Skip to main content

Elevate

FedRAMP Compliance: What It Is and What Changed Under CR26

FedRAMP compliance is how a cloud service earns and keeps the right to handle federal data, and in 2026 the way you demonstrate it changed more than it has in a decade. The Federal Risk and Authorization Management Program has standardized cloud security assessment and authorization for the U.S. government since 2011, but the 2026 consolidated rules, known as CR26, retired the document templates that defined the old process, replaced them with machine-readable JSON, and collapsed the separate authorization paths into a single FedRAMP Authorized designation. If you are evaluating FedRAMP for the first time or you authorized under the previous model and need to understand the transition, this guide explains what FedRAMP compliance means now, who needs it, and how the program actually works after CR26.

One thing to set straight up front, because most published material still describes the old model: the System Security Plan as a standalone document, the Joint Authorization Board, and the provider Plan of Action and Milestones are no longer how FedRAMP works. Those are legacy concepts from before CR26. This guide describes the current program and notes where the transition still matters for organizations authorized under the earlier baseline.

What FedRAMP Compliance Means

FedRAMP compliance means a cloud service provider has proven, through independent assessment, that its service meets the federal government’s security requirements, and that it maintains that security continuously. The program exists to solve a specific problem: without it, every federal agency would separately assess the same cloud service, duplicating cost and effort. FedRAMP replaces that with a “do once, use many times” model. One authorization, reusable across agencies.

The Program and Its Purpose

FedRAMP was created in 2011 as a government-wide program to standardize security assessment, authorization, and continuous monitoring for cloud products and services. It sits within the General Services Administration and applies to cloud offerings that federal agencies use to store, process, or transmit government data. The security requirements have historically drawn from NIST Special Publication 800-53, the federal catalog of security and privacy controls, tailored for cloud environments.

The value proposition has always been reuse. When a cloud service is authorized, its security package becomes available to other agencies, which can accept the existing authorization rather than starting over. For providers, that turns a single authorization into repeatable access to the federal market. For agencies, it turns a slow, custom security review into a faster decision built on work already done.

What Changed in 2026 Under CR26

CR26 is the consolidated FedRAMP rule set that took effect in 2026, and it is now the single source of truth for what the program requires. The governing principle is explicit: if a requirement is not in the consolidated rules, it is not required. That ends the era of scattered guidance documents and informal expectations. [Sure]

Three changes matter most for understanding compliance today. First, FedRAMP retired its document templates. The System Security Plan, the Security Assessment Report, and the other fixed templates are gone, replaced by JSON schemas that carry the same information as structured, machine-readable data. Second, the program consolidated its authorization types into one FedRAMP Authorized designation, ending the distinction between board-led and agency-led paths. Third, the consolidated rule set is a stable baseline. According to FedRAMP’s own working group, CR26 is intended to hold through December 31, 2028, with only minor changes expected absent an urgent security directive. That stability matters, because it means an organization investing in CR26 alignment is building against a known target rather than a moving one. [Likely]

Who Governs FedRAMP Now

FedRAMP is administered within the General Services Administration, and its requirements are published as an open, versioned rule set rather than locked behind internal review boards. The practical effect for a provider is that the requirements are readable, testable, and consistent. There is no separate board negotiating a different standard for high-profile services. Every service is measured against the same consolidated rules, and the authorization decision rests with the federal agency that sponsors or accepts the service.

Because the rules are versioned, the specific counts and structures inside them can change at a version bump. The current framework organizes requirements around Key Security Indicators, and the exact number is tied to the ruleset version in force at assessment. Any provider or advisor should confirm the current KSI count against the published rules at the time of assessment rather than relying on a number quoted in an article. [Sure]

Who Needs FedRAMP Compliance

FedRAMP compliance reaches further than the cloud providers who sell directly to agencies. It pulls in the agencies themselves and the contractors in the federal supply chain.

