What is FedRAMP? FedRAMP (Federal Risk and Authorization Management Program) is the U.S. government program that authorizes cloud services for federal agency use. A cloud provider with FedRAMP authorization has completed a standardized security assessment against NIST SP 800-53 controls, validated by an accredited third-party assessor (3PAO), so any federal agency can reuse that package instead of running its own security review from scratch. If you sell cloud to the federal market, FedRAMP is the gate, not an optional badge.
2026 update: FedRAMP now operates two active paths. Rev5 (Low/Moderate/High) accepts new applications until June 11, 2027. FedRAMP 20x (Class A/B/C/D) replaced the old impact-level structure and is fully live. VDR and VER become mandatory for all authorized offerings on December 7, 2026.
Jump to: FedRAMP certification classes (A–D) · FedRAMP certification cost · VDR & VER requirements (December 7, 2026) · Agency FedRAMP obligations (CR26)
- What is FedRAMP?
- Why does FedRAMP exist?
- Who needs FedRAMP certification?
- FedRAMP Rev5 vs. 20x: the two active paths
- FedRAMP 20x Certification Classes
- FedRAMP Rev5 impact levels
- Authorization paths under M-24-15
- The FedRAMP authorization process
- How to prepare for authorization
- FedRAMP compliance requirements in 2026
- Rev5 end of life: what CSPs need to know
- How Quzara can help
- Frequently asked questions
What is FedRAMP?
FedRAMP is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by U.S. federal agencies. (FedRAMP.gov)
FedRAMP was established in law by the FedRAMP Authorization Act (December 2022) and is governed by OMB Memorandum M-24-15 (July 2024), which replaced the prior policy and established the framework for FedRAMP 20x. The program is managed by the FedRAMP Program Management Office (PMO) within the General Services Administration (GSA). (GSA)
The core principle: a cloud service that earns a FedRAMP Certification can be reused by any federal agency under a presumption of adequacy, without a full independent re-assessment. This "authorize once, use many" model reduces duplicative effort for agencies and cloud providers alike. (M-24-15)
Why does FedRAMP exist?
Before FedRAMP, each federal agency independently assessed cloud vendors against NIST security standards. The result was duplicated effort, inconsistent assessments, and a fragmented patchwork of agency-specific authorizations that created security gaps and slowed cloud adoption government-wide.
FedRAMP standardizes that process. A FedRAMP Certification signals that a cloud service's security posture has been assessed and is "presumptively adequate" for agency use at or below the certified impact level or class. Agencies can then issue their own authority to operate (ATO) or authority to use (ATU) based on the FedRAMP package without starting from scratch.
For CSPs, FedRAMP authorization opens federal procurement opportunities that would otherwise require a separate security review for every agency sale, a process that could take years per agency.
Who needs FedRAMP certification?
Per OMB Memorandum M-24-15 and the FedRAMP Consolidated Rules for 2026, FedRAMP applies to cloud computing products and services that create, collect, process, store, or maintain Federal information on behalf of a Federal agency.
This includes:
- Cloud Service Providers (CSPs) selling SaaS, PaaS, or IaaS to federal agencies
- Managed Security Service Providers delivering cloud-hosted security services to agencies
- DoD contractors operating cloud environments handling Controlled Unclassified Information (CUI)
Only a federal agency can determine whether a specific use case falls within FedRAMP scope. The Consolidated Rules for 2026 identify several categories explicitly outside FedRAMP scope, including single-agency systems not offered as shared services, social media platforms used for public communication, and ancillary services with negligible risk to federal information. (FedRAMP Scope)
FedRAMP Rev5 vs. FedRAMP 20x: the two active paths
As of 2026, FedRAMP operates two active certification paths. CSPs must choose one, or plan a migration from Rev5 to 20x before the June 2027 cutoff.
