By Cyber Defense Technologies July 21, 2026 5 min read
The Federal Risk and Authorization Management Program (FedRAMP) standardizes how federal agencies evaluate and authorize cloud products and services. For a cloud service provider that wants federal customers, a FedRAMP authorization, or certification in the program's newer terminology, is often the price of entry.
The program is in the middle of its most significant change since it began. FedRAMP 20x aims to replace much of the traditional, narrative-heavy approach with automated, continuously validated security evidence. In June 2026, FedRAMP published its Consolidated Rules for 2026 (CR26), bringing FedRAMP 20x and the rules for existing Rev5 holders into a single framework.
This article covers what is changing, what is not, and how to prepare. Because the program is evolving quickly, always confirm current requirements on fedramp.gov before committing to a plan.
What is changing
As published, the 2026 rules:
- Organize certifications into classes A through D, with increasing expectations, mapped roughly to the familiar impact levels. Class A corresponds to a new, time-limited pilot baseline; Class B to the Low and tailored low-impact SaaS baselines; Class C to Moderate; and Class D to High.
- Express requirements as Key Security Indicators (KSIs) that condense NIST SP 800-53 control narratives into outcomes that can be validated continuously, rather than long written descriptions.
- Set a transition timeline for Rev5. FedRAMP has said it will stop accepting new Rev5 certifications in June 2027, while Rev5 remains available for existing holders through at least the end of 2028.
The direction is clear: less time writing about controls, more time proving they work, with machine-readable evidence.
What is not changing
Some fundamentals hold regardless of the path:
- The boundary matters. You must define precisely what is being authorized, including every component, data flow and external service.
- Security engineering matters. Identity, encryption, logging, vulnerability management and configuration management must be implemented well, whatever the documentation format.
- Independent assessment matters. Third-party assessment organizations still validate your claims.
- Continuous monitoring matters. Certification is the start of an ongoing obligation.
Getting ready for FedRAMP
-
1
Decide
Confirm the federal market, the likely class of certification and the sponsoring path.
-
2
Define
Draw the authorization boundary and inventory every component and external service.
-
3
Close gaps
Implement required controls and indicators, and fix what a readiness review would flag.
-
4
Automate evidence
Build machine-readable, continuously validated evidence rather than static narratives.
-
5
Engage
Work with an assessor and prepare for ongoing monitoring after certification.
Readiness, step by step
1. Decide deliberately
Confirm there is real federal demand, identify the likely class based on the data your service will handle, and understand the sponsorship or authorization path available to you. FedRAMP is a significant investment; it should follow a market decision.
2. Draw the boundary
Inventory every component: compute, storage, databases, management tooling, identity, logging, CI/CD pipelines, and third-party services. Decide what is inside the boundary, and document how you rely on external services that are not.
3. Close the gaps
Assess your environment against the applicable requirements and indicators. Common gaps include:
- FIPS-validated cryptography not used everywhere it is required
- Multifactor authentication missing for some administrative paths
- Incomplete logging, or logs without review and alerting
- Vulnerability scanning that misses containers, images or infrastructure components
- Weak separation between customer environments, or between production and development
- Supply chain and third-party risk left undocumented
4. Automate the evidence
FedRAMP 20x rewards providers that can show, continuously and automatically, that controls work. Invest in configuration-as-code, policy-as-code, automated compliance checks and centralized logging. The same automation also makes continuous monitoring far less painful.
5. Engage early and honestly
Bring in an experienced assessor or advisor for a readiness review before a formal assessment. Findings in a readiness review are cheap; findings in a formal assessment are expensive.
Common mistakes
- Selling to agencies before readiness work begins
- Treating FedRAMP as a documentation exercise
- Underestimating the scope of shared services and tooling
- Ignoring continuous monitoring costs after certification
Building evidence you can automate
Traditional authorization packages describe controls in prose. The direction of FedRAMP 20x is to show, with data, that controls are in place and working. Providers can start building toward that now, regardless of which path they take:
- Infrastructure as code: define networks, compute, storage and identity policies in version-controlled templates, so the approved configuration is always known.
- Policy as code: express security rules, such as encryption required, public access denied and logging enabled, as automated checks that run continuously.
- Centralized logging: collect audit logs from every layer, including the control plane, and prove retention and review.
- Automated vulnerability management: scan hosts, containers, images and dependencies in the pipeline and in production, and track remediation automatically.
- Change evidence: connect deployments to approved changes, tests and security review.
These practices make certification easier, but they pay off long after it, in lower continuous monitoring cost and fewer surprises.
Frequently asked questions
How long does readiness take? It depends on the gap. Mature, well-engineered services may need months of documentation and evidence work; services that need significant architecture changes can take longer. A readiness assessment early is the only reliable way to estimate.
Should we wait for FedRAMP 20x to settle? Delaying rarely helps. The engineering needed, such as strong identity, encryption, logging, vulnerability management and configuration control, is the same under any path. Build it now and choose the path when you are ready to engage.
Does a commercial certification help? Existing programs such as SOC 2 or ISO/IEC 27001 can give you a head start on processes and evidence, but they do not substitute for FedRAMP requirements.
How CDT can help
CDT's FedRAMP readiness engagements help cloud providers define boundaries, close technical gaps and prepare evidence, drawing on our secure systems engineering and DevSecOps teams.