Skip to main content

CMMC Pause: What DoW & Primes Still Require

  • blog
  • FedRAMP 20x Roadmap: Key Dates for the Phased Rollout [August 2026 Update]

FedRAMP 20x Roadmap: Key Dates for the Phased Rollout [August 2026 Update]

  • January 19, 2026
Author

Emily Bonnie

Senior Content Marketing Manager

Reviewer

Rob Gutierrez

Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP

Over the past year, FedRAMP 20x has steadily reshaped federal cloud authorizations. FedRAMP introduced Phase One and Phase Two pilots, tested a new Key Security Indicator–based assessment model, and began reworking standards around continuous monitoring, vulnerability management, and authorization data sharing.

In January 2026, FedRAMP followed that work with a coordinated set of updates, including six new Requests for Comment, the announcement of Phase Two Moderate pilot participants, and additional guidance tied to the FedRAMP Authorization Act.

For cloud service providers, the key question is not just what appears on the FedRAMP 20x roadmap, but how these changes affect their compliance efforts. After all, FedRAMP 20x is not just a procedural update to legacy FedRAMP — it represents a fundamental shift in how cloud security is assessed for federal agencies.

The latest FedRAMP 20x updates: August 2026

On June 25, 2026, FedRAMP launched the Consolidated Rules for 2026 (CR26), a single stable ruleset that formalizes the FedRAMP 20x requirements, resolves the January Requests for Comment, and makes 20x a widely available certification path for any cloud service provider.

Two changes from CR26 reshape the vocabulary of everything below. "FedRAMP Authorization" is now "FedRAMP Certification," and the Low, Moderate, and High impact levels became Certification Classes B, C, and D, joined by Class A, a new time-limited entry tier. For the full breakdown of what changed, read our guide to FedRAMP 20x and the 2026 Consolidated Rules.

The rollout now runs on published dates:

Date Milestone
June 25, 2026 CR26 launches, making FedRAMP 20x widely available
July 4, 2026 CR26 takes effect; mandatory for new 20x certification applications
July 6, 2026 Marketplace listings open for providers in the Initial Implementation Phase
July 28, 2026 FedRAMP Ready retires and becomes "Legacy FedRAMP Ready"
August 3, 2026 FedRAMP 20x Class A pipeline opens
August 10, 2026 Temporary Rev5 pipelines open for eligible Class B and C providers (Ready Conversion and Lost Sponsor paths)
August 31, 2026 FedRAMP 20x Class B and Class C pipelines open
November 17, 2026 Deadline for Rev5 Ready providers to convert to Class A Certification (if their annual assessment hasn't expired)
January 1, 2027 CR26 becomes mandatory for all providers; start of the default grace period
Q1 to Q2 FY2027 FedRAMP 20x Class D (High) pilot expected to begin
June 11, 2027 FedRAMP stops accepting new Rev5 certification applications
December 31, 2027 "Legacy FedRAMP Ready" status removed entirely
February 1, 2028 End of grace period; providers not following CR26 lose their FedRAMP Certification

As of this update, FedRAMP Ready has retired, the Class A pipeline is open, and the Class B and C pipelines open at the end of August. The window that matters most for planning is January 1, 2027, when CR26 becomes mandatory for every provider, including current Rev5 certifications.

For the canonical schedule, refer to the official CR26 timeline on FedRAMP.gov.

The January 2026 RFCs and their outcomes

On January 13, 2026, FedRAMP released six Requests for Comment, along with new program updates and Phase Two pilot announcements.

Each RFC targeted a specific friction point that had historically slowed or complicated FedRAMP adoption. All six were resolved through outcome notices and the Consolidated Rules for 2026, and here's where each landed.

RFC-0019 focused on reporting assessment costs, proposing requirements to give FedRAMP better visibility into assessment pricing without publicly exposing sensitive cost data. This is the one proposal without a clear landing spot: the CR26 ruleset contains no cost-reporting requirements, so this effort appears to have been deferred or absorbed elsewhere.

