# FedRAMP: What It Is, Who Needs It, and Where to Start

> What FedRAMP is, who needs it, and how to get certified under the 2026 Consolidated Rules, including the 20x and Rev5 paths and where to start.

canonical: https://secureframe.com/blog/fedramp

FedRAMP sets the gold standard for cloud security, and achieving certified status can open up significant growth opportunities in both government and private sectors. Understanding and navigating FedRAMP compliance, however, can be complex and full of questions.

Does your organization need to be FedRAMP compliant? Even if you’re not legally required to comply, what are the benefits of achieving FedRAMP authorization? What does the authorization process entail, and how do you get started? How much resources, time, and money will it take to get FedRAMP compliant? 

This article demystifies FedRAMP authorization and offers practical guidance and best practices for organizations considering compliance.

# What is FedRAMP?

## What is FedRAMP?

The [Federal Risk and Authorization Management Program](https://www.fedramp.gov/) (FedRAMP) is designed to ensure that all cloud services used by US federal agencies meet strict security requirements, mitigating the risk of data breaches and cyber threats. It provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud technologies.

FedRAMP was introduced in 2011 and enacted into law in December 2022 as part of the US National Defense Authorization Act. In 2025 and 2026, the program underwent its most significant redesign since its creation: [FedRAMP 20x](https://secureframe.com/blog/fedramp-20x) replaced the paperwork-heavy legacy model with automated, machine-readable validation, and the Consolidated Rules for 2026 (CR26) brought every requirement into a single ruleset. Under CR26, "FedRAMP Authorized" became "FedRAMP Certified," and the familiar Low, Moderate, and High impact levels became Certification Classes B, C, and D.

The result is a program that remains one of the most rigorous cloud security standards in the world, with a certification path that is faster and more accessible than it has ever been.

### What is the purpose of FedRAMP?

As federal agencies began to replace traditional software with cloud-based solutions, cloud service providers (CSPs) were required to prepare an authorization package for each agency they wanted to work with. Much like[ vendor security questionnaires](https://secureframe.com/blog/security-questionnaire), requirements for these authorization packages were inconsistent, resulting in significant manual and duplicate work for both cloud solutions creating the authorization packages and the agencies reviewing them.

FedRAMP offers a consistent, standardized approach to streamline this process. By using a "do once, use many" framework, FedRAMP enables CSPs and federal agencies to reuse existing security assessments, saving significant time and reducing duplicated efforts.

### Benefits of FedRAMP certification

Cloud service providers with a FedRAMP Certification are listed in the [FedRAMP Marketplace](https://marketplace.fedramp.gov/products), which government agencies use to find cloud-based solutions that already meet federal security requirements. A Marketplace listing makes you much more likely to win business from government agencies, since it's easier for an agency to adopt a certified product than to start the process with a new vendor. The Marketplace has grown dramatically since FedRAMP 20x launched, with more than 650 cloud services listed as of mid-2026, nearly double the count from two years earlier.

Beyond access to the federal market, a FedRAMP Marketplace listing can also give you a significant competitive advantage in the private sector. FedRAMP is a rigorous and respected security standard, so authorization can give current and potential customers the highest confidence in your commitment to meeting stringent cloud security standards.

## The Ultimate Guide to Federal Frameworks

Get an overview of the most common federal frameworks, who they apply to, and what their requirements are.

## Who needs to be FedRAMP compliant?

## Who needs to be FedRAMP compliant?

All cloud service providers that process or store federal data must be FedRAMP certified. 

This requirement extends to organizations that handle federal data, directly or indirectly, through cloud computing environments. It's not only the CSPs that need to be concerned with FedRAMP; federal agencies and state and local governments that use cloud services must also ensure their providers are compliant. In addition, businesses seeking to enter the federal marketplace must achieve FedRAMP certification.

![](https://images.prismic.io/secureframe-com/65d4182a6df829d21997f7b1_FedRAMPCompliant%402x.png?auto=format,compress)

## FedRAMP requirements

## FedRAMP requirements

What FedRAMP requires of you now depends on which certification path you take. Under the Consolidated Rules for 2026, there are two: the modern 20x path built on automated validation, and the legacy Rev5 path, which accepts new applications until June 11, 2027.

