Key Takeaways:
- FedRAMP 20x replaced the legacy Low, Moderate, and High impact levels with Certification Classes A through D, moving from static documentation to continuously validated Key Security Indicators.
- Class B and Class C pipelines opened August 31, 2026, following Class A’s opening on August 3, closing out 20x’s pilot phase.
- Class A is a fast, low-documentation on-ramp for federal marketplace listing, qualified by a Readiness Assessment Report or SOC 2 Type II report, but providers have 12 months after their first federal agency use to begin transitioning to Class B or higher.
- Class B covers the modernized version of the old Low impact level for smaller-scale, lower-harm services. Class C replaces the old Moderate impact level for services handling Controlled Unclassified Information or other sensitive data, and requires deeper, mandatory automated validation.
- Class D, mapped to the former High impact level, is still in development, with piloting expected later in 2026 and general availability targeted for early 2027.
FedRAMP 20x stopped being an experiment on August 31, 2026. That’s the day the FedRAMP Program Management Office opened submission pipelines for Class B and Class C, the two certification paths that will carry the bulk of federal cloud workloads. Combined with the Class A pipeline that opened four weeks earlier, cloud service providers now have a complete, non-pilot route through FedRAMP’s rebuilt authorization model for the first time since the program launched.
FEDRAMP 20X REPLACES IMPACT LEVELS WITH CERTIFICATION CLASSES
The original FedRAMP program sorted cloud services into Low, Moderate, and High impact levels, each with its own fixed control baseline and a lengthy, document-heavy authorization package. FedRAMP 20x keeps the idea that risk should scale with what’s at stake, but it replaces the old baselines with four Certification Classes, A through D, and it replaces static documentation with Key Security Indicators that a cloud service provider validates on an ongoing basis, many of them automatically.
The shift matters beyond terminology. Under 20x, a provider’s security claims are checked continuously against measurable evidence instead of reviewed once during a point-in-time audit. FedRAMP’s program principles call for transparency in how a provider makes security decisions, flexibility for different engineering approaches, and automated validation wherever the evidence supports it.
CLASS A IS A FAST ON-RAMP WITH A BUILT-IN DEADLINE
Class A replaced FedRAMP Ready as the entry point for cloud service providers new to the federal marketplace. A provider can list in Class A with a completed Readiness Assessment Report or an existing SOC 2 Type II report, which gets a service in front of federal buyers with far less upfront documentation than the legacy process required. The tradeoff comes with a clock attached: once a federal agency starts using a Class A service, the provider has 12 months to begin transitioning to Class B or a higher class. Class A is designed for speed to market, with a defined runway before a provider has to move up.
CLASS B AND CLASS C SPLIT ALONG THE OLD LOW AND MODERATE LINES
Class B is the modernized version of the former Low impact level. It fits smaller-scale or limited-use services where a breach would cause limited harm, typically services that hold little more than login credentials or generally public information. Automated validation of Key Security Indicators is expected at Class B, though some evidence can still be self-attested.
Class C replaces the legacy Moderate impact level and is the default path for services handling Controlled Unclassified Information, financial records, or other personal data beyond basic account credentials, the kind of information where a breach could cause serious harm to an agency’s mission. Class C calls for a deeper and more mature set of Key Security Indicators than Class B, and automated validation is required rather than optional, backed by longer evidence retention and more extensive continuous monitoring.
Each class reflects a different assurance and reporting commitment, sized to the data at stake and the scale of federal reliance on the service, rather than a ranking of which cloud service is more secure.
CLASS D IS STILL COMING, BUILT FOR THE HIGHEST-IMPACT WORKLOADS
Class D, mapped to the old High impact level, remains in development. FedRAMP has targeted piloting later in 2026 with formal availability expected in early 2027. Until then, Class C is the ceiling for providers pursuing 20x authorization.
WHAT THIS MEANS FOR A CLOUD SERVICE PROVIDER’S ROADMAP
A provider evaluating FedRAMP 20x now has a real decision to make, not a pilot to watch from the sidelines. The right starting question is what data the service actually handles and what federal agencies actually need from it. A service with minimal PII and a narrow use case fits comfortably in Class B. A service headed for agency-wide deployment with sensitive data is better served building toward Class C requirements from the start, rather than detouring through Class B and redoing the evidence work later.
Providers already holding a Readiness Assessment Report or a SOC 2 Type II report have the clearest path into Class A today, with the 12-month transition clock a planning input rather than a surprise. Providers with a firmer sense of their target class can build their Key Security Indicator evidence and automated validation capability toward Class B or C directly, skipping the Class A detour altogether.
360 Advanced helps guide companies to the right certification class, offering a full suite of FedRAMP services.Review the certification class details on FedRAMP’s official 20x program page.