Skip to main content

Elevate

FedRAMP ATO for AI Platforms: What CR26 Changed, and Why FedRAMP Never Issued One

If you are budgeting for a FedRAMP ATO for your AI platform, start with a correction that will save you a procurement conversation: FedRAMP does not issue an Authority to Operate. It never has. Under the Consolidated Rules for 2026 (CR26), FedRAMP issues a Certification, and a federal agency issues the ATO for its own system under the NIST Risk Management Framework. The two are different instruments, granted by different bodies, and conflating them is the fastest way to lose credibility with a contracting officer.

CR26 rewrote almost every term this topic used to run on. “FedRAMP Authorized” is retired vocabulary. The Joint Authorization Board no longer exists, so there is no Provisional Authority to Operate to pursue. The Low, Moderate, and High labels no longer name FedRAMP certification baselines. And for a significant share of providers, an agency sponsor is no longer required at all. This guide explains what a FedRAMP ATO actually means for an AI platform today, what the technical requirements are beneath the vocabulary, and where the defense market raises the bar further.

What a FedRAMP ATO Really Is, and Who Issues It

Getting this right is not pedantry. It changes what you tell agencies, what you put on your website, and what you can legally claim.

Certification vs. Authority to Operate

The phrase FedRAMP ATO compresses two separate acts into one. FedRAMP reviews a cloud service offering’s completed assessment and issues a FedRAMP Certification. That certification is what a federal agency draws on when it decides whether to run your service inside its own information system. The agency, not FedRAMP, then issues the Authority to Operate under the Risk Management Framework, and it does so at whatever FIPS 199 security category it deems appropriate for its own system.

This is why “FedRAMP Certification” replaced “FedRAMP Authorization” as the single official label. The FedRAMP Authorization Act defines a FedRAMP authorization as a certification by FedRAMP, so the new term simply aligns the language to the statute. A service holding a FedRAMP Certification is FedRAMP authorized for the purposes of meeting statutory and regulatory requirements. The label changed. Your controls and your boundary did not.

The Joint Authorization Board Is Gone

The old model offered two routes. The Joint Authorization Board, staffed from GSA, the Department of Defense, and DHS, granted a Provisional Authority to Operate. Alternatively, a single agency sponsored a provider and issued an ATO letter. Neither description is current. The JAB no longer exists and the P-ATO is not an available outcome.

CR26 replaced that structure with two certification paths. The Program path lets a qualifying provider submit directly to FedRAMP with no agency sponsor at all, which removes what was for a decade the single hardest barrier to the federal market. The Agency path retains a federal sponsor for providers who want or need one. Only the highest certification class still requires an agency partner. For AI vendors without existing federal relationships, the Program path is the material change, and it deserves to sit at the center of your go-to-market plan rather than a footnote.

Why the Old Vocabulary Costs You Deals

Contracting officers read your collateral. A website that still advertises “FedRAMP Authorized,” a proposal that describes a “JAB P-ATO,” or a data sheet that promises a “FedRAMP ATO” tells a federal buyer that your compliance team has not read the current rules. That is a poor signal from a vendor asking to process federal data. Elevate’s breakdown of FedRAMP CR26 covers the full terminology change and the dates that govern it.

The Certification Classes That Replaced Impact Levels

The second structural change matters most for AI platforms, because AI workloads sit at the upper end of the scale.

How the Classes Map

CR26 retired the FIPS 199 impact level labels as names for FedRAMP certification baselines and replaced them with four Certification Classes. Class A is a new time-limited pilot tier. Class B covers the former Low and Li-SaaS baselines. Class C covers the former Moderate baseline. Class D covers the former High baseline.

FedRAMP chose letters rather than numbers or the word “levels” specifically to end the chronic confusion with the Department of Defense Impact Level system, where a FedRAMP Moderate and a DoD IL4 were routinely mistaken for one another. Note the precise scope of the change. FIPS 199 impact levels still exist, and agencies still categorize their own information systems as low, moderate, or high. What changed is that a FedRAMP certification baseline is no longer named after one.

A Class Is an Assurance Commitment, Not a Security Rating

FedRAMP is explicit that a Certification Class does not describe how secure a cloud service is. It describes the depth, frequency, and quality of the certification data a provider commits to supplying to agencies, and FedRAMP instructs agencies not to treat a Class as a one for one replacement for an impact level. A higher Class means you are supplying more assurance information on a tighter cadence, which raises both your initial and your recurring cost.

