home / frameworks / fedramp

// U.S. frameworks that reach Canada

Federal Risk and Authorization Management Program (FedRAMP)

FedRAMP is the U.S. government program that assesses and certifies cloud services for use by federal agencies. In 2026 it replaced impact levels with Certification Classes A to D and made its automated FedRAMP 20x path generally available.

United States

Overview

FedRAMP gives U.S. federal agencies a standard way to assess the security of cloud services, so one assessment can be reused across many agencies. The FedRAMP Authorization Act of December 2022 put the program into law. It's run by the General Services Administration, and the FedRAMP Marketplace lists certified services, agencies using them, and recognized assessors. In October 2026 the Marketplace showed 538 certified services, 32 of them through FedRAMP 20x.

2026 brought big changes. FedRAMP published its Consolidated Rules for 2026 on June 25, 2026. They replace Low, Moderate, and High impact levels with Certification Classes A to D, rename authorization as FedRAMP Certification, and rename continuous monitoring as ongoing certification. Third-party assessment organizations (3PAOs) are now called independent assessors, and FedRAMP accepts assessments only from FedRAMP Recognized assessors. Adoption has been optional since July 4, 2026 and becomes mandatory on January 1, 2027.

Two paths exist side by side. FedRAMP 20x uses Key Security Indicators (KSIs), which are measurable outcomes validated largely through automation instead of long control narratives. Its Phase 2 pilot at the Moderate level ended in March 2026, and FedRAMP says the pilots are over. Class A applications opened on August 3, 2026, and Class B and C applications on August 31, 2026. The Rev5 path, based on NIST SP 800-53 Rev. 5 baselines, continues for now. FedRAMP will stop accepting new Rev5 applications after June 11, 2027, and existing Rev5 certifications stay active until at least December 31, 2028.

Who it applies to in Canada

Cloud service providers, including SaaS, PaaS, and IaaS vendors, that want U.S. federal agencies to use their services, and the independent assessors that evaluate them.

Canadian SaaS and cloud companies need FedRAMP Certification to sell cloud services to U.S. federal agencies, either directly or through a U.S. reseller or prime. Some U.S. state governments and contractors also ask for it as evidence of security, so it can come up in deals that aren't federal.

Controls at a glance

Under the 2026 rules, requirements are set by certification class, with 20x classes measured through KSI themes and Rev5 classes through SP 800-53 controls.

Certification classes

  • Class A: minimal assurance for mature providers entering the market
  • Class B: Low impact, small-scale or light-use services
  • Class C: Moderate impact, common enterprise services
  • Class D: High impact, offered through Rev5 for now
  • Agencies still authorize their own use of each service

FedRAMP 20x indicator themes (part 1)

  • Cloud native architecture
  • Service configuration
  • Identity and access management
  • Monitoring, logging, and auditing
  • Change management

FedRAMP 20x indicator themes (part 2)

  • Policy and inventory
  • Recovery planning
  • Supply chain risk
  • Cybersecurity education
  • Incident response

Rev5 path

  • Implement the SP 800-53 Rev. 5 baseline for the class
  • Document security decisions in the certification package
  • Independent assessor tests controls
  • No new Rev5 applications after June 11, 2027

Ongoing certification

  • Report security status to agencies on a regular schedule
  • Track and fix vulnerabilities within set timeframes
  • Report incidents to FedRAMP and agency customers
  • Get approval or notify before significant changes

Certification and assessment

The provider prepares a certification package, and a recognized independent assessor validates it, either through 20x KSIs or Rev5 control testing. FedRAMP reviews the package and grants FedRAMP Certification, after which the service is listed on the Marketplace. Each agency then decides whether to use the service for its own systems.

Dates to know

2026-03
FedRAMP 20x Phase 2 (Moderate) pilot completes
2026-06-25
FedRAMP launches the Consolidated Rules for 2026
2026-07-04
Optional early adoption of the Consolidated Rules for 2026 begins
2026-08-31
FedRAMP 20x Class B and C application pipelines open
2027-01-01
Consolidated Rules for 2026 become mandatory for all stakeholders
2027-06-11
Last day FedRAMP accepts applications for new Rev5 certifications
2028-12-31
Existing Rev5 certifications remain active until at least this date

Resources

Official texts and free tools for FedRAMP. Links open the publisher’s site.

Need help? Browse the directory or read the guides.

References

  1. Propelling change: FedRAMP launches Consolidated Rules for 2026 (June 25, 2026), FedRAMP, GSA
  2. Consolidated Rules for 2026: Important dates, FedRAMP, GSA
  3. FedRAMP 20x, FedRAMP, GSA
  4. FedRAMP definitions, FedRAMP, GSA