FedRAMP

A practical introduction to FedRAMP certification for cloud services sold to U.S. federal agencies, including the 2026 shift from Rev5 impact levels to 20x Certification Classes A through D, who assesses, what it costs, and how to start.

federal · cloud

What is FedRAMP

FedRAMP, the Federal Risk and Authorization Management Program, is the U.S. government’s program for deciding which commercial cloud services federal agencies may use. It started in 2011 as an OMB policy, became law in the FedRAMP Authorization Act of 2022, and is run by a program office at the General Services Administration. The idea is “assess once, use many times”: a cloud service is assessed against one federal ruleset, FedRAMP certifies it and lists it on the FedRAMP Marketplace, and every agency can rely on that package instead of running its own assessment.

In 2026 the program rewrote itself. The Consolidated Rules for 2026 (published June 25, 2026, mandatory January 1, 2027) replaced a decade of guidance with one rulebook and changed the vocabulary agencies and vendors had used since 2012:

  • A FedRAMP authorization is now a FedRAMP Certification. The word “authorization” was causing people to believe the government had accepted the risk of the service on every agency’s behalf; it had not, and it still has not.
  • The Low, Moderate, and High impact levels became Certification Classes B, C, and D, plus a new entry-level Class A.
  • Continuous monitoring became Ongoing Certification, and Plans of Action and Milestones (POA&Ms) were replaced by a list of Accepted Weaknesses.

Two certification types run in parallel. FedRAMP 20x is the new cloud-native approach: instead of a hundreds-of-pages System Security Plan, providers publish machine-readable Key Security Indicators with automated validation and a Security Decision Record, and FedRAMP itself processes the certification without an agency sponsor. FedRAMP Rev5 is the legacy approach built on NIST SP 800-53 Rev. 5 control baselines and agency sponsorship; it stops accepting new applications on June 11, 2027, and existing Rev5 certifications are guaranteed only through December 31, 2028.

Two misconceptions cause the most expensive mistakes. First, FedRAMP is not a general security certification you can hold to impress commercial customers; agencies are the only audience, and without one in the pipeline you have no reason to pursue it. Second, a FedRAMP Certification does not authorize anything by itself. Each agency still makes its own authorization decision under the Risk Management Framework using your package, which is why the class you hold and the class an agency wants can differ.

Who FedRAMP applies to

FedRAMP applies to cloud service offerings that hold or process federal information for a federal agency. The law and OMB policy direct agencies to use FedRAMP-certified services, and agency contracting offices translate that into a clause: no certification, no award, or an award contingent on getting one. In practice the obligation lands on:

  • SaaS companies whose product a civilian agency wants to buy, including small vendors whose first federal deal comes from a single program office;
  • infrastructure and platform providers that other vendors build on, since a certified platform lets customers inherit large parts of the control set;
  • managed service and data providers whose service touches agency data even if an agency never logs in; and
  • defense-adjacent vendors, because Department of Defense cloud rules and the CMMC program reference FedRAMP Moderate (now Class C) as the bar for cloud services that handle controlled unclassified information.

FedRAMP does not apply to on-premises software, to services sold only to state and local governments (those use StateRAMP, now GovRAMP, which FedRAMP accepts as a Class A entry credential), or to federal systems the agency runs itself. It also does not apply, strictly, to a commercial company that merely wants to look secure; there are cheaper ways to do that.

The surprise case is the reseller or subcontractor. If your product is embedded in a prime contractor’s offering to an agency, the prime will pass the FedRAMP requirement down to you, often with the class already set by the agency’s system categorization. Ask for that categorization before you budget.

