FedRAMP RFC-0033: A Roadmap for Class D and Self-Hosted Services in FedRAMP 20x
The path to FedRAMP 20x Class D is beginning to take shape, and CSPs that wait for the final requirements may already be behind.

The path to FedRAMP 20x Class D is beginning to take shape, and CSPs that wait for the final requirements may already be behind.
With RFC-0033, FedRAMP has proposed an initial approach for developing, testing, and refining requirements that may support FedRAMP 20x Class D. The RFC also opens a related discussion about how the 20x model could apply to cloud services that are not primarily cloud-hosted.
Instead of forcing higher-impact certification, self-hosted architectures, and assessment methodology into a single pilot, FedRAMP proposes three parallel tracks designed to develop the requirements, operating model, and independent assurance approach together:
- Develop and test the requirements and approach for a 20x Class D pilot
- Work directly with existing self-hosted and hybrid-hosted CSPs on 20x requirements
- Engage independent assessors to develop the corresponding assessment approach
Track 1: Class D Pilot Requirements for Cloud-Hosted Services
The first track is the most direct continuation of the FedRAMP 20x certification model: a Class D cloud-hosted pilot.
Important eligibility requirement: CSPs seeking to participate in the Phase 4 pilot must obtain a CR26-compliant FedRAMP 20x Class C certification by December 1, 2026.
The major milestones are:
| Date | Milestone |
|---|---|
| October 14, 2026 | RFC containing the full FedRAMP 20x Class D Certification pilot requirements |
| November 18, 2026 | Final Class D Certification pilot requirements published |
| December 1-4, 2026 | Class D Pilot application window |
| December 7-18, 2026 | Initial discussions with pilot participants |
| February 17, 2027 | Mandatory draft package submission and initial progress review |
| March 17, 2027 | Final pilot package submission deadline |
| March 23, 2027 | Tentative FedRAMP Day |
While detailed Class D requirements are still being developed, RFC-0033 provides an early view of FedRAMP’s direction. The RFC anticipates requirements addressing certification maturity, underlying IaaS and PaaS dependencies, third-party information resources, assurance engineering, automation, availability, and foreign ownership, control, or influence. FedRAMP also expects the finalized Class D model to provide greater assurance than legacy FedRAMP Rev. 5 Class D for workloads where a loss of confidentiality, integrity, or availability could cause catastrophic harm, including loss of life.
For CSP program managers, Class D readiness is not merely a compliance documentation exercise. It is a coordinated program spanning architecture dependencies, third-party services, engineering capacity, assessment readiness, certification sequencing, budget, executive sponsorship, and sustained agency support. The immediate decision is whether the organization can complete Class C on the proposed schedule while retaining enough capacity to participate credibly in the Class D pilot.
FedRAMP proposes publishing the full Class D pilot requirements in a follow-on RFC on October 14, 2026. CSPs should monitor the official RFC page because the schedule and requirements may change in response to public comments.
Track 2: Extending 20x to Self-Hosted and Hybrid-Hosted Services
To support the broader FedRAMP marketplace, the 20x model must account for systems that are not built primarily on hyperscale cloud platforms. FedRAMP therefore proposes working directly with existing Rev. 5 Class C and Class D CSPs that operate primarily self-hosted or hybrid-hosted services.
Rather than immediately publishing requirements for these environments, FedRAMP plans to engage qualifying providers directly as it develops them.
