FedRAMP 20x Resource

Know your 20x path before the authorization work begins.

FedRAMP 20x changes the authorization conversation from static paperwork to continuously validated trust. Use this page to understand Classes A, B, C, and D, where XBU40 fits, and when to start with the ATO Path Finder.

Quick Answer

What is FedRAMP 20x?

FedRAMP 20x is an automation-forward approach to cloud security authorization that emphasizes current validation data, machine-readable evidence, reusable trust information, and continuous proof over static package assembly.

From FedRAMP.gov

FedRAMP.gov 20x page reviewed July 10, 2026.

20x moves cloud assurance toward security decisions, measurable outcomes, machine-readable evidence, and continuous validation.
20x Classes

Choose the class that matches the government use case.

FedRAMP.gov says Class A, Class B, and Class C are available now. Class D is planned for a future Phase 4 pilot. The practical question is not just “can we get certified?” — it is “what kind of government use are we preparing to support?”

Class A

Marketplace entry for mature programs.

For cloud services with mature security and compliance programs that need a lighter initial path into the federal marketplace.

Class B

Smaller-scale or lighter-use services.

For common services where an entire agency is unlikely to rely on the service for important work or broad mission delivery.

Class C

Enterprise and important government services.

For services likely to be used across an agency or used to provide important government services. This is where XBU40’s Class C-ready foundation fits.

Explore XBU40 20x
Class D

Future path for High-impact needs.

FedRAMP.gov says Class D will be developed during Phase 4, with an estimated FY27 Q1-Q2 window for a High pilot.

Core Principles

20x is about better decisions, not prettier paperwork.

FedRAMP.gov frames 20x around transparency, flexibility, accountability, accuracy, and automatic validation. In practice, that means providers must explain their service honestly, show why security decisions fit the environment, and prove that those decisions continue to work.

TransparentShare scope, security decisions, evidence sources, and assumptions clearly.
ContinuousValidate evidence as systems operate, not only during assessment windows.
ContextualMatch the certification path to agency mission, data sensitivity, service scope, and buyer expectations.
Where XBU40 Fits

For Class C conversations, start with an operating foundation.

Class C is where enterprise use, important government services, evidence expectations, and ongoing monitoring become more serious. XBU40 gives teams a secure foundation with operations, evidence, and response workflows already designed around regulated cloud readiness.

Build

Start from a secure foundation.

Use proven architecture, boundary patterns, identity, logging, and control implementation designed for regulated cloud work.

Operate

Keep the environment aligned.

Connect cloud operations, patching, vulnerability work, change activity, and ownership into a daily operating model.

Prove

Make evidence current.

Use telemetry and structured evidence to show control health, validation status, scope, and remediation activity.

Defend

Respond with context.

Use 24x7 monitoring and response to connect risk, control impact, and remediation back to trust posture.

Program Timeline

20x has moved from pilot into formal adoption.

FedRAMP.gov lists 20x as active in Phase 3, focused on wide-scale adoption and finalizing the certification types. Future dates are estimates and should be watched against FedRAMP.gov updates.

Phase 1 completeThe Low pilot tested automation-based assessment and validation.
Phase 2 completeThe Moderate pilot tested whether automated validation could scale to higher impact services.
Phase 3 activeFedRAMP is formalizing Class A, B, and C certification types and preparing wider adoption.
Phase 4 futureClass D is planned for future High-impact needs.
Phase 5 futureFedRAMP.gov states new Rev5 certifications stop being accepted on June 11, 2027, with transition guidance expected.
Readiness Map

Questions to answer before choosing a path.

The right authorization path depends on your buyer, service scope, impact level, and operating maturity. These are the same themes the ATO Path Finder walks through interactively.

What are you selling?

Light-use SaaS, agency-wide platform, defense workload, or mission-critical service?

Who is the buyer?

Civilian agency, DoW, prime contractor, regulated enterprise, or mixed public-sector market?

What data is involved?

Low, Moderate, High, CUI, PHI, IL4, IL5, law enforcement, or other sensitive mission data?

What proof exists today?

SOC 2, ISO, cloud telemetry, vulnerability data, diagrams, policies, control ownership, and remediation history.

FedRAMP 20x FAQ

FAQ (Frequently Asked Questions)

Is FedRAMP 20x replacing Rev. 5?

FedRAMP.gov positions 20x as the go-forward model, but timing still depends on buyer requirements, current package work, impact level, and transition planning. Teams should decide whether to pursue 20x first, maintain Rev. 5, or preserve both options. FedRAMP.gov: 20x overview ↗

Which FedRAMP 20x class should we pursue?

The right class depends on use case, agency reliance, assurance depth, and evidence maturity. Class C is often relevant for enterprise and important government services that need stronger validation and ongoing reporting. FedRAMP.gov: 20x classes ↗

What makes 20x different from traditional FedRAMP?

20x shifts the focus from static package collection to security outcomes, Key Security Indicators, operational evidence, and validation that stays current as the service changes. FedRAMP.gov: certification rules ↗

Do we still need policies, diagrams, and documentation?

Yes. Documentation still explains scope, boundaries, and responsibilities, but it should be backed by current operational proof rather than standing alone. FedRAMP.gov: using 20x packages ↗

Where does XBU40 help?

XBU40 helps teams align secure cloud foundation, inherited patterns, evidence automation, monitoring, vulnerability response, and operating proof before authorization work becomes rework. FedRAMP.gov: ruleset reference ↗

When should we use the ATO Path Finder?

Use it before committing budget or engineering effort to one path. It frames buyer, data, boundary, timeline, current proof, and operating expectations into a practical next step. Start ATO Path Finder ↗

Find Your Starting Point

Not sure whether to start with 20x, Rev. 5, or DoW IL5?

Use the ATO Path Finder to answer a few questions about your market, data, environment, and timeline.

Start ATO Path Finder Talk to an expert