Quzara Blog

FedRAMP Authorization Process: Steps, Rev5 & 20x (2026)

Written by Quzara LLC | Sep 4, 2025

Key Takeaways

FedRAMP (Federal Risk and Authorization Management Program) is the U.S. government's standardized security authorization program for cloud services. Any cloud product or service that processes federal information on behalf of an agency must be FedRAMP Certified. As of 2026, FedRAMP operates two active paths: the legacy Rev5 system and the new FedRAMP 20x model, which replaces Low/Moderate/High impact levels with Certification Classes A, B, C, and D. FedRAMP 20x is now fully live with open submission pipelines. New Rev5 applications stop being accepted on June 11, 2027.

Table of Contents

What Is FedRAMP?

FedRAMP, the Federal Risk and Authorization Management Program, is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by U.S. federal agencies. (FedRAMP.gov)

FedRAMP was established in law by the FedRAMP Authorization Act (December 2022) and is governed by OMB Memorandum M-24-15 (July 2024), which replaced the prior policy and established the framework for FedRAMP 20x. The program is managed by the FedRAMP Program Management Office (PMO) within the General Services Administration (GSA). (GSA)

The core principle: a cloud service that earns a FedRAMP Certification can be reused by any federal agency under a presumption of adequacy, without a full independent re-assessment. This "authorize once, use many" model reduces duplicative effort for agencies and cloud providers alike. (M-24-15)

Why Does FedRAMP Exist?

Before FedRAMP, each federal agency independently assessed cloud vendors against NIST security standards. The result: duplicated effort, inconsistent assessments, and a fragmented patchwork of agency-specific authorizations that created security gaps and slowed cloud adoption government-wide.

FedRAMP standardizes that process. A FedRAMP Certification signals that a cloud service's security posture has been assessed and is "presumptively adequate" for agency use at or below the Certified impact level or class. Agencies can then issue their own authority to operate (ATO) or authority to use (ATU) based on the FedRAMP package without starting from scratch.

Who Needs FedRAMP Certification?

Per OMB Memorandum M-24-15 and the FedRAMP Consolidated Rules for 2026, FedRAMP applies to cloud computing products and services that create, collect, process, store, or maintain Federal information on behalf of a Federal agency.

This includes:

  • Cloud Service Providers (CSPs) selling SaaS, PaaS, or IaaS to federal agencies
  • Managed Security Service Providers delivering cloud-hosted security services to agencies
  • DoD contractors operating cloud environments handling Controlled Unclassified Information (CUI)

Importantly, only a federal agency can determine whether their specific use case falls within FedRAMP scope. The Consolidated Rules for 2026 identify several categories explicitly outside FedRAMP's scope, including single-agency systems not offered as shared services, social media platforms used for public communication, search engines, and ancillary services with negligible risk to federal information. (FedRAMP Scope)

FedRAMP Rev5 vs. FedRAMP 20x: The Two Active Paths

As of August 2026, FedRAMP operates two active Certification paths:

Rev5 FedRAMP 20x
Framework NIST SP 800-53 Rev 5 OMB M-24-15, Consolidated Rules 2026
Structure Low / Moderate / High impact levels Class A / B / C / D
Assessment model Point-in-time 3PAO assessment Continuous automated validation
Status Active; new applications end June 11, 2027 Fully live; Class A/B/C pipelines open July 2026
Class D (High equivalent) Available now Phase 4, estimated FY27 Q1 to Q2

FedRAMP 20x Certification Classes

FedRAMP 20x replaces Low/Moderate/High with Certification Classes. The rules for Class A, B, and C are finalized and submission pipelines opened in July 2026. (FedRAMP.gov)

Class A: For cloud services with mature security and compliance programs entering the federal marketplace. Requires a smaller set of initial ongoing monitoring and reporting requirements.

Class B: For small-scale or light-use services where agency-wide adoption is unlikely. Lower ongoing maintenance burden. Roughly analogous to Rev5 Low.

