Skip to main content

🔔 Notifications Hub: See compliance updates in one place

  • blog
  • Ready for FedRAMP 20x Moderate? What You Need for Class C Certification

Ready for FedRAMP 20x Moderate? What You Need for Class C Certification

  • September 15, 2026
Author

Emily Bonnie

Senior Content Marketing Manager

The FedRAMP 20x Class C pipeline opened on August 31, 2026, and with it, the most important tier of the new certification model. Class C replaces the FedRAMP Moderate impact level, and Moderate is where the federal cloud market lives: roughly 80% of FedRAMP authorized services have historically needed Moderate.

If you've been searching for "FedRAMP 20x Moderate," Class C is what you're looking for. This guide covers what Class C certification requires, the preparation runway most providers underestimate, and two cautions that matter before you commit: how Class C relates to agency acceptance, and why it does not currently satisfy CMMC requirements.

What is FedRAMP 20x Class C?

Under the FedRAMP Consolidated Rules for 2026 (CR26), certifications are organized into classes rather than impact levels. Class C covers common enterprise services likely to be used across an entire federal agency or that support important government functions. It's the 20x analog to FedRAMP Moderate, which historically covered systems where a loss of confidentiality, integrity, or availability would have serious adverse effects on an agency's operations, assets, or individuals.

One important distinction is that a class is not the same as an impact level. Your class describes how much security evidence you share and how often, while an impact level describes the sensitivity of an agency's own system under FIPS 199. An agency running a Moderate impact system will look for a Class C (or higher) certified service, but the class belongs to your certification and the impact level belongs to their system.

Class C sits between Class B (small-scale or light-use services, the old Low tier) and Class D (the old High tier, which has no 20x path yet and remains on Rev 5). If your buyers are agencies whose systems handle personally identifiable information, financial data, or mission operations, Class C is most likely your target.

Recommended reading

The FedRAMP Compliance Hub

20x Class C is not equivalent to Rev 5 Moderate

Before the requirements, clear up the misconception that trips up the most providers: Class C inherits Moderate's market position, not its requirements.

Rev 5 Moderate is a baseline of NIST 800-53 controls, each documented in an implementation narrative and tested by a 3PAO. Class C is 46 KSIs demonstrated through automated evidence. The KSIs reference related 800-53 controls, but they are not a mapping of the Moderate baseline: control coverage is partial by design, and providers should not assume KSI validation satisfies control-level requirements.

That distinction has two important implications:

Agency acceptance is not automatic. Every agency knows how to review a Rev 5 Moderate package. 20x Class C review processes are still being built, and agencies with their own control-level requirements layered on top of FedRAMP (VA 6500 is a common example) may need artifacts a Class C package doesn't contain. Before committing to Class C, ask your target agencies directly whether they're prepared to accept a 20x certification, and let their answers guide your path. A certification gets you listed in the marketplace, but it doesn't obligate any agency to accept it.

Class C does not currently satisfy CMMC or DFARS 7012 requirements. If your customers are defense contractors handling CUI, their obligation under DFARS 252.204-7012 is that your service be FedRAMP Moderate authorized or meet FedRAMP Moderate equivalency, a standard DoD defined against the Rev 5 Moderate baseline. Cyber AB leadership stated at its August 2026 town hall that FedRAMP 20x does not currently meet CMMC or DFARS 7012 requirements, with written guidance to assessors expected to follow; Rev 4 and Rev 5 authorizations remain accepted.

DoD is expected to publish updated policy as Rev 5 winds down, but until it does, a Class C certification is not a substitute for the Moderate baseline if the defense supply chain is your market. Providers serving both federal agencies and the DIB may need to carry Class C evidence and Moderate baseline coverage in parallel.

Recommended reading

FedRAMP 20x vs. Rev 5: What's Changing and How to Decide Your Transition Path

FedRAMP 20x Class C requirements under CR26

Everything CR26 asks of a Class C provider answers one of three questions: what you have to prove (the Key Security Indicators), how you have to prove it (automated validation, packaged as data, checked by an assessor), and how often (the cadences that start at application and never stop). 

