Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

The FedRAMP authorization checklist for 2026

The FedRAMP authorization checklist under the Consolidated Rules for 2026: four certification classes, Program vs Agency paths, and the deadlines that bind.

Rendered from FedRAMP Consolidated Rules for 2026 version 2026.07.14.01 · dataset last updated 2026-07-14
In short
  • FedRAMP authorization is called FedRAMP Certification under the Consolidated Rules for 2026, and it comes in four classes.
  • You may no longer need a sponsoring agency. Program Certification is applied for directly; Agency Certification still requires a signed ATO letter from a sponsor.
  • Pick one path per offering. The rules forbid seeking both Rev5 and 20x Program Certification for the same cloud service, and FedRAMP plans to stop accepting new Rev5 certifications on June 11, 2027.
  • Scope is not a single number. The three classes that carry a Rev5 baseline owe 155 controls (class B), 322 controls (class C) and 409 controls (class D).

What FedRAMP authorization is called in 2026

FedRAMP authorization is now FedRAMP Certification. The Consolidated Rules for 2026 define four certification classes and two routes to each: Program Certification, which a provider applies for directly, and Agency Certification, which requires a sponsoring agency. Rev5 and 20x run in parallel until FedRAMP stops accepting new Rev5 certifications.

This matters for a checklist because the first step changed. Under the legacy path, a provider without a sponsoring agency had nothing to do but go find one. FedRAMP’s 2026 certification rules state that a provider seeking Program Certification must not use a third party to apply on their behalfand must already be listed in the FedRAMP Marketplace before applying — two requirements that describe a self-service route, not a sponsored one.

The dataset behind this page is FedRAMP’s own: FedRAMP Consolidated Rules for 2026, version 2026.07.14.01, last updated 2026-07-14. It carries 246 requirements across 17 documents, and 46 Key Security Indicators grouped into 10 themes.

Which certification class do you owe?

Class determines your entire workload, and the classes are not evenly sized. Each row below is the Rev5 control baseline the rules assign to that class, split by whether any Key Security Indicator reaches the control — because the controls no indicator reaches are the ones you will be writing by hand rather than fetching.

ClassCommonly read asBaselineReached by a KSINarrative
Class BLow1559560
Class CModerate322199123
Class DHigh409199210
Class ANo Rev5 baseline — an absence the rules state, not a zero.

“Commonly read as” is an interpretation, not a dataset fact: the Consolidated Rules never say Low, Moderate or High. They say class B, C, D. Treat the mapping as a translation aid for readers arriving from Rev5 vocabulary, and cite the class.

Program Certification or Agency Certification?

Program Certification needs no agency sponsor; Agency Certification does. That is the whole decision, and it is the one that determines whether your timeline depends on another organisation’s calendar. FedRAMP’s certification rules attach different evidence-freshness requirements to each route.

Program Certification

No sponsor. You apply directly — the rules forbid a third party applying for you. Requires a Marketplace listing first, and a certification package the provider verified and validated within the previous 7 days. Class B certification additionally requires a FedRAMP independent assessment from within the previous 3 months.

Agency Certification

A sponsoring agency completes its ATO process and sends a formal signed ATO letter to FedRAMP over official government channels. The legacy Rev5 route: optional FedRAMP Ready designation, then pre-authorization, then 3PAO assessment, then FedRAMP review.

One constraint applies to both, and it is easy to trip over while hedging: providers must not seek both FedRAMP Rev5 Program Certification and FedRAMP 20x Program Certification for the same cloud service offering. Choose per offering.

The checklist

In dependency order. Each step links to the slice of the rules that answers it, so the checklist is navigable rather than merely readable. The worked figures use class C because it is the most commonly scoped; substitute your own class in any link.

  1. Decide your certification class

    Class sets the size of everything downstream. Compare the three baselines side by side on coverage & orphans, or read one class end to end on its baseline enumeration. Class A carries no Rev5 baseline at all.

  2. Choose Rev5 or 20x — not both

    The rules forbid seeking both Program Certifications for one offering. FedRAMP plans to stop accepting new Rev5 certifications on June 11, 2027, which makes 20x the default for work starting now.

  3. Choose Program or Agency Certification

    Program if you can carry your own package and want no dependency on an agency calendar; Agency if you already have a sponsor willing to issue an ATO. See the comparison above.

  4. Get listed in the FedRAMP Marketplace

    The rules require a Marketplace listing before applying for certification. Doing this late stalls an otherwise finished package.

  5. Scope the baseline you actually owe

    Class C carries 322 controls across 18 families, of which 80 fall in the annual independent-assessment subset. Do not assume the classes nest: they do not.

  6. Map the Key Security Indicators to your controls

    The 46 indicators reach 209 distinct controls between them, and they are not evenly weighted. Walk the mapping both ways on the crosswalk, and see which indicators carry the most control footprint on indicator weight.

  7. Build the evidence plan

    Group the work by KSI theme rather than by control id — one configuration fetch usually proves several controls. The class C plan organises 64 authored AWS recipes across 9 themes, covering 94of the class’s controls.

  8. Write down what no API can prove

    123 of class C’s controls are reached by no indicator. No telemetry maps to them, so they stay narrative in your Security Decision Record. The narrative register names every one. Media Protection and Physical and Environmental Protection are whole families in this category.

  9. Assemble the artifacts every requirement owes

    Each FRR requirement owes 5 default artifacts and each KSI indicator owes 5, stated once at dataset level rather than repeated per rule. The evidence planner deduplicates them into a real worklist.

  10. Set the clocks before you need them

    The rules carry 68timeframed entries, and the units are never converted for display — a deadline stated in business days is not a deadline in days. The obligation clock lists every one, including the notification deadlines that start running on incident discovery.

