compli.ai
From the blog

The FedRAMP Authorization Process Explained (2026)

This guide explains FedRAMP certification (formerly authorization) in 2026: the FedRAMP Board, 20x with KSIs, Rev 5 baselines, agency sponsors, and timelines.

FedRAMP certification (formerly FedRAMP authorization) works differently in 2026 than the guides written even two years ago describe. FedRAMP renamed its authorizations "certifications" in February 2026, while each agency still issues its own Authorization to Operate (ATO). The Joint Authorization Board (JAB) is gone, and governance now runs through the FedRAMP Board. FedRAMP 20x, which replaces the old document-heavy process with Key Security Indicators (KSIs) and machine-readable evidence and requires no agency sponsor, is now the standard path going forward. It covers low- and moderate-impact services today, and the traditional Rev5 path stops accepting new certifications on June 11, 2027. This guide explains each path, the current Rev 5 baselines, marketplace designations, and a realistic timeline for what certification actually takes.

First, the vocabulary

FedRAMP, the Federal Risk and Authorization Management Program, is the U.S. government's standardized approach for assessing cloud products for federal use. It is run by the General Services Administration (GSA). A cloud service provider (CSP) that earns a FedRAMP certification can sell to federal agencies without each agency re-doing the full security review.

An Authorization to Operate (ATO) is the decision that lets a federal system go live. In FedRAMP, an agency's Authorizing Official grants that ATO for a cloud service after reviewing its security package. That agency decision is still an authorization, and the program-level approval that lets agencies reuse the review is now a FedRAMP certification.

If you have read older material, drop three ideas: that a "JAB P-ATO" still exists, that FedRAMP's own approval is called an authorization, and that the process is purely a control-by-control narrative exercise.

What changed: the post-JAB, 20x world

Three changes define FedRAMP in 2026.

Authorizations are now certifications. In February 2026, FedRAMP renamed its authorizations "certifications," so a cloud service now earns a FedRAMP certification (formerly FedRAMP authorization). Agencies still issue their own ATOs, so "authorization" now refers only to that agency decision.

The JAB is gone, and the FedRAMP Board runs governance. The old Joint Authorization Board that issued provisional authorizations no longer exists. Under the FedRAMP Authorization Act, governance now runs through the FedRAMP Board, made up of up to seven senior agency officials. Certifications now come either through an agency sponsor on the traditional Rev5 path or directly from FedRAMP on the 20x path.

20x replaces documents with measurable outcomes. The 20x pilots are over, and under FedRAMP's Consolidated Rules for 2026, FedRAMP 20x is the standard path going forward. Instead of writing a control-by-control narrative and shipping a stack of PDFs, 20x asks CSPs to demonstrate Key Security Indicators (KSIs), which are measurable security outcomes, through machine-readable, automated evidence packages. FedRAMP processes 20x certifications directly, without an agency sponsor. 20x currently covers low- and moderate-impact services (Classes B and C), and Class D, the high-impact class, is still in development.

The rollout timing to plan around:

MilestoneDateWhat it means
Authorizations renamed certificationsFebruary 2026FedRAMP's approval is now a certification; agencies still issue their own ATOs
20x becomes the standard pathIn effect nowThe pilots are over; 20x covers low- and moderate-impact services (Classes B and C)
20x Class D (high impact)In developmentHigh-impact services use the traditional Rev5 path for now
Rev5 stops accepting new certificationsJune 11, 2027The traditional path closes to new certifications
Existing Rev5 certificationsActive until at least December 31, 2028Current Rev5 holders keep their status through the transition

Source: FedRAMP.gov, including the Consolidated Rules for 2026 and 20x documentation.

The four current paths to certification

As of the 2026 framing, a CSP has four routes. They are not equally suited to every product - pick based on your sponsor situation, your engineering maturity, and your timeline.