To participate, a provider must:
- Be FedRAMP Rev. 5 Class C or Class D Certified
- Have at least 15 agency uses on record
- Operate a service that is primarily self-hosted or hybrid-hosted
- Meet the participation criteria at the provider level, with providers operating multiple qualifying offerings counted only once
The proposed timeline extends into March 2027:
| Date | Milestone |
|---|---|
| October 12, 2026 | Qualifying cloud service offerings receive instructions for opting into the engagement. |
| October 16, 2026 | Opt-in deadline |
| November 4, 2026 | FedRAMP publishes an RFC containing general questions about existing certifications and management of self-hosted or hybrid-hosted services. |
| November 4-20, 2026 | Round 1 CSP discussions establish the initial scope, intentions, and questions. |
| January 4-15, 2027 | Round 2 discussions focus on answers, responses, and potential impacts. |
| February 10, 2027 | FedRAMP publishes an RFC covering proposed 20x rules for self-hosted and hybrid-hosted services. |
| March 15-26, 2027 | Round 3 CSP discussions address the final rules. |
Why This Track Matters
A CSP running on a hyperscale cloud platform and a provider operating its own physical or hybrid infrastructure may ultimately need to demonstrate the same security outcomes, but the evidence and technical mechanisms used to demonstrate those outcomes can look very different.
Track 2 gives FedRAMP a mechanism to develop those requirements in collaboration with organizations already operating these architectures under FedRAMP Rev. 5.
Track 3: Bringing Independent Assessors into the Development Process
Requirements are only part of the equation. If FedRAMP changes how security is demonstrated, the assessment model must evolve alongside it.
FedRAMP plans to work directly with recognized independent assessment services that have relevant experience evaluating the self-hosted and hybrid environments addressed in Track 2.
To qualify, an independent assessment service must be either:
- The current assessor of record, or
- The primary assessor within the previous three years for a CSP that qualifies for the direct engagement track.
The proposed engagement schedule is:
| Date | Activity |
|---|---|
| October 12, 2026 | Qualifying independent assessment services receive opt-in instructions |
| October 16, 2026 | Opt-in deadline |
| October 19-23, 2026 | Round 1 assessor meetings |
| January 19-22, 2027 | Round 2 assessor meetings |
| March 8-12, 2027 | Round 3 assessor meetings focused on final rules |
This parallel track is important. FedRAMP is not simply asking, "What should CSPs have to demonstrate?" It is also working through how independent assessors should evaluate that demonstration under 20x.
Rather than treating Class D and self-hosted environments as a simple extension of earlier 20x work, FedRAMP is creating dedicated feedback loops for the organizations that will have to implement and assess the resulting requirements.
The Bigger Picture
FedRAMP 20x is more than a new set of security requirements. It represents a broader shift in how federal cloud security is demonstrated, validated, and maintained.
RFC-0033 begins extending that model into some of FedRAMP’s most complex environments.
The next phase is not simply a move from Class C to Class D. FedRAMP must show that the 20x approach can scale across higher-impact systems, self-hosted and hybrid architectures, and the independent assessments that support them.
The three-track structure provides the first high-level roadmap for getting there.
For CSPs, assessors, and agencies following FedRAMP 20x, October 2026 through March 2027 will be a critical period. During that window, today’s high-level concepts are expected to move into proposed requirements, hands-on testing, direct industry engagement, and a clearer definition of FedRAMP 20x Class D.
InfusionPoints’ Continuous Trust Platform (CTP) can help CSPs accelerate this path by operationalizing continuous evidence collection, control validation, and machine-readable certification data across cloud-hosted, self-hosted, and hybrid environments. By connecting engineering, compliance, and assessment workflows, CTP helps teams identify readiness gaps earlier and reduce the effort required to prepare for Class C and emerging Class D requirements.
The window to prepare is open now. CSP program managers should use the period before the proposed Class D application window to validate Class C eligibility, map architecture and third-party dependencies, reserve engineering and assessment capacity, and identify gaps that could block participation. Review RFC-0033, submit comments before the October 9, 2026 deadline, and build a readiness plan that can adapt as FedRAMP finalizes the Phase 4 requirements.
References
- FedRAMP RFC-0033: 20x Phase 4 Development Tracks for 20x Class D
- FedRAMP Consolidated Rules for 2026: 20x Class C Ruleset Reference
- FedRAMP Consolidated Rules for 2026: 20x Assessments
Class D planning starts before the final rule lands.
Validate your Class C path, map dependencies, and prepare the evidence model now so your team is ready as FedRAMP finalizes Phase 4 requirements.
Start the conversation