  11. Book the independent assessment to the freshness window

    Freshness is a rule, not a courtesy. A Program Certification package must have been verified and validated by the provider within the previous 7 days, and a Class B independent assessment must be from within the previous 3 months. Schedule the assessment against the application date, not the other way round.

  12. Apply directly

    No third party may apply on your behalf. Confirm the package is complete against the class’s readiness pack before submitting.

  13. Keep collecting after authorization

    20x replaces the annual audit with continuous KSI validation, so collection is the steady state rather than the finish line. Each of the 51 recipes in the collection index states its own cadence, the AWS calls that satisfy it, and an honest rating of how much of it actually automates.

The dates FedRAMP has announced

These are programme dates — when a pipeline opens, when a path closes — and FedRAMP publishes them on its own timeline rather than in the rules. They are authored here, each with the page it was read from and the day it was read, and they are versioned separately from the dataset for the same reason a recipe’s citation is: a claim about somebody else’s programme has an edition.

  1. 2026-07-0420x · Rev5

    Optional early adoption opens — stakeholders may begin transitioning to the 2026 Consolidated Rules.

    fedramp.gov timeline · read 2026-08-27

  2. 2026-07-28Rev5

    FedRAMP Ready goes legacy — no new FedRAMP Ready submissions are accepted; providers are directed to Class A instead.

    fedramp.gov timeline · read 2026-08-27

  3. 2026-08-0320x

    The FedRAMP 20x Class A pipeline opens — applications for Class A Certifications begin.

    fedramp.gov timeline · read 2026-08-27

  4. 2026-08-10Rev5

    Temporary Rev5 Program Certification pipelines open for eligible Class B and Class C providers, through the Ready Conversion and Lost Sponsor paths.

    fedramp.gov timeline · read 2026-08-27

  5. 2026-08-3120x

    The FedRAMP 20x Class B and Class C pipelines open — applications for Class B and C Certifications begin.

    fedramp.gov timeline · read 2026-08-27

  6. 2027-01-0120x · Rev5

    Mandatory adoption — the Consolidated Rules for 2026 take effect for all stakeholders, and a provider must follow them to obtain or maintain a Certification.

    fedramp.gov timeline · read 2026-08-27

  7. 2027-06-11Rev5

    End of new Rev5 Certifications — FedRAMP stops accepting new Rev5 applications.

    fedramp.gov timeline · read 2026-08-27

The dates the rules actually state

The 2026 rules do not switch on in one day. Every rules document carries its own rollout — a date providers mayadopt it, a date they must have obtained certification under it, a date they must maintain it from, and a date the grace period ends — and the dates differ by document and by certification type. Below is every distinct milestone date in the dataset.

DateWhat falls dueApplies toEntries
2026-01-05must obtain by, must maintain byall2
2026-03-01must obtain by, must maintain byall2
2026-07-01grace endsall2
2026-07-04must obtain by, must maintain by, may adopt, grace endsall20xrev544
2026-12-07must obtain by, must maintain byall4
2027-01-01must maintain by, grace ends, must obtain by20xrev540
2027-03-07grace endsall2
2027-04-02must maintain byrev51
2027-06-01grace endsrev53
2027-07-01must maintain byrev51
2027-08-01must maintain by, grace endsrev53
2027-10-01grace endsrev51
2028-02-01grace endsrev51

“Entries” counts document-and-rule pairs falling on that date, not distinct documents — obtain and maintain frequently share one date for one document. The obligation clock breaks each row down by document.

Where this checklist stops being automatable

A checklist that implies all of FedRAMP can be fetched will get its reader caught over-claiming in an assessment. Across the three baselines, 60 of class B’s 155, 123 of class C’s 322 and 210 of class D’s 409 controls are reached by no Key Security Indicator. That residue is not a gap in this dataset; it is the writing workload the rules leave to a person, and it is stated rather than hidden.

The same honesty applies to the AWS recipes: each one carries a rating of how much of it a machine can actually do, and some are marked narrative precisely because no API call proves them. Read the residue per class in the narrative register.

Frequently asked questions

Does FedRAMP authorization still require an agency sponsor?
No. The Consolidated Rules for 2026 define Program Certification, which a provider applies for directly with no agency sponsor. Agency Certification remains available and still requires a sponsoring agency to send a signed ATO letter to FedRAMP over official government channels. A provider picks one route per cloud service offering.
Can I pursue both Rev5 and 20x certification at once?
No. The rules state that providers must not seek both FedRAMP Rev5 Program Certification and FedRAMP 20x Program Certification for the same cloud service offering. Pick one path per offering. FedRAMP plans to stop accepting new Rev5 certifications on June 11, 2027, so new work increasingly points at 20x.
What are the FedRAMP certification classes?
The 2026 rules define four: Class A, Class B, Class C and Class D. Three of them carry Rev5 control baselines and are commonly read as Low, Moderate and High — a reading, not something the rules say. Class A carries no Rev5 baseline at all.
How long does FedRAMP authorization take?
FedRAMP publishes no guaranteed timeline, so the pilot record is the best available evidence. The 20x Phase One Low pilot ran from April to September 2025. The Phase Two Moderate pilot ran from November 18, 2025 to March 2026, with the first cohort authorized on March 6, 2026.
Which FedRAMP evidence cannot be automated?
Every class baseline contains controls that no Key Security Indicator reaches. Those stay narrative — written by a person into a Security Decision Record rather than fetched by an API call. Media Protection and Physical and Environmental Protection are whole families present in every baseline that no indicator touches.
When do the FedRAMP 2026 rules take effect?
Each rules document carries its own rollout: an optional adoption date, an obtain date, a maintain date and a grace date, and they differ by document and by certification type. The calendar in this dataset runs from January 2026 into 2028, and the checklist above renders every date in it.