By:
Nick Rundhaug
August 26th, 2026
FedRAMP is undergoing its biggest structural shift in over a decade. In this conversation, Schellman's Nick Rundhaug, Managing Director and Federal Practice Leader, unpacks what FedRAMP 20x actually changes for cloud service providers (CSPs) and what to prioritize before walking into an assessment.
By:
Nick Rundhaug
August 6th, 2026
FedRAMP's consolidated 2026 rules landed at the end of June, and the shift they represent is significant, featuring new Key Security Indicators (KSIs) for automated, continuous compliance reporting, a leaner but more technical documentation model built around machine-readable CPO and SDR files, and a compressed timeline that's already cutting review periods from years down to about a month.
By:
Douglas Barbin
June 9th, 2026
CMMC certification is mandatory if you want federal contracts, but the journey doesn't end there.
By:
Matt Hungate
May 27th, 2026
The FedRAMP landscape is shifting. With the introduction of FedRAMP 20x, cloud service providers now face a critical decision: pursue the newer 20x authorization pathway, stay the course with Rev 5, or chart a hybrid strategy that positions them for both short-term and long-term success.
By:
Matt Hungate
January 28th, 2026
FedRAMP is entering a period of meaningful transformation. Recent Requests for Comments (RFCs) released by the FedRAMP Program Management Office (PMO) signal a clear vision for the future focused on automation, reuse of existing compliance efforts, and expanded access to the federal marketplace.
By:
Matt Hungate
January 21st, 2026
FedRAMP is signaling a significant shift in how cloud service providers (CSPs) can enter and navigate the federal marketplace. Recent Requests for Comments (RFCs), while still in draft form, provide a clear preview of the program’s direction, which prioritizes modernization, automation, and faster pathways to authorization.
By:
Avani Desai
December 15th, 2025
The new FedRAMP 20x low baseline pilot is the most significant modernization of federal cloud security in more than a decade, and it could represent a big opportunity for cloud service providers looking to enter or expand within the federal marketplace.
By:
Matt Hungate
November 17th, 2025
FedRAMP 20X is emerging as one of the most significant changes to federal cloud security authorization in years. Designed to streamline how cloud service providers (CSPs) work with the U.S. government, 20X introduces a faster, more accessible alternative to the traditional FedRAMP Rev5 authorization path. For organizations looking to enter or expand within the federal market, understanding this new model is essential.
By:
Marci Womack
August 9th, 2023
One of the questions that we get the most often when we're talking about Federal assessments is how long does it take to get through the assessment process and what happens afterward to actually get to FedRAMP authorization?
By:
Marci Womack
July 5th, 2023
So you're looking to achieve a CMMC certification. In this video, we will cover the