#### FedRAMP 20x requirements: Key Security Indicators

The 20x path replaces control-by-control narrative documentation with 46 Key Security Indicators (KSIs) organized into 10 families:

1. Cloud Native Architecture
2. Service Configuration
3. Identity and Access Management
4. Monitoring, Logging, and Auditing
5. Policy and Inventory
6. Change Management
7. Recovery Planning
8. Incident Response
9. Supply Chain Risk
10. Cybersecurity Education

Each KSI is a specific, measurable security outcome that maps back to NIST 800-53 controls, and providers demonstrate them through automated, machine-readable evidence rather than written descriptions. Many KSIs must be validated "persistently," meaning continuously verified from the production environment rather than checked once at assessment time. For a full breakdown, see our guide to [FedRAMP Key Security Indicators](https://secureframe.com/hub/fedramp/key-security-indicators-ksi).

#### FedRAMP Rev5 requirements: NIST 800-53 baselines

The Rev5 path is a derivative of [NIST Special Publication 800-53](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final) and uses its control baselines, adding FedRAMP-specific parameters and additional control requirements. The baselines were historically labeled Low, Moderate, and High; under CR26, those became Certification Classes B, C, and D, with Class B having the fewest controls and Class D the most controls and strictest parameters.

There is also a privacy control baseline applied to systems of every class. If a CSP processes personally identifiable information (PII), for instance, it must implement controls assigned to the privacy control baseline.

Rev5 requirements are broken down into 18 control families based on NIST 800-53 Rev. 5:

1. Access Control
2. Awareness and Training
3. Audit and Accountability
4. Security Assessment and Authorization
5. Configuration Management
6. Contingency Planning
7. Identification and Authentication
8. Incident Response
9. Maintenance
10. Media Protection
11. Physical and Environmental Protection
12. Planning
13. Personnel Security
14. Risk Assessment
15. System and Services Acquisition
16. System and Communication Protection
17. System and Information Integrity
18. Supply Chain Risk Management (new with Revision 5)

## Recommended reading

FedRAMP 20x: Goals, Timeline, and the 2026 Consolidated Rules

## The FedRAMP certification process

## Understanding the FedRAMP certification process

Here's an overview of the FedRAMP certification process under the Consolidated Rules for 2026:

### Step 1. Determine your security categorization and target class

Start by understanding what kind of federal data your service will handle. The [FIPS 199 assessment](https://nvlpubs.nist.gov/nistpubs/fips/nist.fips.199.pdf) involves three main steps:

**1. Identification of information types:** Identify the types of information your system processes, stores, or transmits, such as personally identifiable information (PII), financial data, or proprietary information.

**2. Categorization based on potential impact:** Each type of information is categorized based on the potential impact to the organization if confidentiality, integrity, or availability were compromised: limited adverse effect, serious adverse effect, or severe and catastrophic adverse effect.

**3. System categorization:** The system is categorized based on the highest impact level among the information types it handles. If a system processes information at both the lowest and highest categories, the system as a whole takes the highest.

This categorization maps to the FedRAMP Certification Class you'll pursue. Under CR26, Class B corresponds to the former Low baseline, Class C to Moderate, and Class D to High. One important nuance: a class describes the scope and depth of the FedRAMP assessment, and the agency using your service makes the final determination about whether your certification fits their security category and use case.

There's also Class A, a time-limited entry tier that doesn't map to an impact level. Providers with a SOC 2 Type II or GovRAMP assessment completed within the past 12 months can use it to enter the Marketplace while working toward a full certification.

### Step 2. Choose your certification path: 20x or Rev5

CR26 defines two paths to FedRAMP Certification. 

FedRAMP 20x is the modern path, built on automated validation of the 46 Key Security Indicators, machine-readable evidence, and continuous monitoring. It requires no agency sponsor: providers apply directly through Program Certification. This is the recommended path for cloud-native services, and it will eventually be the only path.

FedRAMP Rev5 is the legacy agency-sponsored path, now governed by CR26 rules and accepting new applications only until June 11, 2027. It remains the right choice in three situations: you're already working through a sponsored authorization, you run your own infrastructure rather than a cloud-native architecture, or you need a Class D (High) certification, since the 20x path for Class D is still in development. Even in that last case, FedRAMP recommends pursuing 20x at Class C now and planning for Class D when it becomes available.

Whichever path you choose, all certifications are governed by the same consolidated ruleset, and Rev5 providers are expected to transition to 20x over time. For a full comparison, read our guide to [FedRAMP 20x and the 2026 Consolidated Rules](https://secureframe.com/blog/fedramp-20x).

### Step 3. Prepare your documentation and evidence

What you prepare depends on your certification path.

