If you sell cloud services to the federal government, the language of FedRAMP just changed. And this is not a rebranding exercise. The Consolidated Rules for 2026 (CR26) represent the biggest structural shift in the program's history.
Start with the vocabulary. "FedRAMP Authorization" is retired. The term is now "FedRAMP Certification." This is not cosmetic. FedRAMP owns the assessed evidence. The agency owns the authorization decision. Those two things used to blur together. Now they split cleanly.
The impact levels you've used for years — Low, Moderate, High — are gone. In their place are Classes A through D. Class A covers cloud services with mature security programs entering the federal marketplace. Class B covers low-risk, limited-use services (roughly the old Low and Li-SaaS baselines). Class C covers common enterprise services (the old Moderate). Class D covers the most sensitive systems (the old High), and it's still on the legacy Rev 5 path for now.
The bigger change is how you prove compliance. Under the old model, you wrote a System Security Plan (SSP) — a narrative document describing your controls. That SSP was reviewed in a point-in-time assessment. Then you did a new annual audit to stay current.
FedRAMP 20x replaces that model with continuous, machine-readable evidence. You define Key Security Indicators (KSIs). You validate them automatically. The government pulls your evidence through Open Security Controls Assessment Language (OSCAL) — a standardized, machine-readable format — instead of reading a PDF.
The FedRAMP website says this shift is about "accuracy over paperwork." The program wants providers to share honest, real-time data about their security posture. Not a snapshot of how things looked on assessment day.
For Class B certification under the 20x path, you need at least one automated method per KSI. Class C requires two. Class D requires four — but Class D's 20x path isn't defined yet and remains on Rev 5 through the Phase 5 sunset window.
The transition timeline matters. FedRAMP will stop accepting new Rev 5 certifications on June 11, 2027. If you're starting your FedRAMP journey now, go 20x from day one. If you hold an existing Rev 5 authorization, you have about 10 months to plan your transition.
Your market presence depends on getting this right. Agencies are being trained to ask for "FedRAMP Certified" providers, not "FedRAMP Authorized" ones. The old language already looks dated in RFIs.
Accuracy Review — Post 2
- Confirm class taxonomy mapping (Low→Class B, Moderate→Class C, High→Class D) against fedramp.gov/2026/providers/updating
- Verify "Authorization retired for Certification" language on fedramp.gov/20x
- Verify June 11, 2027 sunset date for Rev 5 certifications
- Confirm KSI automation counts (Class B: 1 method, Class C: 2, Class D: 4) against CR26 rules
- Verify Class D remains on Rev 5 path through Phase 5 — no 20x path currently defined