Elevate

FedRAMP CR26: What the 2026 Consolidated Rules Actually Mean for Cloud Providers

FedRAMP CR26, the Consolidated Rules for 2026, is the most significant structural change the program has made in over a decade, and it arrived on schedule at the end of June. For any cloud service provider selling to federal agencies, the underlying security requirements have barely moved, but almost everything about how those requirements are labeled, documented, and assessed has changed. Elevate read the full ruleset so you don’t have to. This piece breaks down what changed, what stayed the same, and what it means for your roadmap between now and mandatory adoption, including one vulnerability deadline that lands in December 2026, ahead of the broader January 1, 2027 transition.

What FedRAMP CR26 Actually Is

FedRAMP CR26 is a single, consolidated rulebook that replaces the patchwork of memos, Requests for Comment, and notices that have governed the program since the FedRAMP Authorization Act passed. Understanding its structure matters because it changes how you will read and apply requirements going forward.

From Scattered Memos to One Rulebook

For the past two years, staying current with FedRAMP meant tracking a constant stream of RFCs and notices, with no fixed reference point. Providers consistently reported the same frustration: the rules kept changing, and there was no stable target to plan against. CR26 collapses that scattered guidance into one authoritative source organized into rulesets, subsets, and individual rules.

The rules themselves are written as plain-language, declarative statements using the IETF RFC-2119 convention of MUST, MUST NOT, SHOULD, SHOULD NOT, and MAY. A rule reads as a responsible party, a force, an action, and the conditions under which it applies. This removes much of the interpretation gap that produced “ghost requirements” under the old narrative model, where commonly accepted interpretations were never actually written down.

A Stable 30-Month Window

The single most strategically important feature of CR26 is its shelf life. The ruleset is intended to hold from July 2026 through December 31, 2028, when it will be replaced by the next consolidated set. FedRAMP will still publish notices and minor adjustments during that window, but the structural pieces, including certification classes, the assessment model, and marketplace mechanics, are meant to stay put.

For anyone trying to build a multi-year FedRAMP roadmap, this is the first realistic opportunity to do so in years. The compliance posture that earns certification in late 2026 will not be invalidated by a rule change in early 2027.

Machine-Readable by Design

CR26 maintains its source of truth as structured, machine-readable JSON published on GitHub, with the human-readable website serving only as a reference. The practical effect is that the FedRAMP requirements catalog now functions more like an API than a library shelf. If your governance, risk, and compliance pipeline can consume structured requirements, it can pull updates directly. This pairs with the program’s broader move toward machine-readable certification packages and connects to the same logic behind OSCAL-based documentation.

The Terminology Changes That Affect Your Contracts and Documentation

Most of CR26 changes labels, not controls. That sounds cosmetic, but if your contract language, sales collateral, or documentation templates hard-code the old terms, you have cleanup work ahead. The following table summarizes the shifts that matter most.

Old term (pre-CR26)New term (CR26)What actually changed
FedRAMP AuthorizedFedRAMP CertifiedLabel only. Same controls, same boundary.
Impact Levels (Low / Moderate / High)Certification Classes (A / B / C / D)New labels for existing baselines, increasing in assurance.
System Security Plan (SSP)Security Decision Record (SDR)A living, verified record rather than a static narrative document.
Third-Party Assessment Organization (3PAO)Independent AssessorNew terminology plus stricter recognition rules.
Authorization PackageCertification PackageRenamed to align with statutory language.

The controls behind these labels have not materially changed. What changed is the vocabulary your team, your auditors, and your federal customers will use to describe them.

“Authorized” Becomes “Certified”

The single official label for all FedRAMP paths going forward is FedRAMP Certification or FedRAMP Certified. The term “FedRAMP Authorized,” which has appeared on vendor websites for years, is being retired as the operative phrase. This aligns with the FedRAMP Authorization Act, which defines a FedRAMP authorization as a certification by FedRAMP. A cloud service that is FedRAMP Authorized today becomes FedRAMP Certified under CR26, with the same controls and the same boundary.

Impact Levels Become Certification Classes

The FIPS 199 impact level labels of Low, Moderate, and High are being replaced by Certification Classes A through D. FedRAMP deliberately chose letters rather than numbers or the word “levels” to avoid confusion with the Department of War Impact Level system, which is a separate construct. The classes represent an increasing ladder of assurance, from minimal at Class A to significant at Class D.

Certification ClassMaps to (legacy baseline)Typical use
Class ANew pilot baselineEntry-level designation, often a step toward B, C, or D
Class BLi-SaaS and LowLimited or low-sensitivity federal data
Class CModerateThe majority of federal deployments, including most CUI
Class DHighThe most sensitive unclassified government data

If your offering is FedRAMP Authorized at the Moderate level today, the practical translation is that you are looking at Class C under CR26. Mapping your current baseline to the correct class is the right preparation activity right now, and it connects directly to the work covered in our guide on the FedRAMP Rev5 transition.