Who manages and enforces FedRAMP

Several federal bodies share the program, each with a distinct job:

  • FedRAMP (the program office at GSA) writes the Consolidated Rules, operates the Marketplace, recognizes independent assessors, reviews certification packages with its own federal technical staff, and issues or revokes FedRAMP Certifications. Its public notices carry binding changes.
  • The FedRAMP Board, created by the FedRAMP Authorization Act and appointed by OMB, sets program direction. It replaced the Joint Authorization Board (JAB) in 2024, and the JAB’s provisional authorization path went with it.
  • OMB sets government-wide policy. Memorandum M-24-15 (July 2024) ordered the modernization that became FedRAMP 20x and told agencies to presume FedRAMP packages adequate for reuse.
  • Federal agencies are the enforcers. Each agency’s authorizing official decides whether to use your service in the agency’s information system, under FIPS 199, FIPS 200, and the Risk Management Framework. Under Rev5, an agency also “sponsors” the certification; under 20x, no sponsor is needed.
  • Independent assessors (formerly 3PAOs) are private firms accredited by A2LA and recognized by FedRAMP. They assess; they do not certify.
  • CISA issues Binding Operational Directives that FedRAMP passes through to providers, most recently BOD 26-04 on vulnerability prioritization, which is why Vulnerability Detection and Response becomes mandatory for all certified services on December 7, 2026.

There is no fine for lacking FedRAMP. The consequence is commercial: agencies cannot buy the service, or must stop using it. FedRAMP can also revoke a certification for a provider that stops meeting Ongoing Certification rules, and revocation is public on the Marketplace.

What is in scope

Scope in FedRAMP is the certification boundary: the set of components, services, people, and third-party services that deliver the cloud offering to agency customers and that FedRAMP’s rules apply to. Under the 2026 rules the boundary is defined by the provider and documented in the Certification Package; the historic “authorization boundary diagram” arguments with reviewers have been replaced with rules about what must be inside and what must be disclosed.

Scope grows in the usual directions:

  • Inherited services. Most 20x offerings run on an already-certified infrastructure or platform (the major cloud providers hold FedRAMP certifications for their government regions). Controls the platform operates are inherited, which is the single largest cost lever in the program. Rev5 typically assumed a separate government-only deployment; 20x is designed for the commercial service itself to be certified.
  • Third-party services that handle federal information (support tooling, email, monitoring, identity providers) are in scope unless they are themselves FedRAMP certified or the data flow is controlled.
  • People. Everyone with privileged access to the boundary, including subcontractors and offshore staff, matters, and some agencies add personnel restrictions in contract.
  • Cryptography. Federal information in transit and at rest must use FIPS 140-validated modules, a requirement that regularly forces architecture changes.
  • Corporate systems that administer the boundary (build pipelines, identity, endpoint management) are pulled in to the extent they can affect it.

A scope exercise you can run this week:

  1. Name the offering an agency would buy, and list every component that delivers it.
  2. Mark which components run on a FedRAMP-certified platform and which you operate yourself.
  3. List every external service that touches the data or the administration path, and check each on the Marketplace.
  4. Draw the boundary, then draw the data flows that cross it.
  5. Write down the class your agency customer’s system categorization implies.

A narrow boundary is legitimate and cheaper. Class A exists so a mature commercial service can be certified largely as it stands; going straight to Class C or D without an agency customer that requires it is the mistake FedRAMP itself warns against.

What FedRAMP requires

The Consolidated Rules for 2026 hold every requirement for both certification types. Rules are written as MUST, SHOULD, and MAY statements with stable identifiers (for example FRC-CSO-PKG for the Certification Package), organized into rule families such as Marketplace Listing, FedRAMP Certification, the FedRAMP Boundary, Assurance, Package Materials, and, for 20x, Key Security Indicators. Machine-readable versions of the rules are published alongside the prose.

Certification type decides what your package looks like:

  • FedRAMP 20x replaces the narrative System Security Plan with a Certification Package Overview and a Security Decision Record (what you decided and why, not what you plan to do), plus Key Security Indicators (KSIs): outcome statements about the service that you must validate with automated methods and publish in FedRAMP’s JSON schemas. Independent assessors review your automation and its results rather than re-reading documents.
  • FedRAMP Rev5 keeps the NIST SP 800-53 Rev. 5 control baselines and the SSP, Security Assessment Plan, and Security Assessment Report, but with 2026 changes: most assigned parameter values were removed so providers set and justify their own, Ongoing Certification rules apply in full, and POA&Ms are gone.

