FedRAMP 20x vs Rev 5: Requirements, Timeline and the CR26 Classes
FedRAMP 20x is now the default path and Rev 5 closes to new applications in June 2027. Here is the real difference between them, the CR26 timeline, the new Certification Classes A through D, and how to choose.
By the Scrutineer team
July 2026 · 10 min read
Last updated July 2026. FedRAMP 20x is now the default path, and Rev 5 is on a published runway to retirement. The Consolidated Rules for 2026 (CR26) took effect in early July 2026 and become mandatory for everyone on January 1, 2027. They also renamed the program's core terms: a FedRAMP Authorization is now a FedRAMP Certification, and the Low, Moderate and High impact levels are now Certification Classes A through D. FedRAMP has said it will stop accepting new Rev 5 applications in June 2027, with Rev 5 certifications sunsetting by the end of 2028.
If you are starting a federal authorization effort today, the practical answer is that 20x is where the program is going and where the shorter runway is. If you are already deep in a Rev 5 package, you are not stranded, but you should know the date your path closes. Here is the actual difference between the two, the timeline, and how to choose.
What is the difference between FedRAMP 20x and Rev 5?
Rev 5 is built around audit-day proof. FedRAMP 20x is built around everyday proof. Under Rev 5 you write a narrative description for every control in your baseline, assemble a System Security Plan that frequently runs to hundreds of pages, and demonstrate it to an assessor during a defined window. Under 20x you satisfy a much shorter list of Key Security Indicators, and you are expected to prove them with automated, machine-readable evidence that keeps running after the assessment ends.
| Dimension | FedRAMP Rev 5 | FedRAMP 20x |
|---|---|---|
| Unit of compliance | NIST SP 800-53 controls, written up individually | Key Security Indicators (KSIs), validated by evidence |
| Scale | About 156 controls at Low, 323 at Moderate, 410 at High | Dozens of indicators rather than hundreds of narratives |
| Evidence model | Documentation and point-in-time testing | Automated, continuously produced, machine-readable |
| Agency sponsor | Normally required before you begin | Not required on the Program path |
| Who signs | The sponsoring agency | The FedRAMP Director, on the Program path |
| Reusability | Reusable by other agencies after authorization | Reusable, and reachable without a sponsor first |
| Status | Closing: no new applications after June 2027 | Generally available since June 2026 |
The sponsor change deserves more attention than it usually gets. Under the traditional model, a cloud vendor had to persuade a federal agency to sponsor its authorization before any of the work counted, which meant selling to an agency that could not legally buy from you yet. The 20x Program path removes that circular problem. FedRAMP itself assesses your posture and the result is reusable by any agency, which opens the market to a much larger pool of SaaS companies.
What are the FedRAMP 20x requirements?
The core requirement is that you can demonstrate each Key Security Indicator with evidence a machine can read, and that the demonstration keeps working. KSIs group into families covering areas like cloud-native architecture, service configuration, identity and access management, monitoring and logging, incident response, third-party information resources and change management. Reported counts from the Phase 2 pilot were 56 indicators at the Low baseline and 61 at Moderate.
Automation is not optional flavor text here. Phase 2 pilot participants were expected to automate roughly 70 percent of their evidence, and the direction of travel is toward more. That is the single biggest practical shift for engineering teams: the artifact you owe FedRAMP is no longer a well-written paragraph, it is a working pipeline that emits proof about your production environment on a schedule.
In most stacks the evidence already exists somewhere. Identity events are in your IdP, change records are in your ticketing system, configuration state is in your cloud provider's API, and vulnerability data is in your scanner. The work is connecting those systems and APIs so they emit structured output instead of screenshots, then attaching each output to the indicator it actually proves. Teams that skip this step end up automating a screenshot factory, which satisfies nobody.
What is the FedRAMP 20x timeline?
The program moved through pilots before opening up. Phase 1 tested the KSI concept at the Low baseline. Phase 2 ran from November 2025 to the end of March 2026 and extended the model to Moderate, with the first cohort receiving pilot authorizations on March 6, 2026. Phase 3, the wide-adoption phase, is where the program sits now.
| Date | What happens |
|---|---|
| March 6, 2026 | First Phase 2 pilot authorizations issued at the Moderate level |
| May 4, 2026 | Public preview of the Consolidated Rules for 2026 opens |
| Late June 2026 | CR26 finalized and published |
| July 2026 | CR26 effective, optional early adoption begins |
| January 1, 2027 | CR26 becomes mandatory for all stakeholders |
| June 2027 | FedRAMP stops accepting applications for new Rev 5 certifications |
| December 31, 2028 | Rev 5 certifications sunset, and the CR26 ruleset itself expires |
Two dates matter most for planning. January 1, 2027 is when the new rules and terminology stop being optional, so any customer-facing material, trust page or RFP boilerplate that says "FedRAMP Authorized" has a deadline attached to it. June 2027 is the real fork: after that, Rev 5 is closed to new entrants and 20x is the only way in.
