Overview
FedRAMP gives U.S. federal agencies a standard way to assess the security of cloud services, so one assessment can be reused across many agencies. The FedRAMP Authorization Act of December 2022 put the program into law. It's run by the General Services Administration, and the FedRAMP Marketplace lists certified services, agencies using them, and recognized assessors. In October 2026 the Marketplace showed 538 certified services, 32 of them through FedRAMP 20x.
2026 brought big changes. FedRAMP published its Consolidated Rules for 2026 on June 25, 2026. They replace Low, Moderate, and High impact levels with Certification Classes A to D, rename authorization as FedRAMP Certification, and rename continuous monitoring as ongoing certification. Third-party assessment organizations (3PAOs) are now called independent assessors, and FedRAMP accepts assessments only from FedRAMP Recognized assessors. Adoption has been optional since July 4, 2026 and becomes mandatory on January 1, 2027.
Two paths exist side by side. FedRAMP 20x uses Key Security Indicators (KSIs), which are measurable outcomes validated largely through automation instead of long control narratives. Its Phase 2 pilot at the Moderate level ended in March 2026, and FedRAMP says the pilots are over. Class A applications opened on August 3, 2026, and Class B and C applications on August 31, 2026. The Rev5 path, based on NIST SP 800-53 Rev. 5 baselines, continues for now. FedRAMP will stop accepting new Rev5 applications after June 11, 2027, and existing Rev5 certifications stay active until at least December 31, 2028.
Who it applies to in Canada
Cloud service providers, including SaaS, PaaS, and IaaS vendors, that want U.S. federal agencies to use their services, and the independent assessors that evaluate them.
Canadian SaaS and cloud companies need FedRAMP Certification to sell cloud services to U.S. federal agencies, either directly or through a U.S. reseller or prime. Some U.S. state governments and contractors also ask for it as evidence of security, so it can come up in deals that aren't federal.
Controls at a glance
Under the 2026 rules, requirements are set by certification class, with 20x classes measured through KSI themes and Rev5 classes through SP 800-53 controls.
Certification classes
- Class A: minimal assurance for mature providers entering the market
- Class B: Low impact, small-scale or light-use services
- Class C: Moderate impact, common enterprise services
- Class D: High impact, offered through Rev5 for now
- Agencies still authorize their own use of each service
FedRAMP 20x indicator themes (part 1)
- Cloud native architecture
- Service configuration
- Identity and access management
- Monitoring, logging, and auditing
- Change management
FedRAMP 20x indicator themes (part 2)
- Policy and inventory
- Recovery planning
- Supply chain risk
- Cybersecurity education
- Incident response
Rev5 path
- Implement the SP 800-53 Rev. 5 baseline for the class
- Document security decisions in the certification package
- Independent assessor tests controls
- No new Rev5 applications after June 11, 2027
Ongoing certification
- Report security status to agencies on a regular schedule
- Track and fix vulnerabilities within set timeframes
- Report incidents to FedRAMP and agency customers
- Get approval or notify before significant changes
Certification and assessment
The provider prepares a certification package, and a recognized independent assessor validates it, either through 20x KSIs or Rev5 control testing. FedRAMP reviews the package and grants FedRAMP Certification, after which the service is listed on the Marketplace. Each agency then decides whether to use the service for its own systems.
Dates to know
- 2026-03
- FedRAMP 20x Phase 2 (Moderate) pilot completes
- 2026-06-25
- FedRAMP launches the Consolidated Rules for 2026
- 2026-07-04
- Optional early adoption of the Consolidated Rules for 2026 begins
- 2026-08-31
- FedRAMP 20x Class B and C application pipelines open
- 2027-01-01
- Consolidated Rules for 2026 become mandatory for all stakeholders
- 2027-06-11
- Last day FedRAMP accepts applications for new Rev5 certifications
- 2028-12-31
- Existing Rev5 certifications remain active until at least this date
Resources
Official texts and free tools for FedRAMP. Links open the publisher’s site.
- FedRAMP home page and Marketplace, FedRAMP, GSA
- FedRAMP Consolidated Rules for 2026, FedRAMP, GSA
- FedRAMP 20x, FedRAMP, GSA
- FedRAMP program page, U.S. General Services Administration
- What's changing in the Consolidated Rules for 2026, FedRAMP, GSAguidance
- Information for independent assessors, FedRAMP, GSAguidance
Need help? Browse the directory or read the guides.
References
- Propelling change: FedRAMP launches Consolidated Rules for 2026 (June 25, 2026), FedRAMP, GSA
- Consolidated Rules for 2026: Important dates, FedRAMP, GSA
- FedRAMP 20x, FedRAMP, GSA
- FedRAMP definitions, FedRAMP, GSA
General information, reviewed 2026-10-11. Not legal advice. Confirm requirements with the publisher, your regulator, or a qualified advisor.