# FedRAMP 20x Roadmap: Key Dates for the Phased Rollout [August 2026 Update]

> Get a practical breakdown of the FedRAMP 20x roadmap, including August 2026 updates, key milestones, and how CSPs should prepare.

canonical: https://secureframe.com/blog/fedramp-20x-roadmap

Over the past year, [FedRAMP 20x](https://secureframe.com/hub/fedramp) has steadily reshaped federal cloud authorizations. FedRAMP introduced [Phase One](https://secureframe.com/blog/fedramp-20x-phase-one-pilot) and [Phase Two](https://secureframe.com/blog/fedramp-20x-phase-two) pilots, tested a new [Key Security Indicator](https://secureframe.com/hub/fedramp/compliance-requirements)–based assessment model, and began reworking standards around continuous monitoring, vulnerability management, and authorization data sharing.

In [January 2026](https://www.fedramp.gov/2026-01-13-realizing-the-fedramp-authorization-act/), FedRAMP followed that work with a coordinated set of updates, including six new Requests for Comment, the announcement of [Phase Two Moderate pilot participants](https://www.linkedin.com/posts/secureframe_its-official-fedramp-has-selected-all-activity-7417566295258271744-qW3M), and additional guidance tied to the [FedRAMP Authorization Act](https://www.congress.gov/bill/117th-congress/house-bill/21). 

For cloud service providers, the key question is not just what appears on the FedRAMP 20x roadmap, but how these changes affect their compliance efforts. After all, FedRAMP 20x is not just a procedural update to legacy FedRAMP — it represents a fundamental shift in how cloud security is assessed for federal agencies.

## The latest FedRAMP 20x updates: August 2026 

On June 25, 2026, FedRAMP launched the Consolidated Rules for 2026 (CR26), a single stable ruleset that formalizes the FedRAMP 20x requirements, resolves the January Requests for Comment, and makes 20x a widely available certification path for any cloud service provider.

Two changes from CR26 reshape the vocabulary of everything below. "FedRAMP Authorization" is now "FedRAMP Certification," and the Low, Moderate, and High impact levels became Certification Classes B, C, and D, joined by Class A, a new time-limited entry tier. For the full breakdown of what changed, read our guide to [FedRAMP 20x and the 2026 Consolidated Rules](https://secureframe.com/blog/fedramp-20x).