Every 20x certification is demonstrated through 46 Key Security Indicators (KSIs) across 10 capability areas:

Domain Requirements
Cloud native architecture
  • Defining functionality and privileges
  • Minimizing attack surface
  • Networking configuration
  • Restricting inbound traffic
  • Restricting outbound traffic
  • Isolating resources
  • Denial of service protection
  • Enforcing intended state
Change management
  • Logging modifications
  • Redeploying resources
  • Testing changes
  • Managing emergency changes
Identity and access management
  • Passwordless authentication
  • Phishing-resistant MFA
  • Securing non-user accounts
  • Least privileged access
  • Just-in-time authorization
  • Terminating access
Incident response
  • After-action reports
  • Reviewing response procedures
  • Analyzing incident patterns
Monitoring, logging, and auditing
  • Operating a SIEM
  • Protecting log integrity
  • Authorizing log access
  • Persistently reviewing logs
  • Retaining audit records
Policy and inventory
  • Security policies
  • Automated inventory
  • Authoritative sources
  • Executive support
  • Documenting responsibilities
Recovery planning
  • Defining recovery objectives
  • Aligning backups
  • Testing recovery
  • Maintaining recovery plans
Supply chain risk
  • Identifying supply chain risks
  • Monitoring third-party software
Service configuration
  • Configuration management
  • Detecting drift
  • Automated secret rotation
  • Encrypting communications
  • Encrypting at rest
  • Validating communications
  • Preventing residual risk
  • Removing unwanted data
Cybersecurity education
  • Reviewing training effectiveness

At Class C, five KSIs that are optional at Class B become required:

  1. Enforcing intended state (KSI-CNA-EIS): Automated services persistently assess your machine-based resources and automatically enforce their intended operational state
  2. Authorizing log access (KSI-MLA-ALA): A least-privileged, role- and attribute-based, just-in-time model governs who can touch your logs, persistently reviewed
  3. Preventing residual risk (KSI-SVC-PRR): Plans, procedures, and resource state are persistently reviewed after changes to limit what gets left behind
  4. Removing unwanted data (KSI-SVC-RUD): Federal customer data is removed promptly when an agency requests it, in alignment with customer agreements
  5. Validating communications (KSI-SVC-VCM): The authenticity and integrity of machine-to-machine communications are persistently validated

The pattern across the five is automation of things teams often do manually or after the fact: state enforcement, log access governance, post-change review, data deletion, and service-to-service trust. 

FedRAMP 20x Compliance Checklist

Get a step-by-step checklist to walk you through the process of preparing for FedRAMP 20x certification. View requirements by certification class, plan your transition, and track your progress towards readiness.

Implement at least two automated validation methods per KSI

Next, how you prove it. Knowing your KSIs are healthy isn't enough on its own; CR26 wants your systems to check them continuously, and to check them more than one way. Providers seeking Class C certification must implement at least two automated methods for each KSI that persistently verify and validate its accuracy and completeness.

Two methods per indicator, across 46 indicators, means your validation layer is a real engineering deliverable, not a reporting exercise. A configuration-drift indicator might be validated by both an infrastructure-as-code scanner and a cloud security posture tool; an access indicator by both your identity provider's reporting API and an independent access review job. Redundant validation is the point: it lets FedRAMP and agencies trust the evidence without re-deriving it.

Document what you inherit from your cloud platform

If your service runs on AWS, Azure, GCP, or another certified platform, some of your security story comes from beneath you, and CR26 expects you to document exactly where. Your Minimum Assessment Scope must identify the third-party services likely to handle federal customer data or affect its confidentiality, integrity, or availability, including your underlying infrastructure, and your Security Decision Record documents the mechanisms behind each rule and KSI, including inheritance.

The principle carries over from Rev 5: leveraging a FedRAMP certified infrastructure provider means its layer of the stack is covered by its own certification, and building on non-certified infrastructure means that infrastructure lands inside your scope. What changes under 20x is what inheritance can't do for you. 

The KSIs describe capabilities of your service as you operate it, so your platform's certification doesn't produce your evidence: encryption at rest may run on your provider's KMS, but demonstrating that your resources use it, persistently and with two automated validation methods, is your job. Treat inheritance as a scoping tool that shrinks what you must prove, not a substitute for proving it.