Class C: For common enterprise services used across an entire agency or that support important government functions. Higher ongoing reporting requirements. Roughly analogous to Rev5 Moderate.

Class D: Planned for Phase 4 (estimated FY27 Q1 to Q2). Will address the highest-sensitivity services currently handled under Rev5 High.

FedRAMP 20x is built on five principles: Transparency (honest disclosure of security decisions), Flexibility (informed engineering decisions over rigid checklists), Accountability (continuous security evidence over point-in-time audits), Accuracy (assessing effectiveness of decisions, not just their existence), and Automatic Validation (continuous, automated enforcement wherever possible). (FedRAMP 20x)

FedRAMP Rev5 Impact Levels

For CSPs on the Rev5 path, impact levels are still relevant until June 11, 2027:

Impact Level Data Sensitivity Control Count Typical Use
Low Minimal if compromised ~125 controls Public-facing info systems
Moderate Serious impact ~325 controls Most federal agency systems
High Severe or catastrophic 420+ controls Law enforcement, health, financial, DoD

Roughly 80% of federal cloud use cases fall under Moderate.

Authorization Paths Under M-24-15

OMB Memorandum M-24-15 established two primary authorization paths, replacing the prior JAB P-ATO structure. The Joint Authorization Board (JAB) no longer functions as an authorization path. Existing JAB P-ATOs have been re-designated by the FedRAMP PMO. (M-24-15 Authorization Process)

Agency Authorization: Signed by the federal agency's authorizing official. Indicates the agency assessed the CSP's security posture per FedRAMP guidelines and found it acceptable for their use case and risk tolerance. Can also be conducted jointly by multiple agencies.

Program Authorization: Signed by the FedRAMP Director. Indicates FedRAMP assessed the cloud service directly and found it meets FedRAMP requirements for reuse by agency authorizing officials. Used when no agency sponsor has been identified but broad federal adoption is expected.

Both paths result in a FedRAMP Certification listed on the FedRAMP Marketplace. Both carry the presumption of adequacy that allows other agencies to reuse the package.

The Rev5 Authorization Process (Step by Step)

For CSPs pursuing Rev5 (still the only path for High/Class D until FY27):

Step 1: Readiness Assessment. Most CSPs commission a Readiness Assessment Report (RAR) from an accredited 3PAO before formal authorization. Not required, but it significantly reduces surprises. See Quzara's guide to FedRAMP 3PAO assessments for what to expect.

Step 2: System Security Plan (SSP). Documents your system boundary, data types, NIST SP 800-53 controls implemented, and inherited controls from your cloud platform. Quzara's complete FedRAMP authorization guide covers SSP development in detail.

Step 3: 3PAO Assessment. An accredited Third-Party Assessment Organization independently tests your controls and produces a Security Assessment Report (SAR) and Plan of Action & Milestones (POA&M).

Step 4: Agency or Program Authorization. An agency authorizing official (Agency Authorization) or the FedRAMP Director (Program Authorization) reviews the package and issues Certification. The service is then listed on the FedRAMP Marketplace.

Step 5: Continuous Monitoring. Authorization is ongoing. Monthly vulnerability scans, annual assessments, and regular POA&M updates are required throughout the life of the Certification. Rather than building an internal monitoring capability from scratch, many CSPs leverage a FedRAMP Certified SOC-as-a-Service to meet this requirement. Quzara Cybertorchâ„¢ is a FedRAMP Certified Class D MDR and SOC-as-a-Service, staffed exclusively by US-citizen analysts, providing 24/7 threat monitoring and the continuous monitoring coverage FedRAMP requires.

FedRAMP 20x: How It Works

FedRAMP 20x is not a streamlined version of Rev5. It is a different model. The core shift: from compliance-focused, point-in-time audits to continuous, automated evidence of security decisions.

Under FedRAMP 20x, CSPs define their security goals for their specific environment, measure the effectiveness of those decisions continuously, and demonstrate assurance to agencies through progressively increasing commitments tied to the Certification Class. The government's position is that a CSO does not need to be evaluated against a single binary "secure/not secure" standard; different services carry different risks, and Certification Classes reflect that.

