What Is FedRAMP 20x? A Guide to the Future of Federal Cloud Certification
FedRAMP 20x is the federal government’s modern certification model for cloud services. It replaces much of the traditional document-heavy approach with Security Decision Records, Key Security Indicators, structured data, automation, independent validation, and persistent knowledge of the cloud service’s security state.
Executive Summary
What Is FedRAMP 20x?
FedRAMP 20x is a redesigned approach to certifying and maintaining cloud services for federal use.
Traditional FedRAMP Rev. 5 relies heavily on formal control narratives, a System Security Plan, spreadsheets, assessment documents, vulnerability reports, POA&Ms, and recurring continuous-monitoring submissions.
FedRAMP 20x moves toward a more structured model built around declarative rules, Security Decision Records, Key Security Indicators, machine-readable certification information, measurable security outcomes, historical metrics, secure configuration guidance, independent assessment, and persistent validation.
The purpose is not to reduce federal cloud security. The goal is to reduce unnecessary manual friction while making the cloud service’s real security posture easier to understand, verify, maintain, and reuse.
FedRAMP 20x asks cloud providers to continuously demonstrate how their security works rather than rebuilding a mostly static compliance package before every major review.
FedRAMP 20x Is No Longer Only a Pilot Concept
FedRAMP introduced the 20x initiative in March 2025 and tested its early concepts through multiple pilot phases.
In June 2026, FedRAMP launched the Consolidated Rules for 2026. These rules establish the certification, assessment, package, validation, Marketplace, security, and ongoing requirements used across the modernized program.
Marketplace listings for providers entering the initial implementation stage opened July 6, 2026. The Class A pipeline is scheduled to open August 3, 2026, followed by the Class B and Class C pipelines on August 31, 2026.
This means cloud providers should no longer treat FedRAMP 20x as a distant possibility. It is an active certification path with defined rules, certification classes, package requirements, assessment expectations, and transition dates.
Package-Centered Model
Security is documented through a formal control-based package supported by assessment and recurring continuous monitoring.
- System Security Plan
- Control implementation narratives
- Security Assessment Report
- POA&M and vulnerability reporting
- Monthly and annual activities
Decision and Validation Model
Security is documented through maintained decisions, KSIs, structured data, measurable outcomes, validation, and certification-class requirements.
- Security Decision Record
- Key Security Indicators
- Machine-readable certification data
- Persistent validation
- Classes A through D
Why FedRAMP 20x Exists
FedRAMP helped standardize federal cloud security, but traditional certification often became difficult for smaller SaaS providers and fast-moving cloud companies to pursue.
Large documentation packages, manual screenshots, repeated spreadsheets, lengthy reviews, assessment coordination, and package maintenance could require significant time and money.
At the same time, modern cloud services operate continuously. Infrastructure changes through code. Security tools generate telemetry throughout the day. Vulnerability scanners, identity platforms, logging systems, deployment pipelines, containers, APIs, and configuration-management tools constantly produce operational data.
A static document may accurately describe the cloud service when written but become outdated as the environment changes.
FedRAMP 20x is intended to better connect certification information to the cloud service’s actual operating state.
The FedRAMP 20x Mindset Shift
Traditional compliance projects often begin by asking what documents must be collected for an assessment.
FedRAMP 20x encourages providers to ask a more useful question: how can the cloud service continuously prove that its security decisions are being implemented?
That changes compliance from a separate documentation project into part of cloud engineering, security operations, identity management, vulnerability response, configuration management, deployment, monitoring, and incident response.
Decide
Document the Security Decision
Explain the provider’s intended security state, selected implementation, ownership, applicable rule, and expected outcome.
Measure
Define Reliable Indicators
Establish the metrics, evidence sources, tests, scope, frequency, and success criteria used to understand the security outcome.
Validate
Verify the Operating Environment
Use automated and human validation to confirm that machine-based resources and operational processes match the documented decision.
Respond
Investigate Failed Results
Create findings, assign owners, contain risks, correct weaknesses, document exceptions, and verify successful remediation.
Maintain
Keep the Certification Record Current
Update decisions, evidence, metrics, assessments, changes, vulnerabilities, incidents, and configuration guidance as the service evolves.
Core Pillars of FedRAMP 20x
Automation
Repeatable security checks and evidence collection reduce manual effort and provide more current information about the cloud service.
Machine-Readable Information
Certification information should be structured so agencies, assessors, providers, and authorized tools can evaluate it more efficiently.
Security Outcomes
KSIs summarize important cloud-security capabilities and connect decisions, measures, validation, and evidence to practical outcomes.
Persistent Validation
Providers maintain an intentional and continuously understood security state rather than relying only on periodic evidence snapshots.
What Is a Security Decision Record?
The Security Decision Record, or SDR, is a central component of the FedRAMP 20x certification package.
It is a maintained record explaining how the cloud service provider follows applicable FedRAMP rules and makes important security decisions.
