You need FedRAMP when three things are true at once: you operate a cloud service rather than shipping software an agency installs itself; that service creates, collects, processes, stores or maintains federal information on an agency's behalf; and it is used by agencies directly or inside another cloud service they use. If any one of the three is false you are out of scope, and the Consolidated Rules for 2026 list six categories that are out even when all three look true. The agency decides which side of the line its use falls on, not you, and once it lands in scope the agency must use a FedRAMP Certified service and complete its own Authorization to Operate. There is no such thing as being FedRAMP compliant without a Marketplace listing.
That is the answer. The rest of this page is the detail the answer hides: the exclusions, the classes that replaced Low, Moderate and High in February 2026 and which of them you can enter with what you already hold, the two certification paths and the dates on which one of them closes, who does what, what a SaaS boundary has to contain, what it costs, and how FedRAMP relates to the programmes it is confused with, GovRAMP, TX-RAMP, CMMC and the DoD impact levels. The pages that rank for this question were written for a programme that no longer exists in that form; the sponsor, the Joint Authorization Board and the six-step process they describe were all retired between July 2024 and June 2026.
| Your situation | In scope? | Why |
|---|---|---|
| SaaS used by three agencies to manage case files | Yes | Cloud service, federal information, direct government-wide use |
| SaaS used by one agency, built for it, not sold to others | No | Single-agency system: the agency's own ATO covers it |
| A database service inside another vendor's FedRAMP Certified SaaS | Yes | Indirect government-wide use: you are in their boundary and must be certified or covered by it |
| On-premises software an agency installs in its own data centre | No | Not a cloud service; FISMA and the agency ATO apply, not FedRAMP |
| A public weather or market-data API agencies read | No | Information provider that collects no federal information |
| A collaboration tool holding agency documents | Yes | Federal information at rest; typically Class C |
| A DoD prime storing CUI in your SaaS | Not FedRAMP itself | FedRAMP Moderate equivalency under the December 2023 DoD memo, for CMMC Level 2 |
| A city, a state university, a school district | No | GovRAMP or TX-RAMP; FedRAMP Certification is accepted by both |
| A marketing analytics tool with no agency data | No | Negligible-risk ancillary service, if it truly holds nothing federal |
| A security product an agency runs in its own cloud tenancy | Usually no | The agency operates it; ask whether you ever hold or process their data |
What is FedRAMP, in one paragraph?
The Federal Risk and Authorization Management Program is the US government's single standard for assessing and certifying the security of cloud services that hold federal information, so that one assessment can be reused by every agency instead of each doing its own. It was run by the General Services Administration from 2011, written into law by Section 5921 of the FY2023 National Defense Authorization Act in December 2022, and re-founded by OMB Memorandum M-24-15 in July 2024, which set the current scope, replaced the Joint Authorization Board with a FedRAMP Board of agency CIOs, and told the programme to automate. The Consolidated Rules for 2026, finalised on 25 June 2026 and adopted from 4 July, are the rulebook now in force, and they are what this page reads.
Who needs FedRAMP? The three tests
The rules define scope as cloud computing products and services, whether infrastructure, platform or software, that create, collect, process, store or maintain federal information on behalf of a federal agency. Three conditions follow from that sentence, and all three must hold.
1. It is a cloud service you operate
FedRAMP covers services you run and offer, IaaS, PaaS and SaaS. Software an agency licenses and installs in its own environment is not a cloud service in this sense; the agency's own authorisation under FISMA covers it. The test is who operates the system that holds the data, not what the product is called.
2. It holds federal information
The threshold is low. Creating, collecting, processing, storing or maintaining any federal information on an agency's behalf is enough; the rules do not require the information to be sensitive, and the impact level is decided later. What matters is whether federal information ever sits in or passes through your service.
3. It has government-wide use, directly or indirectly
To be listed and certified, a service must be used directly by more than one agency for integration into federal information systems, or indirectly, as a third-party resource inside another cloud service that agencies use. The indirect case catches sub-processors: a data service, an email API or a hosting layer inside a certified SaaS is in scope through that SaaS, and either needs its own certification or must sit inside the certified provider's boundary and evidence. That is ordinary third-party risk management with a harder edge: the agency does not accept a contract clause as a substitute for the sub-processor being in the package.