PathAgency sponsor needed?Documentation liftBest for
1. Traditional Rev 5 (agency-sponsored)YesHeavy - full Rev 5 packageCSPs with a committed agency partner and a mature GRC function
2. Rev 5 with GRC toolingYesLighter, but still narrative-basedSame as above, wanting to reduce manual documentation
3. AcceleratorsInheritedReduced - inherit an existing boundaryCSPs that can deploy inside an already-certified vendor's boundary
4. FedRAMP 20xNoAutomated continuous evidence via KSIsCSPs with strong automation who want the fastest, sponsor-free route

Source: FedRAMP.gov and industry analysis. The traditional Rev5 path stops accepting new certifications on June 11, 2027, and existing Rev5 certifications remain active until at least December 31, 2028.

The headline for most new entrants: 20x removes the single hardest gate on the legacy path, finding an agency willing to sponsor you, for low- and moderate-impact services. That alone reshapes go-to-market for a lot of cloud vendors.

The agency path, mechanically

If you go the traditional Rev 5 route, here is how it actually moves.

  1. Determine your impact level. FedRAMP uses Rev 5 baselines (Low, Moderate, and High) aligned to NIST SP 800-53 Revision 5, and its 2026 rules label them as classes: Class B for low, Class C for moderate, and Class D for high impact. The level follows the sensitivity of the federal data your service will handle. Moderate is the most common target. FedRAMP has also offered a Tailored / Low-Impact SaaS option for the lowest-risk services.
  2. Find an agency sponsor. An agency that wants to use your service agrees to sponsor your certification and, ultimately, to have its Authorizing Official issue the ATO. Without a sponsor there is no traditional Rev5 certification, and this is the step that stalls most CSPs.
  3. Build the security package. Implement the applicable Rev 5 controls, then document them: a System Security Plan (SSP) describing each control's implementation, plus supporting policies, a Plan of Action and Milestones (POA&M) for any gaps, and the rest of the required artifacts.
  4. Engage a 3PAO. An accredited Third-Party Assessment Organization independently tests your controls and produces a Security Assessment Report (SAR). You cannot self-attest your way to a Rev 5 certification.
  5. Agency review and ATO decision. The sponsoring agency reviews the package and the SAR, weighs residual risk, and if it is satisfied, the Authorizing Official grants the ATO.
  6. Continuous monitoring (ConMon). Certification is the start of ongoing work. You submit ongoing evidence, including monthly vulnerability scans, an updated POA&M, and annual assessments, to keep the certification active.

For low- and moderate-impact services, the 20x path removes step 2 and compresses much of steps 3 through 5 into automated, continuously validated KSI evidence, which is the point of the redesign.

FedRAMP Marketplace designations

The FedRAMP Marketplace is the public directory agencies use to find certified services. Understanding its designations tells you where a product actually stands:

  • FedRAMP Certified (listed as FedRAMP Authorized before the 2026 rename): the service holds a current FedRAMP certification, and agencies can use it once they issue their own ATO. This is the status you are working toward.
  • FedRAMP In Process: the service is actively pursuing certification but is not yet certified.
  • FedRAMP Ready: a 3PAO has attested that the service is likely to achieve certification. It is a readiness milestone only.

Designation labels are changing with the 2026 rules, so read each listing itself. A listing's designation, impact level, and certification path all appear on the Marketplace, which is worth checking before you rely on a vendor's own "FedRAMP" marketing claim.

A realistic timeline

The honest answer to "how long does FedRAMP take?" is: it depends heavily on the path, your readiness, and how fast your sponsor moves. Ranges below reflect the two dominant routes.

PhaseTraditional Rev 5 (agency)FedRAMP 20x
Readiness / gap remediation3-9 monthsDepends on automation maturity
Sponsor acquisitionHighly variable (often the longest wait)Not required
Package build + 3PAO assessment3-6 monthsContinuous / automated
Agency review to ATO2-6 monthsProcessed directly by FedRAMP
Typical end-to-end~12-24 monthsDesigned to be faster; no reliable public benchmark yet

The Rev5 figures are planning ranges drawn from industry experience, and scope, engineering maturity, and sponsor engagement drive the real number. FedRAMP 20x has not been the standard path long enough to support a reliable public timeline benchmark, so treat any specific 20x figure as an early estimate.

