Key Takeaways
FedRAMP (Federal Risk and Authorization Management Program) is the U.S. government's standardized security authorization program for cloud services. Any cloud product or service that processes federal information on behalf of an agency must be FedRAMP Certified. As of 2026, FedRAMP operates two active paths: the legacy Rev5 system and the new FedRAMP 20x model, which replaces Low/Moderate/High impact levels with Certification Classes A, B, C, and D. FedRAMP 20x is now fully live with open submission pipelines. New Rev5 applications stop being accepted on June 11, 2027.
FedRAMP, the Federal Risk and Authorization Management Program, is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by U.S. federal agencies. (FedRAMP.gov)
FedRAMP was established in law by the FedRAMP Authorization Act (December 2022) and is governed by OMB Memorandum M-24-15 (July 2024), which replaced the prior policy and established the framework for FedRAMP 20x. The program is managed by the FedRAMP Program Management Office (PMO) within the General Services Administration (GSA). (GSA)
The core principle: a cloud service that earns a FedRAMP Certification can be reused by any federal agency under a presumption of adequacy, without a full independent re-assessment. This "authorize once, use many" model reduces duplicative effort for agencies and cloud providers alike. (M-24-15)
Before FedRAMP, each federal agency independently assessed cloud vendors against NIST security standards. The result: duplicated effort, inconsistent assessments, and a fragmented patchwork of agency-specific authorizations that created security gaps and slowed cloud adoption government-wide.
FedRAMP standardizes that process. A FedRAMP Certification signals that a cloud service's security posture has been assessed and is "presumptively adequate" for agency use at or below the Certified impact level or class. Agencies can then issue their own authority to operate (ATO) or authority to use (ATU) based on the FedRAMP package without starting from scratch.
Per OMB Memorandum M-24-15 and the FedRAMP Consolidated Rules for 2026, FedRAMP applies to cloud computing products and services that create, collect, process, store, or maintain Federal information on behalf of a Federal agency.
This includes:
Importantly, only a federal agency can determine whether their specific use case falls within FedRAMP scope. The Consolidated Rules for 2026 identify several categories explicitly outside FedRAMP's scope, including single-agency systems not offered as shared services, social media platforms used for public communication, search engines, and ancillary services with negligible risk to federal information. (FedRAMP Scope)
As of August 2026, FedRAMP operates two active Certification paths:
| Rev5 | FedRAMP 20x | |
|---|---|---|
| Framework | NIST SP 800-53 Rev 5 | OMB M-24-15, Consolidated Rules 2026 |
| Structure | Low / Moderate / High impact levels | Class A / B / C / D |
| Assessment model | Point-in-time 3PAO assessment | Continuous automated validation |
| Status | Active; new applications end June 11, 2027 | Fully live; Class A/B/C pipelines open July 2026 |
| Class D (High equivalent) | Available now | Phase 4, estimated FY27 Q1 to Q2 |
FedRAMP 20x replaces Low/Moderate/High with Certification Classes. The rules for Class A, B, and C are finalized and submission pipelines opened in July 2026. (FedRAMP.gov)
Class A: For cloud services with mature security and compliance programs entering the federal marketplace. Requires a smaller set of initial ongoing monitoring and reporting requirements.
Class B: For small-scale or light-use services where agency-wide adoption is unlikely. Lower ongoing maintenance burden. Roughly analogous to Rev5 Low.
Class C: For common enterprise services used across an entire agency or that support important government functions. Higher ongoing reporting requirements. Roughly analogous to Rev5 Moderate.
Class D: Planned for Phase 4 (estimated FY27 Q1 to Q2). Will address the highest-sensitivity services currently handled under Rev5 High.
FedRAMP 20x is built on five principles: Transparency (honest disclosure of security decisions), Flexibility (informed engineering decisions over rigid checklists), Accountability (continuous security evidence over point-in-time audits), Accuracy (assessing effectiveness of decisions, not just their existence), and Automatic Validation (continuous, automated enforcement wherever possible). (FedRAMP 20x)
For CSPs on the Rev5 path, impact levels are still relevant until June 11, 2027:
| Impact Level | Data Sensitivity | Control Count | Typical Use |
|---|---|---|---|
| Low | Minimal if compromised | ~125 controls | Public-facing info systems |
| Moderate | Serious impact | ~325 controls | Most federal agency systems |
| High | Severe or catastrophic | 420+ controls | Law enforcement, health, financial, DoD |
Roughly 80% of federal cloud use cases fall under Moderate.
OMB Memorandum M-24-15 established two primary authorization paths, replacing the prior JAB P-ATO structure. The Joint Authorization Board (JAB) no longer functions as an authorization path. Existing JAB P-ATOs have been re-designated by the FedRAMP PMO. (M-24-15 Authorization Process)
Agency Authorization: Signed by the federal agency's authorizing official. Indicates the agency assessed the CSP's security posture per FedRAMP guidelines and found it acceptable for their use case and risk tolerance. Can also be conducted jointly by multiple agencies.
Program Authorization: Signed by the FedRAMP Director. Indicates FedRAMP assessed the cloud service directly and found it meets FedRAMP requirements for reuse by agency authorizing officials. Used when no agency sponsor has been identified but broad federal adoption is expected.
