Framework module · fedramp-20x
FedRAMP 20x
FedRAMP's rebuilt authorization path: continuously validated Key Security Indicators and machine-readable packages instead of a narrative security package.
Consolidated Rules for 2026 (CR26) · FedRAMP 20x · published 2026-06-25
Standing today
Catalog only
01Standing
Catalog only
A directory entry — authority, version ledger, verification — not a workspace you can open.
FedRAMP 20x is tracked in the registry — authority, version ledger, verification — and nothing is modelled for it yet. Import its catalog to begin.
Named and tracked only; KSI definitions not ingested as a control catalog.
02Registry record
checked 2026-08-06
- Registry status
- Planned · namedWe name the regime and track its authority. Nothing is modelled yet.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Key Security Indicators · Machine-readable packages · Continuous validation
- Applies to
- federal cloud · US
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-08-06
- Pending change
- Phase 3 opens 20x to all qualifying providers in Q3 2026. Machine-readable package adoption became optional 2026-07-04 and is scheduled to be mandatory for all stakeholders 2027-01-01.Expected: 2027-01-01 (mandatory machine-readable packages)
03Version ledger
1 edition
| Consolidated Rules for 2026 (CR26) | Current edition | 2026-06-25 |