BlogSeptember 25, 2026FedRAMP 20x

FedRAMP RFC-0033: A Roadmap for Class D and Self-Hosted Services in FedRAMP 20x

The path to FedRAMP 20x Class D is beginning to take shape, and CSPs that wait for the final requirements may already be behind.

FedRAMP RFC-0033: A Roadmap for Class D and Self-Hosted Services in FedRAMP 20x

The path to FedRAMP 20x Class D is beginning to take shape, and CSPs that wait for the final requirements may already be behind.

With RFC-0033, FedRAMP has proposed an initial approach for developing, testing, and refining requirements that may support FedRAMP 20x Class D. The RFC also opens a related discussion about how the 20x model could apply to cloud services that are not primarily cloud-hosted.

Instead of forcing higher-impact certification, self-hosted architectures, and assessment methodology into a single pilot, FedRAMP proposes three parallel tracks designed to develop the requirements, operating model, and independent assurance approach together:

  • Develop and test the requirements and approach for a 20x Class D pilot
  • Work directly with existing self-hosted and hybrid-hosted CSPs on 20x requirements
  • Engage independent assessors to develop the corresponding assessment approach

Track 1: Class D Pilot Requirements for Cloud-Hosted Services

The first track is the most direct continuation of the FedRAMP 20x certification model: a Class D cloud-hosted pilot.

Important eligibility requirement: CSPs seeking to participate in the Phase 4 pilot must obtain a CR26-compliant FedRAMP 20x Class C certification by December 1, 2026.

The major milestones are:

DateMilestone
October 14, 2026RFC containing the full FedRAMP 20x Class D Certification pilot requirements
November 18, 2026Final Class D Certification pilot requirements published
December 1-4, 2026Class D Pilot application window
December 7-18, 2026Initial discussions with pilot participants
February 17, 2027Mandatory draft package submission and initial progress review
March 17, 2027Final pilot package submission deadline
March 23, 2027Tentative FedRAMP Day

While detailed Class D requirements are still being developed, RFC-0033 provides an early view of FedRAMP’s direction. The RFC anticipates requirements addressing certification maturity, underlying IaaS and PaaS dependencies, third-party information resources, assurance engineering, automation, availability, and foreign ownership, control, or influence. FedRAMP also expects the finalized Class D model to provide greater assurance than legacy FedRAMP Rev. 5 Class D for workloads where a loss of confidentiality, integrity, or availability could cause catastrophic harm, including loss of life.

For CSP program managers, Class D readiness is not merely a compliance documentation exercise. It is a coordinated program spanning architecture dependencies, third-party services, engineering capacity, assessment readiness, certification sequencing, budget, executive sponsorship, and sustained agency support. The immediate decision is whether the organization can complete Class C on the proposed schedule while retaining enough capacity to participate credibly in the Class D pilot.

FedRAMP proposes publishing the full Class D pilot requirements in a follow-on RFC on October 14, 2026. CSPs should monitor the official RFC page because the schedule and requirements may change in response to public comments.

Track 2: Extending 20x to Self-Hosted and Hybrid-Hosted Services

To support the broader FedRAMP marketplace, the 20x model must account for systems that are not built primarily on hyperscale cloud platforms. FedRAMP therefore proposes working directly with existing Rev. 5 Class C and Class D CSPs that operate primarily self-hosted or hybrid-hosted services.

Rather than immediately publishing requirements for these environments, FedRAMP plans to engage qualifying providers directly as it develops them.

To participate, a provider must:

  • Be FedRAMP Rev. 5 Class C or Class D Certified
  • Have at least 15 agency uses on record
  • Operate a service that is primarily self-hosted or hybrid-hosted
  • Meet the participation criteria at the provider level, with providers operating multiple qualifying offerings counted only once

The proposed timeline extends into March 2027:

DateMilestone
October 12, 2026Qualifying cloud service offerings receive instructions for opting into the engagement.
October 16, 2026Opt-in deadline
November 4, 2026FedRAMP publishes an RFC containing general questions about existing certifications and management of self-hosted or hybrid-hosted services.
November 4-20, 2026Round 1 CSP discussions establish the initial scope, intentions, and questions.
January 4-15, 2027Round 2 discussions focus on answers, responses, and potential impacts.
February 10, 2027FedRAMP publishes an RFC covering proposed 20x rules for self-hosted and hybrid-hosted services.
March 15-26, 2027Round 3 CSP discussions address the final rules.

