Skip to main content

Elevate

What Is FedRAMP Certification? The ATO vs. Certification Distinction Under CR26

A FedRAMP certification is not an Authority to Operate, and FedRAMP has never issued one. FedRAMP reviews a completed independent assessment and issues a FedRAMP Certification. A federal agency then issues the Authority to Operate for its own information system, under the NIST Risk Management Framework, using that certification package to inform the decision. Two instruments, two issuers, two scopes.

Almost every article on this subject gets that backwards, and until mid-2026 the program’s own vocabulary encouraged the error. The Consolidated Rules for 2026 (CR26) ended it. “FedRAMP Authorized” is retired. The Joint Authorization Board no longer exists, so there is no Provisional Authority to Operate to pursue. The Low, Moderate, and High impact level labels no longer name FedRAMP baselines. This guide explains what a FedRAMP certification actually is, how it differs from compliance and from an ATO, and which certification path a cloud service provider should pursue now.

What Is FedRAMP Certification?

The Federal Risk and Authorization Management Program was established in 2011 to give federal agencies a standardized way to assess and adopt cloud services. It grew out of the Federal Information Security Management Act, which took effect in 2002, and is often described as FISMA for the cloud. Before it existed, every agency evaluated every cloud vendor independently, and the duplication was the reason agencies avoided cloud adoption altogether.

Compliance, Certification, and Authority to Operate

These three terms describe different things, and conflating them is the single most common error in federal cloud procurement conversations.

Term What it is Who grants it Scope
FedRAMP compliance Meeting the security requirements Nobody grants it. It is a state of your system. Your own posture
FedRAMP Certification FedRAMP’s formal determination, following an independent assessment FedRAMP Reusable government-wide
Authority to Operate An agency’s decision to run a service inside its own system The agency, under NIST RMF That agency only

Compliance is what you achieve. A FedRAMP certification is what FedRAMP grants after an independent assessor validates that achievement. An ATO is what an agency grants when it decides to accept the residual risk of running your service. You can be compliant without being certified. You can be certified without holding a single agency’s ATO. Elevate’s overview of where FedRAMP sits among compliance certifications puts the effort in context.

CR26 formalized this. “FedRAMP Certification” is now the single official label for what the program grants, replacing “FedRAMP Authorization” and “FedRAMP Authorized.” The FedRAMP Authorization Act already defined a FedRAMP authorization as a certification by FedRAMP, so the new vocabulary aligns the language with the statute rather than changing any requirement. A service holding a FedRAMP certification is FedRAMP authorized for the purposes of meeting statutory and regulatory requirements.

Assess Once, Use Many

FedRAMP’s value proposition is reuse. Traditional FISMA authorization required separate approval from each agency. Under FedRAMP, a provider completes the assessment once, and every agency can draw on the same package. Agencies still make their own risk decision and still issue their own ATO, but they do not re-run the assessment.

The scale is real. The Government Accountability Office reported that the 24 CFO Act agencies collectively leveraged 1,478 FedRAMP authorizations as of April 2023, and that agency use of the program grew roughly 60 percent between 2019 and 2023.

FISMA and NIST SP 800-53 as Foundations

FedRAMP baselines derive from the NIST SP 800-53 control catalog, adapted for cloud environments with FedRAMP-defined parameters and additional cloud-specific requirements. Elevate’s primer on NIST SP 800-53 Rev 5 covers the catalog and why its revision matters for your baseline.

Cloud providers and their agency customers operate under a shared responsibility model, which defines which controls belong to the provider, which belong to the customer, and which are shared between them. That model is also the mechanism by which a provider on certified infrastructure inherits a substantial part of the work rather than rebuilding it.

The Distinction That Actually Matters in 2026

The old version of this comparison was ATO versus P-ATO. That comparison no longer has a subject.

The Provisional ATO Is Gone

The Joint Authorization Board issued Provisional Authorities to Operate. It was composed of chief information officers from the Department of Defense, the Department of Homeland Security, and the General Services Administration, and its P-ATO was widely treated as FedRAMP’s most rigorous outcome because it represented a government-wide risk review rather than a single agency’s.

The JAB no longer exists. The P-ATO is not an available outcome. Any guidance describing a choice between an agency ATO and a JAB P-ATO, or advising you to “start with a P-ATO at the Moderate baseline,” is describing a program that was dismantled. If a proposal, a vendor deck, or a competitor’s website still frames the decision that way, it has not been updated in over a year.