What are the FedRAMP certification classes?
CR26 retired the FIPS 199 impact-level names in favor of Certification Classes, partly to avoid confusion with Defense Department system levels. Class A is a new baseline with no Rev 5 equivalent, aimed at low-risk pilot use. Class B covers what used to be Li-SaaS and Low. Class C covers the former Moderate baseline, which is where the majority of SaaS sold to agencies lands. Class D covers the former High baseline.
Class A is the genuinely new idea. It gives a service a legitimate, listed status early, so an agency can pilot it at negligible risk while the provider works toward a fuller certification. Providers who take a Class A certification have been given a longer window, reported as two years rather than one, to reach Class B, C or D. For a small vendor that has never sold to the federal government, that is a materially different on-ramp than anything Rev 5 offered.
Existing FedRAMP Authorized services do not lose anything in the renaming. They keep their status and their marketplace listing; the vocabulary updates as new certifications are issued under the new rules.
Should you pursue Rev 5 or FedRAMP 20x?
For a new effort starting now, 20x is the default. It is cheaper to maintain, it does not require you to find a sponsor before you begin, and it is the path that will still exist in 2029. Choosing Rev 5 today means starting a program with a hard closing date on it.
Rev 5 still makes sense in two situations. If your package is substantially complete and an agency sponsor is already engaged, finishing is usually faster than restarting. And if a specific contract explicitly requires a Rev 5 authorization at a named impact level, the contract wins, though it is worth asking the contracting officer whether an equivalent class certification satisfies the requirement, because many of these clauses were written before CR26 existed.
The harder question is readiness rather than path. FedRAMP 20x asks for continuous evidence, and most teams discover that their weakest area is not security engineering but the plumbing that proves it. Before committing to a date, get an honest baseline of which controls you can already evidence automatically, which ones depend on someone remembering to take a screenshot, and which ones you cannot evidence at all. That inventory usually reorders the roadmap.
How to prepare for a 20x assessment
Start with the authorization boundary. Everything downstream, including how much evidence you owe and how much the assessment costs, follows from what you put inside it. A narrow, well-defined boundary with clearly separated production infrastructure is the single biggest lever on effort, and it is the one decision that is expensive to reverse later.
Then work the evidence, indicator by indicator. For each KSI, name the system that holds the proof, the mechanism that will extract it, and the person who owns it. Where a control depends on a third party inside your boundary, you need their posture as well as your own, which is the same discipline as any vendor security assessment, applied to subservice organizations that federal data passes through.
Finally, do not treat the crosswalk as free. If you already hold SOC 2 or ISO 27001, a real share of the underlying control work carries over: access control, multifactor authentication, encryption, logging, change management, incident response. What does not carry over is the federal-specific layer, and it is the expensive layer. The same trap shows up in defense work, where teams assume an existing certification covers CMMC and NIST SP 800-171 and then discover the scoping work was the whole job. Mapping what you have against what a baseline actually requires is exactly what FedRAMP compliance software is for, and it is cheaper to find the gaps yourself than to have a 3PAO find them.
What this does not change
FedRAMP is still a security program, not a paperwork exercise with a new file format. The indicators are shorter than the control narratives they replace because the program is trusting automation to carry more weight, not because the bar dropped. A team that automates evidence for controls it has not actually implemented will fail faster than it used to, which is arguably the point.
It is also worth being clear about who issues what. An accredited third-party assessment organization performs the assessment, and FedRAMP or a sponsoring agency issues the certification. No software product certifies you, and any vendor suggesting otherwise is selling something other than compliance. Tooling gets you ready, keeps the evidence current and tells you where you are weak. The decision, and the attestation, stay with people.
See Scrutineer scrutinize your posture
Connect your stack, and Scrutineer maps your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collects evidence automatically and returns a readiness report with per-control statuses, linked evidence and a prioritized gap list. AI scrutinizes, you decide.