HomeFrameworksCloud & Government AuthorizationFedRAMP

Framework  Cloud & Government Authorization

FedRAMP

FedRAMP is the US government-wide program that authorizes cloud services for federal agency use. It is administered by the FedRAMP Program Management Office at GSA, and the underlying control set is NIST SP 800-53 Revision 5.

Traditionally a cloud service provider (CSP) prepared a System Security Plan and supporting documents, was assessed by an accredited Third Party Assessment Organization (3PAO), and received an authorization at the Low, Moderate or High baseline listed on the FedRAMP Marketplace.

In 2025 the program launched FedRAMP 20x, a redesign built on automated, machine-readable Key Security Indicators instead of narrative control-by-control packages.

As of mid-2026 FedRAMP describes the new outcome as FedRAMP Certification in classes: Class A (entry level, replaces FedRAMP Ready; pipeline opened August 3, 2026), Class B and Class C (replacing the Low and Moderate impact levels; pipelines opened August 31, 2026) and Class D (pilot planned late 2026, formal availability expected early 2027).

The Consolidated Rules for 2026 codify the 20x requirements, and FedRAMP has stated it will stop accepting new Rev5 certifications on June 11, 2027.

Whatever the path, a CSP must have in writing a system security plan or its 20x equivalent, policies and procedures for every control family, a continuous monitoring plan, an incident response plan, and a plan of action and milestones (POA&M) for open findings.

AI-compiled
Share
Sponsored
FedRAMP
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with FedRAMP
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Cloud service providers that want federal agencies to use their service. The trigger is a federal contract or agency sponsorship; agencies must use authorized or certified offerings for cloud services holding federal information.

What the assessor asks to see

Authorization boundary diagram and data flows; System Security Plan or 20x KSI submission with machine-readable evidence; policies and procedures for each NIST 800-53 control family; asset inventory; configuration and vulnerability scan results; penetration test report; incident response plan and contingency plan with test results; FIPS-validated cryptography evidence; personnel screening and training records; continuous monitoring plan; POA&M.

Where the requirement sits: FedRAMP Rev 5, ConMon

FedRAMP 20x

FedRAMP 20x replaces narrative control packages with Key Security Indicators validated by automated evidence. Phase One (Low baseline pilot) ran April to September 2025 and produced 26 submissions; Phase Two (Moderate pilot) ran November 2025 to March 2026 with 14 submissions; Phase Three opened the formal submission pipeline in 2026.

Certification classes are A, B and C now, with Class D planned for a late-2026 pilot. The Rev5 path remains for existing authorizations, with limited Rev5 pipelines for lost-sponsor and ready-conversion cases and a stated end to new Rev5 certifications on June 11, 2027. Verify current dates on fedramp.gov because the program is changing quickly.

Assessors

Who assesses FedRAMP

A Third Party Assessment Organization (3PAO) accredited by A2LA to ISO/IEC 17020 plus the FedRAMP-specific R311 requirements and recognized by FedRAMP. The 3PAO performs readiness assessments, the security assessment plan and report, and annual assessments. Accredited by A2LA (American Association for Laboratory Accreditation), with FedRAMP recognition of the accredited 3PAO.

Public register of assessors: https://marketplace.fedramp.gov/assessors

A-LIGNOn the public register
What they do
Assessor
Which standards
On the public register for CSA STAR, FedRAMP, StateRAMP, HITRUST.
Standards
CSA STARFedRAMPStateRAMPHITRUST
Pricing
Not published
CoalfireOn the public register
What they do
Assessor
Which standards
On the public register for CSA STAR, FedRAMP, StateRAMP, HITRUST.
Standards
CSA STARFedRAMPStateRAMPHITRUST
Pricing
Not published
FortreumOn the public register
What they do
Assessor
Which standards
On the public register for FedRAMP, StateRAMP.
Standards
FedRAMPStateRAMP
Pricing
Not published
360 AdvancedOn the public register
What they do
Assessor
Which standards
On the public register for FedRAMP.
Standards
FedRAMP
Pricing
Not published
Prescient SecurityOn the public register
What they do
Assessor
Which standards
On the public register for FedRAMP, StateRAMP, HITRUST.
Standards
FedRAMPStateRAMPHITRUST
Pricing
Not published

Consultants

Who helps with FedRAMP

A large ecosystem: FedRAMP advisory firms write SSPs and 20x submissions, run gap assessments, build the technical evidence pipeline, and manage continuous monitoring. Many 3PAOs also sell advisory services but cannot assess the same system they advised on. Engagements typically run six to eighteen months from readiness to authorization.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a FedRAMP consultant listing yet. Claim yours →

Related reading

  1. Deep dive into FedRAMP 20x key security indicators: decoding the 63 KSIsGoes through the key security indicators that replace the old control narratives, and what evidence each one expects.Amazon Web Services
  2. Prepare for FedRAMP 20x with AWS automation and validationShows how continuous machine-readable validation replaces the annual document package, written for providers making the move.Amazon Web Services

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for FedRAMP

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with FedRAMP

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.