Framework · FedRAMP
Since June 2026 the program runs on the Consolidated Rules: certification classes instead of impact levels, machine-readable packages instead of the 300-page System Security Plan, and no agency sponsor below the highest tier. Here is how the two paths work, what they cost, and where the old documents went, current as of September 2026.
Certification classes
The entry point
Low, rebuilt
The Moderate successor
The highest bar
No agency sponsor for A–C
The Classes
Impact levels described the data. Certification classes describe how much verification stands behind the service, from an existing attestation at Class A to continuous, automated, historical proof at Class D.
For established commercial products that already hold a SOC 2 Type II, a FedRAMP Rev 5 authorization, or a GovRAMP status, serving non-sensitive use cases. An independent assessment is optional. It replaces FedRAMP Ready.
Most Low-impact use cases: Key Security Indicators documented and validated, a fresh independent assessment, and automated verification with historical metrics behind it.
Most Low and Moderate use cases, with substantially more automation investment per indicator. This is where most SaaS selling to agencies lands.
The highest assurance short of classified. Today it is reachable only through the legacy Rev 5 path with an agency sponsor; a 20x Class D pilot is anticipated but not yet open.
The Two Paths
Rev 5 is the document era winding down; 20x is the ruleset that replaced it. Which one you take is mostly decided for you, by the class you need and the calendar.
Rev 5 · the legacy path
Closes Jun 2027Control implementation statements, boundary and data-flow diagrams, and a stack of attachments. Commonly hundreds of pages, prepared over months.
A sponsoring agency carries the package, and Rev 5 is the only route to Class D today.
Under FedRAMP's published timeline, new Rev 5 submissions move from Word documents to machine-readable packages, with OSCAL the primary format, and a grace period to September 2027.
New Rev 5 applications are accepted until 11 June 2027. After that, the path is closed to new entrants.
20x · the CR26 path
The way forwardThe certification package is machine-readable JSON validated against FedRAMP's schemas. Key Security Indicators replace the control narrative, most of them verified automatically.
The narrative that remains: a human-readable and JSON rationale for how each rule is followed, or the risk accepted where it is not, signed by a senior official.
Providers work with FedRAMP directly. The sponsor hunt, long the slowest step, is gone for everything below Class D.
Classes B and up need a fresh independent assessment within three months of applying, plus historical metrics per indicator that scale with the class.
Strip the formats away and both paths ask for the same inputs: a defined boundary, a control set with real implementation status, and evidence that is current. That is a record, not a document, and teams that keep the record can produce whichever format the program asks for.
What Happened to the SSP
FedRAMP's own conclusion after a decade of narrative SSPs was that the document drifts from reality almost immediately, and that reviewing prose does not scale. NIST reached a parallel conclusion: SP 800-18 Rev 2, final in June 2026, reframes system plans around structured, machine-readable data collected automatically. The direction of both is the same: the plan is a record; documents are views of it.
FedRAMP unveils an automation-first overhaul with a stated goal of validating most requirements automatically, without narrative documents, and begins rebuilding the program around it.
A Low-impact pilot takes 26 complete submissions and authorizes about half of them, a useful signal that automation-first does not mean easier. A Moderate pilot follows from November in invited cohorts.
The Consolidated Rules for 2026 take 20x from pilot to the government-wide ruleset. Certification classes A through D replace the old impact levels, and "authorization" formally becomes "certification."
Marketplace listings open 6 July, Class A applications 3 August, Classes B and C 31 August. FedRAMP Ready closes to new entrants, replaced by Class A.
New Rev 5 submissions are expected in machine-readable form, with OSCAL the primary format. A telling detail from the year before: over a hundred Rev 5 authorizations were processed in 2025 without a single OSCAL submission. The mandate is ahead of the tooling.
CR26 becomes mandatory for all stakeholders on 1 January 2027, and new Rev 5 applications end on 11 June 2027. Class D remains on Rev 5 until the 20x high-assurance path opens.
