Frameworks

What is FedRAMP?

In short

FedRAMP (the Federal Risk and Authorization Management Program) is a US government program that standardizes how cloud services are security-assessed, certified and continuously monitored for use by federal agencies. Under the Consolidated Rules for 2026 a certification is labelled with a Certification Class, A through D, in place of the Low, Moderate and High impact levels the program used before.

Definition

FedRAMP is a US federal program that provides a standardized approach to security assessment, certification and continuous monitoring for cloud products and services used by government agencies. Since the Consolidated Rules for 2026, an offering is certified at a FedRAMP Certification Class from A to D, and that class states the level of assurance information the provider has committed to supplying.

Background

Federal agencies buy a lot of cloud software, and FedRAMP exists so each agency does not have to assess the same service from scratch. A provider is assessed against the requirements FedRAMP sets, is certified once, and other agencies can rely on that work. A Rev5 Agency Certification still runs through the agency sponsor's authorization to operate process, which concludes with a signed ATO letter the agency sends to FedRAMP over official government channels. The program was put on a statutory footing by the FedRAMP Authorization Act. What changed in 2026 is the label. FedRAMP used to authorize a service at a Low, Moderate or High impact level, each carrying its own NIST SP 800-53 control baseline, and the Consolidated Rules for 2026 replaced that label with a Certification Class from A to D. Impact levels did not stop existing. They stopped being the thing a FedRAMP certification is labelled with: agencies still categorize their own systems under FIPS-199 and FIPS-200, then judge whether a given class supplies enough assurance for the system they are buying for.

Why it matters

FedRAMP is the entry ticket to selling cloud software to US federal agencies. It is rigorous and resource-intensive, so it matters most to vendors targeting the public sector, and for SMBs selling only commercially it is usually out of scope even though its NIST 800-53 lineage overlaps heavily with commercial frameworks. Which class you certify at is a commercial question as much as a security one, because agencies ask for the class their own categorization tells them they need. Two dates set the pace. The Consolidated Rules take mandatory effect program-wide on 2027-01-01, subject to earlier effective dates in certain areas, and several of those areas already bind providers today. FedRAMP stops accepting applications for new Rev5 certifications on 2027-06-11, so the Rev5 door is closing and new entrants after it go through FedRAMP 20x.

Step by step

  1. Ask your agency customers which Certification Class they need. They categorize their own system under FIPS-199 and FIPS-200 and then decide which class gives them enough assurance, so the class comes from them rather than from your own read of your data.
  2. Pick a target certification profile. FedRAMP builds one from three parts: a type, which is Rev5 or 20x; a path, which is Program or Agency; and a Certification Class. Classes B, C and D on the Rev5 type each carry a NIST SP 800-53 Rev. 5 control baseline that FedRAMP selects, and the baselines nest, so everything in the class below is in the class above. Class A carries no Rev5 baseline and sits on the 20x type.
  3. Check the route between types before you commit to one. You cannot hold a Rev5 Program Certification and a 20x Program Certification for the same offering, so on that route you pick one type. FedRAMP separately publishes a way to obtain a 20x Class A Certification and then change it to Rev5 Class B, C or D through an Agency Certification, so a type is not a one-way door.
  4. Implement what the class requires: the Rev5 control baseline with the parameter values and guidance FedRAMP sets on top, or the Key Security Indicators on the 20x type, and record the decisions in a Security Decision Record.
  5. Meet the Consolidated Rules that bind providers directly. They state duties no control baseline covers, and how many of them reach you depends on your class, because most of the rulesets are scoped to Classes B, C and D. Keeping a monitored FedRAMP security inbox binds at every class, while significant change notification does not bind at Class A and vulnerability reporting is not a MUST there.
  6. Get listed in the FedRAMP Marketplace, then apply for certification yourself. No third party, assessors included, may apply on your behalf. Independent verification and validation by a FedRAMP Recognized independent assessment service is required at Classes B, C and D, and optional at Class A.
  7. Keep the certification current through ongoing certification reporting, the reviews your class calls for, and independent assessment at the cadence set for your type and class.

Examples

  • A SaaS vendor pursuing federal customers learns from them that Class C is what they require, implements the Rev5 baseline FedRAMP selects for that class, and certifies at it. Other agencies can then rely on the same certification.
  • An agency categorizes its own system as Moderate under FIPS-199 and then decides for itself whether a Class C certification supplies enough assurance for that system. The two labels sit on different axes, so the agency makes a judgement rather than reading a mapping off a table.
  • A vendor with only commercial customers holds SOC 2 and ISO 27001 instead, because FedRAMP is not required outside government.

Common mistakes

  • Reading a Certification Class as an impact level. FedRAMP tells agencies not to treat the classes as one-for-one replacements for Low, Moderate and High, so calling Class C "FedRAMP Moderate" repeats a mapping FedRAMP itself refuses to make.
  • Assuming FedRAMP is needed for commercial (non-government) sales; it generally is not.
  • Planning around 2027-01-01 alone. Several areas of the Consolidated Rules already bind providers, and applications for new Rev5 certifications close on 2027-06-11.
  • Underestimating the time and cost of independent assessment and ongoing certification.
  • Treating a class baseline as plain NIST SP 800-53. FedRAMP sets its own parameter values and guidance on top, and some of them read differently depending on the class.

FAQ

What are the FedRAMP impact levels?

FedRAMP used to label an authorization Low, Moderate or High, each matching a NIST SP 800-53 control baseline and reflecting the sensitivity of the data involved. The Consolidated Rules for 2026 replaced that label with a Certification Class from A to D. Impact levels still exist as the FIPS-199 and FIPS-200 categorization an agency performs on its own system, and they are no longer what a FedRAMP certification is labelled with.

What is a FedRAMP Certification Class?

A Certification Class, A through D, states how much assurance information a provider has committed to supplying. It describes neither how secure the service is nor how sensitive an agency system is. On the Rev5 type, Classes B, C and D carry a NIST SP 800-53 Rev. 5 control baseline that grows with the class, and Keel scores 155 controls at Class B, 322 at Class C and 409 at Class D, counted from the class tags in FedRAMP's own generated control reference. On the 20x type, those same three classes carry the full set of 46 Key Security Indicators that Keel scores in its FedRAMP 20x framework. Class A is the exception at both ends: it carries no Rev5 baseline and no full set of indicators either. It rests on a certification completed within the past 12 months under one of FedRAMP's approved alternative security frameworks, SOC 2 Type II, GovRAMP and a FedRAMP Rev5 or Ready certification among them, and adds a short subset of the Key Security Indicators that FedRAMP names rule by rule.

Is FedRAMP Certification Class C the same as FedRAMP Moderate?

No, and FedRAMP says so itself. Its guidance for agencies is that Certification Classes should not be treated as one-for-one replacements for the Low, Moderate and High impact levels. Categorize your own system first, then judge whether a class supplies enough assurance for it. Keel never renders a class as an impact level for the same reason.

When do the FedRAMP 2026 rules take effect?

The Consolidated Rules take mandatory effect program-wide on 2027-01-01, subject to earlier effective dates in certain areas, and several of those areas bind providers already. FedRAMP stops accepting applications for new Rev5 certifications on 2027-06-11. Existing Rev5 certifications continue until at least 2028-12-31 unless FedRAMP directs otherwise, and FedRAMP tells providers holding one to start planning the move to 20x now.

Do most SMBs need FedRAMP?

No. FedRAMP applies to cloud services sold to US federal agencies. If you are not selling to the federal government, commercial frameworks like SOC 2 or ISO 27001 are the usual path.

Next step

Do this in Keel, not a spreadsheet

Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.