From Foundation to Implementation: Scaling a Better Path to Cloud Security
October 8, 2026
This month marks the transition of FedRAMP, and the rest of the federal government, from fiscal year 2026 (FY26) to fiscal year 2027 (FY27). It also marks just over 2 years since the release of OMB Memorandum M-24-15 set a bold new direction for FedRAMP, based on the FY23 FedRAMP Authorization Act. This new direction, called FedRAMP 20x, is designed to bring thousands of cloud services into the FedRAMP Marketplace by leveraging existing commercial investments in security instead of ordering the use of a specific government-focused approach.
FedRAMP completed the first major overhaul of its internal processes in FY25 and processed the entire historical backlog of cloud services pending FedRAMP’s final review. At the same time we launched FedRAMP 20x and developed a new approach to assessment in public collaboration with industry via the 20x Phase 1 pilot. FY25 set the foundation, and FY26 was all about delivering on that promise.
In FY26, FedRAMP delivered the first set of Consolidated Rules and opened pipelines to the public for the new generation of FedRAMP 20x Certifications. The Consolidated Rules created a progressive assurance framework designed to encourage rapid entry into the FedRAMP Marketplace with Initial Implementation listings and FedRAMP 20x Class A Certifications. Requirements for FedRAMP 20x Class B and C were also finalized, and updated improvements for FedRAMP Rev5 were formalized to begin the legacy transition to 20x.
FY26 By the Numbers
FedRAMP 20x is already delivering results, not only by bringing services into the Marketplace, but by enabling agencies to use those services and their security assessments. Since Class B and Class C opened to all cloud service providers at the end of August, federal agencies are already using services certified through the 20x framework. FedRAMP continued to deliver Rev5 and 20x certifications in FY26, certifying the second-highest number of cloud services in the program’s history, surpassed only by FY25.
In FY26, FedRAMP:
- Reviewed and issued 92 new FedRAMP Certifications, including 66 Rev5 and 26 20x Certifications
- Ended the year with a total of 538 FedRAMP Certified cloud service offerings
- Created and added 71 service offerings to the new Initial Implementation listing
- Recorded 760 new agency ATOs or ATUs
The Team Behind the Delivery
FedRAMP continued to deliver while building the workforce needed to support a growing Marketplace.
The program saw 4 new employees join or convert to permanent positions with FedRAMP and maintained stable staffing levels across the program. However, we still operated at a more than 50% reduction in staff from 2 years prior and continue to look for quality candidates to help fill the currently open staffing vacancies.
Continuing on FedRAMP’s goals in FY25 and FY26, FedRAMP will continue to expand and build upon the technical capacity and skillsets FedRAMP was able to add in FY26. The core team ended the year with 17 federal employees and 15 contractors and came in at spending a little less than $9M of our $10M budget.
Engaging the FedRAMP Community
FedRAMP continued to expand its engagement with the FedRAMP Community in FY26 by building additional communication channels and new community update streams. Today, community members have access to a nearly overwhelming amount of frequently updated information about FedRAMP’s progress and goals.
Stay engaged with us:
- Events
- Requests for Comment (RFCs)
- Public Notices (subscribe to our RSS feed)
- Public Comments
Winding Down FedRAMP Rev5 Certifications
FedRAMP will stop processing Legacy FedRAMP Rev5 Certification applications on June 11, 2027, and expects to have clear transition paths and timelines published by the end of FY27 for all cloud services to move to FedRAMP 20x. Cloud service providers that have not already invested significant progress into FedRAMP Rev5 with a guaranteed sponsor should pivot to FedRAMP 20x immediately.
At the end of July, FedRAMP retired FedRAMP Ready and in August, opened a limited Lost Sponsor/Ready Conversion pathway for eligible providers whose planned or in-progress sponsorship was affected by rapid changes in federal acquisitions over the last two years. This pathway helps certain providers preserve and build on prior Rev5 investments while pursuing a Class B or Class C Certification.
To date, FedRAMP received 40 applications through this pathway, and the process has already resulted in multiple certifications on an accelerated timeline. FedRAMP does not plan to expand eligibility or allow access to this program before the sunset of new FedRAMP Rev5 Certifications.
A Headline About The Road Ahead
The path ahead of us is simple in principle, but difficult and complex in execution. Our goals for FY27 include:
- Build 100% coverage of all FedRAMP Certification options into the FedRAMP 20x umbrella, including Class D Certifications and FedRAMP 20x rulesets for self-hosted and hybrid-hosted services.
- Begin the transition of cloud services with legacy FedRAMP Rev5 Certification to FedRAMP 20x, including FedRAMP 20x Class C or D Certifications for hyperscale cloud service providers.
- Continue to deliver initial assessment decisions within 30 days of application for FedRAMP Certification.
- Provide a detailed FedRAMP Agency Cloud Use Framework, built by the FedRAMP Board and Technical Advisory Group, to ensure agencies have the full processes and policies they need to rapidly and securely adopt cloud services under FedRAMP 20x.
As always, FedRAMP will continue to build and operate in public as much as possible, and you can follow along with us as we drive towards these goals.