New Report: The State of AI Governance 2026

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

The FedRAMP 20x Blueprint: What It Will Take to Scale Secure Cloud Adoption

FedRAMP | Federal Assessments

Published: Aug 3, 2026

Highlights from our GovFORWARD 8th Annual Carahsoft Summit on FedRAMP breakout session, featuring Schellman's Matt Hungate.

During this year's GovFORWARD Carahsoft Summit on FedRAMP breakout session, "The Path to 4,500: Scaling Secure Cloud Adoption Across Government," the panel of subject matter experts from government and industry tackled one of the most pressing questions in federal IT modernization today: how do we scale the FedRAMP marketplace from where it stands now to a future where thousands of secure, certified solutions are readily available to agencies?

If you missed the session, or want a refresher on the key takeaways, here's a recap of the conversation.

The Legacy Loop: Why "More People" Won’t Solve the Problem

The panel opened with a candid diagnosis of what's held modernization back for years: not a lack of people, but a broken review process. Adding more reviewers to a flawed system doesn't fix the system, it just scales the inefficiency.

The result has been a review process that has often left both government and industry in the "Circular Cycle", which is a repetitive loop in which a provider submits materials, gets flagged for errors, resubmits without fully resolving them, and the loop repeats, consuming months of effort on both sides without producing a certified product

That fatigue is what FedRAMP 20x is designed to eliminate by replacing ambiguous documentation requirements with clear, structured rules that let reviewers focus their time on technology and security outcomes.

The 20x Revolution: From Gatekeepers to Open Marketplace

Perhaps the biggest shift discussed was the move away from the legacy "Rev 5" stage-gate model, which required Cloud Service Providers (CSPs) to secure an agency sponsor before they could even be considered for certification. That requirement effectively made agencies the bottleneck for the entire marketplace.

FedRAMP 20x eliminates this bottleneck through Program Certifications, a sponsor-free path that allows CSPs to submit their assessment results directly to FedRAMP. FedRAMP also introduced Class A Certifications, an entry point that leverages existing industry compliance reports like SOC 2, allowing agencies to pilot products with real data much earlier in the process. The panel described this as "opening the floodgates," giving venture-backed and emerging innovators a realistic path into the federal market for the first time.

  Legacy Stage Gate (Rev 5) 20x Accelerated Path (Class A)
Market Entry Requires an Agency Sponsor first Sponsor-free entry via the FedRAMP PMO
Security Foundation Manual, high-granularity controls Leverages existing audits (e.g., SOC2)
Speed Beholden to agency leadership timelines "Opening the floodgates" for any viable tool

Structure as the Enabler of Speed

With the gates open, the panel turned to the question of scale: how do you avoid trading one bottleneck for chaos? The answer, they explained, lies in strict machine-readable standards: JSON schemas that give the government a consistent, automatable way to validate submissions, regardless of whether a company offers a sophisticated AI platform or something as simple as an internal tracking tool.

The panel walked through the automated intake process now in place for Marketplace applications:

  1. Automated Intake: Providers initiate contact through streamlined, dev-team-monitored channels.
  2. JSON Schema Validation: Submissions must match the exact data structure required for marketplace automation.
  3. Marketplace Listing: Validated products move quickly into the initial implementation phase.

The early results are promising: in just the first two weeks of this phase being open, more than 20 services applied and 6 were immediately listed, which is a strong signal that structure, not headcount, is what unlocks speed.

The Human Side of Modernization

Technology and process aside, the panel spent significant time on the people who have to adapt to this new model, and the very different friction points each group faces:

  • Agency Mission Owners, who need to see 20x as a source of "plug-and-play" solutions that fill real gaps in operations and mission delivery.
  • Agency Authorizing Officials (AO), who need reassurance that a FedRAMP certification already covers the necessary security clauses, without requiring them to build new processes from scratch.
  • Legacy Contractors, many of whom are locked into rigid Contract Line Item Numbers (CLINs) written for the old process and are, in some cases, contractually unable to pivot to the new one without renegotiation.
  • Technology Innovators, often small, high-growth companies far outside the D.C. beltway who have the technology agencies need but little visibility into how to reach the federal market. The panel was clear: government needs to go to them, both geographically and technically, rather than waiting for them to find their way in.

The Path to 4,500: Scaling Secure Cloud Adoption Across Government

Reaching 4,500 certified services isn't a vanity metric, it's the tipping point for a genuinely modern government marketplace. A larger, more competitive marketplace:

  • Keeps vendors sharper, because they can no longer rely on being the only sponsored option in a category.
  • Lets agencies deploy certified tools faster to meet real citizen needs.
  • Ends the "GRC trap" — agencies staying with underperforming tools simply because that vendor was the one that found a sponsor. A 4,500-service marketplace ensures that the best technology wins, not just the most "connected."

The era of the "billion-dollar, two-person company" is already here. The task now is making sure government is structurally ready to adopt that innovation, and 20x, with its grounded rules and machine-readable standards, is the mechanism built to get us there.

Want to keep the conversation going? If your organization is navigating the shift to FedRAMP 20x, whether you're a CSP evaluating Class A certification, an agency rethinking procurement, or a contractor working through CLIN constraints, we'd love to talk. Reach out to our team to discuss how these changes affect your roadmap.

In the meantime, discover additional FedRAMP 20x insights in the below resources:

About Matt Hungate

Matt Hungate is a Principal with Schellman based in Richmond, VA. Matt specializes in Federal Assessments at Schellman, including compliance with standards such as FedRAMP, NIST, ITAR, and CJIS. Prior to joining Schellman in 2019, Matt worked as a Cybersecurity Consultant for a large advisory firm where he specialized in strategy and assessment services for NIST 800-53 and FedRAMP. Matt also led and supported various other projects, including the development of an enterprise wide cybersecurity strategy and cloud transition plan for a large federal agency. Matt has experience comprised of serving clients in both the private and public sectors, and his credentials include the CISSP, CISA, and CPA.