The SDR can include implementation information, verification and validation, independent assessment details, clarifications, related artifacts, KSI information, security metrics, and other certification records required by the provider’s class.
Higher certification classes may require historical metrics, giving agencies and assessors visibility into security performance over time rather than only on the day evidence was collected.
It changes how security information is organized by connecting rules, decisions, evidence, metrics, validation, assessment, and ongoing certification maintenance.
What Are FedRAMP 20x Key Security Indicators?
Key Security Indicators are summaries and measures showing how the provider demonstrates important security outcomes.
Instead of requiring agencies to interpret hundreds of disconnected pieces of information, KSIs create a clearer way to understand major capabilities across identity, secure development, vulnerability management, infrastructure, recovery, incident response, monitoring, and other security areas.
A KSI is not merely a checklist item. The provider should be able to explain the decision, measure the outcome, identify the evidence source, validate the result, and respond when the expected security state is not maintained.
Higher certification classes require stronger assurance, more validation, additional assessment information, historical measures, and greater automation.
Can Your Cloud Environment Produce FedRAMP 20x Evidence Today?
Emgage helps cloud providers define scope, map KSIs, organize Security Decision Records, evaluate evidence sources, identify automation gaps, and build a practical certification roadmap.
Review Your FedRAMP 20x ReadinessMachine-Readable Evidence in FedRAMP 20x
Every FedRAMP 20x certification package is expected to include machine-readable certification data across the package lifecycle.
This can include structured information supporting initial certification, security decisions, KSIs, secure configurations, vulnerabilities, significant changes, ongoing reporting, assessment, validation, and remediation.
Evidence may originate from cloud platforms, asset inventories, identity systems, vulnerability scanners, configuration tools, ticketing platforms, source-code repositories, deployment pipelines, logging systems, SIEM platforms, and incident-management tools.
The benefit is not simply that software can read the file. The evidence can be compared, validated, reproduced, searched, updated, and reused more efficiently.
! Machine-Readable Does Not Automatically Mean Trustworthy
Automated evidence may still be incomplete when it excludes assets, uses inaccurate inventories, measures the wrong condition, ignores failed results, or does not cover the complete certification boundary.
What Is Persistent Validation?
Persistent validation is the practice of repeatedly confirming that documented security decisions and policies are being implemented throughout the cloud service offering.
The objective is for the provider’s operational state to remain intentional, understood, documented, and known.
Machine-based information resources may be checked automatically, while human-managed procedures may be reviewed on appropriate recurring schedules.
Failed validation should create action. The organization should investigate the condition, identify affected resources, determine risk, assign remediation, preserve evidence, and verify restoration of the expected state.
This prevents compliance from becoming a series of successful screenshots that hide declining security performance between assessments.
FedRAMP 20x Classes A Through D
A FedRAMP Certification Class describes the level of assurance information a provider supplies for its cloud service offering.
The classes do not merely rename the old Low, Moderate, and High baselines. They define package, validation, assessment, historical-information, monitoring, and certification requirements under the current program rules.
Class A
The entry class in the 20x model, designed around applicable certification rules, maintained security decisions, KSIs, evidence, and validation.
Class B
Introduces greater assurance, independent assessment expectations, stronger package requirements, and additional security-performance information.
Class C
Requires more extensive automation, historical metrics, recurring validation, independent assessment, and assurance across the service boundary.
Class D
Represents the highest class in the current structure and is intended for cloud services requiring the strongest applicable assurance.
Does FedRAMP 20x Eliminate Third-Party Assessment?
No. FedRAMP 20x does not allow cloud providers to replace all external assessment with their own automated tools.
Independent verification and validation remain important, particularly for Classes B and C and for certification requirements requiring assessor review.
Assessors may evaluate the service boundary, provider decisions, KSIs, evidence sources, automation logic, historical metrics, security configurations, vulnerabilities, assessment procedures, and remediation processes.
The assessor also needs confidence that automated data can be trusted. That means understanding where the data originates, which resources it covers, how frequently it is generated, and what occurs when the result fails.
What Happens to FedRAMP Rev. 5?
FedRAMP Rev. 5 is not disappearing immediately.
Existing certifications remain part of the program, and selected temporary Rev. 5 certification paths continue during the transition.
However, FedRAMP has identified 20x as the new direction. The Consolidated Rules establish updated expectations and a defined timeline for ending new Rev. 5 applications.
FedRAMP plans to stop accepting applications for new Rev. 5 Certifications on June 11, 2027. Existing Rev. 5 providers will receive transition guidance for maintaining or moving their certifications.
Existing SSP content, evidence, policies, monitoring, assessment records, vulnerabilities, and security processes can help support the transition when properly mapped into the current certification model.
Why Cloud-Native Providers Should Care
FedRAMP 20x may be particularly valuable for providers already operating modern engineering and security environments.