The rules are explicit that the agency determines whether a specific use falls in scope. A provider cannot certify its way into a sale that the agency has judged out of scope, and cannot avoid certification for a use the agency has judged in scope. Under the agency-use rules, once in scope the agency must use a FedRAMP Certified service, must complete its own Authorization to Operate, must review your Secure Configuration Guide, and must notify FedRAMP when it authorises you. The certification is reusable government-wide; the ATO is the agency's own.
Who does not need FedRAMP?
The 2026 rules carry six exclusions, and they are about the information and the use, not the vendor. The same product can be in scope for one agency and out for another.
- Single-agency systems. Built for one agency on cloud infrastructure and not offered as a shared service. The agency authorises it alone.
- Social media and communications platforms used under agency policy, where no sensitive federal information is collected.
- Search engines that do not collect or maintain federal data, where users are told not to enter sensitive information.
- Information providers. Widely available commercial services that supply data to agencies but collect none from them.
- Ancillary services of negligible risk. Services whose compromise would pose a negligible risk to federal information or systems.
- Anything the FedRAMP Board excludes with the Federal CIO's concurrence.
Two groups outside the six also do not need FedRAMP as such. State, local, tribal and education buyers run their own programmes, GovRAMP and, in Texas, TX-RAMP, both of which accept FedRAMP Certification. And Department of Defense contractors protecting controlled unclassified information need the cloud services they use to be FedRAMP Moderate or equivalent under CMMC, which is a requirement on the contractor's supplier, not on the contractor.
Which class do you need? Low, Moderate, High and the 2026 classes
The impact level still comes from FIPS 199: you categorise the information your service holds by the harm its loss of confidentiality, integrity or availability would do, and the highest of the three sets the level. Low means limited adverse effect, Moderate serious, High severe or catastrophic. What changed in February 2026, with notice NTC-0004, is the label the Marketplace uses: one word, FedRAMP Certification, and four classes, A to D. The rules are explicit that a class describes the assurance a provider commits to supply, not how secure the service is. Class B is adequate for most Low-impact agency systems, Class C for most Low and Moderate systems, Class D for most systems regardless of impact, and Class A only for pilots, configuration and testing, public information, or getting started with very few users.
| Class | Adequate for, in the rules' words | Replaces | Rev 5 controls | 20x | Independent assessment |
|---|---|---|---|---|---|
| Class A | Pilots, configuration and testing, public information, very few users | New; Legacy FedRAMP Ready converts here | None: 20x only | 46 KSIs; automation optional | Optional. SOC 2 Type II, GovRAMP or Rev 5 within 12 months, or a readiness report, gets you in |
| Class B | Most Low-impact agency systems | Low, LI-SaaS | 156 | 46 KSIs; at least one automated check per KSI recommended | Required, under three months old |
| Class C | Most Low and Moderate systems | Moderate | 323 | 46 KSIs; at least two automated methods per KSI and six months of KSI history | Required, under three months old |
| Class D | Most systems regardless of impact | High | 410 | Pilot expected late 2026, formal early 2027; four automated methods and 18 months of history | Required |
Most services land in Class C, because most federal information is Moderate. Class B exists for genuinely low-sensitivity tools and for what used to be the LI-SaaS profile of very simple applications. Class D is for the small set of systems where a breach would be catastrophic, and its control count reflects that. The Rev 5 counts are the NIST SP 800-53 Revision 5 baselines as FedRAMP tailors them; the NIST Risk Management Framework is the process those baselines were built for. The 20x path replaces the control list with 46 Key Security Indicators in ten families, from change management and cloud-native architecture to supply chain risk and recovery planning, and the same 46 apply to Class B and Class C; what rises between the classes is how much automation and how much history you must show for each one.
Class A is the change worth understanding, because the ranking pages describe it as the old FedRAMP Ready and it is not. It is a real certification an agency can use for a pilot or a public-information workload. It can be entered with a SOC 2 Type II report, a GovRAMP assessment or a Rev 5 package less than twelve months old, or with a readiness assessment report; the independent assessment is optional; and once a federal customer adopts the service in earnest, the provider must begin Class B or higher within twelve months. Providers holding Legacy FedRAMP Ready must convert to a certification, usually 20x Class A, by the later of their annual assessment's expiry or 17 November 2026, and the legacy label is removed from the Marketplace on 31 December 2027.
