SOC 2 → FedRAMP Class A
Your SOC 2 Type II may be a FedRAMP Class A on-ramp.
FedRAMP vs SOC 2 is no longer an either/or. Run your SOC 2 Type II report against this checklist and know your gap to FedRAMP 20x Class A eligibility in an afternoon.
3
18
No Sponsor
No-cost
WHAT IS INSIDE
The three checks an assessor runs before your SOC 2 can carry a Class A submission.
CHECK 1
Scope and boundary alignment
Confirm the system described in your SOC 2 is the exact system you take federal. A boundary mismatch is the most common gap, and the on-ramp does not carry without it.
CHECK 2
Criteria coverage
See how many of the five Trust Services Criteria your report covers. The thinner your selection, the more you close later to meet federal requirements.
CHECK 3
Evidence that holds over time
Test whether your evidence is Type II, current, and collected continuously rather than at a point in time. Class A is heading toward always-on, machine-readable evidence.
ON TOP
KSIs and mandatory rules
Know the additions you take on beyond your SOC 2: the Key Security Indicators and the short list of mandatory rules specific to federal listing.
Three steps to your SOC 2 to Class A gap
Download the checklist
Enter your work email and get the SOC 2 to FedRAMP Class A Readiness Checklist as a print-and-tick document. No cost, no obligation.
Run your SOC 2 report against it
Tick every box your current SOC 2 Type II already satisfies across the three checks. Any unchecked box in Checks 1 to 3 is a gap you can see in an afternoon.
Book your no-cost review
Bring your ticked checklist to a review with our team. We work from the assessor side, so you get what actually gets checked, not theory, and a practical path to Class A.
Get the Checklist
Know your SOC 2 to Class A gap in an afternoon.
Enter your work email and we will send you the SOC 2 to FedRAMP Class A Readiness Checklist. Eighteen checkpoints, written from the assessor side of the table.
- The three checks an assessor runs first
- The additions you take on top of your SOC 2
- Key terms and the boundaries of the Class A on-ramp
- A direct next step to a no-cost review
BUILT FROM THE ASSESSOR SIDE
Written by people who sit on the grading side of the table.
This checklist is the field guide from Scott Moody, CISA, CRISC, who leads SOC 2 and IT risk assessment work at Elevate. The three checks are the same ones he runs before he will call a SOC 2 program ready to carry a federal listing.
Elevate’s FedRAMP practice is led by Angela Polania, who holds CISA, CISM, and CRISC. Together the team works both sides of the SOC 2 to FedRAMP bridge, so the guidance reflects what an assessor actually checks, not a generic reading of the rules.
This is a working aid, not an official FedRAMP submission and not legal or compliance advice. FedRAMP 20x is a developing program, so confirm the specifics against the current ruleset with your advisor.
+18
+500
10%
+500
The door that was closed just opened. First movers get listed first.
Get the checklist, run your SOC 2 against it, and let our team tell you exactly where your gap to Class A is, and how to close it.
QUESTIONS
FedRAMP vs SOC 2: frequently asked questions
What is the difference between FedRAMP and SOC 2?
SOC 2 is a commercial attestation, performed by a CPA firm against the AICPA Trust Services Criteria, that reports on how a service organization’s controls are designed and operating. FedRAMP is a US government program that authorizes cloud services for federal use. They serve different audiences, but they overlap: under the FedRAMP 20x Class A on-ramp, a mature commercial cloud provider with a recent SOC 2 Type II can use that work to move toward a FedRAMP Marketplace listing without an agency sponsor.
Does FedRAMP require a SOC 2?
FedRAMP does not universally require a SOC 2. However, the FedRAMP 20x Class A path is designed for providers that already hold a recent qualifying assessment such as a SOC 2 Type II. If you have invested in a strong SOC 2, that investment may now support a more direct path into the FedRAMP Marketplace than the traditional sponsored route.
Can a SOC 2 Type II get me into FedRAMP Class A?
A SOC 2 Type II can qualify a provider for the FedRAMP 20x Class A path, but a SOC 2 alone does not list you. Class A adds a set of Key Security Indicators and a short list of mandatory rules specific to federal listing, on top of your report. For a provider with a clean, current, well-scoped SOC 2, the gap is typically a targeted addition, not a second audit cycle.
Is a SOC 2 alone enough for FedRAMP Class A?
No. A SOC 2 Type II is the foundation, but Class A requires you to satisfy Key Security Indicators and additional mandatory rules on top of the report. The Elevate SOC 2 to FedRAMP Class A Readiness Checklist walks the three things an assessor checks first, scope and boundary alignment, criteria coverage, and evidence that holds over time, then flags the additions you take on beyond your SOC 2.
What does the SOC 2 to FedRAMP Class A checklist cover?
The checklist covers three assessor checks plus the additions on top. Check one is scope and boundary alignment: the system in your SOC 2 must equal the system you take federal. Check two is criteria coverage: how many of the five Trust Services Criteria your report includes. Check three is evidence that holds over time: Type II, current, and collected continuously rather than at a point in time. It then flags the Key Security Indicators and mandatory rules you add on top of the report.