Marketplace entry for mature programs.
For cloud services with mature security and compliance programs that need a lighter initial path into the federal marketplace.
FedRAMP 20x changes the authorization conversation from static paperwork to continuously validated trust. Use this page to understand Classes A, B, C, and D, where XBU40 fits, and when to start with the ATO Path Finder.
FedRAMP 20x is an automation-forward approach to cloud security authorization that emphasizes current validation data, machine-readable evidence, reusable trust information, and continuous proof over static package assembly.
FedRAMP.gov 20x page reviewed July 10, 2026.
20x moves cloud assurance toward security decisions, measurable outcomes, machine-readable evidence, and continuous validation.
FedRAMP.gov says Class A, Class B, and Class C are available now. Class D is planned for a future Phase 4 pilot. The practical question is not just “can we get certified?” — it is “what kind of government use are we preparing to support?”
For cloud services with mature security and compliance programs that need a lighter initial path into the federal marketplace.
For common services where an entire agency is unlikely to rely on the service for important work or broad mission delivery.
For services likely to be used across an agency or used to provide important government services. This is where XBU40’s Class C-ready foundation fits.
Explore XBU40 20xFedRAMP.gov says Class D will be developed during Phase 4, with an estimated FY27 Q1-Q2 window for a High pilot.
FedRAMP.gov frames 20x around transparency, flexibility, accountability, accuracy, and automatic validation. In practice, that means providers must explain their service honestly, show why security decisions fit the environment, and prove that those decisions continue to work.
Class C is where enterprise use, important government services, evidence expectations, and ongoing monitoring become more serious. XBU40 gives teams a secure foundation with operations, evidence, and response workflows already designed around regulated cloud readiness.
Use proven architecture, boundary patterns, identity, logging, and control implementation designed for regulated cloud work.
Connect cloud operations, patching, vulnerability work, change activity, and ownership into a daily operating model.
Use telemetry and structured evidence to show control health, validation status, scope, and remediation activity.
Use 24x7 monitoring and response to connect risk, control impact, and remediation back to trust posture.
FedRAMP.gov lists 20x as active in Phase 3, focused on wide-scale adoption and finalizing the certification types. Future dates are estimates and should be watched against FedRAMP.gov updates.
The right authorization path depends on your buyer, service scope, impact level, and operating maturity. These are the same themes the ATO Path Finder walks through interactively.
Light-use SaaS, agency-wide platform, defense workload, or mission-critical service?
Civilian agency, DoW, prime contractor, regulated enterprise, or mixed public-sector market?
Low, Moderate, High, CUI, PHI, IL4, IL5, law enforcement, or other sensitive mission data?
SOC 2, ISO, cloud telemetry, vulnerability data, diagrams, policies, control ownership, and remediation history.
FedRAMP.gov positions 20x as the go-forward model, but timing still depends on buyer requirements, current package work, impact level, and transition planning. Teams should decide whether to pursue 20x first, maintain Rev. 5, or preserve both options. FedRAMP.gov: 20x overview ↗
The right class depends on use case, agency reliance, assurance depth, and evidence maturity. Class C is often relevant for enterprise and important government services that need stronger validation and ongoing reporting. FedRAMP.gov: 20x classes ↗
20x shifts the focus from static package collection to security outcomes, Key Security Indicators, operational evidence, and validation that stays current as the service changes. FedRAMP.gov: certification rules ↗
Yes. Documentation still explains scope, boundaries, and responsibilities, but it should be backed by current operational proof rather than standing alone. FedRAMP.gov: using 20x packages ↗
XBU40 helps teams align secure cloud foundation, inherited patterns, evidence automation, monitoring, vulnerability response, and operating proof before authorization work becomes rework. FedRAMP.gov: ruleset reference ↗
Use it before committing budget or engineering effort to one path. It frames buyer, data, boundary, timeline, current proof, and operating expectations into a practical next step. Start ATO Path Finder ↗
Use the ATO Path Finder to answer a few questions about your market, data, environment, and timeline.
Start ATO Path Finder Talk to an expert