Skip to main content
—
Framework library
Framework module · fedramp-20x

FedRAMP 20x

FedRAMP's outcome-focused certification approach, centered on continuously maintained certification data, Key Security Indicators, and packages that remain human-readable and are machine-readable where required.

Consolidated Rules for 2026 (CR26) · FedRAMP 20x · published 2026-06-25

Standing today
Directory entry

00Answer

from the registry record
What is FedRAMP 20x?
FedRAMP's outcome-focused certification approach, centered on continuously maintained certification data, Key Security Indicators, and packages that remain human-readable and are machine-readable where required.
Who does FedRAMP 20x apply to?
FedRAMP 20x applies to federal cloud, US, per FedRAMP 20x.
What is the current version of FedRAMP 20x?
The current edition is Consolidated Rules for 2026 (CR26), issued by FedRAMP 20x and published 2026-06-25. Source: https://www.fedramp.gov/20x/.
What does an assessment under FedRAMP 20x require?
No control catalog has been ingested for FedRAMP 20x yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

FedRAMP 20x is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

Named and tracked only; KSI definitions not ingested as a control catalog.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Key Security Indicators · Human- and machine-readable certification data · Certification Package Overview · Security Decision Record · Secure Configuration Guide · Continuous validation
Applies to
federal cloud · US
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-09-06
Pending change
CR26 took effect 2026-07-04 (optional) and becomes mandatory 2027-01-01. The Class A application pipeline opened 2026-08-03. Class B and C application pipelines opened 2026-08-31. Class D has not yet opened (targeted FY27 Q1-Q2).Expected: 2027-01-01 (CR26 mandatory)

03Version ledger

1 edition
Consolidated Rules for 2026 (CR26)Current edition2026-06-25

03aCoexisting versions

1 other version in force
  1. FedRAMP Rev. 5 baselines

    Applies to: Existing Rev. 5 authorizations, and new Rev. 5 certification applications until 2027-06-11

    No scheduled end date — FedRAMP has not set a date by which Rev. 5 authorizations must convert to 20x; existing Rev. 5 authorizations remain valid through at least 2028-12-31.

    Source (opens in a new tab)

04Authority intelligence

reviewed 2026-08-30

Curated primary-source signals connected to this registry record. An authority change creates review work; it does not silently change tenant posture, evidence credit, or prior decisions.

  1. Program update

    FedRAMP 20x Class B and Class C pipeline opens August 31.

    The Consolidated Rules for 2026 move FedRAMP toward persistently maintained security-decision records, reusable certification data, and human- and machine-readable packages, with the Class B and Class C pipeline scheduled to open August 31, 2026.

    Operating move

    Connect each security decision to its measure, validation, independent review, change history, and released package rather than rebuilding a static folder for every agency.

05Change history

06Related frameworks

scored from registry facts
  1. Also applies to federal cloud · The legacy FedRAMP certification path built on tailored NIST SP 800-53 Rev. 5 baselines and independent assessment, providing reusable security assurance for federal agency authorization decisions.

  2. UK Cyber EssentialsRequirements for IT infrastructure v3.3

    Commonly assessed together · The UK government-backed certification scheme for five foundational technical controls. Cyber Essentials is questionnaire-based; Cyber Essentials Plus adds independent technical verification. Tracking the requirements does not claim either certificate.

  3. AIUC-1Q3 2026 (2026-07-15 release)

    Commonly assessed together · A quarterly updated standard and certification program for AI agents covering data and privacy, security, safety, reliability, accountability, and societal risk. Only AIUC can issue its certificate; registry inclusion makes no certification claim.

  4. Commonly assessed together · The Cloud Security Alliance's vendor-neutral control framework for cloud-based AI systems, with implementation and auditing guidance plus the companion AI-CAIQ. It is a control catalog, not by itself a certification or STAR for AI designation.

FedRAMP 20x | ControlFrame