Certification class decides how much assurance is required. The classes are cumulative and designed to be entered progressively:

  • Class A is the entry pilot for existing commercial services with a mature program. You must have completed a SOC 2 Type II, a FedRAMP Rev5 (including Ready) assessment, or a GovRAMP certification within the past twelve months, supply a small package, and take on a small subset of Ongoing Certification reporting. No independent assessor is required. Once an agency is using the service, you are expected to move to Class B or higher within about twelve months.
  • Class B (formerly Low and Li-SaaS) is for small-scale or light-use services an agency is unlikely to rely on for important work. Independent assessment is required; KSI automation is recommended (at least one automated method per KSI).
  • Class C (formerly Moderate) is for common enterprise services used across an agency or delivering important government services. Independent assessment is required, and each KSI must have at least two automated validation methods.
  • Class D (formerly High) is for the most sensitive systems, with four automated methods per KSI under 20x. Today it is reachable only through Rev5 with an agency sponsor; the 20x Class D pilot is planned for late 2026 into early 2027.

Across both types, Ongoing Certification is where most of the 2026 change landed: Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules (mandatory December 7, 2026, with corrective action plans tolerated only to March 7, 2027), incident reporting, availability reporting, and package maintenance on a defined cadence. Failing them means losing the certification, not filing a POA&M.

The documents that matter, and how much weight each carries:

  • The Consolidated Rules for 2026 are the binding requirements and the definitions. Start with the important dates and the provider getting-started pages.
  • FedRAMP public notices amend the rules between editions; NTC-0014 is the one that set the VDR deadline.
  • The FedRAMP Marketplace is the record of who is certified, in process, and recognized to assess.
  • The legacy Rev5 documentation, still needed by Rev5 applicants and their sponsors, is linked from the rules site as reference.

How compliance is validated

FedRAMP is validated by certification, and the 2026 rules created two paths whose names describe who does the work:

  • Program Certification is processed directly by FedRAMP. It is the path for every 20x certification (Classes A, B, and C today) and, for a limited window, for Rev5 Class B and C providers that lost an agency sponsor or held FedRAMP Ready before July 28, 2026. No agency sponsor is required.
  • Agency Certification is the legacy Rev5 path: an agency authorizes the service for its own use first, then sponsors it for FedRAMP Certification. It is the only route to Class D today and generally the route for Rev5 Class B and C.

The steps in a Class B or C certification:

  1. Marketplace listing at the Initial Implementation stage, which signals to agencies that you are working toward certification.
  2. Package preparation. Boundary definition, the Certification Package Overview and Security Decision Record (or Rev5 SSP), KSI automation and evidence.
  3. Independent assessment by a FedRAMP Recognized assessor: for 20x, review of your automated validation methods and their results plus penetration testing; for Rev5, the traditional control-by-control assessment producing a Security Assessment Report.
  4. FedRAMP review by the program’s federal technical staff, with questions back to you and the assessor.
  5. Certification and listing, after which agencies can reuse the package to authorize the service in their systems.
  6. Ongoing Certification reporting, with the assessor returning annually.

Class A skips step 3: you submit the package with proof of your qualifying external assessment.

The result is a certification tied to a boundary and a class, not a permanent status. It continues as long as Ongoing Certification rules are met and can be revoked when they are not.

Who may perform the work

Only FedRAMP Recognized independent assessment services may perform the assessment for Class B, C, and D. Recognition requires accreditation by the American Association for Laboratory Accreditation (A2LA) under ISO/IEC 17020 plus FedRAMP-specific requirements, and the firms are listed on the Marketplace’s Assessors tab, where FedRAMP also flags assessors currently in remediation. FedRAMP’s own guidance is to interview several, get two or three proposals on the same boundary, and check whether the firm can review code-based automated validations, since that is what 20x assessments consist of.