Which class can you enter with what you already have?
The certification rules turn the classes into a ladder of evidence, and the rungs are concrete. Every applicant first lists the service on the Marketplace and applies itself; a consultant or a reseller cannot apply on your behalf, and you remain accountable for every statement in the package even when a third party wrote it. The package must be under seven days old when it is submitted, and the independent assessment under three months old, though a stale assessment may be refreshed until it is nine months old. For Class B the rules say you should run at least one automated method that continuously verifies each Key Security Indicator; for Class C you must run at least two, and you must be able to show six months of historical KSI metrics; for Class D the numbers are four methods and eighteen months.
Two consequences follow. The first is that a SOC 2 Type II report less than a year old is a ticket into Class A, which is the reason the entry class exists: a commercial SaaS with a current Type II can be listed, piloted by an agency and paid, and then has twelve months to reach Class B or C. ISO 27001 does not appear in the rules' list of alternative frameworks, so an ISO-only company enters through a readiness report instead. The second is that Class C's six months of KSI history means the telemetry has to be running well before you apply. The calendar starts when your monitoring does, not when you sign the 3PAO, and the tooling choice a SaaS makes for SOC 2 is usually the one it will be feeding KSIs from a year later.
Who does what? Provider, 3PAO, agency, PMO and Board
Four parties, and the confusion between them is where most bad advice comes from.
You, the provider, scope the offering, choose the class, implement and document the controls, pay for the assessment and report continuously afterwards. The third-party assessment organisation, accredited by A2LA under the FedRAMP requirements, tests whether the controls operate and produces the assessment evidence; it cannot advise on the things it then assesses. The agency decides whether its use is in scope, reviews the certification and your Secure Configuration Guide, and issues its own ATO. The Program Management Office at GSA sets standards, grants the certification, runs the Marketplace and reviews packages; the FedRAMP Board of agency CIOs sets policy and can exclude categories from scope. Since M-24-15 there is no Joint Authorization Board, and under the 2026 rules the PMO certifies for the whole government, which is why the old idea of finding an agency sponsor first no longer describes the path most providers take.
How do you get certified in 2026: Rev 5 or 20x?
Two paths run in parallel until 2027, and which one you start on is decided by the calendar as much as by preference.
Rev 5 is the document-based path everyone knows: a System Security Plan of several hundred pages, policies for every control family, a 3PAO Security Assessment Report, a Plan of Action and Milestones for what is not yet closed, and a PMO review. It is the path if you are already deep in a package, or if you need Class D before the 20x route for it opens in 2027. The dates are now fixed by the Important Deadlines page: FedRAMP stops accepting new Rev 5 applications on 11 June 2027; from 1 January 2027 every Rev 5 application and every active certification must follow the 2026 rules, which replace the Word and Excel templates with JSON or OSCAL, the POA&M with an Accepted Weaknesses list, the SSP with a Certification Package Overview and a Security Decision Record, and continuous monitoring with Ongoing Certification; grace periods expire on 1 February 2028, when anything not fully on the 2026 rules loses its certification; and Rev 5 certifications stay valid through at least 31 December 2028, by which point the 2026 rules themselves expire and the 2027 or 2028 release applies. The PMO's instruction to Rev 5 holders is to move to 20x as quickly as possible.
FedRAMP 20x, announced in March 2025, replaces the document with machine-readable evidence validated against the 46 Key Security Indicators, assessed by a 3PAO where the class requires it and reviewed by the PMO in weeks. The Phase One pilot for Low opened in May 2025 and had certified 26 services by the end of August; Phase Two extended the model to Moderate from November 2025 into the second quarter of 2026; the Consolidated Rules were finalised on 25 June 2026 and took effect on 4 July; and the pipelines opened in August, Class A on 3 August, Class B and Class C on 31 August, with a limited Rev 5 pipeline from 10 August for providers who lost a sponsor or hold Legacy Ready. If you are starting now on Class A, B or C, this is the path. The controls still have to exist, and that is where the cost is; what 20x removes is the year of writing about them.