For an AI platform, this reframes the decision. You are not choosing how secure to be. You are choosing how much evidence about your models, your training data, and your pipeline you are willing to produce continuously for federal customers. Elevate’s guide to FedRAMP controls and classes breaks down what each Class requires.

Which Class an AI Platform Actually Needs

Most AI platforms land at Class C or Class D, because AI systems typically exercise some degree of control over sensitive data rather than merely storing public information. Government data confirms where providers cluster. Of the FedRAMP authorizations leveraged by the 24 CFO Act agencies as of April 2023, the Government Accountability Office reported that approximately 76 percent were moderate-impact and 17 percent were high-impact, with the low baseline and its tailored SaaS variant together accounting for under 7 percent. Mapped onto CR26, that is roughly three quarters of the market at Class C and one sixth at Class D.

On the Rev5 path, Class B carries roughly 156 controls, Class C roughly 323, and Class D roughly 410. On the FedRAMP 20x path there is no control count at all, because assurance is demonstrated through Key Security Indicators and machine-readable evidence rather than a documented control set. AI workloads handling law enforcement, emergency services, financial, or health data generally require Class D. Class D is also the one tier with no Program path and no 20x path, so it still requires a federal agency sponsor under Rev5.

FedRAMP Class D and DoD IL5 for Defense AI Workloads

For AI platforms targeting defense agencies, Class D is often the floor rather than the ceiling. When the Department of Defense handles its most sensitive unclassified data, it applies a separate, stricter standard known as Impact Level 5, defined in the DoD Cloud Computing Security Requirements Guide (CC SRG).

What IL5 Is and How It Differs

IL5 is the highest security level for unclassified DoD cloud systems. It covers Controlled Unclassified Information requiring enhanced protection due to mission sensitivity, and unclassified National Security Systems workloads. IL6 by contrast covers classified information through the SECRET level.

The distinction that matters: IL5 is not a FedRAMP class. It is a DoD standard that builds on FedRAMP. The CC SRG establishes that a FedRAMP High baseline assessment, supplemented with DoD FedRAMP+ controls and control enhancements, is what a cloud service offering is assessed against toward a DoD IL5 provisional authorization. In practice, the FedRAMP baseline is necessary but not sufficient for IL5. A platform must meet both sets of requirements to operate across civilian and defense high-assurance environments.

The CC SRG Has Not Caught Up With CR26

Here is a wrinkle that will trip up anyone reading both documents side by side. The CC SRG describes IL5 as building on a FedRAMP High provisional authorization. Under CR26 there are no provisional authorizations, because the body that granted them no longer exists, and there is no baseline called High. The defense-side documentation still speaks the pre-CR26 language.

Treat this as a translation problem rather than a contradiction. The underlying baseline is unchanged, and Class D is the CR26 name for it. But do not assume DoD program offices have updated their solicitation language. Expect to see “FedRAMP High” in defense requirements documents for some time, and expect to have to explain the mapping.

Why IL5 Matters for AI Platforms

A defense contractor running AI workloads on a Class C platform faces a hard ceiling. The Class C baseline does not satisfy IL5 requirements, so when a DoD program office mandates IL5 for CUI workloads, a Class C certified tool cannot operate in that environment. The contractor must either migrate to a Class D platform or maintain separate IL5-compliant infrastructure at significant cost.

IL5 also adds requirements beyond the FedRAMP baseline. It demands stricter access controls, expanded monitoring, and enhanced isolation, including physical and logical separation of DoD-only tenants. Personnel with access to IL4 and IL5 data are restricted to US citizens, US nationals, or US persons, with no foreign-person access permitted. For AI vendors with distributed engineering teams, that personnel restriction is frequently the binding constraint, and it is discovered late.

How to Verify an IL5 Claim

If your platform plans to claim IL5 readiness, expect agencies to verify it. Contracting officers are advised to ask vendors directly and check the FedRAMP Marketplace or the DISA list of authorized cloud products, because a service in progress is not a service that is certified. Buyers will also ask whether IL5 was achieved through your own infrastructure or inherited through a pre-accredited platform, because the scope and inheritance of controls differ sharply between the two pathways.

The Technical Requirements AI Platforms Underestimate

Beneath the vocabulary sits a set of controls that determines whether AI platforms succeed or stall in the federal market.

NIST SP 800-53 Control Families That Matter for AI

NIST SP 800-53 controls are the foundation of the Rev5 certification path. AI systems place unusual weight on specific families. Access Control governs identity management and privilege restriction around models and training data. System and Communications Protection governs data flows and encryption. System and Information Integrity governs the detection of unauthorized modification, which for an AI platform means model weights and training pipelines rather than only binaries. Elevate’s primer on NIST SP 800-53 Rev 5 covers the catalog.

