for certification. The request goes through FedRAMP's Marketplace Provider Listing Request Form; FedRAMP does not accept listing applications by email.
It requires you to:
- show the service is intended either for direct use by agency customers or for inclusion inside other services that agencies use;
- demonstrate continuous progress toward certification, documented on your trust center or website and updated at least quarterly;
- have an assessment for Class B, C, or D scheduled within two years of the initial listing, or FedRAMP removes the listing until you can show one is booked.
On assessors, the ground has shifted. Validation now runs through a FedRAMP-recognized assessor (the role formerly called a 3PAO), and FedRAMP recognition, not the legacy accreditation, is the bar. The relationship is also more collaborative than the old arm's-length audit: your assessor may advise you during the assessment. An independent assessment is required for a Class B, C, or D certification and optional for Class A, and when one is part of your package it must be recent, completed by your independent assessor within the previous three months.
One more rule: you must apply for certification yourself. A third party, including your assessor, cannot apply on your behalf, though they can help you prepare the materials.
Step 5: Build and Submit Your Certification Package
A complete certification package, per the rules, contains three things:
- an overview of the cloud service offering;
- implementation, validation, and assessment information for every relevant FedRAMP requirement, control, and KSI, carried in the Security Decision Record;
- a real or example Ongoing Certification Report.
The full contents and formats live in the FedRAMP 20x Certification Rules, and two points in them are worth internalizing before you submit. First, you stay accountable for the accuracy and completeness of everything in the package, even the parts an assessor, adviser, or external tool produced for you. Second, this is a choice you cannot hedge: you must not pursue both a Rev5 Program Certification and a 20x Program Certification for the same service. Pick one.
Step 6: Maintain Certification Through Continuous Validation
Certification is not an end state. Ongoing Certification Reports have to stay current, supplied every three months and carrying the target date of the next one, and your independent verification and validation continues on a recurring basis rather than stopping at the finish line.
This is where Step 3 pays off. The same pipelines that got you certified are the ones that keep you certified. A team that instrumented its controls as living data maintains the certification almost as a byproduct; a team that assembled the package by hand has to assemble it again every reporting cycle. Building the pipeline properly is the cheaper path, and it is cheaper the whole way down.
How Long It Takes
Duration figures for federal compliance vary widely and are often quoted without a source. The numbers below are only the ones we have checked, each named for where it comes from. No reliable end-to-end duration figure for a 20x certification exists yet, so the pilot recap and the legacy numbers are the closest anchors available.
For the legacy route, IDGA's beginner's guide to FedRAMP certification puts the authorization process at anywhere from 10 to 19 months: a preparation phase of 2–4 months, security package development of 3–7 months, third-party assessment of 2–4 months, and an authorization process of 3–4 months. Plan around the top of that range, not the bottom.
For 20x, the useful anchor is FedRAMP's own account of the 2025 pilot. The Phase 1 pilot ran from April through September 2025, and FedRAMP received 26 complete packages between May 30 and August 18, 2025, with the first cohorts receiving their pilot authorizations in late July. And for a sense of how new this all still is: at the time of writing, the FedRAMP Marketplace lists 529 certified cloud services in total (including nine in remediation), and just 28 of them are FedRAMP 20x Certified.
What We Learned Doing It Ourselves
We ran this path on our own platform. Anecdotes participated in the FedRAMP 20x pilot and became the first agentic GRC platform to achieve Class C (Moderate) certification on our own platform.
And we did not reach Class C on the first assessment. We landed at Class B, used the findings to improve the environment, validated again, and then achieved Moderate. That is the framework working as intended. A class is something you climb with evidence, not a pass/fail gate, and the climb is worth planning around rather than being surprised by.
If there is one thing to take from this, it is that FedRAMP 20x is won on machine-readable evidence, not paperwork. Instrument your controls as living data before you open the package at all. Submitting then becomes mostly a matter of pointing at proof you already have. That conviction is what we built into our FedRAMP 20x solution.
Frequently Asked Questions
What are the FedRAMP 20x classes?
Certification Classes A through D, defined by the kind of government use a service is built for: Class A is the light entry tier for providers with mature security and compliance programs entering the federal market, Class B covers common small-scale or light-use services, Class C covers enterprise services used across an agency, and Class D is still being developed in Phase 4. For most providers the practical choice is to enter at Class A and climb toward Class C, the class most enterprise SaaS ultimately needs. Class B is the closest heir of the old Low baseline and Class C of Moderate, a lineage rather than a rename; FedRAMP warns that the classes are not one-for-one replacements for the old impact levels.
Do you need an agency sponsor for FedRAMP 20x?
No. FedRAMP certifies 20x services directly through the Program Certification path, so you do not need a federal agency to sponsor you to begin. Agencies still decide which certified services they authorize and use; what disappears is the sponsorship gate at the start. The legacy Rev5 route (Agency Certification) works the other way around, with a federal agency authorizing and sponsoring the service first, and it stops accepting new certifications on June 11, 2027.
What replaced the SSP in FedRAMP 20x?
The Security Decision Record (SDR). It replaces the narrative System Security Plan with a living record of the security decisions behind your service and how each applicable FedRAMP rule is addressed, maintained, verified, and validated on an ongoing basis and supplied in both human-readable and machine-readable form.
What is a KSI in FedRAMP 20x?
A Key Security Indicator is a measurable, machine-checkable statement of a required security outcome: proof that a protection is working, validated with evidence rather than described in prose. 20x assesses your certification package against the KSI set instead of prose control narratives. For every indicator, grouped theme by theme with the evidence each takes, see our FedRAMP 20x KSI checklist.
Key Takeaways
- The path has six steps: choose a Certification Class, map the KSIs, automate evidence, list on the Marketplace and engage a recognized assessor, submit the package, and maintain it through continuous validation.
- 20x is certified directly by the program, with no agency sponsor, while the legacy Rev5 route stops accepting new certifications on June 11, 2027.
- Classes A–D are defined by intended government use. Class B is the closest heir of the old Low baseline and Class C of Moderate, a lineage rather than a rename; the normal path is to enter at Class A and climb toward Class C, the class most enterprise SaaS ultimately needs.
- The Security Decision Record replaces the SSP, and evidence is machine-readable proof validated continuously, which is the reason to instrument your controls as living data before you build the package.