What the FedRAMP Board Does

Governance moved to the FedRAMP Board, established under the FedRAMP Authorization Act. The Board is the voting body for the program, works directly with the FedRAMP Director, and is composed of seven federal technology executives drawn from different agencies and selected by the Federal Chief Information Officer at the Office of Management and Budget.

The Program Management Office, housed at GSA, continues to support agencies and providers through the process and maintains the repository of certification packages that makes reuse possible.

Certification Is Government-Wide. The ATO Is Not.

Here is the correct version of the distinction the old article tried to draw. A FedRAMP certification is reusable across the federal government. It says the assessment was completed and reviewed to a defined standard. It does not say any particular agency has accepted the risk of running your service.

An ATO is agency-specific by definition. It is the decision of that agency’s Authorizing Official to operate your service inside their information system at a security category they determine under FIPS 199. A certification is the input. The ATO is the output, and it belongs to the agency. FedRAMP cannot accept risk on an agency’s behalf, which was true of the JAB and remains true of the Board.

Certification Classes Replaced Impact Levels

CR26 retired Low, Moderate, and High as names for FedRAMP certification baselines and replaced them with four Certification Classes. FedRAMP chose letters rather than numbers or the word “levels” specifically to end the chronic confusion with the Department of Defense Impact Level system, which uses similar language for a different framework.

Class A is a new time-limited tier. Class B covers the former Low and LI-SaaS baselines. Class C covers the former Moderate baseline. Class D covers the former High baseline. On the Rev5 path Class B carries roughly 156 controls, Class C roughly 323, and Class D roughly 410. On the FedRAMP 20x path there is no control count at all.

A Class Measures Assurance, Not Security

FedRAMP states directly that a Certification Class does not describe how secure a cloud service is. It describes the depth, frequency, and quality of the certification data a provider commits to supplying agencies, and FedRAMP instructs agencies not to treat a Class as a one for one replacement for an impact level.

Note the precise scope of that change, because getting it wrong will cost you an agency conversation. FIPS 199 impact levels still exist. Agencies still categorize their own information systems as low, moderate, or high. What changed is that a FedRAMP baseline is no longer named after one. Elevate’s guide to FedRAMP Classes and controls covers the mapping, and its breakdown of CR26 covers the dates that govern the transition.

Most providers land at Class C. GAO reported that approximately 76 percent of the authorizations agencies leveraged as of April 2023 were moderate-impact and 17 percent were high-impact, with the low baseline and its tailored SaaS variant together accounting for under 7 percent.

Rev5 or FedRAMP 20x: Which Certification Type to Pursue

The decision that replaced ATO versus P-ATO runs on two separate axes, and providers routinely collapse them into one.

Certification type is the first axis: FedRAMP 20x or Rev5. Certification path is the second: Program or Agency. It is the Program path, not the 20x type, that removes the agency sponsor requirement, and the Program path is available on Rev5 as well. A provider choosing the traditional type is not thereby forced into an agency partnership.

If this describes you Type Path Likely Class
Cloud-native, on certified infrastructure, strong automation FedRAMP 20x Program B or C
Traditional architecture, documentation-led compliance program Rev5 Program or Agency B or C
Entering the market with a qualifying prior audit Either Program only A, capped at two years
Mission-critical federal data Rev5 only Agency, sponsor required D
Selling to the Department of Defense at IL5 Rev5 Agency D, plus DoD FedRAMP+ controls

Read the table as a starting hypothesis, not an answer. Three points deserve emphasis.

FedRAMP 20x is no longer a pilot. CR26 formalized it as a certification type with its rules published in the consolidated ruleset. It replaces the document-centric model with Key Security Indicators, machine-readable evidence, and continuous validation, which suits a cloud-native provider and penalizes one whose compliance strength is documentation. Elevate’s overview of the FedRAMP 20x assessment model explains what assessors examine.

Rev5 remains the only route to Class D, and FedRAMP stops accepting new Rev5 certification applications on June 11, 2027. Existing Rev5 holders are never forced to migrate, but a provider that needs Rev5 and has not started is working against a closing window.

Defense work raises the bar again. DoD Impact Level 5 is not a FedRAMP Class. It is a DoD standard that builds on the FedRAMP baseline by adding DoD FedRAMP+ controls, stricter tenant isolation, and personnel restrictions limiting access to US citizens, nationals, or persons. The FedRAMP baseline is necessary but not sufficient for IL5. Note also that the DoD Cloud Computing Security Requirements Guide still describes IL5 as building on a FedRAMP High provisional authorization, which is pre-CR26 language for an instrument that no longer exists. Expect to translate.