AI platforms need controls that conventional software security frameworks handle poorly. Training data, model weights, and configuration settings are assets that the control catalog was not originally written to address, which is why they generate findings that surprise engineering teams during assessment.

The COSAiS Overlays Are Not Final Yet

NIST is developing Control Overlays for Securing AI Systems (COSAiS), which will tailor SP 800-53 controls for specific AI use cases including generative AI, predictive AI, and single and multi-agent systems. Understand the status precisely before you build a compliance plan around it. NIST published a concept paper in August 2025 and an annotated outline discussion draft in January 2026. There is no initial public draft, no final overlay, and no announced FedRAMP adoption of COSAiS.

Treat COSAiS as an early signal of where federal AI security requirements are heading, not as a requirement you can implement today. Mapping your AI systems to the emerging use case categories now is prudent. Telling an agency that your platform is COSAiS-compliant is not, because there is nothing yet to comply with. For a broader picture of how AI frameworks interlock, see Elevate’s mapping of FedRAMP and ISO to the NIST AI RMF and its essential guide to AI audits.

Data Residency and Boundary Enforcement for AI Models

The authorization boundary covers every component of a cloud service offering that handles federal information or affects its confidentiality, integrity, or availability. For AI platforms, models trained on agency data must stay inside that boundary unless explicitly authorized to leave it.

FedRAMP does not impose data location restrictions across all baselines, but the Class D baseline carries control SA-9(5) governing processing, storage, and service location. Providers must document every component, relationship, data flow, and security enforcement point, and must hold information exchange agreements with external systems that specify encryption methods and access controls. Boundary discipline is also the highest-leverage cost decision available to you, and Elevate’s guidance on scoping an enclave applies directly.

Encryption: FIPS 140-3 Replaces FIPS 140-2 in September 2026

This is the requirement most likely to be wrong in your current documentation, and the deadline is close.

FedRAMP requires cryptographic modules to be validated under the NIST Cryptographic Module Validation Program. Historically that meant FIPS 140-2. On September 21, 2026, every remaining FIPS 140-2 certificate moves to the CMVP Historical list. Modules keep working. Their compliance standing does not. From that date, a FedRAMP review, a CMMC assessment, or a DFARS verification that asks for validated cryptography will find a FIPS 140-2 certificate insufficient. CMVP stopped accepting new FIPS 140-2 submissions years ago, and FIPS 140-3 validations have been averaging well over a year.

For AI platforms specifically, validated cryptography must protect training, validation, and testing datasets, model artifacts and weights, and system and application logs that may contain sensitive inputs. Two practical warnings. First, a product that embeds a validated module cannot itself claim to be validated, only that it uses one. Second, “FIPS compliant” is not “FIPS validated,” and only the latter satisfies FedRAMP. Verify the exact vendor, module name, version, and Active status in the CMVP database, and confirm FIPS mode is actually enabled at runtime rather than merely available.

If your architecture, your Security Decision Record, or your sales collateral still cites FIPS 140-2, you have roughly one quarter to fix it.

Audit Logging and Traceability in AI Pipelines

AI pipelines must track every privileged action rather than simply retaining logs. Sensitive operations such as data exports or infrastructure changes should route through approval workflows where a designated engineer reviews and authorizes the action, which creates a durable audit record and eliminates self-approval.

Traceability has to span the entire AI lifecycle. Every step from model training through deployment and update must carry documentation sufficient to demonstrate continuous compliance. This is where AI platforms diverge most sharply from conventional SaaS, because the artifact under audit is a model whose behavior changes over time.

Model Integrity Validation

The System and Information Integrity family carries unusual weight for AI. SI-7 addresses software, firmware, and information integrity, and for an AI platform that means detecting unauthorized modification to model weights, configuration files, and training pipelines. SI-4 addresses system monitoring.

Without integrity validation, AI systems are exposed to adversarial injection and backdoors introduced upstream in the training pipeline. Integrity checking must extend to the algorithms and the data, not only to the deployed binary. Elevate’s guide to AI risk management and asset scoping covers how to inventory these assets before an assessor asks.

Security Architecture Adjustments for AI Certification

AI platforms need architectural changes beyond standard cloud security practice.

