FedRAMP certification has a reputation of being slow, documentation-heavy, and difficult to navigate without an agency sponsor. FedRAMP 20x is the program’s answer to that criticism. Developed in collaboration with industry and government, it aims to dramatically expand the FedRAMP Marketplace by making it faster and more accessible for Cloud Service Providers (CSPs) to reach certification.
What FedRAMP 20x changes
Traditionally, FedRAMP certification took years, requiring extensive documentation and layers of review. FedRAMP 20x simplifies this process, approving cloud services in weeks. Rather than reviewing compliance control by control, the program uses Key Security Indicators (KSIs), which are a set of security capabilities that focus on measurable outcomes instead of prescriptive processes.
Key improvements include:
- Automation of compliance: Using machine-readable processes to reduce manual tasks.
- Adoption of industry standards: Aligning with frameworks like SOC 2 and ISO 27001 to leverage existing security investments.
- Continuous monitoring: Validating security through real-time data instead of periodic audits.
- Direct collaboration: Encouraging more agile relationships between Cloud Service Providers (CSPs) and federal agencies.
- Rapid innovation: Eliminating delays to enable faster adoption of secure cloud services.
This initiative prioritizes flexibility, empowering CSPs and agencies to work more directly and limit bureaucratic bottlenecks.
FedRAMP 20x phases
FedRAMP 20x is being rolled out in phases. Timelines are estimates and subject to change based on pilot outcomes.
Phase 1 – Low pilot (complete)
Phase 1 tested the 20x approach on low-impact cloud systems and was open to any CSP. It replaced the traditional 325-item control baseline with KSIs and required machine-readable security submissions assessed by a 3PAO. A-LIGN participated as both a 3PAO assessor and as a CSP, achieving 20x Low certification for A-SECEND, the firm’s proprietary audit management platform.
Phase 2 – Moderate pilot (active, est. through Q2 2026)
Thirteen CSPs selected from the Phase 1 pilot are working with FedRAMP and 3PAOs to test the Moderate impact certification approach. The phase is designed to answer three questions:
- Can CSPs meet automated validation requirements for both initial and ongoing certification?
- Can 3PAOs effectively assess those automated capabilities?
- How should providers and assessors collaborate to produce credible, ongoing evidence of cloud security decisions?
Phase 3 (est. Q3–Q4 2026)
Low and Moderate impact certifications under the 20x model open to the public, once FedRAMP finalizes requirements based on Phase 1 and 2 outcomes.
Phase 4 (est. Q1–Q2 2027)
A pilot for High impact certifications begins, targeting hyperscale IaaS and PaaS providers. All existing Rev. 5 certified providers will be required to transition to machine-readable certification data.
Phase 5 (est. Q3–Q4 2027)
FedRAMP will stop accepting new Rev. 5 certification applications on June 11, 2027. A transition path for existing Rev. 5 certified CSOs will be provided, with deadlines expected to span multiple years.
New naming conventions
FedRAMP is replacing the Low/Moderate/High impact level terminology with a lettered class system:
- Class A: Replaces FedRAMP Ready
- Class B: Replaces Low
- Class C: Replaces Moderate
- Class D: Replaces High
Additionally, all certification systems will now be called “FedRAMP Certified”, as the “FedRAMP Validated” naming convention has been dropped.
Benefits of FedRAMP 20x
For CSPs targeting the federal market, FedRAMP 20x offers major benefits:
- Faster approvals: Reduce certification timelines from years to weeks.
- Easier processes: Minimized paperwork and increased automation lower costs and effort.
- Self-initiation: No agency sponsor needed for low-impact systems, opening opportunities for smaller providers.
- Cloud-native alignment: Requirements are more developer-friendly, focusing on agility and outcomes.
- Encouraged innovation: Continuous monitoring ensures new features can roll out quickly without delaying compliance.
By lowering barriers and fostering competition, FedRAMP 20x brings more providers into the federal sector, supporting rapid technological advancement.
Getting ready for FedRAMP 20x
Where 20x fits into your planning depends on where you are in the certification process.
If you haven’t started yet: The 20x pathway isn’t fully available to the public yet, but the direction is clear. Automation and machine-readable evidence are central to where the program is heading.
If you’re mid-certification under Rev. 5: Switching paths mid-process isn’t a decision to make without careful analysis. That said, build awareness of 20x now and understand how it may affect future offerings.
If you’re already certified: Monitor how certification and continuous monitoring requirements evolve under 20x. Plan for the eventual transition to machine-readable certification data, which will be required starting in Phase 4.
Regardless of where you are, 20x should be part of your compliance roadmap for 2026 and beyond.
How A-LIGN can support your FedRAMP journey
Navigating FedRAMP alone can be challenging. A-LIGN, as a trusted FedRAMP-accredited 3PAO, offers expert guidance for traditional FedRAMP and the 20x pilot.
- Readiness assessment: We help identify gaps, align security controls, and prepare your team for FedRAMP requirements.
- Assessment and documentation: Our expertise ensures seamless evaluations, minimizing surprises during the submission process.
- Continuous monitoring: A-LIGN supports post-certification security through ongoing assessments and adaptable strategies.
With FedRAMP 20x reshaping compliance standards, having a knowledgeable partner can make all the difference. We’re committed to supporting you at every stage, from preparation to long-term success.