On the 20x path, the traditional System Security Plan is replaced by the Security Decision Record (SDR), a persistently maintained record of the security decisions you've made across the lifecycle of your service, supplied in both human-readable and JSON formats. Alongside the SDR, you'll produce machine-readable evidence demonstrating each applicable Key Security Indicator, validated automatically from your production environment wherever possible. Certification data, including your policies and procedures, is stored and shared through a FedRAMP-compatible trust center, which serves as the definitive source for your certification package. Wherever FedRAMP publishes a JSON schema for a deliverable, your submission must validate against it.

On the Rev5 path, you'll prepare the legacy documentation package: policies and procedures, a configuration management plan, a contingency plan, an incident response plan, a supply chain risk management plan, a continuous monitoring plan, and a Plan of Action and Milestones (POA&M) tracking known findings and remediation. One change under CR26 applies even here: a streamlined Certification Package Overview replaces the historically required base System Security Plan.

Whichever path you take, thorough preparation matters, and many CSPs work with assessors and consultants to confirm their documentation accurately reflects their security posture before assessment begins.

### Step 4. Complete your independent assessment

Independent assessment is required on both paths. 

Providers pursuing Class B, C, or D Certifications must complete an independent verification and validation assessment of all applicable FedRAMP rules with a FedRAMP Recognized assessor at least once per year, starting with the initial certification. Verification confirms your documented measures are implemented; validation confirms they're working effectively.

What the assessor reviews differs by path. On Rev5, the assessment follows the traditional model: a Security Assessment Plan defines the scope and methodology, the assessor tests your controls, and a Security Assessment Report documents the findings. 

On 20x, the assessor verifies that your automated evidence pipelines work as intended and that your KSI validations accurately reflect your production environment. 

In both cases, you are responsible for the accuracy and completeness of everything you submit. The assessor's role is to verify and validate it.

### Step 5. Submit your package and get certified

On the 20x path, you apply directly to FedRAMP through Program Certification, with no agency sponsor required. Marketplace listings are available even during the initial implementation stage, so agencies can see you're on the path before certification is complete.

On the Rev5 path, your sponsoring agency reviews your package, conducts its risk analysis, and issues an Authority to Operate based on its risk tolerance. Your certification then becomes reusable: other agencies can leverage your existing package to make their own authorization decisions, which is the "do once, use many" principle at the heart of the program.

### Step 6. Maintain certification

FedRAMP Certification is ongoing, and CR26 defines a maintenance rhythm that applies across paths:

- **Quarterly Ongoing Certification Reports (OCRs):** Every three months, you'll supply a report summarizing changes, planned changes, accepted vulnerabilities, transformative changes, updated recommendations, agencies using the product, and any FedRAMP Reportable Incidents (or an attestation that none occurred).
- **Quarterly Reviews:** Class C and D providers must host a synchronous review each quarter to walk agency customers through the most relevant changes. Class B providers are encouraged to.
- **Significant Change Notifications (SCNs):** When you change your service, you notify stakeholders rather than seeking pre-approval, with changes classified as adaptive, routine recurring, or transformative, and 12 months of notification history kept available.
- **Vulnerability management:** Vulnerability detection and response activity must be reported at least monthly, with detection running continuously against your environment.
- **Annual independent assessment:** The yearly verification and validation assessment from Step 4 continues for as long as you hold the certification.

## Recommended reading

FedRAMP 20x Continuous Monitoring Requirements: What’s Changed, What Hasn’t, and Where Teams Can Get Stuck

## Tips for getting started with FedRAMP compliance

## Tips for getting started with FedRAMP compliance

Embarking on the journey to FedRAMP compliance can be a daunting task, but learning about the process and following best practices can make compliance much more manageable.

Here are some essential tips and best practices for organizations that are just getting started with FedRAMP compliance:

### Thoroughly understand requirements for your certification path

Familiarize yourself with the Consolidated Rules for 2026, which define every FedRAMP requirement in plain MUST and MUST NOT language and are published as machine-readable data on GitHub. If you're pursuing 20x, study the 46 Key Security Indicators and the NIST 800-53 controls they map to. If you're on the Rev5 path, focus on the NIST SP 800-53 baseline for your target class.

### Perform a gap analysis to understand how your current environment aligns with FedRAMP 

This gap analysis should cover all aspects of your cloud service, from data encryption and user authentication to incident response and risk management practices. The outcome will provide a clear roadmap for bridging any gaps and ensuring your services are fully compliant with FedRAMP standards.

### Secure support and commitment across your organization

Achieving FedRAMP compliance is a significant endeavor that requires a concerted effort across your organization. It's essential to garner support and commitment from both the executive leadership and the technical teams responsible for implementing the necessary changes. It can be a costly endeavor, so we recommend doing a budget and resource analysis to ensure feasibility and preparedness for the assessment and process.

