How to Navigate the FedRAMP 20x Certification Process
Published: Aug 25, 2026
This article was drafted based on a LinkedIn Live discussion between Schellman’s Nick Rundhaug and SecureIT's Tim Sandage and Corey Clements. View their full conversation here.
FedRAMP's 2026 consolidated rules went into effect at the end of June, and they mark one of the biggest structural changes to the certification process in years. For cloud service providers (CSPs) already on the Rev 5 path, or those considering a new authorization, the questions are immediate and practical: Which pathway should we be on? What actually changed? And what deadlines are now on the clock?
In this article, we break down what's actually different between FedRAMP Rev 5 and FedRAMP 20x, the dates CSPs need to be aware of, and how to know if you should pivot from Rev 5 to 20x.
What's Actually Different Between FedRAMP Rev 5 vs. 20x
FedRAMP Rev 5 is built on the familiar NIST 800-53 control set, but with an additional layer of new rules on top that all CSPs now need to comply with as detailed in the Consolidated Rules for 2026 (CR 26).
FedRAMP 20x takes a different approach entirely. Rather than the roughly 320 traditional Rev 5 controls, 20x introduces 46 Key Security Indicators (KSIs), which are standard security mechanisms like maintaining a firewall. Plus, one additional major catch: CSPs are expected to automate compliance checking and reporting on an ongoing basis, not just demonstrate compliance at a point in time. That's a meaningful engineering lift that didn't exist under Rev 5, often requiring custom coding and scripting to generate machine-readable compliance data continuously.
The documentation model has changed, too. The familiar System Security Plan (SSP) is being replaced by two new documents: the Certification Package Overview (CPO) and the Security Decision Record (SDR), both of which must conform to a JSON schema rather than free-form narrative. It's a leaner set of documentation overall, but it demands more structure and technical precision than writing a traditional SSP ever did.
On the assessment side, independent assessors are now validating not just whether a control is satisfied, but whether the automation and reporting infrastructure behind a KSI genuinely works as claimed. Notably, assessors are no longer tasked with producing risk ratings, as that responsibility now shifts more heavily onto the agencies and stakeholders consuming the reports.
The FedRAMP Timeline: Key Dates CSPs Need to Track
Three key dates CSPs need to track right now:
- August 31, 2026: the first date non-pilot 20x packages (Classes A, B, and C) can be officially submitted. Class D, roughly equivalent to a "High" baseline, is still to come.
- January 1, 2027: adoption date for the consolidated rules (CR26), after which all stakeholders, including existing Rev 5-authorized systems, are expected to comply.
- June 11, 2027: the current cutoff for submitting traditional Rev 5 packages for initial certification. To make this date, an agency sponsor needs to have already reviewed, authorized, and issued an ATO letter, meaning assessment needs to start well before the deadline itself to leave room for remediation and agency review. FedRAMP will maintain these certified Rev5 packages on the FedRAMP Marketplace at a minimum through the end of 2028.
As with most FedRAMP timelines, some movement on these dates wouldn't be surprising, but nothing has changed as of this writing.
A Machine-Readable Future for FedRAMP
One of the more forward-looking components of FedRAMP 20x is the shift toward machine-readable compliance data. FedRAMP wants the ability to query a CSP's compliance posture on demand, which is useful in scenarios like a zero-day vulnerability, where agencies need to know immediately whether a given product is affected.
The mandated format is JSON, though notably, OSCAL, the schema the community has been building toward since 2018, isn't yet front and center in the new rules. The consumers of that machine-readable data extend well beyond FedRAMP itself to sponsoring agencies and other CSPs who rely on an underlying cloud service as part of their own offering.
FedRAMP 20x: An Agency-Less Path and Faster Reviews
For CSPs who've spent years fighting to find an agency sponsor, 20x introduces a genuine structural fix with an agency-less submission path. FedRAMP now functions more like a clearinghouse, letting stakeholders assess risk on their own rather than requiring a sponsor to greenlight the process from the start. Getting listed on the marketplace requires no advisor or sponsor at all, just an application and a basic trust center, and dozens of CSPs had already done so within the first week it opened.
Review timelines have also improved dramatically. What used to take up to a year under the old process has consolidated to around a month in recent pilots, though a temporary slowdown is expected as submissions ramp up after August 31.
Should CSPs Pivot from FedRAMP Rev 5 to 20x?
Whether or not CSPs should pivot from Rev 5 to 20x depends on their specific contract needs.
If an agency sponsor is firm on requiring FISMA-style NIST baselines, staying the Rev 5 course still makes sense. This is particularly true for CSPs pursuing DoD-related impact levels, where guidance on how 20x interacts with those requirements is still evolving. If speed to market and lower lift are a priority, especially without a committed sponsor, 20x is worth targeting directly.
For CSPs already deep into a Rev 5 package, most of that investment isn't wasted as the underlying security controls carry over, and the shift to CR 26 is largely about layering automation and machine-readable reporting on top of work already done. Some organizations may find themselves supporting both formats for a period, maintaining traditional templates for agencies that still want a human-readable package alongside the newer machine-readable output.
Moving Forward with FedRAMP
FedRAMP 20x represents a genuine simplification in some respects with regards to fewer total requirements, a faster review process, and a path to authorization that no longer depends entirely on finding a willing agency sponsor. But it also introduces new engineering demands that didn't exist before, such as less established guidance to lean on than the decades of documentation behind NIST 800-53, and firm deadlines that are already close at hand.
For CSPs navigating the transition, the near-term priority is clear: understand which pathway fits your current contracts and roadmap, and build backward from June 11, 2027, to make sure your timeline actually works. To learn more about how to proceed on your FedRAMP journey, contact us today.
In the meantime, discover other insights in these helpful resources:
About Nick Rundhaug
Nick Rundhaug is a Managing Director and Federal Practice Leader with Schellman. Nick has over 20 years of experience in the information technology field with 15 years’ experience in Federal frameworks for information technology. With a background as a network engineer and assessor, Nick specializes in the areas of cryptography, networking, and security mechanisms in cloud environments.