Live Webinar | Building AI Governance That's Audit-Ready on September 23 @ 1:00PM ET

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

FedRAMP 20x Decoded: An Assessor's Guide to KSIs, Automation, and the New Path to Authorization

FedRAMP | Federal Assessments

Published: Sep 10, 2026

Insights from a conversation with Nick Rundhaug, Managing Director and Federal Practice Leader at Schellman. See his full interview here.

Key Takeaways

  • FedRAMP 20x replaces control-by-control compliance with Key Security Indicators (KSIs), shifting the focus from checking individual controls to demonstrating the intent behind them.
  • Machine-readable documentation (JSON) is the biggest bottleneck for most CSPs converting from Rev 5.
  • FedRAMP 20x is sponsor-less, making it the more practical path for CSPs without an existing agency relationship.
  • Rev 5 remains viable for now, with packages accepted through June 11 and listings expected through at least 2028.
  • Class A offers a lower-cost on-ramp, leveraging an existing SOC 2 report to demonstrate baseline security maturity before pursuing full authorization.
  • Continuous monitoring shifts to quarterly check-ins and persistent evidence, trading the annual reporting spike for ongoing accountability.

The FedRAMP program is undergoing its biggest structural shift in over a decade. The move from Rev 5's control-by-control model to FedRAMP 20x, built around Key Security Indicators (KSIs), fundamentally changes how cloud service providers (CSPs) prove they're secure.

To unpack what's actually changing, we sat down with Nick Rundhaug, who leads Schellman's federal practice and has spent the last decade as a FedRAMP assessor (after starting his career as a signal officer in the U.S. Army). Here's what CSPs, readiness partners, and stakeholders need to understand right now about the FedRAMP program's new direction.

FedRAMP 20x KSIs: The Shift from Control-by-Control to Intent-Based Compliance

The traditional Rev 5 model was prescriptive. NIST 800-53 laid out over a thousand controls, and assessors (historically called Third Party Assessment Organizations, now simply referred to as "independent assessors") worked through a compendium that dictated exactly how each control needed to be interviewed, tested, and examined.

With 20x, instead of a fixed mechanism, FedRAMP now evaluates if CSPs are meeting the intent, and that shows up as a three-part evaluation:

  1. Are you doing what you say you're doing? Assessors compare the CSP's Package Overview and Security Decision Record documentation against what's actually happening in the environment.
  2. Does that meet the intent of the KSI? In other words, does your approach actually satisfy the underlying security objective?
  3. Is it automated to the degree you claim? If a CSP says a control is fully automated, it has to cover the entire attack surface, spanning MFA across VPN, web app, and mobile, for example.

Another deliberate departure from the older model is that FedRAMP 20x explicitly does not do traditional risk ratings based on impact and likelihood.

Why Automation Is Now a Requirement for FedRAMP 20x Authorization

One of the more consequential changes in 20x is that FedRAMP now wants evidence to be available on-demand, rather than a once-a-year snapshot. Instead of waiting for an annual report that might be describing a system state from six months ago, stakeholders should now be able to go to a CSP's trust center and pull current KSI/rule status at any time.

That expectation was strict enough that, during the pilot phase, FedRAMP reportedly rejected packages that weren't at least ~70% automated, sending CSPs back to raise their automation coverage before resubmitting.

As a result, assessors are now reviewing scripts, code, and native platform mechanisms live, in real time, rather than requesting evidence packages in advance. Currently, most CSPs land in "partially automated," which means assessors have to write a detailed narrative explaining exactly where automation exists, where it doesn't, and whether the results being pulled are accurate.

Machine-Readable Documentation in FedRAMP 20x Compliance

We've found it's the documentation format that is actually slowing CSPs down in the transition. The SSP is essentially splitting into two artifacts:

  • CPO (Package Overview): closer to a threat narrative
  • SDR (Security Decision Record): closer to the controls documentation

Both now need to be produced in machine-readable JSON, following FedRAMP-published schemas (best reviewed via GitHub, since FedRAMP's own site doesn't pretty-print them). For most CSPs, this is new territory, and it's proving to be the single biggest friction point in cohort submissions so far.

It's best practice to start by defining what's actually being asked for in human terms first, confirm it can be pulled from the system reliably, and only then build the automation or GRC pipeline that renders it into the required machine-readable format. Trying to jump straight to JSON without that translation step is where most teams get stuck.

FedRAMP Rev 5 vs. FedRAMP 20x: Which Authorization Path Should CSPs Choose?