This involves educating stakeholders about the value and implications of FedRAMP compliance, including the potential for expanded business opportunities within the federal market and the overall enhancement of your security posture. Establishing a cross-functional team dedicated to achieving compliance can facilitate collaboration and ensure that all efforts are aligned with your organization's goals.

### Decide whether you need an agency sponsor 

One of the biggest changes under FedRAMP 20x is that an agency sponsor is no longer required. Providers on the 20x path apply directly through Program Certification, which removes what was historically the single hardest prerequisite for smaller CSPs entering the federal market.

An agency sponsor is still required on the Rev5 path. If that's your route, partnering with a federal agency that currently uses your service or is committed to adopting it can significantly streamline the process, provide insight into agency-specific security concerns, and add credibility to your application. Engage early and often with potential agency partners to build the relationship and secure commitment.

Even on the 20x path, building agency relationships matters: agencies make the final decision about using your service, and the certification model expects direct, ongoing communication with your agency customers through quarterly reporting and reviews.

### Carefully define your system boundaries

A critical step in the FedRAMP compliance process is accurately defining the boundaries of your cloud system. This includes:

- **Internal Components:** Identifying all elements within your cloud service, from infrastructure and applications to data storage and processing units, ensuring that security controls are uniformly applied.
- **External Service Connections:** Cataloging all connections to external services and third-party providers, assessing the security implications of these integrations, and ensuring they do not compromise your compliance posture. If you don't have on-premise components and rely on cloud services such as AWS, Azure, or Google Cloud Platform, there may be areas of shared responsibility or inheritance for controls.
- **Data and Metadata Flows:** Mapping out the flow of data and metadata within and outside your system to understand potential vulnerabilities and apply appropriate security measures. This comprehensive understanding of your system's boundaries is essential for implementing effective security controls and for documenting your security posture in your certification package. [FedRAMP’s Minimum Assessment Scope rules](https://www.fedramp.gov/2026/reference/20x/c/minimum-assessment-scope/), formalized during the 20x rollout, give providers clearer guidance for narrowly defining information resource boundaries while still capturing all necessary components.

### Approach FedRAMP as an ongoing commitment 

FedRAMP compliance is not a one-time achievement.  It’s an ongoing, continuous commitment to maintaining high security standards. It requires regular monitoring, updating security controls, and periodic reassessments to adapt to evolving threats and changes in your cloud services and threat landscape. 

Under CR26, quarterly Ongoing Certification Reports, annual independent assessments, and continuous vulnerability monitoring are standing requirements for every certified provider. Adopting a mindset that treats FedRAMP as an integral part of your operational processes will help you stay compliant and secure over time.

### Use FedRAMP resources

The FedRAMP Program Management Office (PMO) remains an essential resource, though how you engage with it has changed. FedRAMP has revived [help.fedramp.gov](https://help.fedramp.gov) as its central repository of guidance, FAQs, and articles, and it is shifting intake from the shared [info@fedramp.gov](mailto:info@fedramp.gov) inbox toward structured request forms that route questions more consistently. Retired templates and legacy guidance are preserved at [fedramp.gov/legacy](https://www.fedramp.gov/legacy/) for reference, while current requirements live in the Consolidated Rules at [fedramp.gov/2026](https://www.fedramp.gov/2026/).

Engaging with these resources early and often can help you navigate the process, avoid common pitfalls, and develop a successful strategy for achieving and maintaining certification. FedRAMP also runs public community working groups and monthly community updates, which are the best window into how requirements are being interpreted in practice.

## FedRAMP Compliance Checklist

Get a step-by-step checklist to walk you through the process of preparing for FedRAMP authorization.

# Streamline FedRAMP compliance with automation

## How to streamline FedRAMP compliance with automation + AI

Because it's a rigorous standard, achieving FedRAMP certification requires a significant amount of time and resources. On the 20x path, you'll need to stand up automated evidence collection, validate your Key Security Indicators, and maintain machine-readable certification data. On the Rev5 path, you'll complete a gap analysis and readiness work, implement NIST 800-53 controls for your target class, and collect documentation and evidence for your assessor. And once certified, every provider maintains compliance through quarterly reporting, continuous monitoring, and annual assessments.

Cybersecurity platforms like [Secureframe Defense](https://secureframe.com/cmmc) can significantly cut down on the amount of time and effort it takes to complete these manual tasks, freeing up your team to focus on strategic objectives. 

