FedRAMP Explained

Questions / Answer

FedRAMP 20x Phase 3: What Changes for Cloud Vendors Right Now

October 10, 2026

Your cloud vendor's FedRAMP paperwork may be changing under you. On October 8, 2026, FedRAMP published an official recap of its fiscal year. It confirms that the 20x overhaul is now in Phase 3, the wide-scale adoption stage. The new rules are final for the first three certification classes. If you buy or sell cloud services to the government, this changes your planning. Here is what moved and what to do.

What is FedRAMP 20x?

FedRAMP is the Federal Risk and Authorization Management Program. It is the government's standard for checking cloud security before agencies buy a cloud product. The old process, called Rev5, was slow and paper-heavy. FedRAMP 20x is the rebuild. It replaces long written documents with automated, machine-readable evidence of security posture. It also renames the old Low, Moderate, and High impact levels to certification classes A, B, C, and D.

What did Phase 3 finalize?

FedRAMP runs the 20x rollout in five phases. Phases 1 and 2 were pilots for Low and Moderate. Phase 3 is active now. Its job is to formalize the 20x requirements from the pilots and open them to everyone. Three things are done.

First, the Consolidated Rules are final for Class A, Class B, and Class C. The Consolidated Rules gather FedRAMP's requirements into one official ruleset for the first time. Second, Class B and Class C opened to all cloud service providers at the end of August 2026. Federal agencies are already using 20x-certified services. Third, FedRAMP urges any provider that lacks real Rev5 progress and a guaranteed sponsor to pivot to 20x now.

What comes next?

Phase 4 will pilot Class D, the old High level. It is estimated for the first half of fiscal year 2027. Phase 5 will end new Rev5 certifications on June 11, 2027. After that date, FedRAMP stops accepting new Rev5 certification packages.

Why should a defense contractor care?

You may not sell cloud software. You still feel this. One defense contract clause covers covered defense information you store in the cloud. It says you must use a FedRAMP Moderate authorized cloud or an equivalent. That clause is DFARS 252.204-7012. DFARS stands for the Defense Federal Acquisition Regulation Supplement.

Class C is the 20x replacement for the Moderate level. When you check a vendor's status, the label you see on the vendor's listing is changing. Know the new names so you read the vendor's proof correctly.

What should you do now?

If you are a cloud vendor with a Rev5 package that has no agency sponsor, shift to 20x. The program tells you to. Start with Class A, the transition class, if you plan to move up later.

If you are a buyer, ask each cloud vendor two questions. Which certification class does your offering hold under 20x? And what is your timeline for the old Rev5 label to expire? Write the answers into your vendor review file.

Finally, watch ongoing certification. FedRAMP 20x replaces the old periodic checkups with quarterly ongoing certification reports. Those reports list changes, accepted vulnerabilities, and reported incidents. Ask your vendor to share the relevant summary each quarter. It becomes your evidence that their posture stayed current.

Sources

Next step

Checking which FedRAMP class your cloud stack sits in? Map your Azure configuration to the right controls first.

See how PolicyCortex collects Azure evidence