What to Know as FedRAMP 20x Opens the Door to Class B and Class C
Published: Aug 31, 2026
FedRAMP's modernization effort, known as FedRAMP 20x, is continuing to advance. On August 31, 2026, the FedRAMP 20x program opened Class B and Class C as the next phase of its rollout. Under the program's official Consolidated Rules for 2026 (CR26), Class B pipeline replaces the old Low impact level for small-scale cloud services, and the Class C pipeline replaces the old Moderate impact level for common enterprise services.
If you've been tracking FedRAMP's shift toward faster, more automated certifications, this is the next milestone worth understanding.
What is FedRAMP 20x?
FedRAMP 20x is the PMO's effort to restructure how cloud service providers (CSPs) get certified to serve federal agencies. Instead of the traditional, document-heavy certification process under Rev 5, 20x leans on automation, machine-readable evidence, and continuous validation against a defined set of Key Security Indicators (KSIs).
The FedRAMP 20x Rollout So Far:
- July 6, 2026: FedRAMP Marketplace listings opened to any CSP wanting to enter the initial implementation stage.
- August 3, 2026: The Class A pipeline opened.
- August 31, 2026: The Class B and Class C pipelines opened.
What Opened for FedRAMP 20x on August 31, 2026
At a high level, Class B and C differ from Class A and from each other in key areas such as:
- Scope or impact level: which types of cloud services and risk levels each class covers
- Eligibility: whether CSPs need prior FedRAMP experience, an existing ATO, or other prerequisites to apply
Where FedRAMP 20x is Headed
For the broader compliance community, this is a signal that FedRAMP 20x is moving from pilot to scale. Class B and C opening means:
- More CSPs will soon have a faster path to federal certification
- Agencies will have a larger pool of 20x-certified providers to choose from sooner than under the legacy process
- The KSI framework and continuous validation approach are likely to become the default expectation, not just a pilot experiment
What to Watch Next with FedRAMP 20x
A few things worth keeping an eye on as the program continues to roll out:
- Official guidance and updates from the FedRAMP PMO on Class B/C requirements and timelines
- Early participants: which CSPs move first, and how their experience compares to the 20x pilot cohort
- Agency adoption: whether federal agencies keep pace with the faster certification timelines
- KSI updates: any changes to the Key Security Indicators as the program scales
Moving Forward with FedRAMP 20x
August 31 marks another step in FedRAMP's push toward a faster, automation-driven certification model. Whether you're watching from the CSP side, the agency side, or just tracking federal compliance trends generally, it's a good moment to check FedRAMP's official announcements and see how Class B and C actually shape up in practice.
About Matt Hungate
Matt Hungate is a Principal with Schellman based in Richmond, VA. Matt specializes in Federal Assessments at Schellman, including compliance with standards such as FedRAMP, NIST, ITAR, and CJIS. Prior to joining Schellman in 2019, Matt worked as a Cybersecurity Consultant for a large advisory firm where he specialized in strategy and assessment services for NIST 800-53 and FedRAMP. Matt also led and supported various other projects, including the development of an enterprise wide cybersecurity strategy and cloud transition plan for a large federal agency. Matt has experience comprised of serving clients in both the private and public sectors, and his credentials include the CISSP, CISA, and CPA.