The 2026 to 2028 calendar, date by date
Every date below is from fedramp.gov, and they matter in a specific way: they decide which path you can still start on and how long what you hold stays valid. Dates that other pages give for "the end of Rev 5" and do not appear here are not in the rules.
| Date | What happens | Who it affects |
|---|---|---|
| 25 June 2026 | Consolidated Rules for 2026 finalised | Everyone |
| 4 July 2026 | Rules in effect; every new 20x application must follow them | New 20x applicants |
| 3 August 2026 | 20x Class A pipeline opens | Providers with a SOC 2 Type II, GovRAMP or Rev 5 within 12 months, or a readiness report |
| 10 August 2026 | Limited Rev 5 pipelines open: lost-sponsor and Ready-conversion paths | Rev 5 providers stranded by M-24-15 |
| 31 August 2026 | 20x Class B and Class C pipelines open | Anyone starting now on Low or Moderate |
| 30 September 2026 | FedRAMP Day | Everyone |
| 17 November 2026 | Legacy FedRAMP Ready holders must have converted, or by their assessment's expiry if later | Legacy Ready providers |
| Late 2026 | 20x Class D pilot expected; formal availability expected early 2027 | High-impact services |
| 1 January 2027 | 2026 rules mandatory for every Rev 5 application and every active certification | All certified providers |
| 11 June 2027 | No new Rev 5 applications accepted | Anyone still planning a document-based package |
| 31 December 2027 | Legacy FedRAMP Ready status removed from the Marketplace | Anyone who did not convert |
| 1 February 2028 | All grace periods expire; services not fully on the 2026 rules lose certification | All certified providers |
| 31 December 2028 | The 2026 rules expire; the 2027 or 2028 release applies. Rev 5 certifications valid at least until here | All certified providers |
Do you need it? A decision tree
Work the tree honestly on the second question. Providers routinely underestimate what counts as federal information; a support ticket with an agency user's name and email is federal information, and so is a log line with an agency IP address. If the answer is uncertain, the agency will decide it for you, and it will decide it in the direction that keeps its own ATO defensible.
FedRAMP for a SaaS company: the boundary, what you inherit and your sub-processors
Most of the companies asking this question are SaaS businesses with a first federal or defence prospect, and the scope question they actually face is not whether but what: which components are inside the certification boundary. The rules' answer is that the boundary is every component that creates, collects, processes, stores or maintains federal information, and every service those components depend on. Three things follow for a typical SaaS.
You inherit the platform, never the application. Running on a FedRAMP Certified IaaS or PaaS lets you cite the provider's evidence for physical and environmental security, the hypervisor and network fabric, storage encryption at rest and the region and backup infrastructure. Every control that touches your customer's data, your users or your code stays yours: identity and passwordless access, tenant isolation proven with a penetration test, logging of every change and every access, change control that survives continuous deployment, vulnerability detection and response, FIPS-validated encryption of sensitive data, and the one-hour incident report. Under the 2026 rules the last of these is not a Rev 5 relic; the reporting clocks for federal work are shorter than for anything in Europe.
Every sub-processor that touches federal data is in scope through you. The email API that sends an agency user a password reset, the error tracker that captures a stack trace with a request body, the analytics tool with a session recording, the CDN that terminates TLS, the identity provider, the support desk that receives a screenshot, the AI API you send a document to. Each is either inside your boundary and your evidence, or FedRAMP Certified in its own right, or cut off from federal data by architecture rather than by contract. This is the part that breaks first for startups, because the commercial stack accumulates fifteen such services without anyone deciding to, and a third-party assessment that only reads their questionnaire answers does not satisfy an agency reading your package.
The programme does not mandate a region or a citizenship test; contracts do. FedRAMP Certification is available to non-US companies on the same test, and the 2026 rules do not require a government-only cloud region for Class B or C. What imposes US-only hosting, US-person access and reviewed privileged access is the contract, DoD impact levels from IL4 upward, and export-control regimes such as ITAR when the data carries them. Read the contract, not the programme, and separate the federal environment from your corporate IT, marketing site and billing so that those stay outside the boundary by construction.
What does FedRAMP cost, and how long does it take?
