If your organization sells cloud services to the federal government, or if you work inside an agency that buys them, FedRAMP is the gate you have to pass through. For years the program was known for being slow, paperwork heavy, and expensive to navigate. In 2026 that changed in a big way. The government finalized a sweeping set of updates called the Consolidated Rules for 2026, and the vocabulary, the tiers, and the timelines you may have learned are now different. This guide walks through what FedRAMP is, what just changed, and what both cloud vendors and agencies need to do about it.
What FedRAMP Is and Why It Exists
FedRAMP stands for the Federal Risk and Authorization Management Program. It was created to solve a simple but expensive problem. Before FedRAMP, every federal agency assessed cloud products on its own. A cloud provider that wanted to sell to ten agencies might sit through ten separate security reviews, each with its own reviewers, its own paperwork, and its own timeline. FedRAMP introduced a “do once, use many times” model. A cloud service gets assessed against a standardized set of security controls, and other agencies can reuse that work instead of starting from scratch.
The security controls themselves come from NIST Special Publication 800-53, the same control catalog that underpins the federal Risk Management Framework. If you already understand the RMF, FedRAMP will feel familiar. It applies that same control based, risk based thinking specifically to cloud offerings such as software as a service, platform as a service, and infrastructure as a service.
The Big 2026 Change: Consolidated Rules
On June 25, 2026, FedRAMP launched the Consolidated Rules for 2026, often shortened to CR26. This is the largest overhaul the program has seen. Three shifts matter most.
The label changed. The terms “FedRAMP Authorization” and “FedRAMP Authorized” have been retired. The single official label is now “FedRAMP Certification” and “FedRAMP Certified.” This is more than branding. The old wording made people think a FedRAMP authorization was the same thing as a government wide authorization to operate, and it was not. The new term is meant to clear up that confusion.
The tiers changed. The familiar Low, Moderate, and High impact levels are being replaced by certification classes labeled A, B, C, and D. More on those below.
Automation is now expected. Instead of assembling a giant document package once and revisiting it occasionally, cloud providers are expected to keep their certification evidence continuously updated using automation. The goal is security assurance that is measurable, machine readable, and reusable, rather than a static binder that goes stale the day it is signed.
Certification Classes A Through D
The move from impact levels to certification classes is the change most people will trip over, so here is a clear map.
Class A is a transitional designation introduced under FedRAMP 20x. It is available through an external framework, initially SOC 2 Type II, and gives a cloud service a fast on ramp into the federal market. Holders get a two year window to earn a full Class B, C, or D certification through a complete assessment.
Class B replaces the old Low and Li-SaaS baselines. It applies to systems handling non-sensitive federal information where a breach would cause only limited harm.
Class C replaces the old Moderate baseline. It covers systems that handle Controlled Unclassified Information and other non-public federal data where a breach could cause serious but not catastrophic harm. This is the most common tier by far, and roughly 80 percent of certified services live here.
Class D replaces the old High baseline. It covers the most sensitive systems, involves the largest set of controls, and must always go through the agency authorization path rather than a program level shortcut.
If you have been studying cloud security with the older Low, Moderate, High language, the concepts still hold. The sensitivity of the data and the potential impact of a breach still drive the tier. Only the labels and some of the process details have changed.
What FedRAMP 20x Means
FedRAMP 20x started as a small pilot aimed at making certification faster and more automated. With the release of CR26, 20x became a widely available certification path rather than an invite only experiment. The Class A pipeline opened on August 3, 2026, and the Class B and Class C pipelines opened on August 31, 2026. The through line of 20x is clear, measurable, reusable evidence produced with automation instead of manually assembled documents.
The Rev5 Sunset Timeline
If your service is already FedRAMP authorized under the Rev5 baseline, you are not exempt. There is a defined off ramp, and the dates matter.
By December 7, 2026, providers must adopt the new Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rulesets. The Consolidated Rules take mandatory effect for all stakeholders on January 1, 2027. FedRAMP stops accepting new Rev5 applications on June 11, 2027. On February 1, 2028, grace periods expire and noncompliant offerings lose their certification. Rev5 itself sunsets completely by December 31, 2028. Any provider still on the old model past those dates risks losing the ability to sell to federal customers.
What This Means for Vendors and Agencies
For cloud vendors, the takeaway is to plan the transition now rather than in 2028. Map your current authorization to the new class that fits your data sensitivity, decide whether the 20x path or a full agency assessment makes sense, and start building the automated evidence pipeline the new rules expect. The engineers who own that work need a strong grounding in cloud security architecture. Certifications like the CCSP build exactly that foundation, and platform specific training such as AWS and Azure security helps teams implement controls correctly on the platforms they actually run.
For agencies, the job is to understand the new certification classes so you can match a cloud service to the sensitivity of your data, and to keep leaning on reuse so you are not repeating assessments other agencies have already completed. Security leaders steering these decisions benefit from the governance perspective taught in the CISSP and CISM programs, and the control based discipline of the RMF maps directly onto how FedRAMP evaluates risk.
How IT Dojo Can Help
If you need training in cloud security and FedRAMP related compliance, IT Dojo can help. Our CCSP prep course builds the cloud security foundation that FedRAMP work depends on, and our RMF, AWS, and Azure security courses round out the skills your team needs to design, implement, and maintain compliant cloud systems. All IT Dojo courses are live remote online and led by experienced instructors, so your team can learn from anywhere. Contact IT Dojo to talk through the right training path for your organization.