Here are a few reasons organizations choose Secureframe as their partner for achieving and maintaining compliance with federal frameworks: 

- **Government and federal compliance expertise:** Secureframe achieved FedRAMP 20x certification through both the Phase One (Low) and Phase Two (Moderate) pilots, so our platform and guidance reflect direct experience with the new model.
- **Integrations with federal cloud products:** Secureframe integrates with your existing tech stack, [including AWS GovCloud](https://secureframe.com/blog/aws-govcloud-integration), to automate infrastructure monitoring and evidence collection.
- **Trusted 3PAO partner network**: Secureframe has strong relationships with certified Third Party Assessment Organizations like Schellman and Prescient Assurance, and can support FedRAMP and other federal audits such as CMMC and CJIS. 
- **Cross-mapping across frameworks**: FedRAMP and NIST 800-53 have many overlapping requirements with NIST 800-171, CJIS, and other federal frameworks. Instead of starting from scratch, our platform can help map what you’ve already done for FedRAMP to other frameworks so you’re never duplicating efforts. 
- **Continuous monitoring**: By monitoring your tech stack 24/7 to alert you of non-conformities, Secureframe makes it easier to maintain continuous compliance and a strong security posture. You can specify test intervals and notifications for required regular tasks to maintain FedRAMP compliance. You can also use our Risk Register and Risk Management capabilities to support your continuous monitoring efforts and POA&M maintenance. 

To learn more about how Secureframe can help you comply with FedRAMP and other federal frameworks, [schedule a demo](https://secureframe.com/request-demo) with a product expert.

*Note: This post was originally published in February 2024 and has been updated for accuracy. *

### Use trust to accelerate growth

### What is FedRAMP in simple terms?

FedRAMP is a government-wide program that sets security standards for cloud services used by the U.S. government. You can think of it as a security checkpoint that cloud services must pass to work with federal government agencies.

### What does FedRAMP stand for?

FedRAMP stands for the Federal Risk and Authorization Management Program.

### Is FedRAMP mandatory?

FedRAMP authorization is mandatory for cloud service providers (CSPs) that want to work with federal agencies.

### Who needs to be FedRAMP certified?

Cloud service providers that offer services to U.S. federal agencies need to be FedRAMP certified. This can include Software-as-a-Service (SaaS), Infrastructure-as-a-Service (IaaS), and Platform-as-a-Service (PaaS) providers that handle government data.

### Is FedRAMP only for government?

While FedRAMP is designed for government use, its rigorous standards are often adopted by private sector companies seeking to enhance their cloud security posture, especially those wishing to do business with the government.

### Who governs FedRAMP?

FedRAMP is governed by the FedRAMP Board, established in 2024 to replace the Joint Authorization Board. Its members include chief information officers from the Department of Homeland Security (DHS), Department of Defense (DoD), Department of Veterans Affairs, Department of the Air Force, Cybersecurity and Infrastructure Security Agency (CISA), Federal Deposit Insurance Corporation (FDIC), and General Services Administration (GSA). The General Services Administration administers the program.

### What is the difference between NIST and FedRAMP?

NIST (National Institute of Standards and Technology) creates a wide range of security standards and guidelines, including those for cybersecurity. FedRAMP is a program that applies NIST's security standards specifically to cloud services used by the federal government, adding a layer of requirements and processes for authorization and continuous monitoring. Essentially, FedRAMP builds on NIST standards to ensure cloud services meet the specific needs of federal agencies.

### What are the three levels of FedRAMP?

FedRAMP historically used three impact levels: Low, Moderate, and High.  Under the Consolidated Rules for 2026, those became Certification Classes B, C, and D respectively, joined by Class A, a new time-limited entry tier for providers with a recent SOC 2 Type II or GovRAMP assessment.

### Is GovCloud required for FedRAMP certification?

Only for Class D (the former High baseline). Many organizations pursuing Class C (formerly Moderate) use GovCloud because they want to or because their agency customers require it. GovCloud is not required for Class B.

### What is FedRAMP 20x?

FedRAMP 20x is the modernized certification path introduced in 2025 and formalized in the Consolidated Rules for 2026. It replaces narrative documentation and point-in-time audits with 46 Key Security Indicators validated through automated, machine-readable evidence, and it requires no agency sponsor. It is the recommended path for cloud-native providers and will eventually replace the legacy Rev5 process entirely.

### What's the difference between FedRAMP Authorized and FedRAMP Certified?

They describe the same status under different names. The Consolidated Rules for 2026 retired "FedRAMP Authorized" in favor of "FedRAMP Certified" for every provider in the Marketplace, with no change to controls or boundaries. The rename clarifies that a FedRAMP Certification is FedRAMP's validation of a provider's security information, distinct from the Authority to Operate that each agency issues for its own use of the service.