For providers mapping FedRAMP against other frameworks, Elevate Consult maintains a crosswalk of FedRAMP and ISO to the NIST AI RMF.

The FedRAMP Certification Process

The steps changed less than the vocabulary, but two of them changed materially.

The Package: Schemas Replaced Templates

CR26 retired FedRAMP’s fixed template set and replaced it with JSON schemas. The System Security Plan is now a legacy artifact. It remains available, and some agencies including the Department of Defense still require it, but FedRAMP 20x moved away from it entirely. Implementation detail now lives in the Security Decision Record, while the public metadata that populates a Marketplace listing lives in the Certification Package Overview.

The underlying obligation survives the format change. An agency Authorizing Official still has to understand your architecture, your authorization boundary, your data flows, and how each requirement is actually implemented. What changed is that the artifact is machine validated on submission, which shortens review and reduces rework.

The Independent Assessment

An independent assessor evaluates your service and documents the methodology followed, the results, the risks corrected during testing, and the risks that remain. “3PAO” is retired vocabulary; the operative term is independent assessor. A firm that provided advisory services to prepare your documentation cannot also perform your assessment, and CR26 keeps that separation to preserve impartiality.

The engagement itself is shifting. Under CR26 the assessor’s role moves toward verification and validation of processes and outcomes rather than review of static documents, which rewards providers whose evidence is generated by systems rather than assembled by hand.

POA&M and Vulnerability Handling

Control CA-5 still requires a Plan of Action and Milestones documenting remediation for risks identified during assessment and monitoring, with a corresponding item for every risk in the assessment report.

The remediation model is changing. CR26 moves vulnerability management toward contextual detection and response, weighing exploitability, internet reachability, and potential adverse impact rather than applying a flat schedule by severity label. FedRAMP separated the rules into vulnerability detection and response on one side and vulnerability evaluation and reporting on the other, tied to the Known Exploited Vulnerabilities catalog maintained by the Cybersecurity and Infrastructure Security Agency. Build operations that can meet the tightest applicable federal timeline rather than a fixed day count.

Continuous Monitoring

Certification begins the obligation rather than ending it. The legacy model required monthly uploads of an updated POA&M, a system inventory, and raw vulnerability scan files.

CR26 moves continuous monitoring away from monthly artifact submission toward a longer reporting cycle with quarterly review, and makes it collaborative: you share ongoing certification data with all of your agency customers rather than reporting to a single authorizing body. Providers on the 20x path host their own package in their own trust center. Any playbook or vendor proposal built around monthly artifact submission is describing the outgoing model.

What Replaced FedRAMP Ready

FedRAMP Ready moved to Legacy status on July 28, 2026. There is no FedRAMP Readiness Assessment, no Readiness Assessment Report, and no Ready designation displayed on the Marketplace. Any proposal quoting one is pricing a retired program deliverable.

The underlying work did not disappear. Gap analysis, boundary definition, and control implementation still happen. What changed is that they are advisory and engineering work you scope yourself rather than a defined assessor deliverable with a market price attached. Prior audits also changed status. A qualifying prior audit, such as a SOC 2 Type 2 or GovRAMP, is no longer merely an accelerator, because the Class A on-ramp is unavailable without one.

What FedRAMP Certification Costs

No official figure exists, and the ranges circulating online do not survive contact with their source.

FedRAMP charges no program fee and publishes no standard cost estimates. The only government review of the question, published by the Government Accountability Office in January 2024, found that agencies and providers supplied estimated rather than tracked costs, that those estimates ranged from tens of thousands to millions of dollars, and that the variance came largely from participants counting different things. GAO recommended that the Office of Management and Budget begin collecting consistent cost data, because nobody had it, and it drew a deliberately non-generalizable sample it did not independently verify.

What actually sets your cost is your certification type, your target Class, the size of your authorization boundary, and how much security program you already have. Every one of those is decided before an assessor is engaged. To scope them against your actual architecture, talk to an Elevate advisor.

Conclusion

A FedRAMP certification is FedRAMP’s determination that your service completed an independent assessment to a defined standard. An ATO is an agency’s decision to run that service inside its own system. FedRAMP grants the first. Agencies grant the second. No amount of certification obliges any agency to issue an ATO, and no ATO makes you certified.