Why This Track Matters

A CSP running on a hyperscale cloud platform and a provider operating its own physical or hybrid infrastructure may ultimately need to demonstrate the same security outcomes, but the evidence and technical mechanisms used to demonstrate those outcomes can look very different.

Track 2 gives FedRAMP a mechanism to develop those requirements in collaboration with organizations already operating these architectures under FedRAMP Rev. 5.

Track 3: Bringing Independent Assessors into the Development Process

Requirements are only part of the equation. If FedRAMP changes how security is demonstrated, the assessment model must evolve alongside it.

FedRAMP plans to work directly with recognized independent assessment services that have relevant experience evaluating the self-hosted and hybrid environments addressed in Track 2.

To qualify, an independent assessment service must be either:

  • The current assessor of record, or
  • The primary assessor within the previous three years for a CSP that qualifies for the direct engagement track.

The proposed engagement schedule is:

DateActivity
October 12, 2026Qualifying independent assessment services receive opt-in instructions
October 16, 2026Opt-in deadline
October 19-23, 2026Round 1 assessor meetings
January 19-22, 2027Round 2 assessor meetings
March 8-12, 2027Round 3 assessor meetings focused on final rules

This parallel track is important. FedRAMP is not simply asking, "What should CSPs have to demonstrate?" It is also working through how independent assessors should evaluate that demonstration under 20x.

Rather than treating Class D and self-hosted environments as a simple extension of earlier 20x work, FedRAMP is creating dedicated feedback loops for the organizations that will have to implement and assess the resulting requirements.

The Bigger Picture

FedRAMP 20x is more than a new set of security requirements. It represents a broader shift in how federal cloud security is demonstrated, validated, and maintained.

RFC-0033 begins extending that model into some of FedRAMP’s most complex environments.

The next phase is not simply a move from Class C to Class D. FedRAMP must show that the 20x approach can scale across higher-impact systems, self-hosted and hybrid architectures, and the independent assessments that support them.

The three-track structure provides the first high-level roadmap for getting there.

For CSPs, assessors, and agencies following FedRAMP 20x, October 2026 through March 2027 will be a critical period. During that window, today’s high-level concepts are expected to move into proposed requirements, hands-on testing, direct industry engagement, and a clearer definition of FedRAMP 20x Class D.

InfusionPoints’ Continuous Trust Platform (CTP) can help CSPs accelerate this path by operationalizing continuous evidence collection, control validation, and machine-readable certification data across cloud-hosted, self-hosted, and hybrid environments. By connecting engineering, compliance, and assessment workflows, CTP helps teams identify readiness gaps earlier and reduce the effort required to prepare for Class C and emerging Class D requirements.

The window to prepare is open now. CSP program managers should use the period before the proposed Class D application window to validate Class C eligibility, map architecture and third-party dependencies, reserve engineering and assessment capacity, and identify gaps that could block participation. Review RFC-0033, submit comments before the October 9, 2026 deadline, and build a readiness plan that can adapt as FedRAMP finalizes the Phase 4 requirements.

References

  • FedRAMP RFC-0033: 20x Phase 4 Development Tracks for 20x Class D
  • FedRAMP Consolidated Rules for 2026: 20x Class C Ruleset Reference
  • FedRAMP Consolidated Rules for 2026: 20x Assessments
FedRAMP 20x Readiness

Class D planning starts before the final rule lands.

Validate your Class C path, map dependencies, and prepare the evidence model now so your team is ready as FedRAMP finalizes Phase 4 requirements.

Start the conversation