FedRAMP (Rev. 5 baselines)
The legacy FedRAMP certification path built on tailored NIST SP 800-53 Rev. 5 baselines and independent assessment, providing reusable security assurance for federal agency authorization decisions.
Rev. 5 · FedRAMP · published 2023-05-30
00Answer
01Standing
Named, with the authority's acquisition path recorded; onboarding is refused until a control set is registered.
FedRAMP (Rev. 5 baselines) cannot be onboarded yet: Freely published; baselines not ingested as a control catalog. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.
FedRAMP (Rev. 5 baselines) cannot be onboarded yet: Freely published; baselines not ingested as a control catalog. Onboarding is enabled once a control set is registered, so a new project never opens into an empty workspace.
02Registry record
- Registry status
- Roadmap · modelledModeled framework: we model the regime — control families and at least one crosswalk map on disk — but no source-pinned control catalog is ingested.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Low baseline · Moderate baseline · High baseline · Continuous monitoring
- Applies to
- federal cloud · US
- Verification
- Primary — the issuing body's own page was read and states this version. checked 2026-09-06
- Pending change
- FedRAMP 20x is the forward program path, while Rev. 5 remains available during transition. FedRAMP Ready submissions under Rev. 5 stopped being accepted 2026-07-28. FedRAMP will stop accepting applications for new Rev. 5 Certifications on 2027-06-11. Existing Rev. 5 authorizations remain valid through at least 2028-12-31; FedRAMP has not stated a final retirement date for all of them.Expected: 2027-06-11 (end of applications for new Rev. 5 certifications)
03Version ledger
| Rev. 4 | Superseded | date not published |
| Rev. 5 | Current edition · supersedes Rev. 4 | 2023-05-30 |
03aCoexisting versions
- FedRAMP 20x (Consolidated Rules for 2026)
Applies to: New authorizations entering the Class A/B/C application pipelines; optional since 2026-07-04, mandatory for those pipelines from 2027-01-01
No scheduled end date — FedRAMP has not set a date by which Rev. 5 authorizations must convert to 20x; existing Rev. 5 authorizations remain valid through at least 2028-12-31.
Source (opens in a new tab)
04Authority intelligence
Curated primary-source signals connected to this registry record. An authority change creates review work; it does not silently change tenant posture, evidence credit, or prior decisions.
- Program update
FedRAMP 20x Class B and Class C pipeline opens August 31.
The Consolidated Rules for 2026 move FedRAMP toward persistently maintained security-decision records, reusable certification data, and human- and machine-readable packages, with the Class B and Class C pipeline scheduled to open August 31, 2026.
Operating moveConnect each security decision to its measure, validation, independent review, change history, and released package rather than rebuilding a static folder for every agency.
05Change history
- 2027-06-11FedRAMP (Rev. 5 baselines): FedRAMP 20x is the forward program path, while Rev. 5 remains available during transition. FedRAMP Ready submissions under Rev. 5 stopped being accepted 2026-07-28. FedRAMP will stop accepting applications for new Rev. 5 Certifications on 2027-06-11. Existing Rev. 5 authorizations remain valid through at least 2028-12-31; FedRAMP has not stated a final retirement date for all of them.
- 2023-05-30FedRAMP (Rev. 5 baselines) Rev. 5 supersedes Rev. 4 and is the current edition.
06Related frameworks
- FedRAMP 20xConsolidated Rules for 2026 (CR26)
Also applies to federal cloud · FedRAMP's outcome-focused certification approach, centered on continuously maintained certification data, Key Security Indicators, and packages that remain human-readable and are machine-readable where required.
- GovRAMP (formerly StateRAMP)Rev. 5 baselines
Same framework family · A standardized assessment, authorization, and continuous-monitoring program for cloud services used by state and local governments, built on NIST SP 800-53 Rev. 5. Core, Ready, and Authorized are service-offering statuses—not company-wide certifications. StateRAMP rebranded to GovRAMP on 2025-02-14; StateRAMP, Inc. remains the legal entity operating under the GovRAMP name.
- TX-RAMPProgram Manual 4.0
Same framework family · Texas's risk and authorization management program for cloud services used by state agencies and public higher education. Level 1, Level 2, and Provisional are service-offering certifications—not company-wide certifications.
Same framework family · CMS's minimum security and privacy control baseline for CMS information systems and CMS contractors. It is distinct from the Marketplace-focused ARC-AMPE baseline.