The SSP Becomes a Security Decision Record

CR26 replaces the traditional System Security Plan with the Security Decision Record. The SDR is a persistently maintained, verified, and validated record of the security decisions a provider makes over the lifecycle of a cloud service offering. It documents how applicable FedRAMP Practices are addressed, including implementation rationale, resulting customer risk, assessment findings, and supporting artifacts. The shift reflects the broader move away from static narrative documents toward records that stay current with the actual state of the system.

3PAOs Are Now Independent Assessors

FedRAMP has retired the term “Third-Party Assessment Organization” in favor of “Independent Assessor,” aligning with the explicit terminology in the FedRAMP Authorization Act. The change also resolves long-standing confusion caused when the same organizations provided both assessment and advisory services under the 3PAO label. Independent Assessors must be FedRAMP Recognized for their work to count toward certification, and recognition now carries an activity requirement to prevent organizations from claiming the status without performing assessments.

The Deadlines That Should Be on Your Roadmap

CR26 phases in over roughly eighteen months. The dates below are the ones that should drive your planning, drawn directly from FedRAMP’s published implementation schedule.

DateMilestoneWhat it means for you
July 4, 2026Optional early adoption beginsYou may begin transitioning to CR26 incrementally.
July 6, 2026Initial Implementation Marketplace listings openProviders in the Initial Implementation Phase can be listed.
July 28, 2026FedRAMP Ready goes LegacyNo new Ready submissions accepted after this date.
August 3, 2026Class A pipeline opensApplications open for 20x and Rev5 Class A Certifications.
August 10, 2026Temporary Rev5 Class B and C pipelines openLimited path to Class B or C without an agency sponsor.
August 31, 202620x Class B and C pipeline opensApplications open for 20x Class B and C Certifications.
December 7, 2026VDR and VER rules become mandatoryThe new vulnerability rules apply to all offerings obtaining or maintaining FedRAMP Certification.
January 1, 2027Mandatory adoptionCR26 takes mandatory effect for all stakeholders.
March 7, 2027VDR and VER grace period endsCertification is subject to revocation for offerings not following the new vulnerability rules.
June 11, 2027End of new Rev5 CertificationsFedRAMP stops accepting new Rev5 applications.

Why July 28 Is the Hardest Date for Some Providers

The retirement of the FedRAMP Ready designation on July 28 is the deadline most likely to catch providers off guard. After that date, no new Ready submissions will be accepted, and existing Ready listings convert to Legacy FedRAMP Ready. Organizations that have been using FedRAMP Ready as a sales credential without pursuing full certification need an actual conversion plan before that date, because Legacy Ready offerings will not be eligible for certification under the new model. If that describes your situation, FedRAMP’s guidance is to pursue Rev5 Class A Certification instead.

What Mandatory Adoption Means

January 1, 2027 is when CR26 takes mandatory effect, though some individual rules carry their own later effective dates to give providers time to make changes. Between the optional adoption window opening in July 2026 and the mandatory date, you have roughly six months of transition runway. That runway exists specifically so you can plan and execute deliberately rather than scramble.

The Vulnerability Deadline That Moved Up to December

One deadline in the table above lands before mandatory adoption, and it is the one most providers do not yet have on their roadmap. CR26 makes FedRAMP’s Vulnerability Detection and Response (VDR) and Vulnerability Evaluation and Reporting (VER) rules mandatory for every cloud service offering obtaining or maintaining FedRAMP Certification effective December 7, 2026.

That date moved. Mandatory adoption of these vulnerability rules was originally planned for June 1, 2027, with a grace period running into 2028. It was pulled forward by roughly six months after CISA issued Binding Operational Directive 26-04 on June 10, 2026, which reprioritizes vulnerability remediation around public exposure, Known Exploited Vulnerability status, exploit automation, and technical impact. FedRAMP aligned its rules to that directive, and the result is a hard date that arrives before the broader January 1, 2027 transition.

The substance matters as much as the timing. The legacy monthly vulnerability scanning process that most Rev5 Certified offerings run today is no longer sufficient on its own. The new rules move providers toward an exposure and threat-based approach: evaluating whether vulnerabilities are reachable over the internet, assuming exploits are automatable unless evidence shows otherwise, and remediating Known Exploited Vulnerabilities on the timelines the directive sets.

