Series: Modernizing Federal Cloud Compliance

Part 2: FedRAMP 20x & CR26: Moving from Paperwork to Continuous Assurance

In Part 1, we looked at how the FedRAMP Authorization Act of 2022 and OMB Memorandum M-24-15 fundamentally changed the structure, authority, and direction of FedRAMP. But policy was only the beginning. M-24-15 called for greater automation, machine-readable security information, and continuous monitoring. FedRAMP 20x and the Consolidated Rules for 2026 (CR26) are turning that policy vision into operational reality.

For Cloud Service Providers (CSPs) and Independent Assessors (formerly 3PAOs), the direction is clear: FedRAMP is moving away from static, point-in-time compliance and toward continuous, machine-readable security assurance.

A New FedRAMP Vocabulary

One of the most visible changes is terminology, but the new language reflects broader changes to how the program operates.

Authorization becomes Certification – The program is moving from “FedRAMP Authorized” to “FedRAMP Certified.” A FedRAMP Certification validates a Cloud Service Offering (CSO) against FedRAMP requirements and provides a standardized package of verified security data, with higher certification classes delivering progressively greater depth of system visibility and automated evidence for agency evaluation. Agency Authorizing Officials still make their own risk-based decisions when issuing an Authority to Operate (ATO).

Low, Moderate, and High become Certification Classes – FedRAMP is also introducing Certification Classes A through D:

  • Class A: A new entry point for eligible SaaS providers with a recent SOC 2 Type II or GovRAMP assessment, creating a faster path to FedRAMP Marketplace visibility.
  • Class B: Generally aligned with the former Low baseline for lower-impact systems.
  • Class C: Generally aligned with Moderate and expected to cover many enterprise federal cloud services.
  • Class D: Intended for the highest-impact, mission-critical systems and currently progressing through the FedRAMP 20x pilot process.

The terminology may be the most obvious change. The more significant change is how CSPs will demonstrate that security requirements are actually being met.

From Documents to Evidence

Historically, FedRAMP assessments have relied heavily on narrative documentation, including large System Security Plans (SSPs), supporting procedures, and point-in-time evidence.

FedRAMP 20x changes that model.

  • Security Decision Records (SDRs) provide structured records of security decisions and implementations rather than relying solely on a large, static narrative SSP.
  • Key Security Indicators (KSIs) and Rulesets translate security expectations into measurable outcomes across areas such as identity, logging, cloud-native architecture, and configuration management.
  • Machine-readable evidence allows security information to be generated, exchanged, and evaluated programmatically through OSCAL and other structured formats.
  • Automated validation increases as certification classes increase, requiring CSPs to build security evidence and validation into their environments rather than assembling it in preparation for an assessment.

The fundamental shift is straightforward:  CSPs increasingly need to have real-time metrics to prove what their systems are actually doing, not simply document what they are designed to do.

The Transition Is Already Underway

For existing FedRAMP CSPs, 20x should not be treated as a future compliance project.The transition is happening now. CSPs should be evaluating how existing Rev. 5 implementations map to KSIs, identifying where security evidence originates, determining which validations can be automated, and understanding where manual processes remain.

For new CSPs, the same transition creates an opportunity. Organizations entering FedRAMP today should think carefully before building extensive legacy processes that may need to be redesigned for 20x.

The 3PAO Perspective: Verification and Validation Still Matters

There is an understandable assumption that increased automation will mean less assessment. In practice, it changes what assessors need to evaluate. Under the traditional model, 3PAOs spend significant time reviewing documentation, collecting evidence, interviewing personnel,  independently testing controls at a point in time, and conducting detailed reporting.

Under 20x, assessment shifts from reviewing static narratives and configurations to auditing the code, logic, and telemetry pipelines generating the evidence.

Consider phishing-resistant MFA – A CSP may have an automated validation that reports MFA is enabled and returns a passing result. But that result alone does not demonstrate that phishing-resistant MFA is actually enforced for the required users, systems, and authentication paths. The assessor still needs to understand what was tested, where the data originated, whether the validation accurately represents the production environment, and whether the test actually demonstrates the KSI requirement.

Automation can tell us that a test passed and may or may not account for nested logic. Independent assessment determines whether that logic is comprehensive, sound, and proves what the CSP says it proves. That distinction becomes even more important as FedRAMP moves toward continuous assurance.

What CSPs Should Be Doing Now

For organizations entering FedRAMP for the first time, evaluate whether the new certification paths apply before investing heavily in legacy documentation and processes. Where possible, design compliance architecture around structured evidence and automation from the beginning. If eligible, use Class A to gain Marketplace visibility while building towards Class B or C under 20x. 

For existing Rev. 5 CSPs, begin mapping current implementations to KSIs and rulesets now. Identify evidence sources, determine which validations can be automated, and evaluate whether your existing tools provide enough transparency for an independent assessor to validate the results. Pay close attention to the ruleset adoption deadlines for Rev 5. 

Most importantly, do not automate a bad process.

The purpose of FedRAMP 20x moves beyond traditional compliance checklists to focus on the security decisions that matter most. Rather than forcing systems into arbitrary, one-size-fits-all requirements, 20x empowers providers to continuously measure and report the real-world effectiveness of their engineering choices.

From Compliance Documentation to Continuous Assurance

M-24-15 established the policy foundation for a modernized FedRAMP. FedRAMP 20x and CR26 are beginning to put that policy into practice.

The result is a significant paradigm shift for CSPs, agencies, and assessors alike. Documentation is not disappearing. Assessments are not disappearing. But both are evolving toward a model where security claims can be supported by structured, repeatable, and increasingly automated evidence.

For CSPs, preparing for that future means building security and compliance together rather than treating assessment as something that happens after the system is built.

For 3PAOs, it means continuing to do what independent assessors have always done: verify that the implementation and evidence actually proves the claim. 

How Lunarline Can Help

Lunarline has been assessing cloud environments since the beginning of FedRAMP. As the program moves toward 20x, our Independent Assessment team can help CSPs evaluate readiness, map existing implementations to KSIs, identify evidence and automation gaps, and independently validate whether automated testing demonstrates the required security outcomes.

In a continuous assurance model, generating evidence is only half the equation. You still have to prove that the logic is sound and the evidence is right.