SaaS companies using infrastructure as code, automated deployments, cloud-native identity, centralized logging, security telemetry, vulnerability scanning, APIs, DevSecOps workflows, and automated configuration validation may already possess many of the systems needed to produce 20x evidence.
Under traditional FedRAMP, those capabilities often had to be translated into screenshots, spreadsheets, narrative descriptions, and manually assembled reports.
FedRAMP 20x creates an opportunity to use operational security information more directly. This can reduce repetitive work, improve evidence quality, speed review, and help smaller providers compete for federal opportunities.
However, providers with weak asset inventory, inconsistent security operations, limited automation, or unreliable telemetry may need significant engineering work before benefiting from the model.
Common FedRAMP 20x Misconceptions
How Cloud Providers Can Prepare for FedRAMP 20x
Confirm Federal Demand and Certification Class
Identify target agencies, intended data, use cases, procurement opportunities, required assurance, likely class, Marketplace path, and expected federal revenue.
Define the Cloud Service Boundary
Document applications, infrastructure, identities, administrative systems, regions, pipelines, support services, dependencies, integrations, and data flows.
Map Security Decisions and KSIs
Connect every applicable requirement to an implementation, owner, evidence source, success measure, validation method, exception process, and remediation workflow.
Centralize Security Evidence
Bring together authoritative information from cloud consoles, scanners, identity tools, logging systems, tickets, repositories, monitoring platforms, and documentation.
Automate High-Volume Evidence
Prioritize asset inventories, vulnerabilities, cloud configuration, access reviews, deployment records, encryption, logging, incidents, changes, and recurring validation.
Validate Data Quality and Coverage
Confirm that automated outputs cover the complete boundary, identify failed assets, can be reproduced, and trigger investigation and remediation.
Prepare for Independent Assessment
Conduct readiness testing, correct major gaps, organize evidence, validate historical metrics, assign technical owners, and test the assessor experience.
FedRAMP 20x Readiness Checklist
Frequently Asked Questions
What is FedRAMP 20x?
FedRAMP 20x is the modern federal cloud-certification model built around declarative rules, Security Decision Records, KSIs, structured evidence, automation, independent validation, and certification Classes A through D.
Is FedRAMP 20x officially active?
Yes. FedRAMP launched the Consolidated Rules for 2026 and scheduled the opening of Class A, B, and C certification pipelines during August 2026.
Does FedRAMP 20x replace traditional FedRAMP immediately?
No. Rev. 5 remains part of the transition for existing certifications and selected paths, but FedRAMP plans to stop accepting new Rev. 5 applications on June 11, 2027.
What replaces the traditional SSP?
The 20x package centers on a maintained Security Decision Record, KSI information, metrics, evidence, assessment details, validation records, clarifications, and other required artifacts.
What are Key Security Indicators?
KSIs summarize and measure important security outcomes, connecting provider decisions, implementation, evidence, validation, assessment, and operational performance.
Does automation eliminate assessors?
No. Independent verification and validation remain part of applicable certification-class and package requirements.
Is FedRAMP 20x cheaper?
It is designed to reduce unnecessary manual burden, but actual cost depends on security maturity, service complexity, automation, evidence quality, assessment scope, remediation, and ongoing operations.
Are Low, Moderate, and High being replaced?
FedRAMP now uses Classes A through D for certification assurance information. Legacy impact terminology remains relevant during the Rev. 5 transition and may still appear in older materials.
Can smaller SaaS providers pursue FedRAMP 20x?
Yes. Smaller providers may benefit from the modernized model when they maintain a focused boundary, strong cloud security, reliable evidence sources, and repeatable validation.
The Bottom Line
FedRAMP 20x changes how cloud providers prove federal cloud security.
Instead of relying primarily on large static packages, the model uses maintained security decisions, Key Security Indicators, machine-readable certification information, measurable outcomes, historical metrics, independent assessment, and persistent validation.
This does not make cloud security optional or eliminate federal oversight. Providers still need to secure the service, define an accurate boundary, remediate vulnerabilities, support assessment, maintain evidence, document changes, and sustain certification over time.
The main opportunity is efficiency. Providers that can generate reliable evidence through normal operations may spend less time rebuilding compliance materials and more time demonstrating current security.
FedRAMP 20x will favor cloud providers that treat certification as an operating capability rather than a document project.
Official Sources
- FedRAMP 20x Overview and Timeline
- FedRAMP Consolidated Rules for 2026
- Launch of the Consolidated Rules for 2026
- FedRAMP Certification Classes
- Using FedRAMP 20x Certification Packages
- Security Decision Record Requirements
- FedRAMP 20x Certification Requirements
- Persistent Validation and Assessment Standard
- Machine-Readable Certification Data
Prepare for FedRAMP 20x Before Formal Assessment Begins
Emgage helps cloud providers define the service boundary, map KSIs, organize Security Decision Records, centralize evidence, identify automation opportunities, evaluate readiness, and build a realistic certification roadmap.
Review Your FedRAMP 20x Readiness