There is a narrow grace window, not a reprieve. Providers who are not fully compliant by December 7 may maintain certification through March 7, 2027 under a corrective action plan that includes notice to their agency customers. After that date, FedRAMP Certification is subject to revocation for any offering not following the rules. The practical translation is that vulnerability management is the one part of this transition where waiting is the wrong move, and it ties directly to the continuous monitoring work covered in our FedRAMP ConMon deliverables guide.

Rev5 or 20x: You Have to Pick a Lane

CR26 publishes both the Rev5 and 20x certification paths in one document, with explicit rules for each. The critical point is that the lanes are not reciprocal. You pick one, and they are not interchangeable.

The Rev5 Path

Rev5 follows the legacy approach built primarily on documented plans and established controls. It is the path most current FedRAMP providers know, and it remains fully supported under CR26. However, FedRAMP will stop accepting applications for new Rev5 Certifications on June 11, 2027, which signals the program’s long-term direction even as it maintains support for existing Rev5 certifications through the CR26 window.

The 20x Path

20x is the modern, automation-forward track built primarily on measured outcomes rather than documented narratives. It relies on Key Security Indicators, which are specific, verifiable data points assessed against a standard baseline, instead of prose descriptions. For cloud-native providers with mature automation, 20x is designed to be faster and less document-heavy. Our breakdown of the FedRAMP 20x assessment model covers how this works in practice.

How to Decide

The right lane depends on your architecture and your automation maturity, not on which one sounds more modern. Providers with established Rev5 programs and documentation-heavy processes may find the Rev5 path the path of least resistance for now. Cloud-native providers building fresh, especially those who can produce machine-readable evidence directly from their infrastructure, are better positioned for 20x. This is a decision worth making deliberately, because reversing it later is not a simple matter.

What CR26 Means for You in Practice

The labels and deadlines matter most when you translate them into action for your specific situation. The first step for every provider is the same: map your current status to the new framework.

Map Your Current Status to the New Framework

Your next move depends entirely on where you sit today. The three scenarios below cover most providers.

If You Are Currently FedRAMP Authorized

Your authorization carries forward as a FedRAMP Certification with the same controls and boundary. Your practical work is translation, not reconstruction. Identify your current impact level, map it to the corresponding Certification Class, and note where your existing documentation references the old terminology. A provider authorized at Moderate becomes Class C, and the controls behind that designation do not change.

If You Are Holding FedRAMP Ready

Treat July 28 as a hard deadline. If you have been relying on the Ready designation as a sales credential, you need a concrete plan to convert to a full Certification track, because Legacy Ready will not be eligible for certification under the new model. Determine whether you are pursuing Class A under CR26 or one of the temporary Rev5 pipelines opening in August, and confirm whether you have an agency sponsor lined up.

If You Have Not Started Yet

You are arguably in the cleanest position, because you can build directly against the CR26 framework without unwinding legacy assumptions. Begin by determining which Certification Class your offering targets based on the sensitivity of the federal data you will handle, then decide between the Rev5 and 20x paths before you invest in tooling or documentation. Our guide on FedRAMP for SaaS providers walks through the foundational requirements.

Audit Your Boilerplate Before the Labels Change

If your contract templates, statements of work, or sales materials hard-code the phrase “FedRAMP Authorized,” schedule a pass through that boilerplate before the change takes full effect. The same applies to any documentation that references impact levels by the old Low, Moderate, and High labels. This is low-effort, high-value cleanup that prevents confusion with federal customers and procurement teams who will be operating under the new vocabulary.

What You Should Not Do Yet

Here is the discipline that separates a measured response from a costly one. Do not rewrite your authorization packages or certification documentation wholesale against early-adoption language before you have confirmed your path, class, and timeline. The prevailing guidance across the FedRAMP community is to do the mapping work now, understand where you land, and execute the substantive documentation changes deliberately rather than reactively. Continuous monitoring obligations also continue uninterrupted throughout this transition, and our FedRAMP ConMon deliverables guide covers what stays in effect while you plan your CR26 transition.

Where an Advisor Fits, and Where One Does Not

CR26 is explicit that advisory services are optional within the FedRAMP shared responsibility model, and that FedRAMP does not certify, review, recommend, or officially recognize advisors. That transparency cuts both ways, and it is worth understanding clearly.

An advisor helps you understand the rules, map your current state to the new framework, plan your path and class, and prepare for assessment, without replacing your responsibility as the provider or the independence of your assessor. What an advisor cannot do is grant you any official status. Any advisory service that presents a FedRAMP Marketplace listing as a special badge or certification from FedRAMP is sending a clear red flag. Elevate’s role is to help you navigate the complexity of CR26 and build a defensible roadmap, while you retain full ownership of your certification and your assessor remains fully independent. If you want help mapping your current FedRAMP status to the CR26 framework, Book a Readiness Call to work through your specific path and timeline.