The same firm cannot build your program and then independently assess it, so advisors and assessors are usually different companies. Aeris Secure performs readiness and remediation work; it is not a FedRAMP Recognized assessor and does not certify.

Verify an assessor on the Marketplace, not on its website. Verify a vendor’s FedRAMP claim by finding the service on the Marketplace and reading its class, type, and status.

The FedRAMP certification process

A first certification runs from a few months for Class A to twelve to eighteen months for a Rev5 Class C with a responsive sponsor, and longer without one. The steps:

  1. Confirm the obligation. Which agency, which contract clause, which class does their system categorization imply, and will they accept a lower class or an in-process listing while you work.
  2. Choose type and class. 20x if you are cloud-native on a certified platform; Rev5 only if you run your own infrastructure, need Class D now, or already have a sponsor deep in the legacy process. Start at Class A unless a contract requires more.
  3. Define the boundary and inheritance, and fix the architecture gaps (FIPS 140 cryptography, separation of federal data, logging) before writing anything.
  4. Build the package. For 20x, wire up automated KSI validation and write the Security Decision Record; for Rev5, the SSP and its appendices.
  5. List on the Marketplace at Initial Implementation and, for Class B and above, engage an assessor early enough to book fieldwork.
  6. Assessment, FedRAMP review, certification.
  7. Maintain through Ongoing Certification and plan the move to the next class or from Rev5 to 20x.

Who decides, and what to ask them

The decision-maker is the agency’s authorizing official and information system security staff, reached through the contracting officer or program manager who wants your product. Ask, and keep the answers in writing:

  • What is the FIPS 199 categorization of the system our service will be part of, and which Certification Class do they expect?
  • Will they accept a 20x Program Certification, or does the contract language name Rev5, Moderate, or a JAB authorization that no longer exists?
  • Will they sponsor a Rev5 certification if that is the only path, and who is the point of contact?
  • Is an in-process Marketplace listing or a Class A certification enough to award the contract, with a deadline to reach a higher class?
  • What agency-specific requirements (personnel, data residency, incident reporting timelines) will be added on top of FedRAMP?

The class answer is the budget. Class A and Class C differ by an order of magnitude in cost and by a year in calendar time, and a Class D requirement means Rev5 and a sponsor today.

Reality check: the calendar is consumed by architecture changes, evidence automation, and review queues, not by assessor fieldwork. Both FedRAMP’s review capacity and recognized assessors book months out.

Cost, time, and internal effort

The cost range on this page covers independent assessor fees for a first Class C certification of one cloud offering, the class most SaaS providers selling to agencies need. That definition keeps standards comparable across this site and is the number you can check against a proposal. FedRAMP itself does not charge a certification fee.

By class, the fees paid to the assessor:

  • Class A: none. There is no independent assessment; you reuse a SOC 2 Type II, Rev5, or GovRAMP result from the past twelve months.
  • Class B: roughly $50,000 to $150,000.
  • Class C: roughly $100,000 to $350,000.
  • Class D: roughly $250,000 to $650,000, through Rev5 with an agency sponsor.
  • Ongoing Certification: roughly $100,000 to $300,000 per year in assessment fees to keep a Class B or C certification.

Outside the range above, and usually larger than it:

  • advisory and documentation help, commonly $75,000 to $300,000 for a Rev5 Class C program;
  • engineering: FIPS 140 cryptography, separation of federal data, logging and vulnerability automation, and, for Rev5, a government-only environment, which published estimates put at $50,000 to $200,000 in infrastructure plus two to four senior engineers for a year;
  • penetration testing and tooling; and
  • internal Ongoing Certification labor, which published all-in figures put at $200,000 to $500,000 per year.

Published all-in first-year figures for a Rev5 Moderate (Class C) authorization cluster between $500,000 and $2,000,000. FedRAMP 20x is explicitly designed to cost less, and early estimates for 20x Class B land around $100,000 to $300,000 all-in, but the program is new and the figures are not yet backed by many completed certifications.