RFC-0020 addressed authorization designations, and its outcome reshaped the program's vocabulary. Rather than the multi-level designation system originally floated, FedRAMP confirmed in February 2026 that "FedRAMP Certification" would replace "FedRAMP Authorization" as the single official label, and that four Certification Classes (A through D) would replace the Low, Moderate, and High impact levels. Class B maps to the former Low baseline, Class C to Moderate, and Class D to High, while Class A is a new time-limited entry tier. For CSPs, the core message stands: certification is no longer a milestone you reach once, but a security posture you sustain continuously.

RFC-0021 proposed expanding the FedRAMP Marketplace, and most of it became CR26 rules. Providers can now be listed early through the Initial Implementation Phase, where they must document continuous progress toward certification at least quarterly and schedule a Class B, C, or D assessment within two years of listing. Assessors and advisory firms are now formally listed in the Marketplace with their own recognition and listing requirements. The pricing transparency piece of the proposal did not make it into the consolidated rules.

RFC-0022 outlined how FedRAMP would leverage external frameworks, and the outcome was narrower than the proposal. CR26 formalized Class A Certification as the external-framework entry point, initially accepting SOC 2 Type II as the most widely used framework, with GovRAMP added as a second approved option. Other candidates discussed during the comment period, including ISO 27001 and CMMC Level 2, were not adopted, and FedRAMP has said additional frameworks will be considered incrementally based on demand. FedRAMP has also been explicit that Class A grants no reciprocity: it is a transitory entry point, not a bridge to a full Class B, C, or D Certification.

RFC-0023 introduced a sponsorless path for certain Rev5 authorizations. That concept is reflected in the temporary Rev5 certification pipelines that opened August 10, 2026, giving eligible Class B and C providers a way forward through the Ready Conversion and Lost Sponsor paths without an agency sponsor.

RFC-0024 proposed mandatory machine-readable authorization packages for Rev5, and CR26 codified the direction broadly: the rules themselves are published as machine-readable JSON, provider submissions must validate against FedRAMP's published JSON schemas wherever a rule defines one, and agencies are required to maintain tooling that can produce and ingest machine-readable artifacts.

These RFCs marked the shift from planning to locking in how the modernized program functions in practice. Faster reviews assume cleaner submissions, continuous validation assumes operational discipline, and marketplace visibility reflects demonstrable progress. CR26 made all three of those assumptions enforceable.

How the FedRAMP 20x rollout is structured

The program rollout was structured in two major phases, supported by parallel updates to public tooling and targeted adjustments to legacy Rev5 requirements.

Phase One focused on FedRAMP Low and served as the proving ground for new standards and processes. Phase Two expanded those lessons to FedRAMP Moderate and introduced higher expectations around continuous validation, cryptography, and remediation discipline. At the same time, Marketplace and Rev5 updates reshaped how CSPs signal progress and maintain their status over time. All of this work fed into the Consolidated Rules for 2026.

Phase one: Modernizing FedRAMP Low

Phase One is where FedRAMP began pressure-testing the 20x model in real environments, starting with Low-impact systems. The goal was to see how these changes work in practice, gather feedback, and refine them before rolling them out at scale. 

It was also the first opportunity for CSPs to experience a faster, more automated path to authorization, while still meeting the government’s security requirements. The standards tested here became the foundation for what is now Class B Certification under CR26.

Key milestones include:

  • August 15, 2025: Authorization Data Sharing Standard
    This standard allows CSPs to self-host FedRAMP authorization data, including continuous monitoring materials, without having to upload them to the FedRAMP Secure Repository. It offers more flexibility while keeping agencies informed.
  • August 29, 2025: Finalize FedRAMP 20x Low Authorization Standard
    Consolidates everything learned during the Phase One pilot into official Low authorization guidance for ongoing use.
  • September 4, 2025: Continuous Vulnerability Management Standard
    This standard merges reporting and monitoring into one unified set of requirements. It sets the expectation that CSPs will continuously detect, prioritize, and remediate vulnerabilities using automated systems.
  • September 12, 2025: Federal Information Technical Assistance
    Provides guidance on what qualifies as federal information for the purposes of the Minimum Assessment Scope, helping CSPs determine which data falls under FedRAMP requirements.
  • September 26, 2025: Finalize Key Security Indicators for FedRAMP Moderate
    Updates the metrics used for assessing FedRAMP Moderate authorizations, ensuring that Phase Two launches with clear and measurable expectations.
  • September 26, 2025: Agency Adoption Pilot for 20x Low
    Pairs early-adopting agencies with Phase One authorized CSPs to evaluate how 20x works in practice and identify opportunities for improvement.
  • October 3, 2025: Collaborative Continuous Monitoring Standard
    Introduces a formal structure for joint monitoring between CSPs and agencies, making the process more efficient and collaborative.
  • October 3, 2025: Agency Reuse Playbook for 20x
    Creates a resource for agencies explaining how to review and reuse 20x authorized services without unnecessary duplication of effort.

