R
RampReady
← Blog/FedRAMP

FedRAMP 20x vs FedRAMP Rev5: What Actually Changed

A practitioner's comparison of FedRAMP 20x (CR26) and the legacy Rev5 authorization process — what changed, what stayed the same, and what it means for CSPs pursuing federal cloud authorization.

The Short Version

FedRAMP 20x, launched under the Consolidated Rules for 2026 (CR26), is a fundamental redesign of the federal cloud authorization process — not an incremental update. The core change is a shift from a control-by-control documentation model to an outcome-focused Key Security Indicator (KSI) model. For CSPs who have been through a Rev5 authorization, 20x will feel like a different program.

What Was Wrong with Rev5

FedRAMP Rev5 — based on NIST SP 800-53 Rev. 5 — required CSPs to document implementation of hundreds of security controls in an SSP, produce dozens of supporting artifacts, undergo a formal 3PAO assessment, and navigate an agency review and ATO process that routinely took 12-24 months from initiation to authorization.

The documentation burden was enormous. A FedRAMP Moderate SSP routinely exceeded 300 pages. The artifact package for a full assessment could include hundreds of individual documents. The process was expensive, slow, and heavily front-loaded — most of the work happened before a CSP could demonstrate anything to an agency.

FedRAMP's own data showed that the average time to authorization was over a year, and many authorizations fell through after significant investment. Small and mid-size CSPs were effectively priced out of the federal market.

What FedRAMP 20x Changes

From Controls to KSIs

The foundational change in 20x is the replacement of the control-by-control NIST SP 800-53 documentation model with 46 Key Security Indicators. KSIs are outcomes — specific, measurable security states that the FedRAMP program has determined are most predictive of actual security posture.

KSIs are organized using CR26 mnemonics (e.g., KSI-IAM-APM for Identity and Access Management — Access and Privilege Management). They are not simply NIST controls renamed; they represent a deliberate selection of outcomes that can be evaluated through technical evidence, not documentation review.

Automated Evidence Over Document Review

In Rev5, the primary evidence format was the SSP — a narrative document describing control implementations. In 20x, the primary evidence format is automated technical evidence: machine-readable outputs from configuration management tools, security scanning systems, and identity platforms.

The 20x model anticipates that KSI compliance can be demonstrated through automated checks — continuous monitoring outputs, scan results, configuration exports — rather than manually authored documentation. This is a significant shift for CSPs whose authorization approach relied heavily on documentation skills rather than technical automation.

The Class A Pathway

FedRAMP 20x introduces Class A authorizations — a transitory pathway for CSPs that can demonstrate equivalency through existing authorizations or assessments. Class A entry points include:

  • Legacy RAR conversion — CSPs with existing FedRAMP authorizations under Rev5 can convert through a streamlined process
  • SOC 2 Type II conversion — CSPs with current SOC 2 Type II reports covering relevant criteria may qualify for a conversion pathway
  • GovRAMP as Approved Alternative Security Framework — CSPs with GovRAMP authorization may use it as an entry point

Class A is explicitly transitory — CSPs entering through Class A must progress to full 20x compliance within defined timeframes.

3PAO Role Changes

Under Rev5, 3PAOs conducted formal assessments against the complete control baseline, producing a Security Assessment Report (SAR) that was a primary input to the ATO decision. Under 20x, the assessment model shifts toward continuous validation of KSI compliance.

3PAOs in the 20x environment focus on:

  • KSI assessment against the CR26 catalog
  • Validation of automated evidence integrity
  • Continuous monitoring oversight rather than point-in-time assessment

The relationship between CSP, 3PAO, and FedRAMP PMO is more continuous under 20x than the project-based engagement model that characterized Rev5 authorizations.

What Stayed the Same

Federal Security Requirements

The underlying security outcomes required of federal cloud systems have not changed. Encryption of data in transit and at rest, strong identity and access management, vulnerability management, incident response, and continuous monitoring remain foundational requirements. What changed is how those requirements are expressed and how compliance is demonstrated.

Agency Authorization Decision

Agencies still make authorization decisions. A FedRAMP 20x authorization still requires an agency ATO — the PMO's role in the process has evolved, but agencies retain their authorization authority under FISMA.

Continuous Monitoring Obligations

CSPs with FedRAMP authorizations of any kind have ongoing continuous monitoring obligations. The cadence and format of ConMon reporting has evolved under 20x, but the fundamental obligation to maintain and demonstrate continuous compliance has not changed.

Penetration Testing

Annual penetration testing remains a requirement under FedRAMP 20x. The scope and methodology align to the updated testing requirements under CR26, but the obligation for independent adversarial testing of the authorization boundary is unchanged.

What It Means for CSPs in Market

CSPs currently authorized under Rev5 need to understand their conversion pathway under CR26. FedRAMP has provided transition guidance for existing authorizations, but CSPs should not assume that their Rev5 authorization automatically converts — active engagement with the PMO and their agency sponsor is needed.

CSPs in-process under Rev5 face a decision about whether to continue the Rev5 path or pivot to 20x. The right answer depends on how far along the Rev5 process they are, their technical readiness for the automated evidence model, and their agency relationships.

CSPs starting fresh should almost certainly pursue 20x. The Rev5 process is effectively sunset for new authorizations, and the KSI-based model, while requiring investment in technical automation, is faster and more sustainable than the document-heavy Rev5 approach.

SaaS and platform CSPs building on existing IaaS/PaaS platforms with FedRAMP authorizations need to understand how their inheritance story translates under 20x. The inheritance model under CR26 has been clarified and documented, but CSPs should verify with their platform providers how KSI inheritance works for their specific service model.

The 46 KSIs at a Glance

The CR26 KSI catalog covers:

  • IAM — Identity and access management, including access and privilege management, authentication, and identity lifecycle
  • VM — Vulnerability management, including scanning cadence, remediation timelines, and patch management
  • CM — Configuration management, including secure baseline maintenance and change control
  • IR — Incident response, including detection capability, response procedures, and reporting
  • SC — System and communications protection, including encryption and network segmentation
  • AU — Audit and accountability, including log collection, retention, and review
  • CA — Security assessment, including continuous monitoring and penetration testing
  • SI — System and information integrity, including malware protection and integrity verification
  • RA — Risk assessment, including risk identification and treatment processes

Each KSI has defined assessment criteria under CR26 that specify what evidence demonstrates the KSI is met.

Practical Takeaways

For practitioners working on FedRAMP authorizations:

  1. Get the CR26 documentation from fedramp.gov — not from legacy sources. The 20x program documentation is at fedramp.gov and is updated as the program evolves. Anything predating CR26 launch (June 24, 2026) reflects the pilot-era program, not the current requirements.

  2. KSI IDs have changed — the pilot program used numeric IDs (KSI-01, KSI-02). CR26 uses mnemonic IDs (KSI-IAM-APM). Any reference to numeric KSI IDs is stale.

  3. Automated evidence infrastructure matters — if your organization does not have systematic configuration management, automated scanning, and continuous monitoring tooling, that is the gap to close before pursuing 20x.

  4. The KSI count is 46 — earlier pilot documentation referenced 61 KSIs. CR26 consolidated and revised the catalog to 46. Use the current CR26 figure.


The RampReady FedRAMP 20x Field Manual (CR26 Edition) covers all 46 KSIs with assessment criteria, evidence requirements, and implementation guidance for CSPs pursuing 20x authorization.

← Back to all posts