With over 200 authorizations in Schellman's portfolio, we've noticed that most Rev 5 CSPs aren't rushing to convert, and this decision tends to be agency-dependent:

  • FedRAMP 20x: CSPs with one or two agency relationships, lower-sensitivity data, or agencies that have already signaled comfort with 20x are the most likely early movers.
    • The other major draw toward 20x is that it is sponsor-less. For CSPs who've struggled to find an agency sponsor since the JAB was discontinued, this alone may be the deciding factor.
  • FedRAMP Rev 5: Everyone else has a real runway. Rev 5 packages can still tentatively be submitted until June 11, 2027, and authorizations will likely continue to be listed through at least the end of 2028.

If your organization is deep into a Rev 5 process, it's advised to finish it, but plan to submit well before the June 11 cutoff, with a minimum of a couple of months of buffer, to make sure sponsorship and everything else lines up smoothly.

FedRAMP Class A Explained: Using SOC 2 as an On-Ramp to Federal Authorization

FedRAMP 20x also introduced Class A, which functions as a rough successor to the old FedRAMP Ready designation, but instead of a bespoke readiness assessment, it derives heavily from an existing SOC 2 report.

It's not a one-to-one replacement, but the logic is similar: demonstrate a baseline level of security maturity, signal seriousness to potential federal customers, and create a lower-cost path into the ecosystem before committing to full authorization. This option won't make sense for every CSP, but for those building credibility with federal-adjacent prospects, it can be a meaningful, inexpensive first step to pursue.

Vulnerability Management Changes in FedRAMP 20x: How Contextual Risk Replaces CVSS-Only Scoring

FedRAMP Rev 5's vulnerability management was rigid, involving CVSS 3.0 scoring, strict SLAs, and everything logged in the POA&M regardless of real-world exploitability.

20x introduces contextual, "actual risk" adjudication. Rather than just a raw CVSS score, CSPs can now factor in things like internet reachability and real exposure when determining whether a finding needs to go into the POA&M as high risk. Pen test results, scan data, control testing, and threat intelligence are now explicitly required to live together in the VDR (Vulnerability Detection Report), rather than being scattered across separate control requirements.

Continuous Monitoring Under FedRAMP 20x: Quarterly Reporting and Real-Time Accountability

20x replaces the once-a-year continuous monitoring crunch with quarterly stakeholder meetings and a persistent evidence model. The trade-off results in less assessment fatigue overall and more continuous accountability. CSPs now have to explain what they're doing about identified risks on a quarterly basis rather than scrambling to address them once a year in a static report.

Under 20x, CSPs are also now required to maintain an explicit change log, meaning a running historical record that stakeholders can check at any time to see what's changed and whether it affects them.

FedRAMP 20x Readiness Checklist

Before starting a FedRAMP assessment, CSPs need:

  1. Trust center that is real-time and stakeholder-facing.
  2. Machine-readable documentation. The JSON/schema work is a real engineering lift, not a documentation afterthought.
  3. Automation coverage built with the full attack surface in mind from day one.

Notably, FedRAMP 20x is built primarily for SaaS products running on major hyperscalers (Azure, GCP, OCI, etc.). CSPs with legacy architecture, edge/point-of-presence components, or anything that doesn't fit that mold don't yet have a clear path and should reach out to FedRAMP directly to confirm their options.

Preparing Your FedRAMP 20x Authorization Strategy

FedRAMP 20x should not be viewed as a lighter version of Rev 5, but rather a fundamentally different way of demonstrating trust: outcome-based rather than checklist-based, continuous rather than annual, and dependent on real engineering investment in automation and machine-readable evidence.

For CSPs starting today without an existing agency relationship, the sponsor-less path alone makes 20x the more practical route. For those deep into Rev 5, there's no need to immediately shift, but the runway isn't infinite, and the sooner teams start building the automation and documentation muscle, the smoother the eventual transition will be.

As cohort packages begin hitting FedRAMP after August 31st, 2026, we expect a wave of real-world feedback and likely some agency-specific tailoring to shape how 20x actually plays out in practice. This is very much a live, evolving program, and CSPs would do well to keep a close eye on FedRAMP's guidance as the rest of the year unfolds.

In the meantime, if you have questions about 20x requirements, your current FedRAMP journey, or which path you should pursue, contact Schellman's Federal Practice team today.

You can also find additional insights in these helpful resources:

About Nick Rundhaug

Nick Rundhaug is a Managing Director and Federal Practice Leader with Schellman. Nick has over 20 years of experience in the information technology field with 15 years’ experience in Federal frameworks for information technology. With a background as a network engineer and assessor, Nick specializes in the areas of cryptography, networking, and security mechanisms in cloud environments.