Who What triggers the requirement What they must do
Cloud service providers Selling a cloud service to a federal agency Achieve and maintain FedRAMP authorization for the offering
Federal agencies Using cloud to handle federal data Use only authorized services; accept or issue authorizations
Defense contractors Handling covered defense information in the cloud Ensure their cloud meets the FedRAMP Moderate baseline or equivalency
State and local government Handling federal data or seeking a security signal Often require FedRAMP authorization from vendors

The table shows why FedRAMP functions as a market gate rather than a niche certification. An authorized service is a prerequisite to sell cloud to federal agencies, and the requirement flows downstream to anyone who touches federal data through that service.

Cloud Service Providers

Any provider that offers Software as a Service, Infrastructure as a Service, or Platform as a Service to federal agencies needs FedRAMP authorization for that offering. Authorization attaches to the specific service, not to the company as a whole, which means a provider with several products authorizes each one that handles federal data. Foreign-owned providers face the same requirement when serving U.S. federal customers.

A point worth clearing up, because it blocks some providers unnecessarily: registration in SAM.gov and a Unique Entity Identifier are not required to begin the FedRAMP process. An agency may want registration in place before it buys, but neither is a gate to starting. [Sure]

Federal Agencies

Federal agencies may only use cloud services that carry FedRAMP authorization for the data they handle. This is what makes the reuse model work. When one agency authorizes a service, another can review the same security package and accept it for its own use, weighing how the service fits its risk profile. The agency that accepts a service owns the authorization decision.

Defense Contractors and the Supply Chain

Defense contractors sit under an additional layer. DFARS clause 252.204-7012 requires that any cloud service a contractor uses to handle covered defense information meets the FedRAMP Moderate baseline or a recognized equivalency. The responsibility falls on the contractor, not the cloud provider, to confirm and document that its cloud meets the standard. Using an already-authorized service satisfies this cleanly; using an equivalent-but-not-authorized service adds a documentation burden the contractor has to carry.

Equivalency itself is more nuanced than it looks, and the standard it maps to has been affected by the CR26 restructuring. Because the details determine whether a contractor is actually compliant, that topic deserves its own treatment rather than a summary here. Contractors weighing this should read the dedicated analysis of FedRAMP Rev 5 Certification and Transition Strategy 2026 and confirm the current equivalency position with a qualified advisor before relying on it.

FedRAMP Impact Levels and the CR26 Control Model

FedRAMP sorts cloud services into impact levels, and the level sets the depth of security required. Understanding the levels is the first step in scoping any FedRAMP compliance effort.

FIPS 199 Impact Levels

The impact level comes from Federal Information Processing Standard 199, which rates a system by the damage a security breach would cause across three properties: confidentiality, the protection of information from unauthorized access; integrity, the protection of information from unauthorized change; and availability, reliable access to information when needed.

Impact level Breach consequence Typical systems
Low Limited adverse effect Public information, simple applications
Moderate Serious adverse effect Most federal cloud services and CUI
High Severe or catastrophic effect Law enforcement, health, emergency, financial

Moderate is the most common level, because it covers the controlled unclassified information that most federal work involves. High is reserved for systems where a failure could risk lives or cause severe national harm. The table maps the levels to the kinds of systems that land in each, but the formal categorization is a documented analysis of confidentiality, integrity, and availability, not a guess based on industry.

The Legacy Rev 5 Baselines

Under the previous model, still known as Rev 5, each impact level mapped to a fixed baseline of NIST 800-53 controls, and the baselines ran from roughly a hundred controls at Low to several hundred at Moderate and High. Organizations authorized under Rev 5 implemented and documented every applicable control in that baseline. Those Rev 5 authorizations remain valid through the transition period; existing authorizations are expected to remain active until at least December 31, 2028. If your organization is already authorized, the Rev 5 model is still your operating reality until you transition. [Sure]

The CR26 Model: Key Security Indicators and JSON Evidence

CR26 reframes how compliance is expressed. Instead of a long baseline of individual controls documented in templates, the current model organizes security expectations around Key Security Indicators grouped into families, and it captures evidence as structured JSON rather than narrative documents. The standalone System Security Plan is gone. Its content now splits into two artifacts: the Certification Package Overview, which holds public-facing metadata and populates the Marketplace listing, and the Security Decision Record, which carries the implementation detail assessed against the indicators and can sit behind authentication. Submissions are JSON, with room for descriptive text inside structured fields. [Sure]

This is the single biggest practical shift for anyone approaching FedRAMP fresh in 2026. The work is no longer assembling a stack of documents to a template. It is producing structured, machine-readable evidence against a defined set of indicators, which is why tooling and automation now carry more weight in a well-run authorization. The connection between structured evidence and time saved is covered in how OSCAL and automation save time in FedRAMP.