The rollout now runs on published dates:

```
<table style="margin-bottom: 32px; font-family: Assistant, sans-serif; width: 100%; border-collapse: collapse;">
  <thead>
    <tr style="background-color: #0CAB6B;">
      <th style="padding: 1rem; color: #fff; font-weight: bold; text-align: left; font-family: Assistant, sans-serif;">Date</th>
      <td style="padding: 1rem; color: #fff; font-weight: bold; font-family: Assistant, sans-serif;">Milestone</td>
    </tr>
  </thead>
  <tbody>
    <tr style="background-color: #EBE9E5;">
      <th style="padding: 1rem; color: #091922; text-align: left;">June 25, 2026</th>
      <td style="padding: 1rem; color: #091922;">CR26 launches, making FedRAMP 20x widely available</td>
    </tr>
    <tr style="background-color: #F5F4F2;">
      <th style="padding: 1rem; color: #091922; text-align: left;">July 4, 2026</th>
      <td style="padding: 1rem; color: #091922;">CR26 takes effect; mandatory for new 20x certification applications</td>
    </tr>
    <tr style="background-color: #EBE9E5;">
      <th style="padding: 1rem; color: #091922; text-align: left;">July 6, 2026</th>
      <td style="padding: 1rem; color: #091922;">Marketplace listings open for providers in the Initial Implementation Phase</td>
    </tr>
    <tr style="background-color: #F5F4F2;">
      <th style="padding: 1rem; color: #091922; text-align: left;">July 28, 2026</th>
      <td style="padding: 1rem; color: #091922;">FedRAMP Ready retires and becomes "Legacy FedRAMP Ready"</td>
    </tr>
    <tr style="background-color: #EBE9E5;">
      <th style="padding: 1rem; color: #091922; text-align: left;">August 3, 2026</th>
      <td style="padding: 1rem; color: #091922;">FedRAMP 20x Class A pipeline opens</td>
    </tr>
    <tr style="background-color: #F5F4F2;">
      <th style="padding: 1rem; color: #091922; text-align: left;">August 10, 2026</th>
      <td style="padding: 1rem; color: #091922;">Temporary Rev5 pipelines open for eligible Class B and C providers (Ready Conversion and Lost Sponsor paths)</td>
    </tr>
    <tr style="background-color: #EBE9E5;">
      <th style="padding: 1rem; color: #091922; text-align: left;">August 31, 2026</th>
      <td style="padding: 1rem; color: #091922;">FedRAMP 20x Class B and Class C pipelines open</td>
    </tr>
    <tr style="background-color: #F5F4F2;">
      <th style="padding: 1rem; color: #091922; text-align: left;">November 17, 2026</th>
      <td style="padding: 1rem; color: #091922;">Deadline for Rev5 Ready providers to convert to Class A Certification (if their annual assessment hasn't expired)</td>
    </tr>
    <tr style="background-color: #EBE9E5;">
      <th style="padding: 1rem; color: #091922; text-align: left;">January 1, 2027</th>
      <td style="padding: 1rem; color: #091922;">CR26 becomes mandatory for all providers; start of the default grace period</td>
    </tr>
    <tr style="background-color: #F5F4F2;">
      <th style="padding: 1rem; color: #091922; text-align: left;">Q1 to Q2 FY2027</th>
      <td style="padding: 1rem; color: #091922;">FedRAMP 20x Class D (High) pilot expected to begin</td>
    </tr>
    <tr style="background-color: #EBE9E5;">
      <th style="padding: 1rem; color: #091922; text-align: left;">June 11, 2027</th>
      <td style="padding: 1rem; color: #091922;">FedRAMP stops accepting new Rev5 certification applications</td>
    </tr>
    <tr style="background-color: #F5F4F2;">
      <th style="padding: 1rem; color: #091922; text-align: left;">December 31, 2027</th>
      <td style="padding: 1rem; color: #091922;">"Legacy FedRAMP Ready" status removed entirely</td>
    </tr>
    <tr style="background-color: #EBE9E5;">
      <th style="padding: 1rem; color: #091922; text-align: left;">February 1, 2028</th>
      <td style="padding: 1rem; color: #091922;">End of grace period; providers not following CR26 lose their FedRAMP Certification</td>
    </tr>
  </tbody>
</table>
```

As of this update, FedRAMP Ready has retired, the Class A pipeline is open, and the Class B and C pipelines open at the end of August. The window that matters most for planning is January 1, 2027, when CR26 becomes mandatory for every provider, including current Rev5 certifications.

For the canonical schedule, refer to the [official CR26 timeline](https://www.fedramp.gov/2026/timeline/) on FedRAMP.gov.

## The January 2026 RFCs and their outcomes

On January 13, 2026, FedRAMP [released six Requests for Comment](https://www.fedramp.gov/2026-01-13-realizing-the-fedramp-authorization-act/), along with new program updates and Phase Two pilot announcements. 

Each RFC targeted a specific friction point that had historically slowed or complicated FedRAMP adoption. All six were resolved through outcome notices and the Consolidated Rules for 2026, and here's where each landed.

[RFC-0019](https://www.fedramp.gov/rfcs/0019/) focused on reporting assessment costs, proposing requirements to give FedRAMP better visibility into assessment pricing without publicly exposing sensitive cost data. This is the one proposal without a clear landing spot: the CR26 ruleset contains no cost-reporting requirements, so this effort appears to have been deferred or absorbed elsewhere.

[RFC-0020](https://www.fedramp.gov/rfcs/0020/) addressed authorization designations, and its outcome reshaped the program's vocabulary. Rather than the multi-level designation system originally floated, FedRAMP confirmed in February 2026 that "FedRAMP Certification" would replace "FedRAMP Authorization" as the single official label, and that four Certification Classes (A through D) would replace the Low, Moderate, and High impact levels. Class B maps to the former Low baseline, Class C to Moderate, and Class D to High, while Class A is a new time-limited entry tier. For CSPs, the core message stands: certification is no longer a milestone you reach once, but a security posture you sustain continuously.