The pattern that holds across both paths: the work you can control is readiness. A clean control implementation, a complete SSP, and a well-managed POA&M shorten every downstream phase - and on the 20x path, mature automation is the entire game.

FAQ

How long does it take to get FedRAMP certified?

It depends on the path. A traditional Rev5 certification through an agency sponsor commonly takes roughly 12-24 months end to end, with sponsor acquisition often the longest and least predictable phase. FedRAMP 20x requires no sponsor and uses automated KSI evidence, and it is designed to be faster, but there is not yet a reliable public benchmark for how long it takes. Your own readiness is the biggest variable you control.

How much does FedRAMP certification cost?

Costs are scope-dependent and are presented as ranges. Industry estimates put a traditional Rev5 Low certification around $250K-$500K initial, Moderate around $500K-$1.5M, and High at $3M and up, plus annual continuous-monitoring costs. FedRAMP 20x shifts spend from assessors and documentation toward engineering and automation, but there is not yet a reliable public cost range for it.

Is there a FedRAMP "certification," or is it an authorization?

Since February 2026, it is a certification. FedRAMP renamed its authorizations "certifications," so a cloud service now earns a FedRAMP certification (formerly FedRAMP authorization), either through the traditional Rev5 path with an agency sponsor or directly from FedRAMP through 20x. "Authorization" now refers to the agency's own Authorization to Operate (ATO), which each agency still issues before it uses the service.

What is FedRAMP 20x?

FedRAMP 20x is FedRAMP's standard path to certification going forward. It replaces the document-heavy, control-by-control process with Key Security Indicators (KSIs), measurable security outcomes validated through machine-readable, automated evidence. FedRAMP processes 20x certifications directly without an agency sponsor. 20x currently covers low- and moderate-impact services (Classes B and C), Class D for high impact is in development, and the traditional Rev5 path stops accepting new certifications on June 11, 2027.

What is the difference between FedRAMP Moderate and High?

Both are Rev 5 baselines aligned to NIST SP 800-53 Rev 5, differing in the sensitivity of data they cover and the number and rigor of controls. Moderate suits most federal data where a breach would have a serious but not catastrophic impact and is the most common target. High covers data where compromise could be catastrophic (for example, law enforcement or emergency services) and requires substantially more controls. Under FedRAMP's 2026 naming, Moderate is Class C and High is Class D, and because 20x does not yet cover Class D, a High certification currently runs through the traditional Rev5 path.

Do I still need an agency sponsor for FedRAMP?

On the traditional Rev5 path, yes, and finding one is often the hardest step. On the FedRAMP 20x path, no: FedRAMP processes 20x certifications directly. Because 20x does not yet cover high-impact services, a High certification still needs a sponsor on the Rev5 path. Removing the sponsor requirement is one of 20x's biggest changes and a major reason it is expected to broaden access to the federal market.

If you are a defense contractor rather than a cloud provider, FedRAMP reaches you through DFARS 252.204-7012, which requires any external cloud service that stores, processes, or transmits your covered defense information to meet security requirements equivalent to the FedRAMP Moderate baseline. That is a question to ask of every cloud vendor inside your CUI boundary.

Compli.ai is built for that side of the equation. It runs your NIST SP 800-171 program inside a SharePoint site in your own Microsoft 365 tenant, in Commercial, GCC, GCC High, or DoD, with no vendor database behind it and a core system that makes no external calls, so the records of your CUI program do not add another cloud service to that analysis.

Explore the Compli.ai overview, read our CMMC certification cost and SSP guides for the defense side of compliance, and book a demo to see how the program runs in your tenant.