The page’s cost and effort ranges are directional, not a quote. The best predictors are the class, whether you are on 20x or Rev5, how much you inherit from a certified platform, and how much of your evidence is already produced automatically.

Time follows the same pattern. Class A for a service with a current SOC 2 Type II can be weeks of packaging. A Rev5 Class C with a sponsor is twelve to eighteen months, and the widest variable is how responsive the sponsoring agency is.

Maintaining compliance

Certification is continuous, and the 2026 rules made that literal. A typical operating rhythm:

  • Meet the Ongoing Certification cadence. Vulnerability Detection and Response and Vulnerability Evaluation and Reporting (mandatory December 7, 2026) replace monthly scan uploads with prioritization by exposure, known exploitation, and impact; incident reports, availability reporting, and package maintenance run on their own clocks.
  • Keep KSI validation running. For 20x, the automated methods that validate each Key Security Indicator are the evidence; when they break, so does the certification.
  • Report significant changes to the boundary, architecture, or third-party services before making them, following the rules’ change guidance.
  • Schedule the annual assessment with your recognized assessor well ahead.
  • Track the program. FedRAMP’s notices and blog announce deadlines with months, not years, of lead time. The Consolidated Rules are valid through 2028 and updated by changelog.
  • Run the risk assessment the rules and every agency’s Risk Management Framework expect, at least annually and after major changes. The free risk assessment tool on this site produces a risk register and report in the browser without sending data anywhere.
  • Plan the transitions: Class A to B or higher within about a year of your first agency customer, and Rev5 to 20x before Rev5 certifications lose their guarantee at the end of 2028.

Scope changes silently: a new microservice, a new support vendor, or a new cloud region can land inside the boundary. Wire the boundary definition into change management and procurement so changes are reviewed before FedRAMP, or an agency, notices.

How to get started

If FedRAMP has just landed on your desk, begin with five concrete actions:

  1. Get the class and type in writing. Ask the agency contact for the system categorization and whether a 20x Program Certification, an in-process listing, or Class A will satisfy the contract, and by when.
  2. Read the rules for providers. The Consolidated Rules for 2026 getting-started pages (choose a path, class, and type) are short and current; the important dates page is the calendar.
  3. Draw the boundary and the inheritance list. Name every component and third-party service, mark what runs on a certified platform, and check each vendor on the Marketplace.
  4. Run a first risk assessment and a gap review. Use a simple method (the risk assessment tool works) and walk the rules for your target class, paying special attention to FIPS 140 cryptography and Vulnerability Detection and Response, which decide the engineering budget.
  5. If you need Class B or above, get proposals from two or three FedRAMP Recognized assessors on the same boundary and class, ask about their 20x experience, and confirm each on the Marketplace’s Assessors tab before signing. If Class A fits, check that your SOC 2 Type II or other qualifying assessment is less than twelve months old.

For official starting points, use fedramp.gov for the program, the Consolidated Rules for 2026 for requirements, the Marketplace for certified services and assessors, and the notices for deadlines.

The first goal is not a Class C package. It is knowing which agency needs which class, on which type, by when. Once those answers are written down, FedRAMP is a project plan with a price, and choosing the smallest class the agency will accept is worth more than any technical shortcut.

Certification Classes

Class A

Who does it apply to?
Existing commercial cloud services with a mature security program (typically a current SOC 2 Type II) that want to enter the federal market before any agency has committed to them. New in 2026; 20x only.
Who audits / assesses?
None. Class A reuses a completed SOC 2 Type II, FedRAMP Rev5 (including Ready), or GovRAMP assessment from the past twelve months; FedRAMP reviews the package directly.
What report is required?
FedRAMP 20x Class A Certification listed on the Marketplace, with a small Certification Package and a subset of Ongoing Certification reporting. Expected to be upgraded to Class B or higher within about twelve months of the first agency customer.
Org effort
80 – 300 hours

Class A is the entry pilot the Consolidated Rules for 2026 created to replace FedRAMP Ready. It exists for a company that already runs a mature commercial security program and wants to be on the Marketplace before it has a federal customer. You qualify by having completed, within the past twelve months, a SOC 2 Type II, a FedRAMP Rev5 assessment (including a Readiness Assessment Report), or a GovRAMP certification, and by addressing the small Class A subset of FedRAMP rules in a package built on FedRAMP’s JSON schemas.