Zero Trust Enforcement in AI Model Access

Zero Trust rests on three principles: verify explicitly, apply least-privileged access, and assume breach. It carries specific weight when AI systems process sensitive government information, because the model itself becomes an access path to the data it was trained on.

Every entity that touches the model or its data needs continuous verification, including automated systems and service accounts, not only human users. Treat applications integrated with large language models as entities requiring stricter access control policy than a typical employee, since a compromised integration can exfiltrate training data through inference rather than through a conventional data path. The federal push toward this posture traces back to Executive Order 14028.

Continuous Monitoring of AI Model Behavior

Under CR26, continuous monitoring is collaborative. You share ongoing certification data with all of your agency customers rather than reporting to a single authorizing body, and providers on the 20x path host their own package in their own trust center.

For AI, SI-4 monitoring has to reach beyond infrastructure scanning. You need to detect model drift, track output patterns and inference behavior, and surface anomalies that conventional security tooling will not flag. AI systems can fail without triggering a single standard alert, which means silent degradation is a compliance event that only model-aware monitoring will catch.

Vulnerability handling also tightened. FedRAMP split its rules into vulnerability detection and response on one side and vulnerability evaluation and reporting on the other, and tied both to the Known Exploited Vulnerabilities catalog maintained by the Cybersecurity and Infrastructure Security Agency. Build your operations to meet the tightest applicable federal timeline.

AI Model Updates Under Change Control

A Security Impact Analysis must precede any significant change, documenting known and potential security risks so the agency’s Authorizing Official can weigh them. After the change, an assessor confirms the modification did not weaken the security posture, and your package documentation must be updated accordingly.

For AI platforms this creates a standing tension. Model retraining and fine-tuning are routine engineering events that can constitute significant changes under FedRAMP’s rules. A fast-moving model roadmap therefore carries a compliance cadence that a static product does not, and pricing that cadence into your engineering plan is the difference between a manageable obligation and a surprise every release. Elevate’s ISO 42001 AI impact assessment guidance offers a structure for evaluating those changes, and its analysis of how ISO 42001 overlaps with ISO 27001 shows where existing work carries forward.

What FedRAMP Certification Actually Costs an AI Platform

No official price for a FedRAMP ATO exists, and the precise figures circulating online do not survive contact with the source.

FedRAMP charges no program fee and publishes no standard cost estimates. The only government review of the question reached an unhelpful but honest conclusion. In January 2024 the Government Accountability Office reported to Congress that agencies and providers supplied estimated rather than actual costs, that those estimates ranged from tens of thousands to millions of dollars, and that the variance came largely from participants counting different things. GAO recommended that the Office of Management and Budget issue guidance so costs are tracked consistently, because without it OMB cannot tell whether its own cost reduction goal is being met. GAO drew a non-generalizable sample and did not independently verify any of the figures it collected.

What actually sets your number is your certification type, your target Class, the size of your authorization boundary, and how much of your security program already exists. An AI platform inheriting controls from certified infrastructure with a tight boundary and mature operations sits at the low end of every one of those. A self-operated platform pursuing Class D with a sprawling boundary compounds cost across all four. To scope your own figure rather than borrow someone else’s, talk to an Elevate advisor.

How to Choose Your Path in 2026

Three decisions determine your route to a FedRAMP ATO, and all three are made before you engage an assessor.

First, certification type. FedRAMP 20x is the cloud-native path built on Key Security Indicators and machine-readable evidence, and it suits AI platforms running on FedRAMP Certified infrastructure with strong automation. Rev5 is the traditional control-baseline path, and it remains the only route to Class D. FedRAMP stops accepting new Rev5 certification applications on June 11, 2027, which puts a clock on that decision. See Elevate’s overview of the FedRAMP 20x assessment model.

Second, certification path. The Program path removes the agency sponsor entirely for Classes A, B, and C. Class D still requires one. For an AI vendor without existing federal relationships, this single change is worth more than any tooling decision on this page.

Third, target Class. Certify at the Class your target agencies require, not the one that looks cheapest and not the one that looks most impressive. Both errors are expensive, and both are made at the scoping stage.

Conclusion

Buyers and vendors still say FedRAMP ATO, but FedRAMP does not issue one. It issues a Certification, and an agency issues the ATO. That single correction carries most of what changed for AI platforms under CR26: no Joint Authorization Board, no Provisional Authority to Operate, no “FedRAMP Authorized,” and no impact levels naming certification baselines. Class C and Class D replaced Moderate and High, and for most AI workloads one of those two is the destination.