How FedRAMP Authorization Works in 2026

FedRAMP compliance under CR26 is granted through the 20x model, the automation-first pathway that replaced the old template-and-review cycle. The path an organization takes depends on where it is starting from.

The 20x Pathway and Classes A, B, and C

The 20x model introduces authorization classes. Class A is an entry path aimed at agency-pilot market entry. It is temporary by design, cannot be held longer than two years, and carries a prerequisite: the organization must already hold a qualifying prior audit, such as a FedRAMP Rev 5 authorization, SOC 2 Type 2, or GovRAMP at any impact level. Stacking unrelated audits does not satisfy the prerequisite. Class A is a stepping stone, not a destination; an organization that shows no progress toward a full authorization within that window is removed from the Marketplace. Classes B and C, the fuller authorization paths, opened for new applications on August 31, 2026. [Sure]

The Evidence Package and the Marketplace

Once assessed, a service’s evidence lives in the CR26 artifacts described earlier. The Certification Package Overview carries the public metadata that populates the FedRAMP Marketplace, the government’s directory of authorized services. A Marketplace listing is what lets other agencies find and reuse an authorization, so the listing is not a formality; it is the mechanism that turns one authorization into repeated federal access.

Continuous Monitoring and Vulnerability Response

FedRAMP compliance does not end at authorization. It requires continuous monitoring, and CR26 modernized how that works. The provider Plan of Action and Milestones, the old running list of open weaknesses, is gone. In its place, CR26 uses an Accepted Weaknesses model paired with Vulnerability Detection and Response and Vulnerability Evaluation and Reporting. Remediation timeframes are set by a matrix that weighs potential agency impact against exploitability and reachability, and those timeframes are version-sensitive to the ruleset in force. The shift favors continuous, automated detection over periodic manual scanning and reporting. What quality continuous monitoring looks like in practice is detailed in FedRAMP ConMon deliverables after authorization.

FedRAMP Compared to CMMC and NIST 800-171

Defense contractors often confuse FedRAMP with the other federal cybersecurity frameworks, because the requirements overlap and sometimes apply at the same time. They certify different things.

Framework What it certifies Who needs it
FedRAMP A specific cloud service Providers selling cloud to federal agencies
CMMC Level 2 An organization handling CUI Defense contractors and subcontractors
NIST 800-171 The control set behind CMMC Contractors handling CUI, self-attested or assessed

The distinction is service versus organization. FedRAMP authorizes a cloud offering. The Cybersecurity Maturity Model Certification certifies that an organization protects controlled unclassified information, whether that organization runs on-premises, hybrid, or in the cloud. CMMC Level 2 aligns to the 110 requirements of NIST 800-171. A defense contractor that delivers a cloud service to the government can need both: FedRAMP for the service, CMMC for the organization. They stack, they do not substitute for each other.

For a contractor, the practical implication is that clearing one framework does not clear the others. The timelines and obligations differ, and CMMC in particular is on its own regulatory schedule that a FedRAMP authorization does nothing to satisfy.

How to Approach FedRAMP Compliance

The most expensive FedRAMP compliance mistakes happen before any assessment starts, when an organization commits to a path or a scope that does not fit its situation. Two decisions front-load most of the risk.

Scope and Readiness First

Before engaging an assessor, an organization needs a clear-eyed view of what its service actually is, where its authorization boundary sits, and how far its current security posture is from the requirements. A readiness or gap assessment produces that view: it maps the current state against the consolidated rules, surfaces the gaps, and turns them into a prioritized plan with a realistic timeline. Skipping this step is what turns a clean authorization into a delayed one, because gaps that surface during assessment cost far more to fix than gaps found before it.

