The Modern FedRAMP Journey: A Step-by-Step Roadmap for CSPs

For many cloud service providers (CSPs), the new, modern FedRAMP can feel overwhelming. There are new certification classes, multiple certification paths, evolving terminology, and different routes depending on whether you’re pursuing civilian agencies or the Department of Defense (DoD). Add in the introduction of FedRAMP 20x and the 2026 Consolidated Rules, and it’s easy to focus on individual requirements without understanding how they fit into the bigger picture. 

Whether you’re just beginning to explore the federal market or preparing to pursue your first certification, every organization moves through a series of decisions that build toward the same goal: demonstrating trust and enabling federal agencies to confidently adopt your cloud service. 

Here’s what that journey looks like under the 2026 Consolidated Rules. 

Step 1: Define your federal market strategy

The first question isn’t about technical implementation, it’s about business development. 

Who are you trying to sell to? 

Your answer will shape the rest of your FedRAMP journey.  

Some organizations are pursuing opportunities with civilian agencies, while others are focused primarily on the DoD. Some say, why not both? 

That distinction matters because while FedRAMP plays a significant role across the federal government, the DoD maintains its own authorization processes and impact level requirements that differ from the civilian FedRAMP certification model.

Understanding your target customer helps determine which certification path makes the most sense and prevents organizations from solving the wrong problem. 

Step 2: Establish your FedRAMP Certification Profile 

With your business objectives defined, the next step is determining your FedRAMP Certification Profile.

A Certification Profile isn’t a single decision, it’s the combination of three key elements that define how your cloud service will pursue certification: 

  • Type: Will you pursue the legacy Rev. 5 framework or the newer FedRAMP 20x framework?
  • Path: Will you pursue Program Certification or Agency Certification? 
  • Certification Class: Which Certification Class (A through D) aligns with your offering and your customers’ security requirements? 

Together, these three decisions form your Certification Profile. More importantly, they determine nearly everything that comes next, including the security practices you’ll implement, the certification package you’ll build, whether you’ll need an agency sponsor, and ultimately how you’ll earn and maintain your FedRAMP Certification.

The good news is that these aren’t arbitrary choices, as your cloud service architecture, target customers, and business objectives will naturally narrow the appropriate profile. A cloud-native SaaS provider targeting civilian agencies may arrive at a very different Certification Profile than a provider pursuing high-impact DoD workloads.

That’s why we encourage organizations to think about their Certification Profile before they think about individual compliance requirements. Once your profile is established, the rest of the journey becomes significantly clearer. 

Step 3: Define your security goals

Once you’ve selected your certification path, the focus shifts from planning to security. 

One of the defining characteristics of FedRAMP 20x is its emphasis on security outcomes rather than documentation for its own sake. Instead of beginning with checklists, organizations start by defining security goals that align with the program’s expectations.

These goals describe what your environment must accomplish to protect federal information and support trustworthy cloud operations, which become the foundation for everything that follows. 

Step 4: Implement security and demonstrate it through KSIs 

Defining security goals is only the beginning. Next comes implementing the technical, operational, and administrative safeguards necessary to achieve those goals.

For organizations pursuing the FedRAMP 20x path, this also means demonstrating that those safeguards are functioning effectively through Key Security Indicators (KSIs). KSIs are designed to provide measurable evidence that security objectives are being achieved within the environment.

Rather than relying solely on narrative documentation, organizations increasingly demonstrate security through structured, repeatable, and machine-readable evidence generated directly from their operational systems.

This is one of the most significant shifts introduced by the Consolidated Rules. The focus moves away from producing documentation and toward producing trustworthy evidence.

Step 5: Build your Certification Package

As your security program matures, you’ll begin assembling the information required to support certification. 

Under the Consolidated Rules, this Certification Package is far more than a collection of documents. It represents the complete body of evidence supporting your certification, including structured technical artifacts, security information, required documentation, and supporting data that demonstrate your cloud service meets the applicable requirements. 

Within your Certification Package is a Security Decision Record. You can think of these as replacing the previous System Security Plan. This is where you outline exactly what you’re doing along with why/how,including rule-by-rule justification of your security posture. 

Rather than viewing this as paperwork, organizations should think of the certification package as the story of their security program, supported by objective, verifiable evidence. 

Step 6: Earn your FedRAMP Certification 

With your package complete, your organization is ready to pursue certification. 

Depending on your certification profile, this may begin with a Class A Certification or move directly toward higher certification classes. 

Certification demonstrates that your cloud service has satisfied the applicable FedRAMP requirements and gets you listed on the FedRAMP Marketplace. It’s an important milestone, but it isn’t the end of the journey, as it’s the beginning of your ability to engage more broadly with federal agencies. 

Step 7: Support agency adoption

One of the biggest misconceptions surrounding the new program is that certification automatically means agencies can begin using your cloud service. 

In reality, agencies still make their own risk-based decisions about adopting cloud technologies. A FedRAMP Certification provides confidence that your service has met the program’s security requirements, giving agencies a trusted foundation for their own authorization and procurement decisions. 

With certification in place, this is where you can lean heavily into business development with federal agencies. 

Step 8: Grow alongside your federal customers

Very few organizations need the highest level of assurance on day one, and the new certification model recognizes that reality. 

As your federal business grows and new agency use cases emerge, your certification journey can grow with it. Organizations may begin with Class A before progressing to higher certification classes as customer requirements evolve. 

Rather than viewing certification as a one-time project, successful providers should think of FedRAMP as a long-term capability that matures alongside their business. 

The journey doesn’t end at certification

The 2026 Consolidated Rules do more than modernize FedRAMP, they provide a clearer roadmap for organizations entering the federal market. 

Instead of asking cloud providers to navigate a collection of disconnected guidance documents, the program now defines a structured journey that begins with eligibility, progresses through security implementation and certification, and ultimately supports long-term success across the federal government. 

Every provider’s journey will look a little different. 

Some will move quickly toward FedRAMP 20x. Others will begin with Rev. 5 during the transition period.  

Some will start with Class A, while others pursue higher certification classes from the outset. 

Regardless of the path, the objective remains the same: build a trustworthy cloud service, demonstrate that trust through objective evidence, and create the confidence federal agencies need to adopt your technology. 

Understanding that journey is the first step toward successfully navigating it. Reach out to our federal team to get started.