Conclusion

FedRAMP CR26 consolidates years of scattered guidance into a single, stable, machine-readable rulebook that will govern the program through the end of 2028. The security requirements behind your certification have barely changed, but the labels, the documentation model, and the assessment paths have. Your most valuable work right now is mapping your current status to the new Certification Class structure, auditing your boilerplate for retired terminology, and deciding deliberately between the Rev5 and 20x paths, all while resisting the urge to rewrite your packages against language that is still settling. The providers who treat the transition window as a planning opportunity rather than a fire drill will enter mandatory adoption on stable footing. Book a Readiness Call to build your CR26 transition plan before the July deadlines arrive.

Key Takeaways

CR26 is the biggest FedRAMP restructuring in over a decade, but it changes labels and structure far more than it changes the underlying security requirements.

  • The vocabulary changed, not the controls. “FedRAMP Authorized” becomes “FedRAMP Certified,” impact levels become Certification Classes A through D, and the SSP becomes a Security Decision Record, all with the same security substance behind them.
  • You have a stable 30-month window. CR26 holds from July 2026 through December 2028, giving providers the first realistic chance in years to plan a multi-year FedRAMP roadmap against a fixed target.
  • July 28 is the deadline to watch. FedRAMP Ready retires that day, and providers using it as a sales credential need a concrete conversion plan to a full Certification track before then.
  • A vulnerability deadline lands before mandatory adoption. The VDR and VER rules become mandatory on December 7, 2026, pulled forward from June 2027 to align with CISA Binding Operational Directive 26-04, and legacy monthly scanning is no longer sufficient on its own.
  • You must choose Rev5 or 20x, and the lanes are not reciprocal. New Rev5 applications end June 11, 2027, while 20x offers an automation-forward, outcomes-based path built on Key Security Indicators.
  • Do the mapping now, but do not rewrite packages yet. Translate your current baseline to its new class and audit your boilerplate, but execute substantive documentation changes deliberately once your path and timeline are confirmed.

The smartest move during the transition window is deliberate preparation: map your status, audit your language, choose your path, and avoid reactive rewrites that the still-settling guidance may force you to redo.

FAQs

Q1. When does FedRAMP CR26 take effect?
CR26 entered an optional early adoption period beginning July 4, 2026, and takes mandatory effect for all stakeholders on January 1, 2027. Some individual rules carry their own later effective dates extending into 2027 to give providers time to make necessary changes. The ruleset is then supported through December 31, 2028, when it will be replaced by the next consolidated set.

Q2. Does CR26 change the actual security controls I need to implement?
No, not substantially. CR26 primarily changes terminology, structure, and documentation format rather than the underlying security requirements. A cloud service authorized at the Moderate level today carries forward as FedRAMP Certified at Class C with the same controls and the same boundary. The change is mostly about labels, machine-readability, and how requirements are expressed.

Q3. What happens to my FedRAMP Authorized status under CR26?
It becomes FedRAMP Certified. “FedRAMP Authorized” is being retired as the operative term in favor of “FedRAMP Certified,” which aligns with the language in the FedRAMP Authorization Act. The controls and boundary behind your authorization do not change, but you should audit any contract language or documentation templates that hard-code the old term.

Q4. What is the difference between the Rev5 and 20x certification paths?
Rev5 is the legacy path built primarily on documented plans and established controls, while 20x is the modern, automation-forward path built on measured outcomes and Key Security Indicators. The two paths are not interchangeable, so you must choose one. FedRAMP will stop accepting new Rev5 applications on June 11, 2027, signaling the program’s long-term direction toward the 20x model.

Q5. Should I start rewriting my FedRAMP documentation for CR26 now?
Map your current status to the new framework now, but hold off on wholesale rewrites until your path, class, and timeline are confirmed. The prevailing guidance is to align your existing documentation and controls to the new class structure as a planning exercise, then execute substantive changes deliberately rather than reactively. Rushing to rewrite packages against language that is still settling risks rework.

Q6. When do the new FedRAMP vulnerability rules take effect? The Vulnerability Detection and Response (VDR) and Vulnerability Evaluation and Reporting (VER) rules become mandatory for any cloud service offering obtaining or maintaining FedRAMP Certification on December 7, 2026. That date was moved forward from a planned June 1, 2027 to align with CISA Binding Operational Directive 26-04, issued June 10, 2026. Providers who are not fully compliant by December 7 may maintain certification through a grace period ending March 7, 2027 under a corrective action plan, after which certification is subject to revocation. The legacy monthly vulnerability scanning model most Rev5 offerings use today is no longer sufficient on its own.