How to Choose the Right Path

The second decision is which path fits. An organization already authorized under Rev 5 is managing a transition, not a fresh start, and its route through CR26 differs from a provider entering for the first time through 20x. A first-time entrant has to weigh whether it meets the Class A prerequisite or should target Classes B or C directly. These are not interchangeable, and the wrong choice wastes months. Elevate helps cloud providers and federal contractors map their situation to the right path and prepare against the current rules, so the assessment tests evidence that already exists. To scope your position, book a readiness call with an Elevate advisor.

Conclusion

FedRAMP compliance in 2026 is the same idea it has always been, proving a cloud service meets federal security requirements and maintaining that security over time, delivered through a process that CR26 rebuilt from the ground up. The templates are gone, the authorization paths are consolidated into one designation, and the evidence is structured JSON assessed against Key Security Indicators. For organizations authorized under Rev 5, the previous model still governs through a transition period that runs to at least the end of 2028. For new entrants, the 20x pathway and its authorization classes are the way in.

The organizations that navigate this well are the ones that scope honestly, choose the right path for where they are starting, and treat the consolidated rules as the single source of truth rather than trusting older material that still describes the retired model. To map your service or your contract obligations against the current requirements, book a readiness call with an Elevate advisor or explore Elevate’s FedRAMP advisory services.

Key Takeaways

FedRAMP compliance is a market gate for federal cloud, and CR26 changed how you demonstrate it in ways that make most older guidance inaccurate.

  • FedRAMP compliance proves a cloud service meets federal security requirements: authorization attaches to the specific service, not the whole company, and it is reusable across agencies once granted.
  • CR26 retired the templates and the SSP: evidence is now structured JSON split into a public Certification Package Overview and a detailed Security Decision Record, assessed against Key Security Indicators.
  • There is one FedRAMP Authorized designation: the separate board-led and agency-led paths are gone, and the consolidated rules are the single source of truth, stable through at least the end of 2028.
  • Rev 5 authorizations remain valid through the transition: organizations authorized under the previous model keep operating under it, with existing authorizations expected to stay active until at least December 31, 2028.
  • FedRAMP, CMMC, and NIST 800-171 stack, they do not substitute: FedRAMP authorizes a cloud service, CMMC certifies an organization handling CUI, and a defense contractor can need both.

FAQs

Q1. What is FedRAMP compliance in simple terms? FedRAMP compliance means a cloud service has proven, through independent assessment, that it meets the U.S. government’s security requirements for handling federal data, and that it maintains that security continuously. Once a service is authorized, federal agencies can use it, and other agencies can reuse the existing authorization instead of assessing the service again. It is the standard gate for selling cloud services to the federal government.

Q2. Is FedRAMP compliance mandatory? For any cloud service that a federal agency uses to store, process, or transmit federal data, yes. Agencies may only use authorized services. Defense contractors face a related requirement under DFARS 252.204-7012, which obligates them to ensure their cloud meets the FedRAMP Moderate baseline or a recognized equivalency, with the contractor responsible for confirming it.

Q3. What changed in FedRAMP in 2026? The 2026 consolidated rules, known as CR26, retired FedRAMP’s document templates and replaced them with machine-readable JSON, eliminated the standalone System Security Plan in favor of a Certification Package Overview and a Security Decision Record, and consolidated the separate authorization paths into a single FedRAMP Authorized designation. The provider Plan of Action and Milestones was also replaced by an Accepted Weaknesses model with continuous vulnerability detection and response.

Q4. What are the FedRAMP impact levels? FedRAMP has three impact levels set by FIPS 199: Low for limited breach impact, Moderate for serious impact, and High for severe or catastrophic impact. Moderate is the most common because it covers the controlled unclassified information involved in most federal work. The level determines the depth of security required for authorization.

Q5. Do defense contractors need both FedRAMP and CMMC? They can. FedRAMP authorizes a specific cloud service, while CMMC certifies that an organization handling controlled unclassified information protects it, aligned to the 110 requirements of NIST 800-171. A defense contractor that provides a cloud service to the government may need FedRAMP for the service and CMMC for the organization. Clearing one does not satisfy the other.