There is no independent assessor and no fee to FedRAMP, which makes Class A the only certification on this page whose cost is mostly internal time. The pipeline opened August 3, 2026, and only the 20x type offers it; FedRAMP’s own guidance is that most providers entering the market should start here rather than at Class C.

Class A is a start, not a destination. Once an agency is using the service, FedRAMP expects you to begin moving to Class B or higher within about twelve months, and a Class A certification can be converted to a Rev5 Class B, C, or D through an agency sponsor if a contract demands the legacy type. Agencies decide for themselves whether a Class A package is enough to authorize your service in their systems; for light use it often is, for mission systems it is not.

Class B

Who does it apply to?
Small-scale or light-use cloud services an agency is unlikely to depend on for important work, such as collaboration, scheduling, or survey tools. Covers what were the Low and Low-Impact SaaS (Li-SaaS) baselines.
Who audits / assesses?
A FedRAMP Recognized independent assessor (formerly 3PAO) is required, for the initial assessment and annually.
What report is required?
FedRAMP Class B Certification (20x or Rev5) listed on the Marketplace, with a Certification Package and Ongoing Certification reporting sized for lighter use.
Typical cost
$50,000 – $150,000
Org effort
400 – 1,200 hours

Class B absorbs the old Low and Low-Impact SaaS (Li-SaaS) baselines. It is meant for services where the potential impact of a breach on the agency is limited and the agency is not going to build mission work on top of them, so FedRAMP does not expect “considerable additional investment in ongoing maintenance and reporting.”

An independent assessor is required from Class B upward, and the 20x pipeline opened August 31, 2026. Under 20x, Key Security Indicator automation is recommended rather than mandatory at this class (FedRAMP asks for at least one automated validation method per KSI as a SHOULD), which is why Class B is where most 20x providers are expected to land first after Class A. Under Rev5, Class B is available through an agency sponsor or, until June 11, 2027, through the limited Ready Conversion and Lost Sponsor Program Certification pipelines.

The class is decided by the agency’s use of the service rather than by your product’s ambition. If an agency plans to use a Class B service across the enterprise or for important data, its authorizing official will want Class C, and the same package will not get you there without more automation and a wider assessment.

Class C

Who does it apply to?
Common enterprise cloud services likely to be used across an entire agency or to deliver important government services, and any service handling controlled unclassified information. Covers the former Moderate baseline, the class most SaaS providers selling to agencies need.
Who audits / assesses?
A FedRAMP Recognized independent assessor (formerly 3PAO) is required, for the initial assessment and annually. Under 20x the assessor reviews your automated KSI validation methods and their results.
What report is required?
FedRAMP Class C Certification (20x or Rev5) listed on the Marketplace, with a full Certification Package (Security Decision Record and KSI results for 20x; SSP, SAP, and SAR for Rev5) and complete Ongoing Certification reporting.
Typical cost
$100,000 – $350,000
Org effort
800 – 3,000 hours

Class C is the former Moderate baseline and remains the class most cloud providers are actually asked for, because Moderate is where controlled unclassified information sits and where agencies place the enterprise services they run their work on. Department of Defense cloud rules and the CMMC program also point to FedRAMP Moderate as the bar for cloud services holding defense CUI, which now reads as Class C.