Phase 3 is currently active (FY26 Q3 to Q4): formalizing 20x requirements, opening submission pipelines, and providing agency training. Phase 4 (Class D pilot, estimated FY27 Q1 to Q2) follows. (FedRAMP 20x)

Rev5 End of Life: What CSPs Need to Know

FedRAMP will stop accepting new Rev5 Certification applications on June 11, 2027. (FedRAMP.gov) FedRAMP has committed to providing a transition path for existing Rev5-Certified providers, but has not yet published the full transition timeline for all existing packages.

CSPs who have not started authorization yet have a clear decision to make: pursue FedRAMP 20x now, or begin Rev5 knowing the end-of-new-application date. CSPs mid-process on Rev5 should evaluate timeline risk carefully.

See Quzara's FedRAMP 20x Roadmap for a detailed breakdown of the phase-by-phase timeline and what it means for CSPs at different stages. For a full breakdown of what authorization costs across both paths, see How Much Does FedRAMP Cost?

How to Get Started

  1. Determine whether FedRAMP applies to your use case. Your agency customer, not FedRAMP, makes this determination. Review the Consolidated Rules Scope guidance.
  2. Choose your path. Rev5 for High (Class D not yet available in 20x) or specific agency requirements. FedRAMP 20x Class A, B, or C for all others.
  3. Commission a gap assessment. Understand where you stand before engaging any assessor.
  4. Adopt OSCAL tooling. OSCAL is the technical foundation of FedRAMP 20x and reduces documentation cost across both paths. NISTcompliance.ai is an AI-powered compliance platform built on OSCAL-native architecture, purpose-built for automating NIST SP 800-53 and FedRAMP documentation so evidence maps directly into authorization workflows.
  5. Engage an advisory partner with 20x experience. The Consolidated Rules for 2026 represent a significant shift; advisors who have worked through Rev5 only may not be current on 20x requirements.

Quzara's FedRAMP Advisory Services covers gap assessments, SSP development, 3PAO coordination, and OSCAL-based automation for both Rev5 and FedRAMP 20x paths. If you're already mid-process on Rev5, see the Rev5 Under 20x transition guide for how to navigate the June 2027 end-of-new-applications deadline.

FAQ

What happened to the JAB and JAB P-ATOs?
The JAB (Joint Authorization Board) no longer functions as a FedRAMP authorization path. Under OMB M-24-15, the two paths are Agency Authorization and Program Authorization. Existing JAB P-ATOs have been re-designated by the FedRAMP PMO.

Is FedRAMP 20x available now?
Yes. FedRAMP 20x is fully live. The rules for Class A, B, and C are finalized under the FedRAMP Consolidated Rules for 2026. The submission pipeline opened in July 2026. Class D is planned for Phase 4 (estimated FY27 Q1 to Q2). (FedRAMP.gov)

Do I still need a 3PAO under FedRAMP 20x?
Under Rev5, an accredited 3PAO is required. Under FedRAMP 20x, the assessment model shifts to continuous automated validation. The specific requirements per Certification Class are in the FedRAMP Consolidated Rules for 2026. Consult an experienced advisory partner for the current requirements for your target Class.

What is the FedRAMP Marketplace?
The FedRAMP Marketplace is the official registry of FedRAMP-Certified cloud services. Federal agencies use it to identify services available for reuse under the presumption of adequacy. Listing on the Marketplace is a significant commercial advantage for any CSP selling to the government.

What is Quzara Cybertorch's FedRAMP Certification status?
Quzara Cybertorchâ„¢ holds FedRAMP Certified Class D status (Class D maps to the legacy Rev5 High baseline), one of a small number of MDR services to hold this designation on Azure Government, authorized for DoD IL-4.

Quzara provides FedRAMP advisory services and OSCAL-based automation for Rev5 and FedRAMP 20x paths. Talk to a FedRAMP advisor to map your Certification strategy.