Recommended reading

FedRAMP 20x: What’s Changing for CSPs — and What Isn’t

Phase two: Scaling to FedRAMP Moderate

Once Phase One established that the 20x model could work at the Low impact level, FedRAMP shifted its focus to scaling those same principles to Moderate authorizations. This phase incorporated lessons learned during the pilot, but it also raised expectations, especially around continuous validation, cryptographic requirements, and modernization of legacy processes like POA&Ms. 

For CSPs, this was where the program moved closer to its vision of a largely automated, continuous authorization process that is faster to achieve and easier to maintain. Phase Two also gave CSPs authorized at Low a smoother transition to Moderate.

Key milestones include:

  • October 31, 2025: Continuous Validation Standard
    Establishes expectations for near real-time validation of security controls, with a target of achieving 80 percent or more validation through automation.
  • October 31, 2025: FIPS Cryptographic Module Application for Commercial Services
    Provides updated guidance on how FIPS 140-3 requirements apply to commercial services, taking a more risk-based approach.
  • November 14, 2025: POA&M Standard
    Updates the decades-old Plans of Action and Milestones process, making it more relevant for modern cloud environments and aligning it with commercial best practices.
  • November 15, 2025: 20xP2 Moderate Pilot Submission and Review Window
    Opens the pilot for Moderate-level authorizations under 20x.
  • December 5, 2025: Finalize FedRAMP 20x Moderate Authorization Standard
    Publishes the final requirements for Moderate authorizations based on pilot results.
  • Expected Q1 to Q2 FY2027: FedRAMP 20x Class D pilot
    With the Moderate standard finalized and folded into CR26, the remaining frontier is Class D, the former High baseline. FedRAMP expects to begin the 20x Class D pilot in the first half of FY2027. Until then, Rev5 is the only path to a Class D Certification, and FedRAMP recommends providers pursue 20x Class C now and plan for Class D when it becomes available.

Modernizing FedRAMP.gov and the Marketplace

Policy changes are only part of the 20x transformation. The program is also investing in the tools and resources that agencies and CSPs rely on every day. 

FedRAMP.gov and the Marketplace were redesigned to make it easier to find information, streamline listings, and ensure that outdated content is clearly marked and archived. Retired templates and guidance are preserved at fedramp.gov/legacy, while current requirements live at fedramp.gov/2026.

Key updates include:

  • August 15, 2025: Major Redesign of FedRAMP.gov
    Delivers a new design and reorganized content focused on 20x, with improved navigation and clearer separation of legacy materials.
  • September 30, 2025: Marketplace Redesign
    Refreshes the FedRAMP Marketplace to improve performance, filtering, and integration with FedRAMP.gov.
  • November 30, 2025: External Data-Driven Marketplace
    Moves toward a model where CSPs provide their own Marketplace listing data through secure feeds, reducing manual updates.

Rev5 balance improvements for a smoother transition

For CSPs already authorized under Rev5, the 20x rollout may feel like a major shift. To manage that transition, FedRAMP introduced a series of balance improvement releases. 

These targeted updates allow CSPs to adopt certain 20x elements without undergoing a full reauthorization, simplifying the path forward and ensuring compliance remains manageable. The improvements also help agencies adjust to new expectations while still working with services already in use.