Everything else in this article follows from that. The Joint Authorization Board that issued Provisional Authorities to Operate is gone, replaced by the FedRAMP Board. Certification Classes A through D replaced the impact level labels, though FIPS 199 impact levels still govern how agencies categorize their own systems. The choice is now between certification types, Rev5 or FedRAMP 20x, and certification paths, Program or Agency, and it is the Program path rather than the 20x type that removes the sponsor requirement for every Class below D.

Elevate Consult works as an advisor rather than an assessor, which keeps that guidance independent of the firm that will eventually test your controls. Its FedRAMP advisory team maps type, path, Class, and boundary before budget is committed. To find out which path fits your service, talk to an Elevate advisor.

Key Takeaways

FedRAMP certification and an Authority to Operate are different instruments granted by different bodies, and CR26 made the distinction explicit.

FedRAMP issues the certification. The agency issues the ATO. A FedRAMP certification is reusable government-wide. An ATO is one agency’s decision to accept residual risk inside its own system. FedRAMP cannot accept risk on an agency’s behalf.

Compliance, certification, and ATO are three separate things. Compliance is a state you achieve. Certification is FedRAMP’s determination after an independent assessment. The ATO is the agency’s operating decision.

The JAB and the P-ATO are retired. Governance moved to the FedRAMP Board, seven federal technology executives selected by the Federal CIO. Any guidance framing a choice between an Agency ATO and a JAB P-ATO is obsolete.

Classes replaced impact levels as baseline names. Class B covers the former Low and LI-SaaS, Class C the former Moderate, Class D the former High. FIPS 199 impact levels still exist for agency categorization.

Type and path are separate decisions. Rev5 or FedRAMP 20x is the type. Program or Agency is the path. The Program path removes the sponsor, not the 20x type, and it is available on Rev5.

FedRAMP Ready is gone. Ready went Legacy on July 28, 2026. A qualifying prior audit now gates the Class A on-ramp rather than merely accelerating it.

No published price exists. GAO reported to Congress in January 2024 that cost estimates ranged from tens of thousands to millions of dollars and that actual cost data were limited.

FAQs

Q1. What is the difference between FedRAMP certification and an ATO?

FedRAMP issues a FedRAMP Certification after an independent assessor validates that a cloud service meets the applicable baseline. That certification is reusable across the federal government. An Authority to Operate is separate: it is a federal agency’s decision to run that service inside its own information system, issued by that agency’s Authorizing Official under the NIST Risk Management Framework. FedRAMP does not issue ATOs and cannot accept risk on an agency’s behalf. A certification is the input to an agency’s ATO decision, not a substitute for it.

Q2. What happened to the JAB and the Provisional ATO?

Both are retired. The Joint Authorization Board, which issued Provisional Authorities to Operate, no longer exists. Governance moved to the FedRAMP Board, established under the FedRAMP Authorization Act and composed of seven federal technology executives selected by the Federal Chief Information Officer. Under CR26 there is no P-ATO to pursue, and any guidance advising providers to choose between an agency ATO and a JAB P-ATO describes a program that has been dismantled.

Q3. What are the FedRAMP Certification Classes?

CR26 replaced the FIPS 199 impact level labels with four Certification Classes. Class A is a new time-limited tier requiring a qualifying prior audit. Class B covers the former Low and LI-SaaS baselines. Class C covers the former Moderate baseline. Class D covers the former High baseline. A Class describes the depth and frequency of assurance data a provider commits to supplying, not how secure the service is, and FedRAMP instructs agencies not to treat a Class as a one for one replacement for an impact level.

Q4. Should a cloud provider pursue Rev5 or FedRAMP 20x?

Rev5 is the traditional path built on NIST SP 800-53 control baselines and documented evidence, and it is the only route to Class D. FedRAMP 20x is the cloud-native type built on Key Security Indicators and machine-readable evidence, with no control count, and it is no longer a pilot. The cheaper type is the one matching how your service is already built. FedRAMP stops accepting new Rev5 certification applications on June 11, 2027, though existing Rev5 holders are never forced to migrate.

Q5. Do cloud providers still need an agency sponsor?

Not in most cases, and the reason is commonly misattributed. The Program path removes the agency sponsor requirement, allowing a qualifying provider to submit directly to FedRAMP for Classes A, B, and C. That path is available on the Rev5 type as well as FedRAMP 20x, so choosing the traditional type does not force an agency partnership. Class D is the exception: it has no Program path and no 20x path, so it still requires a federal agency partner under Rev5.