By:
Matt Hungate
August 31st, 2026
FedRAMP's modernization effort, known as FedRAMP 20x, is continuing to advance. On August 31, 2026, the FedRAMP 20x program opened Class B and Class C as the next phase of its rollout. Under the program's official Consolidated Rules for 2026 (CR26), Class B pipeline replaces the old Low impact level for small-scale cloud services, and the Class C pipeline replaces the old Moderate impact level for common enterprise services.
By:
Nick Rundhaug
August 25th, 2026
This article was drafted based on a LinkedIn Live discussion between Schellman’s Nick Rundhaug and SecureIT's Tim Sandage and Corey Clements. View their full conversation here.
By:
Christian Baer
August 18th, 2026
Insight from Schellman's federal team on the FedRAMP 2026 Consolidated Rule update, featuring the program's biggest overhaul in years.
By:
Matt Hungate
August 3rd, 2026
Highlights from our GovFORWARD 8th Annual Carahsoft Summit on FedRAMP breakout session, featuring Schellman's Matt Hungate.
FedRAMP | Federal Assessments | SOC 2
By:
Matt Hungate
June 29th, 2026
If you’ve heard “FedRAMP” and immediately thought “that’s a year-long, million-dollar project we’re not ready for” — this post is for you. A lot has changed. The program's new Class A certification tier was built specifically for companies that have already done the hard work of achieving SOC 2 Type II. Here’s what your SOC 2 actually gets you, and why the path to the federal marketplace may be shorter than you think.
FedRAMP | News | Federal Assessments
By:
Schellman
June 25th, 2026
Schellman, the nation's No. 1 FedRAMP Independent Assessor, breaks down the most significant restructuring of the federal cloud security program since its 2011 inception.
By:
Matt Hungate
June 25th, 2026
On June 24, 2026, FedRAMP published the Consolidated Rules for 2026, featuring a sweeping overhaul of the policies, requirements, and terminology that govern how cloud service providers (CSPs) obtain and maintain FedRAMP Certification. The rules are effective July 4, 2026, for 20x CSPs and replace a patchwork of legacy guidance documents, memoranda, and program policies with a single machine-readable, structured ruleset. For existing Rev5 CSPs, most requirements become mandatory on January 1, 2027, with optional early adoption available immediately.
By:
Matt Hungate
June 4th, 2026
This article was drafted based on a LinkedIn Live discussion between Schellman’s Matt Hungate (Managing Principal, Federal Practice) and Jacob Karp (VP of Strategic Sales). View their full conversation here.