Key efforts include:

  • October 31, 2025: R5.SCN Significant Change Notification BIR
    Tests a streamlined process for reporting significant changes.
  • October 31, 2025: Consolidated R5 Continuous Monitoring Standard
    Clarifies and consolidates existing continuous monitoring requirements.
  • November 30, 2025: Establish DISA ILx One-Way Reciprocity
    Enables services authorized by DISA to be recognized under FedRAMP without duplicating effort.
  • December 19, 2025: R5.ADS Authorization Data Sharing Standard BIR
    Beta test for applying the Authorization Data Sharing Standard to Rev5 authorizations.
  • January 16, 2026: R5.MAS Minimum Assessment Standard BIR
    Tests adoption of the Minimum Assessment Scope for Rev5 authorizations, with FedRAMP signaling potential changes in approach based on limited pilot participation.
  • January 23, 2026: R5.CRS Continuous Vulnerability Management Standard BIR
    Beta test for the Rev5-aligned Continuous Vulnerability Management Standard, which has been reprioritized to align with broader 20x vulnerability management requirements.

The lessons from these releases were carried into CR26, which now governs Rev5 requirements alongside 20x.

What these updates mean if you're already FedRAMP Certified at Class C

If you hold what was a FedRAMP Moderate authorization, now a Class C Certification, CR26 is a signal to reassess how sustainable your current program is. The designation changes are no longer proposals: your certification carries a new label, machine-readable expectations are codified with deadlines, and the January 1, 2027 mandatory adoption date reduces tolerance for static, manually assembled packages.

This is a good moment to evaluate whether your current tooling and processes can support ongoing validation without quarterly scrambles, or whether they rely on institutional knowledge that won't scale under 20x.

What these updates mean if you’re starting from scratch

For CSPs just entering the federal market, FedRAMP 20x narrows the margin for trial and error. Faster paths exist, but they assume operational readiness. Teams that lack clean asset inventory, repeatable evidence collection, or ownership clarity often experience delays that feel surprising given the promise of 20x.

Preparing for FedRAMP 20x: Turning dates into an action plan

FedRAMP 20x is less about reducing paperwork and more about changing how security programs operate day to day. In our experience, teams that succeed under 20x approach authorization as an ongoing capability, not a one-time event. Evidence should be treated as a byproduct of your daily operations, and controls must be designed to hold up under continuous scrutiny.

Automation plays a central role, but it works best when it sits on top of clear ownership, reliable asset inventory, and disciplined change management. When those foundations are in place, continuous validation reduces friction.

At Secureframe, we've been closely involved in shaping and testing the 20x process from the early stages. We participated in the Phase One pilot, achieved our FedRAMP 20x Low Authorization under the new model, and completed the Phase Two pilot to achieve FedRAMP 20x Moderate authorization, now Class C Certification under CR26. This hands-on experience has given us a clear view of readiness, where teams lose momentum, and what it takes to maintain authorization in a model built around continuous validation and transparency.

If you want to be ready for these milestones, start with a readiness assessment that focuses on scope clarity, evidence durability, and operational ownership. To help, we’ve created a FedRAMP Requirements Checklist that breaks down what you need to address at each stage.

Note: This post was originally published in August 2025 and has been updated for accuracy and comprehensiveness.

FedRAMP Requirements Checklist

Get an overview of the technical and security requirements you’ll need to complete to meet the security requirements of the Low, Li-SaaS, Moderate, and High baselines.

Emily Bonnie

Senior Content Marketing Manager

Emily Bonnie is a seasoned digital marketing strategist with over ten years of experience creating content that attracts, engages, and converts for leading SaaS companies. At Secureframe, she helps demystify complex governance, risk, and compliance (GRC) topics, turning technical frameworks and regulations into accessible, actionable guidance. Her work aims to empower organizations of all sizes to strengthen their security posture, streamline compliance, and build lasting trust with customers.

Rob Gutierrez

Senior Cybersecurity and Compliance Manager, CISA, CCSK, CMMC RP

Rob Gutierrez is an information security leader with nearly a decade of experience in GRC, IT audit, cybersecurity, FedRAMP, cloud, and supply chain assessments. As a former auditor and security consultant, Rob performed and managed CMMC, FedRAMP, FISMA, and other security and regulatory audits. At Secureframe, he’s helped hundreds of customers achieve compliance with federal and commercial frameworks, including NIST 800-171, NIST 800-53, FedRAMP, CMMC, SOC 2, and ISO 27001.