[RFC-0021](https://www.fedramp.gov/rfcs/0021/) proposed expanding the [FedRAMP Marketplace](https://secureframe.com/hub/fedramp/marketplace), and most of it became CR26 rules. Providers can now be listed early through the Initial Implementation Phase, where they must document continuous progress toward certification at least quarterly and schedule a Class B, C, or D assessment within two years of listing. Assessors and advisory firms are now formally listed in the Marketplace with their own recognition and listing requirements. The pricing transparency piece of the proposal did not make it into the consolidated rules.

[RFC-0022](https://www.fedramp.gov/rfcs/0022/) outlined how FedRAMP would leverage external frameworks, and the outcome was narrower than the proposal. CR26 formalized Class A Certification as the external-framework entry point, initially accepting [SOC 2 Type II](https://secureframe.com/hub/soc-2) as the most widely used framework, with [GovRAMP](https://secureframe.com/blog/govramp) added as a second approved option. Other candidates discussed during the comment period, including ISO 27001 and CMMC Level 2, were not adopted, and FedRAMP has said additional frameworks will be considered incrementally based on demand. FedRAMP has also been explicit that Class A grants no reciprocity: it is a transitory entry point, not a bridge to a full Class B, C, or D Certification.

[RFC-0023](https://www.fedramp.gov/rfcs/0023/) introduced a sponsorless path for certain Rev5 authorizations. That concept is reflected in the temporary Rev5 certification pipelines that opened August 10, 2026, giving eligible Class B and C providers a way forward through the Ready Conversion and Lost Sponsor paths without an agency sponsor.

[RFC-0024](https://www.fedramp.gov/rfcs/0024/) proposed mandatory machine-readable authorization packages for Rev5, and CR26 codified the direction broadly: the rules themselves are published as machine-readable JSON, provider submissions must validate against FedRAMP's published JSON schemas wherever a rule defines one, and agencies are required to maintain tooling that can produce and ingest machine-readable artifacts.

These RFCs marked the shift from planning to locking in how the modernized program functions in practice. Faster reviews assume cleaner submissions, continuous validation assumes operational discipline, and marketplace visibility reflects demonstrable progress. CR26 made all three of those assumptions enforceable.

## How the FedRAMP 20x rollout is structured

The program rollout was structured in two major phases, supported by parallel updates to public tooling and targeted adjustments to legacy Rev5 requirements.

Phase One focused on FedRAMP Low and served as the proving ground for new standards and processes. Phase Two expanded those lessons to FedRAMP Moderate and introduced higher expectations around continuous validation, cryptography, and remediation discipline. At the same time, Marketplace and Rev5 updates reshaped how CSPs signal progress and maintain their status over time. All of this work fed into the Consolidated Rules for 2026.

## Phase one: Modernizing FedRAMP Low

## Phase one: Modernizing FedRAMP Low

Phase One is where FedRAMP began pressure-testing the 20x model in real environments, starting with Low-impact systems. The goal was to see how these changes work in practice, gather feedback, and refine them before rolling them out at scale. 

It was also the first opportunity for CSPs to experience a faster, more automated path to authorization, while still meeting the government’s security requirements. The standards tested here became the foundation for what is now Class B Certification under CR26.

Key milestones include:

