FedRAMP is the one framework in a vendor review where the public source is better than anything the vendor can send you. The Marketplace publishes a machine-readable data file with every cloud service offering, its status, its impact level, its authorising agency and its assessor, and CertReports mirrors it every night as registry-verified rows. In 2026 the programme rewrote its rulebook. The Consolidated Rules for 2026 took effect on 4 July 2026, "FedRAMP Certified" replaced "FedRAMP Authorized" as the official label, and "Ready" became a legacy status on 28 July 2026. This article explains the statuses as they stand, the classes that replaced impact levels, and what 20x changes for a buyer.
- 4 Jul 2026
- Consolidated Rules for 2026 in force
- Enforcement for all providers from 1 January 2027
- 561
- FedRAMP rows in the CertReports index
- All registry-verified from the Marketplace file, 18 September 2026
- 502
- services listed on the Marketplace in early 2026
- Knox Systems, FedRAMP Marketplace explained
The 2026 vocabulary
The programme adopted "certification" because the underlying statute defines a FedRAMP authorization as a certification that a cloud product has completed the FedRAMP process, and because "authorization" was routinely confused with an agency’s own authority to operate. A provider that was FedRAMP Authorized in June became FedRAMP Certified in July with the same controls and the same boundary. Impact levels became certification classes, the system security plan became a certification package overview and security decision record, and continuous monitoring became ongoing certification, with loss of certification as the consequence for lapses.
The law defines a "FedRAMP authorization" as "a certification that a cloud computing product or service has completed a FedRAMP authorization process."
| Before 4 July 2026 | From 4 July 2026 | What it means for a buyer |
|---|---|---|
| FedRAMP Authorized | FedRAMP Certified | Same evidence; the strongest public signal a vendor can show for US public-sector use |
| In Process | In Process | Working with an agency toward certification; an intent, not a certification |
| FedRAMP Ready | Legacy since 28 July 2026 | A point-in-time readiness assessment; being phased out |
| Impact level Low, Moderate, High | Certification classes A to D | Class sets the control baseline; check it matches your data |
| Rev5 authorization | Rev5 certification, new ones accepted until 11 June 2027 | Existing Rev5 certifications run to at least 31 December 2028 |
Reading the Marketplace file
The Marketplace data file carries one row per cloud service offering. The fields a buyer reads first are the status, the class or impact level, the certifying or authorising agency, the third-party assessment organisation (3PAO), and the certification date. CertReports records all of them verbatim and links the agency and the assessor to their pages. The status text on a row is whatever the Marketplace published at the last sync; during the transition some rows still carry legacy wording and the index shows it as published rather than rewriting it.
Classes and control baselines
| Class (2026) | Former level | Controls (Rev5 baseline) | Typical offerings |
|---|---|---|---|
| A | Li-SaaS | Subset of Low | Collaboration tools, forms |
| B | Low | 156 | Public-facing and low-sensitivity SaaS |
| C | Moderate | 323 | The bulk of the Marketplace |
| D | High | 410 | Major cloud platforms, some SaaS |
Control counts follow the Rev5 baselines. A class C certification does not cover class D data.
What 20x changes
- Key Security Indicators replace much of the narrative package; vendors publish machine-readable evidence that assessors and agencies validate continuously.
- 20x moved from pilots to a permanent programme in 2026, with the submission pipeline opening in the final quarter of the federal fiscal year.
- The "Ready" designation lost its purpose once certification could be reached faster, which is why it became legacy in July 2026.
- The Marketplace stays the source of truth. CertReports keeps recording the status, class, agency and assessor exactly as the data file states them.
- Rev5 remains the control baseline for existing certifications; 20x changes how evidence is produced and checked, not what the controls are.
FedRAMP 20x is a comprehensive overhaul of the program that will deliver a new approach to authorization based on automation, transparency, and continuous validation.
How to read a FedRAMP row on CertReports
- 1
Status and class
Both come from the data file. Certified is the bar; In Process is intent. A class C certification does not cover class D data.
- 2
Agency and assessor
The 3PAO is the assessor; the agency is who accepted the risk. Both link to their pages in the index.
- 3
The service, not the company
FedRAMP certifies cloud service offerings. Confirm the product on your order form is the one listed.
- 4
Date
The row shows when the Marketplace last listed the status. Browse everything on the FedRAMP registry mirror.
Timeline to keep on file
| Date | What happens |
|---|---|
| 4 July 2026 | Consolidated Rules for 2026 take effect; Certified replaces Authorized |
| 28 July 2026 | FedRAMP Ready becomes a legacy status |
| 1 January 2027 | Enforcement of the 2026 rules for all providers |
| 11 June 2027 | FedRAMP stops accepting new Rev5 certifications |
| 31 December 2028 | Earliest expiry of existing Rev5 certifications |
Vocabulary on CertReports
The index records the Marketplace status as published, never rewritten. Where a row still says "Authorized" it is because the data file says so; the framework note on every FedRAMP row explains the 2026 change.
People also ask
Is it FedRAMP Authorized or FedRAMP Certified?
Since 4 July 2026 the official label is FedRAMP Certified under the Consolidated Rules for 2026. A provider that was Authorized before that date became Certified with the same controls and boundary.
What happened to FedRAMP Ready?
It became a legacy status on 28 July 2026. It was a point-in-time readiness assessment by a 3PAO, and 20x made it unnecessary by shortening the path to certification.
What does In Process mean on the FedRAMP Marketplace?
The provider is working with an agency toward certification and has a target date. It signals intent and an engaged assessor; it is not a certification.
What is the difference between FedRAMP Moderate and High?
Moderate (class C) covers most federal data with a 323-control Rev5 baseline; High (class D) covers data whose loss would be severe or catastrophic with 410 controls. A Moderate certification does not cover High data.
How many services are FedRAMP certified?
The Marketplace listed 502 services in early 2026 according to Knox Systems; the CertReports index carried 561 FedRAMP rows on 18 September 2026 including In Process and legacy entries.
How can I verify a vendor’s FedRAMP status?
Search the Marketplace or the CertReports FedRAMP registry mirror, which is refreshed nightly from the official data file. Check the status, the class, the agency, the assessor and that the listed offering is the product you are buying.
CertReports Research · Index and methodology
Notes from the team that runs the nightly registry syncs, the snapshot pipeline and the state resolver. Every figure quoted is reproducible from the index on the date given.
Read next on CertReports
You might also like
Where PCI DSS evidence actually lives: the Visa and Mastercard registries
CertReports Research · 3 Sep 2026 · 10 min read
The state of public compliance evidence in 2026: what 3,000 vendors actually publish
CertReports Research · 18 Sep 2026 · 12 min read
Three quarters of the Visa registry is not a PCI DSS validation
CertReports Research · 17 Sep 2026 · 10 min read