FedRAMP itself charges no fee. The cost is the engineering to reach the baseline, the 3PAO assessment, the documentation and advisory work, and the continuous monitoring that never stops. The ranges below are the convergence of the estimates assessors and advisers published in 2025 and 2026; they are not FedRAMP figures, and your engineering line depends entirely on how far your architecture already is from the baseline.
| Class B (Low) | Class C (Moderate) | Class D (High) | |
|---|---|---|---|
| Readiness and gap work | USD 30k to 80k | 40k to 100k | 60k to 150k |
| Engineering and remediation | 100k to 250k | 250k to 800k | 600k to 1.5m and up |
| 3PAO assessment | 100k to 150k | 150k to 300k | 250k to 500k |
| Continuous monitoring, per year | 80k to 150k | 150k to 300k | 250k to 500k and up |
| Time to certification, Rev 5 | 9 to 12 months | 12 to 18 months | 18 to 36 months |
| Time to certification, 20x | 3 to 6 months in the pilots | Phase Two: months, not years | Not yet available |
Two things the ranges hide. First, continuous monitoring is an operating line, not a project cost, and over three years it usually exceeds the first-year total. Second, the engineering line is the one you control: a service already running on a FedRAMP Certified IaaS, with a documented boundary, encryption everywhere, FIPS-validated cryptography and centralised logging, sits at the bottom of every range. One that has to be re-architected to get a boundary at all sits at the top.
What do the Marketplace statuses mean?
Legacy FedRAMP Ready means a Rev 5 readiness assessment passed under the old programme; holders must convert to a certification, usually 20x Class A, by the later of their assessment's expiry or 17 November 2026, and the label is removed on 31 December 2027. In Process means a package is under review. Certified is the only status an agency reuses, and a listing carries the class, A to D, the path and the date of the last ongoing certification report, so it is checkable. The Marketplace passed 650 listed services in July 2026 after 114 Rev 5 completions in six months and 29 services through the 20x pilots, nearly double the count of two years earlier. A vendor who says it is FedRAMP compliant but has no listing is describing an intention.
FedRAMP, GovRAMP, TX-RAMP, CMMC and DoD impact levels: which applies to whom?
GovRAMP, StateRAMP until its rebrand on 14 February 2025, is the non-profit programme for state, local, tribal and education buyers, built on the same NIST baselines and assessed by the same 3PAOs; a FedRAMP Certified service can reuse its evidence there, and many state contracts accept FedRAMP outright. TX-RAMP is Texas's own programme for state agencies and universities, validated by the Department of Information Resources rather than a 3PAO, and it accepts FedRAMP and GovRAMP. CMMC 2.0 certifies a DoD contractor's own systems for handling FCI and CUI; it does not certify a cloud service, but the DoD memo of 21 December 2023 requires any cloud service holding a contractor's CUI to be FedRAMP Moderate or equivalent, which means all Moderate controls implemented, a FedRAMP-recognised 3PAO assessment, a complete body of evidence and no open control-related POA&M items. DoD Impact Levels IL2 to IL6 sit on top of FedRAMP for Defense use: FedRAMP Moderate is the entry to IL2 and IL4, and DISA grants its own provisional authorisation above that.
The practical reading: a commercial SaaS with any government ambition builds one control set to the Moderate baseline and reuses it four ways. That is exactly the case for a control crosswalk, where the NIST SP 800-53 control you implement once is the evidence for FedRAMP, GovRAMP, CMMC's 800-171 practices and NIST CSF 2.0 at the same time.
What happens after certification?
Certification is a state you maintain, not a document you file. Monthly, every component is vulnerability-scanned, the Accepted Weaknesses list, which the 2026 rules put in place of the POA&M, is brought up to date, and the inventory is reconciled to the boundary. Yearly, a 3PAO reassesses a subset of controls, the incident response and contingency plans are exercised, policies are re-approved and an ongoing certification report goes to every agency using you. On change, significant changes are notified before they ship, new regions or data types are re-scoped, and a suspected breach is reported within one hour. Under 20x the monthly file drop becomes continuous machine-readable reporting, which is lighter to produce and impossible to backdate; the rules now call the whole obligation Ongoing Certification, and losing it is the consequence of non-compliance, not a fine. Agencies read these reports; the 2026 rules oblige them to, and to tell FedRAMP if what they read would make them rescind their ATO.