| Rev5 | FedRAMP 20x | |
|---|---|---|
| Framework | NIST SP 800-53 Rev 5 | OMB M-24-15, Consolidated Rules 2026 |
| Structure | Low / Moderate / High impact levels | Class A / B / C / D |
| Assessment model | Point-in-time 3PAO assessment | Continuous automated validation |
| Status | Active; new applications end June 11, 2027 | Fully live; Class A/B/C pipelines open July 2026 |
| Class D / High equivalent | Available now | Phase 4, estimated FY27 Q1–Q2 |
Both paths require VDR and VER compliance from December 7, 2026 under NTC-0014. See what VDR and VER require →
FedRAMP 20x Certification Classes
FedRAMP 20x replaces Low/Moderate/High with Certification Classes. Class A, B, and C rules are finalized and submission pipelines opened in July 2026. (FedRAMP.gov)
- Class A: For cloud services with mature security and compliance programs entering the federal marketplace. Smaller set of initial monitoring and reporting requirements.
- Class B: For small-scale or light-use services where agency-wide adoption is unlikely. Lower ongoing maintenance burden. Roughly analogous to Rev5 Low.
- Class C: For common enterprise services used across an entire agency or that support important government functions. Higher ongoing reporting requirements. Roughly analogous to Rev5 Moderate.
- Class D: Planned for Phase 4 (estimated FY27 Q1–Q2). Addresses the highest-sensitivity services currently handled under Rev5 High. Quzara Cybertorch holds a Class D (High) authorization under the Rev5 path (FR2214150164) while 20x Class D finalizes.
FedRAMP Rev5 impact levels
For CSPs on the Rev5 path, impact levels remain relevant until June 11, 2027:
| Impact Level | Data sensitivity | Control count | Typical use |
|---|---|---|---|
| Low | Minimal impact if compromised | ~125 controls | Public-facing information systems |
| Moderate | Serious impact if compromised | ~325 controls | Most government SaaS applications |
| High | Severe impact if compromised | ~420 controls | Law enforcement, emergency services, financial systems |
Authorization paths under M-24-15
Under OMB Memorandum M-24-15, the Joint Authorization Board (JAB) no longer exists. There are two authorization paths:
- Agency Authorization: An agency Authorizing Official (AO) issues the authorization. The CSP works directly with a sponsoring agency. The resulting ATO can be reused by other agencies.
- Program Authorization: The FedRAMP Director issues the authorization. Available for services with broad federal applicability. Results in a FedRAMP Certification recognized program-wide.
Both paths require continuous monitoring, VDR and VER compliance from December 7, 2026, and annual assessments as specified under the Consolidated Rules for 2026.
The FedRAMP authorization process
At a high level, the Rev5 path runs from gap analysis and SSP development, through 3PAO assessment, to authorization package submission and an ATO decision, followed by continuous monitoring. FedRAMP 20x has a streamlined path that differs by Class, with a greater emphasis on continuous automated evidence rather than point-in-time assessment.
For a full step-by-step breakdown of both paths, timelines, and what each stage requires: FedRAMP Authorization Process: Steps, Rev5 & 20x (2026) →
How to prepare for FedRAMP authorization
- Choose your path early: Rev5 or 20x, and which impact level or class, should be decided before documentation begins. The control baselines differ substantially.
- Engage a 3PAO early: For Rev5 and Class D, 3PAO involvement before the formal assessment saves significant time during review.
- Build your SSP to boundary: The System Security Plan must accurately represent the authorization boundary. Gaps between the documented boundary and actual system scope are the most common cause of assessment delays.
- Stand up continuous monitoring before authorization: Agencies and FedRAMP PMO increasingly expect to see a running ConMon program, not a plan to stand one up post-authorization.
- Prepare for VDR and VER: As of December 7, 2026, all authorized CSPs must operate a continuous Vulnerability Detection and Response (VDR) and Vulnerability Evaluation and Reporting (VER) program. Start building this program before authorization, not after.
FedRAMP compliance requirements in 2026
- Security controls: NIST SP 800-53 Rev 5 at the appropriate baseline, or the Consolidated Rules for 2026 under 20x.
- System Security Plan: Comprehensive documentation of controls, system boundary, policies, and procedures.