Choose FedRAMP certified infrastructure, document your information flows across the platform boundary early (this is design input for your Minimum Assessment Scope, not paperwork after the fact), and map which KSIs your platform's capabilities support versus which your own tooling must demonstrate end to end.

Remediate findings

20x has different expectations for findings than the POA&M model you may be familiar with for Rev 5. Under CR26, providers must systematically and persistently track, evaluate, mitigate, remediate, and report every detected vulnerability, a process the rules call Vulnerability Response.

Three parts of that model shape your operations:

  • Remediation timeframes scale with real risk, not just scanner scores. CR26 sets expected mitigation and remediation timeframes based on a vulnerability's Potential Agency Impact rating, whether it's internet-reachable, and whether it's likely exploitable. Known Exploited Vulnerabilities follow the due dates in CISA's KEV catalog under BOD 26-04, even if already mitigated.
  • Serious exposed vulnerabilities get incident treatment. Class C providers should treat internet-reachable, likely exploitable vulnerabilities above a defined impact threshold as FedRAMP Reportable Incidents until they're mitigated below it. A dangerous unpatched internet-facing flaw isn't a line item on a report; it's handled like an active problem.
  • Long-lived findings become accepted vulnerabilities, not POA&M entries. Any vulnerability that won't be fully mitigated or remediated within 192 days of evaluation must be categorized as an accepted vulnerability, with defined information reported about it. Agencies then decide what that acceptance means for their own risk, and maintain their own plans of action on their side. The tracking spreadsheet moves from your deliverables folder into your evidence pipeline, and the risk-acceptance conversation moves into your quarterly reviews.

CR26 treats gaps in your detection process as vulnerabilities themselves, so the goal isn't a clean report. It's a demonstrably working response system.

Build at least six months of historical metrics before you apply

Here's the requirement that sets your calendar, and the one providers most often discover too late. Class C applicants must supply historical metrics, including status from persistent validation, covering at least the past six months for all KSIs.

This requirement has direct implications for your certification runway. If your automated validation isn't running yet, your earliest possible Class C application is six months after you turn it on.

A provider that stands up its validation pipeline today has an earliest possible Class C application in March 2027. Add assessor scheduling and package preparation, and a realistic first wave of Class C certifications for providers starting now lands in mid-2027, right as new Rev 5 applications end.

That makes the decision less about whether 20x is ready and more about whether your evidence is. If your security program already runs on automated monitoring, drift detection, and centralized logging, the KSIs describe capabilities you substantially have, and your work is validation coverage and history. If your evidence is manual, the six-month clock is the forcing function to change that, and the investment pays off under any framework: the same automated evidence satisfies CR26's requirements on the Rev 5 path and strengthens a CMMC body of evidence.

Create a machine-readable certification package

All of that evidence needs a container, and in 20x the container is structured data rather than a document set. Your submission goes to FedRAMP in both human-readable and JSON formats, which is what lets FedRAMP validate it with software and lets every agency customer work from the same continuously maintained package:

  1. A Certification Package Overview describing the offering and its metadata
  2. A Security Decision Record summarizing, at a high level, how you address each applicable rule and KSI, with those historical performance metrics included
  3. A Minimum Assessment Scope identifying every information resource likely to handle federal customer data or affect its confidentiality, integrity, or availability, with documented information flows
  4. KSI evidence and independent assessment results, included without modification

Complete an independent assessment plus annual reassessments

Automated evidence doesn't mean unexamined evidence. Class C applicants must supply an initial independent assessment completed by a FedRAMP Recognized independent assessment service within the three months before applying, and the full package you submit must reflect the state of the offering as verified within the previous seven days. After certification, an independent verification and validation assessment of all applicable rules is required at least annually.

Under 20x, the assessor's job differs from a Rev 5 3PAO's. Rather than testing control implementations against a baseline, the assessor verifies that your KSI evidence is authentic and that your validation methods work as claimed. The assessor confirms the measurement; where a KSI defines no numeric threshold, whether the measured posture is adequate remains an agency determination.