What do the other results get wrong?
- "You need an agency sponsor." That was the Rev 5 agency path. Under 20x and the Consolidated Rules the PMO certifies government-wide and agencies reuse the certification.
- "The JAB authorises." The Joint Authorization Board was dissolved by M-24-15 in July 2024. The FedRAMP Board sets policy; it does not review packages.
- "Low, Moderate, High." Still the FIPS 199 impact levels, but since February 2026 the Marketplace label is Class A to D, and Class A is a certification an agency can pilot on, not the old readiness label.
- "Twelve to eighteen months." True for a Rev 5 package. The 20x Phase One pilots certified services in months, and the PMO's stated review target is weeks.
- "FedRAMP compliant." There is no such status. A service is Certified, In Process, or absent from the Marketplace.
- "StateRAMP." Renamed GovRAMP in February 2025; the older name still appears on most comparison pages.
Frequently asked questions
Who is required to be FedRAMP certified?
Any cloud service that holds federal information on an agency's behalf and is used government-wide, directly by agencies or inside another cloud service they use. The requirement falls on the provider because the agency may only use certified services for in-scope work.
Is FedRAMP mandatory?
For in-scope use, yes: since the FedRAMP Authorization Act of December 2022 and M-24-15, agencies must use FedRAMP Certified services and may not impose their own duplicate requirements without justification. For out-of-scope use it does not apply at all, and there is no voluntary lighter version.
Do small companies or startups need FedRAMP?
Size is irrelevant; scope is everything. A ten-person SaaS holding agency data is in scope, and 20x was designed partly so that a company that size can reach Class B or C without a year of documentation. A large vendor whose product never touches federal information is out.
Does FedRAMP apply to non-US companies?
Yes, on the same test. Where the service is hosted and where the company is incorporated do not change scope, though they affect which agencies will buy and, for some data, whether US-based operations are required by the contract.
Do I need an agency sponsor?
Not in the way the older guides describe. Under the 2026 rules the PMO grants the certification and agencies reuse it. A first customer still helps, because it decides your use is in scope and issues the first ATO, but the certification is no longer gated on finding one.
What is the difference between FedRAMP authorisation and FedRAMP certification?
Nothing in substance; the name changed. Notice NTC-0004 in February 2026 adopted FedRAMP Certification as the single label for what used to be an authorisation or P-ATO, and Classes A to D for what used to be Ready, Low, Moderate and High.
What is FedRAMP 20x?
The automation-based certification path announced in March 2025: machine-readable evidence validated against Key Security Indicators instead of a written package, attested by a 3PAO and reviewed by the PMO in weeks. Its rules took effect on 4 July 2026, the Class A pipeline opened on 3 August and Class B and C on 31 August, and Rev 5 closes to new applications on 11 June 2027.
When does Rev 5 end?
New Rev 5 applications stop on 11 June 2027. Existing Rev 5 certifications must follow the 2026 rules from 1 January 2027, lose certification on 1 February 2028 if they have not, and remain valid at least until 31 December 2028, when the 2026 rules expire and the next release applies. The PMO asks Rev 5 holders to move to 20x as quickly as possible.
How long does FedRAMP take?
On Rev 5, roughly a year for Class B, twelve to eighteen months for Class C and up to three years for Class D, most of it engineering and documentation. On 20x the pilots certified Class B services in three to six months, with the review itself measured in weeks.
How much does FedRAMP cost?
Industry estimates converge on USD 350,000 to 500,000 in the first year for Class B, 800,000 to 2 million for Class C and 2.5 million upward for Class D, followed by 80,000 to 500,000 a year of continuous monitoring depending on class. FedRAMP charges nothing; the money goes to engineering, the 3PAO and the operating burden.
Does FedRAMP replace SOC 2 or ISO 27001?
No, and they do not replace it. SOC 2 and ISO 27001 are commercial assurance; FedRAMP is a federal procurement condition built on NIST SP 800-53. The controls overlap heavily, which is why one control set with a crosswalk serves all three, but none of the certificates is accepted in place of another.