Both paths result in a FedRAMP Certification listed on the FedRAMP Marketplace. Both carry the presumption of adequacy that allows other agencies to reuse the package.
For CSPs pursuing Rev5 (still the only path for High/Class D until FY27):
Step 1: Readiness Assessment. Most CSPs commission a Readiness Assessment Report (RAR) from an accredited 3PAO before formal authorization. Not required, but it significantly reduces surprises. See Quzara's guide to FedRAMP 3PAO assessments for what to expect.
Step 2: System Security Plan (SSP). Documents your system boundary, data types, NIST SP 800-53 controls implemented, and inherited controls from your cloud platform. Quzara's complete FedRAMP authorization guide covers SSP development in detail.
Step 3: 3PAO Assessment. An accredited Third-Party Assessment Organization independently tests your controls and produces a Security Assessment Report (SAR) and Plan of Action & Milestones (POA&M).
Step 4: Agency or Program Authorization. An agency authorizing official (Agency Authorization) or the FedRAMP Director (Program Authorization) reviews the package and issues Certification. The service is then listed on the FedRAMP Marketplace.
Step 5: Continuous Monitoring. Authorization is ongoing. Monthly vulnerability scans, annual assessments, and regular POA&M updates are required throughout the life of the Certification. Rather than building an internal monitoring capability from scratch, many CSPs leverage a FedRAMP Certified SOC-as-a-Service to meet this requirement. Quzara Cybertorchâ„¢ is a FedRAMP Certified Class D MDR and SOC-as-a-Service, staffed exclusively by US-citizen analysts, providing 24/7 threat monitoring and the continuous monitoring coverage FedRAMP requires.
FedRAMP 20x is not a streamlined version of Rev5. It is a different model. The core shift: from compliance-focused, point-in-time audits to continuous, automated evidence of security decisions.
Under FedRAMP 20x, CSPs define their security goals for their specific environment, measure the effectiveness of those decisions continuously, and demonstrate assurance to agencies through progressively increasing commitments tied to the Certification Class. The government's position is that a CSO does not need to be evaluated against a single binary "secure/not secure" standard; different services carry different risks, and Certification Classes reflect that.
Phase 3 is currently active (FY26 Q3 to Q4): formalizing 20x requirements, opening submission pipelines, and providing agency training. Phase 4 (Class D pilot, estimated FY27 Q1 to Q2) follows. (FedRAMP 20x)
FedRAMP will stop accepting new Rev5 Certification applications on June 11, 2027. (FedRAMP.gov) FedRAMP has committed to providing a transition path for existing Rev5-Certified providers, but has not yet published the full transition timeline for all existing packages.
CSPs who have not started authorization yet have a clear decision to make: pursue FedRAMP 20x now, or begin Rev5 knowing the end-of-new-application date. CSPs mid-process on Rev5 should evaluate timeline risk carefully.
See Quzara's FedRAMP 20x Roadmap for a detailed breakdown of the phase-by-phase timeline and what it means for CSPs at different stages. For a full breakdown of what authorization costs across both paths, see How Much Does FedRAMP Cost?
Quzara's FedRAMP Advisory Services covers gap assessments, SSP development, 3PAO coordination, and OSCAL-based automation for both Rev5 and FedRAMP 20x paths. If you're already mid-process on Rev5, see the Rev5 Under 20x transition guide for how to navigate the June 2027 end-of-new-applications deadline.
What happened to the JAB and JAB P-ATOs?
The JAB (Joint Authorization Board) no longer functions as a FedRAMP authorization path. Under OMB M-24-15, the two paths are Agency Authorization and Program Authorization. Existing JAB P-ATOs have been re-designated by the FedRAMP PMO.
Is FedRAMP 20x available now?
Yes. FedRAMP 20x is fully live. The rules for Class A, B, and C are finalized under the FedRAMP Consolidated Rules for 2026. The submission pipeline opened in July 2026. Class D is planned for Phase 4 (estimated FY27 Q1 to Q2). (FedRAMP.gov)
Do I still need a 3PAO under FedRAMP 20x?
Under Rev5, an accredited 3PAO is required. Under FedRAMP 20x, the assessment model shifts to continuous automated validation. The specific requirements per Certification Class are in the FedRAMP Consolidated Rules for 2026. Consult an experienced advisory partner for the current requirements for your target Class.
What is the FedRAMP Marketplace?
The FedRAMP Marketplace is the official registry of FedRAMP-Certified cloud services. Federal agencies use it to identify services available for reuse under the presumption of adequacy. Listing on the Marketplace is a significant commercial advantage for any CSP selling to the government.
What is Quzara Cybertorch's FedRAMP Certification status?
Quzara Cybertorchâ„¢ holds FedRAMP Certified Class D status (Class D maps to the legacy Rev5 High baseline), one of a small number of MDR services to hold this designation on Azure Government, authorized for DoD IL-4.
Quzara provides FedRAMP advisory services and OSCAL-based automation for Rev5 and FedRAMP 20x paths. Talk to a FedRAMP advisor to map your Certification strategy.