Continuously monitor and maintain compliance 

Certification is the start of the operational rhythm, not the finish line, and the cadences are the strictest in the 20x model:

  1. Package freshness: your entire certification package stays current and complete at least every two weeks
  2. Vulnerability detection: at least every 14 days on any resource likely to drift, alongside a standing mandate to discover vulnerabilities through scanning, threat intelligence, disclosure programs, penetration testing, and automated control testing
  3. Quarterly reporting: an Ongoing Certification Report every three months summarizing changes, vulnerabilities, and posture, plus a mandatory synchronous quarterly review meeting open to all agency customers (the live meeting is required at Class C and D, not Class B)
  4. Change notification: transformative changes need notice 30 business days before starting; adaptive changes, notification within 10 business days after finishing

If those cadences sound demanding, that's the honest cost of the model: agencies get a two-week-fresh picture of your service, and your automation is what makes producing it sustainable.

How to apply for Class C certification

The application process itself is short; the preparation is where the work lives. Sequence it this way and nothing surprises you:

  1. List on the FedRAMP Marketplace first. A marketplace listing is a prerequisite for applying, and listings for the initial implementation stage have been open since July 6, 2026.
  2. Build your evidence pipeline and let it run. Implement the KSIs, stand up at least two automated validation methods per indicator, and accumulate the six months of persistent validation history. This is where most of the calendar goes.
  3. Define your Minimum Assessment Scope. Identify every resource that could handle federal customer data or affect it, and document the information flows. Scoping errors are the 20x descendant of the authorization boundary mistakes that stalled Rev 5 packages, so treat this as design work, not paperwork.
  4. Engage a FedRAMP Recognized assessor. Your initial independent assessment must be complete within the three months before you apply. Assessor demand is worth planning around: many 3PAOs are also CMMC assessors, and intake queues are already forming.
  5. Apply directly, with a fresh package. Complete the FedRAMP Certification Application Form yourself (CR26 prohibits third parties, including assessors, from applying on your behalf) and submit a package verified and validated within the previous seven days.

Two rules to know before you start:

First, you can't pursue both a Rev 5 and a 20x Program certification for the same offering; CR26 makes you choose one type.

Second, class upgrades require a new application with all requirements met in advance, so a "start at Class B, upgrade later" plan means budgeting for a second application, though the evidence pipeline carries forward.

How Secureframe Defense helps

Secureframe Defense was built for exactly this model. We were among the first CSPs to achieve FedRAMP 20x certification through the Phase One and Phase Two pilot phases, and the platform continuously monitors your controls and collects evidence automatically, so the two-automated-methods requirement, the six-month metrics history, and the two-week package freshness cadence become outputs of your pipeline rather than a manual reporting burden.

Streamline FedRAMP compliance

Request a demo

FAQs

Is FedRAMP 20x Class C the same as FedRAMP Moderate?

Class C replaces the Moderate impact level in the 20x model and serves the same market position, but the requirements differ. Rev 5 Moderate is a NIST 800-53 control baseline documented in narratives and tested by a 3PAO; Class C is 46 Key Security Indicators demonstrated through automated evidence with at least two validation methods each. The KSIs reference related 800-53 controls but are not a mapping of the Moderate baseline.

Does a FedRAMP 20x Class C certification satisfy CMMC or DFARS 7012?

Not currently. DoD's FedRAMP Moderate equivalency standard is defined against the Rev 5 Moderate baseline, and Cyber AB leadership has stated that FedRAMP 20x does not currently meet CMMC or DFARS 7012 requirements. FedRAMP Moderate authorized services remain accepted, and DoD is expected to publish updated policy as Rev 5 sunsets.

Do I need an agency sponsor for FedRAMP 20x Class C?

No. Class C is available through the 20x Program path, where you work directly with FedRAMP and list on the marketplace.

How long does Class C certification take?

CSPs need six months of historical metrics from persistent validation across all 46 KSIs, plus an independent assessment completed within three months of applying.

Can I hold both a Rev 5 and a 20x certification?

CR26 requires providers to pick one Program certification type per cloud offering.

Emily Bonnie

Senior Content Marketing Manager

Emily Bonnie is a seasoned digital marketing strategist with over ten years of experience creating content that attracts, engages, and converts for leading SaaS companies. At Secureframe, she helps demystify complex governance, risk, and compliance (GRC) topics, turning technical frameworks and regulations into accessible, actionable guidance. Her work aims to empower organizations of all sizes to strengthen their security posture, streamline compliance, and build lasting trust with customers.