FedRAMP 20x Updates: What to Know Ahead of Your Assessment
Published: Aug 26, 2026
FedRAMP is undergoing its biggest structural shift in over a decade. In this conversation, Schellman's Nick Rundhaug, Managing Director and Federal Practice Leader, unpacks what FedRAMP 20x actually changes for cloud service providers (CSPs) and what to prioritize before walking into an assessment.
FedRAMP 20x: From Controls to Intent
FedRAMP Rev 5 relied on a prescriptive catalog of NIST 800-53 controls, each tied to a specific interview, test, or examination method. FedRAMP 20x replaces that with Key Security Indicators (KSIs), an outcome-based model that asks whether a CSP is meeting the intent of a requirement.
Assessors now evaluate three things under 20x:
- Whether a CSP is doing what it says it's doing
- Whether that meets the underlying intent
- Whether the claimed level of automation actually covers the full attack surface
Traditional risk ratings (impact/likelihood) are gone; automation coverage is the new focus.
Automation Is No Longer Optional Under FedRAMP 20x
FedRAMP 20x is built around on-demand, real-time evidence rather than an annual snapshot. During the pilot, packages under roughly 70% automation were reportedly rejected outright. Assessors are now testing systems live, reviewing scripts and code in real time, rather than requesting evidence in advance.
Machine-Readable Documentation
The SSP is splitting into two new artifacts: the Package Overview (CPO) and Security Decision Record (SDR). Both are required in machine-readable JSON format, following FedRAMP-published schemas. For most CSPs, this documentation and engineering lift is proving to be the biggest bottleneck in early cohorts.
Should CSPs Switch from Rev 5 to 20x?
For established CSPs, the answer is usually not yet, and not urgently. Rev 5 packages can still be submitted through June 11, 2027, with authorizations expected to remain listed through at least the end of 2028. The clearest early movers toward 20x are CSPs without an existing agency sponsor, since 20x offers a sponsor-less path, solving one of the biggest pain points of the legacy JAB process.
A Lower-Cost On-Ramp: Class A
FedRAMP 20x also introduces Class A, which leverages an existing SOC 2 report to demonstrate baseline security maturity, a spiritual successor to the old FedRAMP Ready designation. It's not for every CSP, but it offers an inexpensive way to signal readiness to federal customers before committing to full authorization.
Vulnerability Management Gets More Realistic Under 20x
Rev 5 relied heavily on rigid CVSS scoring. FedRAMP 20x introduces contextual risk adjudication, which factors in real-world exploitability and exposure. Pen test results, scans, control testing, and threat intelligence must now be consolidated into a single Vulnerability Detection Report (VDR). Many scanning tools haven't caught up yet, so expect some manual work in the near term.
FedRAMP 20x Continuous Monitoring Requirement
Annual ConMon reporting is being replaced by quarterly stakeholder meetings and persistent, on-demand evidence. The goal is less end-of-year scramble and more sustained accountability. CSPs must also maintain an explicit, stakeholder-visible change log going forward.
What CSPs Shouldn't Overlook for 20x
The top three priorities for any CSP starting today include:
- Trust center: real-time and stakeholder-facing, not a static login page.
- Machine-readable documentation: budget real engineering time for this.
- Automation coverage: build it to span the entire attack surface from day one.
FedRAMP 20x is currently designed primarily for SaaS products built on major hyperscalers (Azure, GCP, OCI). CSPs with legacy or non-standard architectures don't yet have a clearly defined path and should reach out to FedRAMP directly.
Moving Forward with FedRAMP 20x
FedRAMP 20x isn't a lighter version of Rev 5, but rather a different way of proving trust: continuous, outcome-based, and dependent on real automation investment. As cohort packages begin moving through the pipeline this fall, expect more agency-specific guidance to emerge.
For now, CSPs evaluating their path should weigh their current agency relationships, data sensitivity, and appetite for building out machine-readable, automated evidence pipelines.
Watch the full conversation above for more detail on FedRAMP 20x, Class A, and what's ahead for CSPs navigating this transition.
About Nick Rundhaug
Nick Rundhaug is a Managing Director and Federal Practice Leader with Schellman. Nick has over 20 years of experience in the information technology field with 15 years’ experience in Federal frameworks for information technology. With a background as a network engineer and assessor, Nick specializes in the areas of cryptography, networking, and security mechanisms in cloud environments.