FedRAMP 20x
FedRAMP's outcome-focused certification approach, centered on continuously maintained certification data, Key Security Indicators, and packages that remain human-readable and are machine-readable where required.
Consolidated Rules for 2026 (CR26) · FedRAMP 20x · published 2026-06-25
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
FedRAMP 20x is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
Named and tracked only; KSI definitions not ingested as a control catalog.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Key Security Indicators · Human- and machine-readable certification data · Certification Package Overview · Security Decision Record · Secure Configuration Guide · Continuous validation
- Applies to
- federal cloud · US
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-09-06
- Pending change
- CR26 took effect 2026-07-04 (optional) and becomes mandatory 2027-01-01. The Class A application pipeline opened 2026-08-03. Class B and C application pipelines opened 2026-08-31. Class D has not yet opened (targeted FY27 Q1-Q2).Expected: 2027-01-01 (CR26 mandatory)
03Version ledger
| Consolidated Rules for 2026 (CR26) | Current edition | 2026-06-25 |
03aCoexisting versions
- FedRAMP Rev. 5 baselines
Applies to: Existing Rev. 5 authorizations, and new Rev. 5 certification applications until 2027-06-11
No scheduled end date — FedRAMP has not set a date by which Rev. 5 authorizations must convert to 20x; existing Rev. 5 authorizations remain valid through at least 2028-12-31.
Source (opens in a new tab)
04Authority intelligence
Curated primary-source signals connected to this registry record. An authority change creates review work; it does not silently change tenant posture, evidence credit, or prior decisions.
- Program update
FedRAMP 20x Class B and Class C pipeline opens August 31.
The Consolidated Rules for 2026 move FedRAMP toward persistently maintained security-decision records, reusable certification data, and human- and machine-readable packages, with the Class B and Class C pipeline scheduled to open August 31, 2026.
Operating moveConnect each security decision to its measure, validation, independent review, change history, and released package rather than rebuilding a static folder for every agency.
05Change history
06Related frameworks
Also applies to federal cloud · The legacy FedRAMP certification path built on tailored NIST SP 800-53 Rev. 5 baselines and independent assessment, providing reusable security assurance for federal agency authorization decisions.
- UK Cyber EssentialsRequirements for IT infrastructure v3.3
Commonly assessed together · The UK government-backed certification scheme for five foundational technical controls. Cyber Essentials is questionnaire-based; Cyber Essentials Plus adds independent technical verification. Tracking the requirements does not claim either certificate.
- AIUC-1Q3 2026 (2026-07-15 release)
Commonly assessed together · A quarterly updated standard and certification program for AI agents covering data and privacy, security, safety, reliability, accountability, and societal risk. Only AIUC can issue its certificate; registry inclusion makes no certification claim.
Commonly assessed together · The Cloud Security Alliance's vendor-neutral control framework for cloud-based AI systems, with implementation and auditing guidance plus the companion AI-CAIQ. It is a control catalog, not by itself a certification or STAR for AI designation.