- **August 15, 2025: Authorization Data Sharing Standard
**This standard allows CSPs to self-host FedRAMP authorization data, including continuous monitoring materials, without having to upload them to the FedRAMP Secure Repository. It offers more flexibility while keeping agencies informed.
- **August 29, 2025: Finalize FedRAMP 20x Low Authorization Standard
**Consolidates everything learned during the Phase One pilot into official Low authorization guidance for ongoing use.
- **September 4, 2025: Continuous Vulnerability Management Standard
**This standard merges reporting and monitoring into one unified set of requirements. It sets the expectation that CSPs will continuously detect, prioritize, and remediate vulnerabilities using automated systems.
- **September 12, 2025: Federal Information Technical Assistance
**Provides guidance on what qualifies as federal information for the purposes of the Minimum Assessment Scope, helping CSPs determine which data falls under FedRAMP requirements.
- **September 26, 2025: Finalize Key Security Indicators for FedRAMP Moderate
**Updates the metrics used for assessing FedRAMP Moderate authorizations, ensuring that Phase Two launches with clear and measurable expectations.
- **September 26, 2025: Agency Adoption Pilot for 20x Low
**Pairs early-adopting agencies with Phase One authorized CSPs to evaluate how 20x works in practice and identify opportunities for improvement.
- **October 3, 2025: Collaborative Continuous Monitoring Standard
**Introduces a formal structure for joint monitoring between CSPs and agencies, making the process more efficient and collaborative.
- **October 3, 2025: Agency Reuse Playbook for 20x
**Creates a resource for agencies explaining how to review and reuse 20x authorized services without unnecessary duplication of effort.

## Recommended reading

FedRAMP 20x: What’s Changing for CSPs — and What Isn’t

## Phase two: Scaling to FedRAMP Moderate

## Phase two: Scaling to FedRAMP Moderate

Once Phase One established that the 20x model could work at the Low impact level, FedRAMP shifted its focus to scaling those same principles to Moderate authorizations. This phase incorporated lessons learned during the pilot, but it also raised expectations, especially around continuous validation, cryptographic requirements, and modernization of legacy processes like POA&Ms. 

For CSPs, this was where the program moved closer to its vision of a largely automated, continuous authorization process that is faster to achieve and easier to maintain. Phase Two also gave CSPs authorized at Low a smoother transition to Moderate.

Key milestones include:

- **October 31, 2025: Continuous Validation Standard
**Establishes expectations for near real-time validation of security controls, with a target of achieving 80 percent or more validation through automation.
- **October 31, 2025: FIPS Cryptographic Module Application for Commercial Services
**Provides updated guidance on how FIPS 140-3 requirements apply to commercial services, taking a more risk-based approach.
- **November 14, 2025: POA&M Standard
**Updates the decades-old Plans of Action and Milestones process, making it more relevant for modern cloud environments and aligning it with commercial best practices.
- **November 15, 2025: 20xP2 Moderate Pilot Submission and Review Window
**Opens the pilot for Moderate-level authorizations under 20x.
- **December 5, 2025: Finalize FedRAMP 20x Moderate Authorization Standard
**Publishes the final requirements for Moderate authorizations based on pilot results.
- **Expected Q1 to Q2 FY2027: FedRAMP 20x Class D pilot
**With the Moderate standard finalized and folded into CR26, the remaining frontier is Class D, the former High baseline. FedRAMP expects to begin the 20x Class D pilot in the first half of FY2027. Until then, Rev5 is the only path to a Class D Certification, and FedRAMP recommends providers pursue 20x Class C now and plan for Class D when it becomes available.

## Modernizing FedRAMP.gov and the Marketplace

## Modernizing FedRAMP.gov and the Marketplace

Policy changes are only part of the 20x transformation. The program is also investing in the tools and resources that agencies and CSPs rely on every day. 

FedRAMP.gov and the Marketplace were redesigned to make it easier to find information, streamline listings, and ensure that outdated content is clearly marked and archived. Retired templates and guidance are preserved at [fedramp.gov/legacy](https://www.fedramp.gov/legacy/), while current requirements live at [fedramp.gov/2026](https://www.fedramp.gov/2026/).

Key updates include:

- **August 15, 2025: Major Redesign of FedRAMP.gov
**Delivers a new design and reorganized content focused on 20x, with improved navigation and clearer separation of legacy materials.
- **September 30, 2025: Marketplace Redesign
**Refreshes the FedRAMP Marketplace to improve performance, filtering, and integration with [FedRAMP.gov](http://fedramp.gov).
- **November 30, 2025: External Data-Driven Marketplace
**Moves toward a model where CSPs provide their own Marketplace listing data through secure feeds, reducing manual updates.