The Practical Questions
Industry estimates, not official figures: a Low authorization has typically run US$250K to $500K all-in, Moderate $800K to $2M over 18 to 24 months plus continuous-monitoring costs each year, and High multiples of that. Advisory, assessment, remediation, and engineering time all stack. 20x aims to bend this curve; FedRAMP's own pilots say faster, not easier.
Twelve to eighteen months has been the typical Rev 5 arc from a standing start, with the agency-sponsor search historically the least predictable stretch. The 20x path removes the sponsor for Classes A to C and compresses assessment into a three-month window, shifting the long pole to engineering readiness.
FedRAMP has no citizenship or US-ownership requirement, and the CR26 scope rules set no US-presence bar: what matters is a cloud service processing federal information for an agency use case. Two honest caveats: individual agency solicitations can impose personnel and location requirements of their own, and agency demand, not eligibility, decides whether certification pays.
With Alvor
On the Rev 5 path the SSP is still the centrepiece. Alvor maintains the boundary, control set, applicability, and implementation status the document describes, so the narrative is written from a current record instead of reverse-engineered each cycle.
System Security PlanFedRAMP baselines are built on NIST SP 800-53. Alvor publishes a control-by-control alignment map across all 299 active base controls, stating plainly where the platform performs, supports, or records each one.
NIST 800-53 alignmentCertification is the start of continuous monitoring, not the end of the project. Evidence in Alvor carries a freshness state, an owner, and a review date, so the ongoing obligations run on the same record the package came from.
ComplianceAlvor Advisory scopes the boundary, runs the gap, builds the record, and prepares the documentation, on either path. Assessor-ready and stop: the assessment itself always belongs to an independent assessor, by design.
SSP as a ServiceQuestions
On the legacy Rev 5 path, yes: the narrative SSP remains the centrepiece, and under FedRAMP's published timeline new Rev 5 submissions move to machine-readable packages, with OSCAL the primary format, from 30 September 2026. On the 20x path there is no SSP at all: the package is machine-readable JSON built around Key Security Indicators, with the Security Decision Record carrying the remaining narrative. Either way, the inputs are the same record: boundary, controls, implementation status, evidence.
FedRAMP's automation-first rebuild of the program, piloted through 2025 and made the government-wide ruleset by the Consolidated Rules for 2026 (CR26), launched in June 2026. Instead of narrative control statements reviewed by humans, providers demonstrate Key Security Indicators, most validated automatically, and document decisions in a Security Decision Record. CR26 becomes mandatory for all stakeholders on 1 January 2027.
Classes A through D replaced the old Low, Moderate, and High impact levels under CR26. Class A is the entry point for established commercial products holding a SOC 2 Type II, Rev 5, or GovRAMP basis; Class B covers most Low-impact use cases; Class C covers most Low and Moderate use cases; Class D is the highest assurance short of classified, currently reachable only through Rev 5 with an agency sponsor. Verification depth, especially automated verification, scales with the class.
For Classes A through C, no: under CR26 providers work with FedRAMP directly, which removes what was historically the least predictable step in the whole process. Class D still requires an agency sponsor because it currently runs on the legacy Rev 5 path; a 20x high-assurance option is anticipated but not yet open.
Yes. FedRAMP has no citizenship or US-ownership requirement, and the CR26 scope rules set no US-presence bar: what matters is a cloud service processing federal information for an agency use case. Two caveats belong next to that: individual agency solicitations can impose their own personnel and location requirements, and agency demand, not eligibility, is what makes the investment pay off.
Industry estimates, not official figures: Rev 5-era Low authorizations typically ran US$250K to $500K all-in and Moderate $800K to $2M over 18 to 24 months, plus continuous-monitoring costs every year after. The 20x path aims to compress both by replacing document preparation and review with automated validation; FedRAMP's own pilot results, where about half of submissions succeeded, suggest reading that as faster rather than easier.
Get started
Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.