Skip to content
bg-fedramp-assessment-hero(1) bg-fedramp-assessment-hero(1)
Assessment

FedRAMP Assessments for Cloud Service Providers

FedRAMP accepts assessments only from Recognized independent assessment services, formerly known as 3PAOs.

Sera Brynn has performed FedRAMP assessments since 2017.

FedRAMP Assessment Overview

FedRAMP Certification

Under the Consolidated Rules for 2026, FedRAMP Certification is issued two ways. Program Certification comes directly from FedRAMP with no agency sponsor. Agency Certification follows the legacy route, where a federal agency authorizes the service first, then sponsors it.

Three dates drive most buying decisions:

  • July 28, 2026. FedRAMP Ready went legacy. No new submissions accepted. Class A Certification replaces it.
  • January 1, 2027. The 2026 rules become mandatory for every provider holding or pursuing FedRAMP Certification.
  • June 11, 2027. FedRAMP stops accepting applications for new Rev5 Certifications.

If your federal opportunity depends on a Rev5 Certification, the application window closes in under a year. If you are entering the market fresh, FedRAMP 20x Class A is now the shortest credible path.

developing-new-system-2026-01-08-00-16-09-utc 1(1) developing-new-system-2026-01-08-00-16-09-utc 1(1)

Certification Types and Classes

FedRAMP Certification Types

FedRAMP 20x is the modern path. Providers define Key Security Indicators, prove outcomes with living evidence, and pursue certification directly from FedRAMP without an agency sponsor.

FedRAMP Rev5 is the legacy path, built on NIST SP 800-53 control baselines and, in most cases, an agency sponsor. New applications close June 11, 2027.

Program Certifications are limited to one type. Providers must choose 20x or Rev5, not both.

Certification Classes

FedRAMP Classes A through D scale progressively. Each class adds assurance, federal process maturity, automation, and cost.

  • Class A. Entry point for commercial products with a mature security program and SOC 2 Type II. Replaces FedRAMP Ready.
  • Class B. Broader assurance for most Low security objectives.
  • Class C. Covers most Low and Moderate security objectives.
  • Class D. Broadest coverage across agency use cases. Requires an agency sponsor.

 

 Certification Paths by Type and Class

Your path is largely determined by choices you have already made. If you pursue 20x, you are on the Program Certification path.
If you already have an agency sponsor for Rev5, you are on the Agency Certification path. 

 

Certification Path
Description
Program Certification

FedRAMP certifies the service directly. No agency sponsor required. Primarily available for FedRAMP 20x. 

Agency Certification

A federal agency authorizes the service first, then sponsors it for FedRAMP Certification. Rev5 only. 

Type
Class
Program Certification
Agency Certification
20x

Class A

Required
Unavailable
20x

Class B

Required

Unavailable

20x

Class C

Required

Unavailable

20x

Class D

Coming 2027

Unavailable

Rev 5
Class A
Unavailable
Unavailable
Rev 5
Class B
Limited
Generally required
Rev 5
Class C
Limited
Generally required
Rev 5
Class D
Unavailable
Required

 

 Limited Rev5 Program Certification pipelines opened August 10, 2026 for providers that lost a sponsor or completed a FedRAMP Ready assessment between January 2025 and March 2026. Eligibility must be confirmed by FedRAMP before submission. Ask us whether you qualify. 

FedRAMP Assessment Services

FedRAMP accepts independent assessments only from FedRAMP Recognized assessors.
Sera Brynn performs the full range across both certification types.

Initial Certification Assessment 

Independent verification and validation of your security implementation ahead of a FedRAMP Certification decision. Under 20x, this means testing both the security capability and the machinery that measures it. 

FedRAMP Penetration Testing 

Adversarial testing of your cloud infrastructure and applications to surface vulnerabilities that threaten confidentiality, integrity, or availability.

Ongoing Certification Assessment 

Periodic independent assessment confirming controls and practices remain effective as your service, architecture, and threat profile change. 

Continuous Monitoring Support

Validation that your automated checks run at the stated cadence, cover full scope, and produce reproducible results. Living evidence, not screenshots. 

FedRAMP Assessment & Certification Process

The specific path varies by certification type, class, and whether you pursue Program or Agency Certification.
Engage an assessor early. Scope decisions made in week one drive cost across the entire engagement.

1
Scoping and Readiness 

We define the FedRAMP boundary with you, confirm your certification type and class, and identify gaps between your current security program and the 2026 rules before testing begins.  

2
Assessment Planning 

We align on architecture, validation methods, evidence sources, and schedule. FedRAMP no longer issues templates or requires a separate Security Assessment Plan under Program Certification, so we build the plan around your environment and tooling. 

3
Verification and Validation 

We test every applicable FedRAMP rule and validate the practices behind each Key Security Indicator: where source data originates, how it is transformed, what produces the result, and what happens when validation fails. 

4
Independent Assessment Delivery 

We deliver our findings to you for your Security Decision Record. Under Program Certification, assessors no longer issue an overall recommendation. FedRAMP makes the certification decision and we participate in FedRAMP's review to explain our process, findings, and concerns. 

5
Ongoing Assurance

Certification is a continuing commitment. We support periodic assessment and continuous validation so your posture holds up between reviews. 

Abstract White Flow Wave Backgrounds 07 1(1) Abstract White Flow Wave Backgrounds 07 1(1)

Why Sera Brynn For FedRAMP Assessment

Authorized to perform independent assessments of cloud services pursuing FedRAMP Certification. Formerly designated a FedRAMP 3PAO. 

The 2026 rules now require assessors to actually perform assessments to retain FedRAMP Recognition. Sera Brynn has been assessing cloud services for nearly a decade, across both legacy and modern paths. 

Technical depth to test automation, not just read dashboards. Code review, API testing, and cloud architecture analysis where the evidence demands it.

FedRAMP, GovRAMP, and CMMC under one roof, so overlapping federal requirements are assessed by one team that understands all three. 

Partnering with Sera Brynn

Lisa (3) Lisa (3)

Long Standing FedRAMP 3PAO Experience

Transparent "No Surprises" Investment 
Highly Credentialed Assessment Team 
Approachable and Collaborative Assessors
Cost Efficient Assessment Execution

Frequently Asked Questions

Any CSP seeking to provide cloud services to federal agencies must undergo a 3PAO assessment.
FedRAMP Joint Authorization Board (JAB) Provisional ATO and Agency ATO pathways.
Timelines vary based on scope, system complexity, and readiness. We define expectations during planning.
Yes. We support professional engagement with agencies and the FedRAMP PMO as required.
Yes, however, to maintain independence, Sera Brynn does not provide advisory services and assessment to the same clients.
Still have questions? Contact our experts

Begin Your FedRAMP Assessment 

FedRAMP Certification requires an independent assessment by a FedRAMP Recognized assessor, whether you pursue Program Certification directly from FedRAMP or Agency Certification through a federal sponsor.

Tell us where your cloud service stands and the Sera Brynn team will scope the assessment, timeline, and testing approach.

  • Confirm your certification type, class, and likely path
  • Clarify evidence and testing expectations under the 2026 rules
  • Align timing against the June 2027 Rev5 application deadline

 

Not Ready for a Full 3PAO Assessment?
Start With a Readiness Checklist.

Schedule a Consultation

A free 30-minute consultation with a FedRAMP advisor.

Download Our Free

“FedRAMP Readiness Checklist”

No Obligation

Just practical guidance to get you started.