- 3PAO assessment: Required for Rev5 at all levels and 20x Class D.
- Continuous monitoring: Monthly reporting, annual assessments, and ongoing vulnerability management.
- Vulnerability Detection and Response (VDR): Continuous detection cadences by resource class, PAIN-rated evaluations inside defined SLAs, governed remediation. Mandatory December 7, 2026. Learn what VDR requires →
- Vulnerability Evaluation and Reporting (VER): Machine-readable VDT and AVI outputs against published JSON schemas, refreshed at least every 7 days, plus a monthly human activity report. Mandatory December 7, 2026. Learn what VER requires →
- Incident response: Established procedures for detecting, responding to, and reporting security incidents within required timeframes.
Rev5 end of life: what CSPs need to know
- Already authorized under Rev5: Existing authorizations are not revoked. You continue under Rev5 continuous monitoring, subject to VDR/VER from December 7, 2026.
- Currently in the Rev5 pipeline: Applications submitted before June 11, 2027 will be processed. Applications after that date must use FedRAMP 20x.
- Planning a new application: If your timeline extends past mid-2027, start with 20x. The Rev5 window is closing.
- Migrating Rev5 to 20x: FedRAMP is developing migration guidance. Monitor FedRAMP.gov for pathways as they are published.
How Quzara can help
- FedRAMP Advisory: Path selection (Rev5 vs 20x, impact level or class), SSP development, gap analysis, 3PAO coordination, and authorization package preparation.
- Continuous Monitoring: Quzara Cybertorch™ is a FedRAMP Class D (High) authorized MDR platform (FR2214150164) staffed by U.S.-citizen analysts operating inside a GovCloud boundary, 24/7.
- VDR & VER Program Operations: We operate the full VDR and VER program from inside the authorization boundary: continuous detection, PAIN/LEV/IRV evaluations, governed exceptions, and schema-valid machine-readable reporting. Mandatory from December 7, 2026.
- NISTcompliance.ai: NISTcompliance.ai automates evidence collection, control validation, and compliance reporting across FedRAMP, NIST, and related frameworks.
Contact Quzara to speak with a FedRAMP advisor, or review the December 7, 2026 VDR/VER requirements.
Frequently asked questions
What is the difference between FedRAMP Rev5 and FedRAMP 20x?
Rev5 uses Low/Moderate/High impact levels and point-in-time 3PAO assessments. FedRAMP 20x uses Certification Classes A through D and requires continuous automated validation under OMB M-24-15. New Rev5 applications stop June 11, 2027. Both paths require VDR and VER compliance from December 7, 2026.
How long does FedRAMP authorization take?
Rev5 Moderate typically takes 12 to 18 months from kickoff to ATO. Rev5 High runs longer. FedRAMP 20x Class A and B are designed to be faster. In all cases, starting early is the critical variable. See the full step-by-step breakdown for timeline detail by path.
Does FedRAMP authorization expire?
FedRAMP authorizations do not have a fixed expiration date, but they are maintained through continuous monitoring. An authorization can be suspended or revoked if a CSP fails ongoing requirements, including VDR/VER from December 7, 2026.
What is a 3PAO and do I need one?
A Third-Party Assessment Organization (3PAO) is an accredited firm that independently assesses a CSP's system against FedRAMP security controls. Required for Rev5 at all impact levels and for 20x Class D. Class A, B, and C under 20x have different assessment models. Verify current requirements at fedramp.gov.
What is VDR and VER, and when do they become required?
VDR (Vulnerability Detection and Response) and VER (Vulnerability Evaluation and Reporting) are mandatory rulesets under NTC-0014, effective December 7, 2026, for all authorized offerings regardless of path. Full VDR and VER requirements →
What happened to the JAB?
The JAB no longer exists under OMB M-24-15. Its function was replaced by Agency Authorization (issued by an agency AO) and Program Authorization (issued by the FedRAMP Director). Existing JAB P-ATOs remain valid and will transition to the new structure.