Underneath the vocabulary, the technical bar for AI platforms is genuinely higher than for conventional SaaS. Validated cryptography protects model weights and training data, and the FIPS 140-2 certificates most documentation still cites lose their standing on September 21, 2026. Model integrity, boundary enforcement, and behavior monitoring all demand controls the catalog was not written for. On the defense side, Class D is the foundation for DoD IL5, which layers on isolation and US-person personnel restrictions that distributed engineering teams discover late.

Elevate Consult helps AI vendors map their architecture to the right certification type, path, and Class, and works as an advisor rather than an assessor, which keeps that guidance independent. To find out where your platform stands and what it takes to reach your target Class, talk to an Elevate advisor.

Key Takeaways

The terminology changed, the paths changed, and one encryption deadline lands this quarter.

FedRAMP issues a Certification, not an ATO. The agency issues the Authority to Operate for its own system under the Risk Management Framework. “FedRAMP Authorized” and “FedRAMP ATO” are both retired as descriptions of what FedRAMP grants.

The Joint Authorization Board no longer exists. There is no Provisional Authority to Operate. CR26 offers a Program path with no agency sponsor for Classes A, B, and C, and an Agency path for those who want or need a sponsor.

Classes replaced impact levels. Class B covers the former Low and Li-SaaS baselines, Class C the former Moderate, and Class D the former High. A Class describes assurance depth, not how secure a service is.

Most AI platforms need Class C or Class D. GAO reported that roughly 76 percent of agency-leveraged authorizations were moderate-impact and 17 percent high-impact as of April 2023. Class D has no Program path and no 20x path.

FIPS 140-2 expires as a compliance basis on September 21, 2026. Every remaining certificate moves to the CMVP Historical list. AI platforms must confirm Active FIPS 140-3 modules protecting training data, model weights, and logs.

DoD IL5 builds on the FedRAMP baseline, it does not replace it. IL5 adds DoD-specific controls, tenant isolation, and US-person personnel restrictions. Note that the CC SRG still uses pre-CR26 language.

COSAiS is a draft, not a requirement. NIST published a concept paper in August 2025 and a discussion draft in January 2026. No final overlay exists and FedRAMP has announced no adoption.

FAQs

Q1. Does FedRAMP issue an ATO?

No. FedRAMP issues a FedRAMP Certification. A federal agency issues the Authority to Operate for its own information system under the NIST Risk Management Framework, using the FedRAMP Certification Package to inform that decision. Under CR26, “FedRAMP Certification” is the single official label, replacing “FedRAMP Authorization” and “FedRAMP Authorized.” The Joint Authorization Board and its Provisional Authority to Operate no longer exist, so a P-ATO is not an available outcome.

Q2. Which FedRAMP Certification Class does an AI platform need?

Most AI platforms need Class C or Class D, because AI systems typically exercise control over sensitive federal data rather than only public information. Class C replaces the former Moderate baseline and Class D replaces the former High baseline. AI workloads handling law enforcement, emergency services, financial, or health data generally require Class D, which is the only Class with no Program path and no FedRAMP 20x path, meaning it still requires a federal agency sponsor under Rev5.

Q3. What is DoD IL5 and how is it different from a FedRAMP Certification?

IL5 is the highest security level for unclassified DoD cloud systems, covering high-sensitivity Controlled Unclassified Information and unclassified National Security Systems workloads. It is not a FedRAMP Class. It builds on the FedRAMP baseline by adding DoD-specific controls, stricter tenant isolation, and US-person personnel requirements. The FedRAMP baseline is necessary but not sufficient for IL5, so a platform must satisfy both to operate in defense high-assurance environments.

Q4. Does an AI platform still need FIPS 140-2 validated encryption?

No. On September 21, 2026, every remaining FIPS 140-2 certificate moves to the Historical list maintained by the NIST Cryptographic Module Validation Program. Modules continue to function, but a FIPS 140-2 certificate no longer satisfies FedRAMP, CMMC, or DFARS requirements for validated cryptography from that date. AI platforms should confirm Active FIPS 140-3 modules protecting training data, model artifacts and weights, and logs, and should verify that FIPS mode is enabled at runtime rather than merely available.

Q5. Do AI platforms still need an agency sponsor for FedRAMP?

Not in most cases. CR26 introduced a Program Certification path that lets qualifying providers submit directly to FedRAMP with no agency sponsor for Classes A, B, and C. The Agency path remains available for providers who want or need a sponsor. Class D is the exception: it has no Program path and no FedRAMP 20x path, so it still requires a federal agency to act as sponsor under Rev5.