Under 20x, Class C requires an independent assessment and at least two automated validation methods for every Key Security Indicator; the pipeline opened August 31, 2026, and no agency sponsor is needed. Under Rev5, Class C is the classic Moderate authorization built on roughly 320 NIST SP 800-53 Rev. 5 controls, a System Security Plan, and an agency sponsor, with the 2026 changes to Ongoing Certification and parameters layered on. New Rev5 applications end June 11, 2027.

Class C is where the budget and calendar warnings on this page apply in full. FedRAMP itself cautions providers not to go straight to Class C unless an existing government contract requires it; a Class A or B certification first, upgraded when an agency asks, is the intended route for a company entering the market from zero.

Class D

Who does it apply to?
Cloud services supporting an agency's most sensitive systems, where a breach could have severe or catastrophic effects, including law enforcement, emergency services, financial, and health systems. Covers the former High baseline.
Who audits / assesses?
A FedRAMP Recognized independent assessor (formerly 3PAO) is required, for the initial assessment and annually, with the largest control set and most intensive testing in the program.
What report is required?
FedRAMP Class D Certification listed on the Marketplace. Today only through Rev5 with an agency sponsor (Agency Certification); a 20x Class D pilot is planned for late 2026 into early 2027.
Typical cost
$250,000 – $650,000
Org effort
2,000 – 6,000 hours

Class D is the former High baseline, built on roughly 410 NIST SP 800-53 Rev. 5 controls under Rev5, for services an agency would put its most sensitive unclassified systems on. Few commercial services need it; the ones that do are usually infrastructure and platform providers or products built specifically for law enforcement, health, financial, or emergency-services missions.

As of September 2026, Class D is available only through FedRAMP Rev5 with an agency sponsor. The 20x Class D pilot is scheduled for FedRAMP’s Phase 4 (late 2026 into early 2027), with four automated validation methods per Key Security Indicator planned. FedRAMP’s own guidance is that a provider entering the market today will usually reach a 20x Class C certification and then upgrade to 20x Class D faster than it could complete a Rev5 Class D from scratch.

Do not pursue Class D without a contract that requires it. The assessment is the largest in the program, the ongoing obligations are the heaviest, and the Rev5 type it currently depends on closes to new applicants on June 11, 2027.

Version history

VersionStatusReleasedEffectiveRetiredSummary
Consolidated Rules for 2026 (FedRAMP 20x) current Jun 25, 2026Jan 1, 2027n/aOne rulebook for both certification types, valid through December 31, 2028, and the product of the modernization OMB ordered in Memorandum M-24-15 (July 2024). Renamed authorizations to FedRAMP Certifications and Low, Moderate, and High to Classes B, C, and D, added the Class A entry pilot, replaced the System Security Plan with a Certification Package Overview and Security Decision Record, replaced POA&Ms with an Accepted Weaknesses list, and made 20x a full path. Class A opened August 3, 2026; Classes B and C on August 31, 2026.
Rev5 baselines current
→ Consolidated Rules for 2026 (FedRAMP 20x)
May 30, 2023May 30, 2023n/aMoved the Low, Moderate, and High baselines to NIST SP 800-53 Rev. 5 with a year-long transition for authorized services. Still the required path for services on their own infrastructure and for Class D today, but FedRAMP stops accepting new Rev5 applications on June 11, 2027 and existing Rev5 certifications are guaranteed only through December 31, 2028.
Rev4 baselines retired
→ Rev5 baselines
Jun 6, 2014n/aMay 30, 2023Baselines built on NIST SP 800-53 Rev. 4, the version most long-standing FedRAMP authorizations were first issued against, with the Low-Impact SaaS (Li-SaaS) tailored baseline added in 2017 and the JAB provisional authorization path at its height.
Program launch (Rev3 baselines) retired
→ Rev4 baselines
Dec 8, 2011Jun 6, 2012Jun 6, 2014OMB's December 2011 memorandum established FedRAMP as the government-wide program for assessing and authorizing cloud services once and reusing the result across agencies. Operations began in June 2012 with baselines from NIST SP 800-53 Rev. 3.

New versions are announced in news. Follow this standard to get notified.