## Rev5 balance improvements

## Rev5 balance improvements for a smoother transition

For CSPs already authorized under Rev5, the 20x rollout may feel like a major shift. To manage that transition, FedRAMP introduced a series of balance improvement releases. 

These targeted updates allow CSPs to adopt certain 20x elements without undergoing a full reauthorization, simplifying the path forward and ensuring compliance remains manageable. The improvements also help agencies adjust to new expectations while still working with services already in use.

Key efforts include:

- **October 31, 2025: R5.SCN Significant Change Notification BIR
**Tests a streamlined process for reporting significant changes.
- **October 31, 2025: Consolidated R5 Continuous Monitoring Standard
**Clarifies and consolidates existing continuous monitoring requirements.
- **November 30, 2025: Establish DISA ILx One-Way Reciprocity
**Enables services authorized by DISA to be recognized under FedRAMP without duplicating effort.
- **December 19, 2025: R5.ADS Authorization Data Sharing Standard BIR
**Beta test for applying the Authorization Data Sharing Standard to Rev5 authorizations.
- **January 16, 2026: R5.MAS Minimum Assessment Standard BIR
**Tests adoption of the Minimum Assessment Scope for Rev5 authorizations, with FedRAMP signaling potential changes in approach based on limited pilot participation.
- **January 23, 2026: R5.CRS Continuous Vulnerability Management Standard BIR
**Beta test for the Rev5-aligned Continuous Vulnerability Management Standard, which has been reprioritized to align with broader 20x vulnerability management requirements.

The lessons from these releases were carried into CR26, which now governs Rev5 requirements alongside 20x.

## What these latest updates mean for CSPs

## What these updates mean if you're already FedRAMP Certified at Class C

If you hold what was a FedRAMP Moderate authorization, now a Class C Certification, CR26 is a signal to reassess how sustainable your current program is. The designation changes are no longer proposals: your certification carries a new label, machine-readable expectations are codified with deadlines, and the January 1, 2027 mandatory adoption date reduces tolerance for static, manually assembled packages.

This is a good moment to evaluate whether your current tooling and processes can support ongoing validation without quarterly scrambles, or whether they rely on institutional knowledge that won't scale under 20x.

## What these updates mean if you’re starting from scratch

For CSPs just entering the federal market, FedRAMP 20x narrows the margin for trial and error. Faster paths exist, but they assume operational readiness. Teams that lack clean asset inventory, repeatable evidence collection, or ownership clarity often experience delays that feel surprising given the promise of 20x.

## Preparing for FedRAMP 20x

## Preparing for FedRAMP 20x: Turning dates into an action plan

FedRAMP 20x is less about reducing paperwork and more about changing how security programs operate day to day. In our experience, teams that succeed under 20x approach authorization as an ongoing capability, not a one-time event. Evidence should be treated as a byproduct of your daily operations, and controls must be designed to hold up under continuous scrutiny.

Automation plays a central role, but it works best when it sits on top of clear ownership, reliable asset inventory, and disciplined change management. When those foundations are in place, continuous validation reduces friction. 

At Secureframe, we've been closely involved in shaping and testing the 20x process from the early stages. We participated in the Phase One pilot, achieved our [FedRAMP 20x Low Authorization](https://secureframe.com/blog/announcing-fedramp-20x-authorization) under the new model, and completed the Phase Two pilot to achieve [FedRAMP 20x Moderate authorization](https://secureframe.com/blog/announcing-fedramp-20x-moderate-authorization), now Class C Certification under CR26. This hands-on experience has given us a clear view of readiness, where teams lose momentum, and what it takes to maintain authorization in a model built around continuous validation and transparency.

If you want to be ready for these milestones, start with a readiness assessment that focuses on scope clarity, evidence durability, and operational ownership. To help, we’ve created a [FedRAMP Requirements Checklist](https://secureframe.com/compliance-resources/fedramp-requirements-checklist) that breaks down what you need to address at each stage.

*Note: This post was originally published in August 2025 and has been updated for accuracy and comprehensiveness.*

## FedRAMP Requirements Checklist

Get an overview of the technical and security requirements you’ll need to complete to meet the security requirements of the Low, Li-SaaS, Moderate, and High baselines.
