Skip to main content

FedRAMP 20x

FedRAMP 20x is the Federal Risk and Authorization Management Program's next-generation authorization framework. It replaces hundreds of narrative NIST 800-53 control descriptions with Key Security Indicators (KSIs) — measurable security outcomes that cloud service providers (CSPs) must prove through automated, machine-readable evidence rather than point-in-time paperwork audits.

Why it was created

OMB Memorandum M-24-15 (July 2024) replaced prior FedRAMP policy with a vision centered on new authorization paths, automation, and government-wide cloud adoption — aiming to cut the time and cost of getting a cloud service authorized for federal use.

Five Core Principles

  1. Transparency — honest security information without arbitrary compliance bars
  2. Flexibility — engineering decisions producing secure outcomes appropriate to the provider
  3. Accountability — continuous enforcement, monitoring, and reporting instead of point-in-time audits
  4. Accuracy — assess the effectiveness of decisions, not just the validity of each decision on paper
  5. Automatic Validation — status and outcomes are enforced automatically wherever possible

Key Security Indicators (KSIs)

63 KSIs are organized across 12 themes:

ThemeCountFocus
Cross-Cutting (CSX)3Implementation summaries, scope, priority ordering
Authorization by FedRAMP (AFR)10Vulnerability disclosure, scanning, POA&M, continuous monitoring
Cloud Native Architecture (CNA)8Network segmentation, DDoS protection, API security
Change Management (CMT)4Change control, immutable infrastructure
Identity and Access Management (IAM)7Phishing-resistant MFA, least privilege, JIT access
Monitoring, Logging, Auditing (MLA)5Audit logs, SIEM integration, config evaluation
Service Configuration (SVC)8Encryption, FIPS cryptography, secrets management
Recovery Planning (RPL)4RTO/RPO, backup procedures, recovery testing
Policy and Inventory (PIY)5Asset inventory, SDLC security
Incident Response (INR)3Response plans, post-incident reviews
Cybersecurity Education (CED)4Training programs across roles
Supply Chain Risk (SCR)2Risk assessments, third-party monitoring

Evidence and automation:

  • Automated validation must cover at least 70% of KSIs (Phase 2 pilot requirement); every KSI must be addressed in both human-readable and machine-readable formats
  • Machine-based KSI validation must run at least every 3 days for moderate-impact systems; non-machine KSIs require validation at least every 3 months
  • Three validation buckets: fully automatable (e.g. encryption, MFA enforcement via config/security-hub tooling), process & documentation (e.g. training records, executive attestation), and hybrid (e.g. vulnerability detection requiring both scanning and remediation SLAs)
  • In the Phase 2 pilot: 56 KSIs for the Low impact baseline, 61 for the Moderate impact baseline

Certification Classes

  • Class A — mature security programs entering the federal marketplace; minimal upfront requirements
  • Class B — small-scale or light-use services with limited ongoing burden
  • Class C — common enterprise services likely used across agencies
  • Class D — future addition (Phase 4, estimated FY27 Q1-Q2), covering High-impact systems

Rollout Phases (2025-2027)

  • Phase 1 (completed FY25) — Low-impact pilot, 26 submissions, 13 reviews completed
  • Phase 2 (completed FY26 Q1-Q2) — Moderate-impact pilot, 14 qualifying submissions
  • Phase 3 (active FY26 Q3-Q4) — wide-scale adoption; submission pipeline opens July 2026
  • Phase 4 (estimated FY27) — Class D (High-impact) pilot
  • Phase 5 (estimated FY27) — end of life for new Rev5 authorizations (June 11, 2027)

How it differs from traditional FedRAMP

Traditional FedRAMP evaluates compliance against a uniform, government-wide set of controls with binary "secure/not secure" verdicts, assessed largely through narrative documentation at a point in time. FedRAMP 20x instead lets providers make context-dependent engineering decisions appropriate to their architecture, and continuously proves those decisions work via automated, machine-readable evidence — shifting from "did you document a plan" to "can you prove the control is operating right now."

  • Compliances — SOC 2, PCI-DSS, and other compliance frameworks