What is FedRAMP Moderate equivalency?
The standard the DoD set on 21 December 2023 for cloud services that hold a defence contractor's CUI without holding a FedRAMP certification: every Moderate control implemented, assessed by a FedRAMP-recognised 3PAO, with a complete body of evidence and no open control-related POA&M items. It is the CMMC Level 2 supplier requirement, not a FedRAMP status.
Is GovRAMP the same as FedRAMP?
No. GovRAMP, StateRAMP until February 2025, is the programme for state, local, tribal and education buyers, built on the same NIST baselines and assessed by the same 3PAOs. It accepts FedRAMP Certification and reuses its evidence, but its statuses and governance are its own.
What happens if a provider loses certification?
Under the 2026 rules a certification that lapses, for example after the grace period for corrective action ends on 1 February 2028 for non-compliant providers, drops off the Marketplace, and every agency ATO built on it has to be reconsidered. Agencies are obliged to report to FedRAMP when ongoing reports raise concerns that would make them rescind.
Which regulation is FedRAMP based on?
FISMA, through NIST SP 800-53 Revision 5 for the controls, FIPS 199 for impact categorisation and SP 800-37 for the authorisation process, codified by the FedRAMP Authorization Act and administered under OMB M-24-15 and the Consolidated Rules for 2026.
Does a SOC 2 Type II report count for anything?
Yes, specifically. A SOC 2 Type II, a GovRAMP assessment or a Rev 5 package less than twelve months old is the entry ticket to 20x Class A, the class for pilots, testing and public-information use. It is not a substitute for Class B or C, and once an agency adopts the service in earnest you have twelve months to begin the higher class.
Do I need GovCloud, US-only hosting or US-person staff?
Not from FedRAMP. The programme applies the same test to non-US companies and the 2026 rules do not require a government-only region for Class B or C. Those requirements come from the contract, from DoD impact levels IL4 and above, and from export-control regimes such as ITAR where the data carries them, so the answer is in the solicitation, not the rulebook.
Can I sell through a reseller, a marketplace or a prime that is already certified?
Their certification covers their service, not yours. A reseller lists nothing on the Marketplace; the provider must apply itself and remains accountable for the package. If your service sits inside a certified provider's boundary and evidence you are covered through them, in the same way their sub-processors are; if it merely integrates with theirs, it is a separate cloud service and needs its own listing.
What replaced the POA&M and the SSP?
Under the 2026 rules the Plan of Action and Milestones becomes an Accepted Weaknesses list, the System Security Plan becomes a Certification Package Overview with a Security Decision Record, continuous monitoring becomes Ongoing Certification, and the Word and Excel templates give way to JSON or OSCAL. Rev 5 holders must adopt the new forms by 1 January 2027; 20x applicants have used them since 4 July 2026.
Primary sources
- FedRAMP, Scope of FedRAMP, Consolidated Rules for 2026
- FedRAMP, Agency use of FedRAMP Certified cloud services
- FedRAMP, Providers, Consolidated Rules for 2026
- FedRAMP, The FedRAMP Authorization Act, Section 5921 of the FY2023 NDAA
- OMB, Memorandum M-24-15, Modernizing FedRAMP, 25 July 2024
- FedRAMP, Initial outcome of the Rev 5 baseline RFCs
- DoD CIO, FedRAMP Moderate Equivalency for Cloud Service Provider Offerings, 21 December 2023
- GovRAMP, StateRAMP announces rebrand to GovRAMP, February 2025
- FedRAMP, Certification Classes, Consolidated Rules for 2026
- FedRAMP, FedRAMP Certification rules for 20x, Consolidated Rules for 2026
- FedRAMP, Key Security Indicators, Consolidated Rules for 2026
- FedRAMP, Important Deadlines, Consolidated Rules for 2026
- FedRAMP, What is changing in 2026
- FedRAMP, FedRAMP Certification paths are heating up, 30 July 2026
Written by the Venvera compliance team. Scope, exclusions, classes, certification rules and every date are quoted from the Consolidated Rules for 2026 and FedRAMP notices as published on fedramp.gov; cost ranges are industry estimates and are labelled as such. Checked in September 2026.





