US federal compliance

FedRAMP 20x vs Rev5: what the 2026 Consolidated Rules change for cloud providers

FedRAMP 20x moves from long narrative packages to automated evidence and certification classes. Here is how it compares with the Rev5 path and what existing providers need to do.

Short answer

FedRAMP 20x vs Rev5 is automation versus narrative. Rev5 assesses cloud services against NIST SP 800-53 Rev 5 baselines with long System Security Plans. 20x, written into the Consolidated Rules for 2026, uses Key Security Indicators with machine-readable evidence and certification classes A to D. The new rules become mandatory on 1 January 2027.

Key takeaways

  • Rev5 is the legacy, baseline-driven path; 20x is automation-first with Key Security Indicators.
  • The Consolidated Rules for 2026 were published on 25 June 2026 and apply to everyone from 1 January 2027.
  • Certification classes A to D replace the Low, Moderate and High labels.
  • Agencies still decide whether a certified service fits their system.

The two paths

Under Rev5, a cloud service provider documents how it meets a NIST SP 800-53 Rev 5 baseline in a System Security Plan, a third-party assessment organization (3PAO) tests it, and an agency or the program issues an authorization. Under FedRAMP 20x, providers show security outcomes through Key Security Indicators (KSIs), validated with machine-readable and largely automated evidence.

Rev5FedRAMP 20x
BasisNIST SP 800-53 Rev 5 baselinesKey Security Indicators mapped to 800-53
EvidenceNarrative SSP, SAR, POA&MMachine-readable, automated validation
LevelsLow, Moderate, HighCertification classes A, B, C, D
Status in 2026Transition; existing holders move to the new rulesPipelines opened August 2026
Mandatory from—1 January 2027 (Consolidated Rules for 2026)

Certification classes

FedRAMP describes the classes by the assurance they give agencies. Class A is adequate for pilots and very low-risk uses. Class B is adequate for most Low-impact systems, Class C for most Low or Moderate systems, and Class D for most agency systems regardless of impact level, each with compensating controls where needed. Classes are not a one-to-one rename of baselines, so read the class rules rather than mapping control counts.

What existing Rev5 providers should do

Checklist

Preparing for 1 January 2027

0 of 5 done

Dates and cut-offs in the transition are set by FedRAMP; check fedramp.gov for the current Rev5 application deadline before planning a new Rev5 package.

Put this into practice on QULDEX

Frequently asked questions

What is FedRAMP 20x?

FedRAMP's automation-first approach, announced in March 2025 and written into the Consolidated Rules for 2026. It uses Key Security Indicators with machine-readable evidence instead of long narrative packages.

Is FedRAMP Rev5 going away?

Rev5 remains during the transition. Existing Rev5 holders must adopt the new rules, which become mandatory for all stakeholders on 1 January 2027, and FedRAMP is phasing out new Rev5 applications.

What are FedRAMP certification classes?

Classes A to D describe the assurance a certified service gives agencies. They replace the Low, Moderate and High labels, but agencies still decide whether a service fits their own systems.

Sources

  1. Propelling change: FedRAMP launches Consolidated Rules for 2026, FedRAMP
  2. Certification Classes (Consolidated Rules for 2026), FedRAMP
  3. OMB Memorandum M-24-15, Modernizing FedRAMP, OMB