Editor’s note: Originally published July 1, 2025. Updated August 18, 2026 to reflect the FedRAMP Consolidated Rules for 2026.
Federal buyers won't bring your cloud service in-house until you hold FedRAMP Certification. Most of what decides whether you get it happens long before you submit an application, and this guide walks through what to have in place first.
Sera Brynn is a FedRAMP Recognized Independent Assessor (3PAO), listed directly on the FedRAMP Marketplace. Several people on our advisory team have run FedRAMP assessments themselves, and that experience shapes the guidance below.
One note before we start. If you're targeting Class D, the highest assurance category, you're on the Rev5 Agency path for now. FedRAMP hasn't opened 20x to Class D yet, that pilot is expected sometime in 2027, so talk to us directly about the Rev5 process. Everyone targeting Class A, B, or C should keep reading. 20x is where FedRAMP is sending new applicants, and Rev5 stops accepting new submissions on June 11, 2027.
The Seven Steps to FedRAMP Readiness at a Glance
Step 1: Know Your Class Before You Do Anything Else
FedRAMP certifies by class now instead of by impact level, and the class you target sets almost everything that follows. Decide this first.
Class A is the entry point for providers who already hold a commercial certification. Think of it as a fast start rather than a destination. Class B and Class C carry a full FedRAMP certification, with assurance and automation requirements rising at each level. Class D stays on Rev5, as covered above.
Providers routinely aim higher than they need to. Look at what your actual federal customers require, then target that. Skip the class that just sounds impressive on a sales call.
Step 2: Get Your Existing Certifications in Order
Skip this step if Class A isn't your target.
Class A will accept a completed SOC 2 Type II, FedRAMP Rev5 (including legacy Ready status), or GovRAMP certification in place of a full FedRAMP package, as long as it was completed within the past 12 months. The certificate alone won't satisfy FedRAMP. You'll also need the complete report, any bridge or gap letter, your audit engagement documentation, and the schedule for your next report.
If your SOC 2 or GovRAMP report is getting close to that 12-month mark, plan your renewal now, around your target application date, rather than dealing with it later.
Step 3: Build the Evidence Pipeline Before You Apply
Most providers underestimate this step, and it's usually the one that actually sets their timeline.
FedRAMP 20x runs on Key Security Indicators across ten families: Change Management, Cloud Native Architecture, Cybersecurity Education, Identity and Access Management, Incident Response, Monitoring and Logging and Auditing, Policy and Inventory, Recovery Planning, Service Configuration, and Supply Chain Risk. Each one needs automated validation, and how much depends on your class. Class B needs at least one automated method per indicator, Class C needs at least two, and Class D needs at least four.
A working mechanism isn't enough on its own. FedRAMP wants a track record behind it. Class C requires six months of persistent validation history, Class D requires eighteen. If that instrumentation isn't running yet, your realistic application date starts counting from today, not from whenever you decide you're ready to apply.
This work sits with engineering. Providers who moved fastest through FedRAMP 20x had product and platform teams building this from day one. The ones who left it to compliance to backfill later struggled to catch up.
Step 4: Get Listed and Document Your Use Case
You need a FedRAMP Marketplace listing before you can apply. Getting listed takes two things: a documented agency use case, whether that's direct use in a federal system or indirect use inside another provider's certified offering, and evidence of continuous progress, kept current at least quarterly.
Open this listing early. It runs in parallel with the technical build in Step 3, so there's no reason to wait on one before starting the other.
Step 5: Assemble the Package Materials Early
Three documents have replaced the old System Security Plan model, and they're worth starting well ahead of your target submission date.
The Certification Package Overview gives reviewers and customers a concise summary of the offering. The Security Decision Record tracks the security decisions made across your offering's lifecycle as an ongoing document you keep current. The Secure Configuration Guide walks through the security impact of whatever configuration choices your customers control themselves.
Every machine-readable submission has to validate against FedRAMP's published JSON schemas. Confirm your tooling handles this well before you're up against a deadline.
Step 6: Line Up Your Assessor
FedRAMP retired the term 3PAO in favor of FedRAMP Recognized Independent Assessor, though most people in the industry still say 3PAO out of habit. Class B, C, and D applicants need an assessment completed within three months of submission. Class A applicants can include one, though it isn't required.
Timing this well matters. An assessment older than three months needs a review of what's changed to stay valid, and past nine months it needs a full reassessment. Book your assessor against your actual application timeline, not how ready you feel on a given week, or you risk losing a valid assessment to the calendar.
Step 7: Know the Clock Once You Apply
Two timing rules govern the application itself. Your package has to reflect verification and validation performed within the previous seven days, which means the final push needs fresh evidence, not something assembled weeks earlier. FedRAMP targets an initial decision within 30 days, though that clock pauses whenever FedRAMP is waiting on you, so how fast your team turns around requests genuinely affects how long this takes.
You also have to apply directly. Your assessor can't submit on your behalf, and neither can anyone else.
What Readiness Actually Buys You
The formal assessment still has to happen. What changes is how long it takes once you get there. Providers who work through Steps 1 through 6 before bringing in an assessor tend to move through certification in weeks, where this process used to routinely run past a year.
Get Help Building Your Readiness Plan
Frequently Asked Questions
How long does readiness take before I can apply?
It comes down almost entirely to Step 3. Providers with mature DevSecOps practices and existing automation can be ready within months. Providers starting from scratch on KSI instrumentation should plan for longer, especially at Class C or D, where a minimum validation history has to be in place before you can even apply.
Do I need an agency sponsor?
Not under 20x. Class A, B, and C run on the Program Certification path, which FedRAMP grants directly. Class D is the only one that still needs an agency sponsor today.
What if I'm already pursuing Rev5?
Existing Rev5 certifications stay valid, but they'll need to adopt FedRAMP's current ruleset by January 1, 2027. New Rev5 applications close entirely on June 11, 2027. If you're mid-process, this is a good moment to weigh your remaining Rev5 timeline against starting fresh on 20x.
Can I start before I've chosen an assessor?
Yes, and you probably should. Steps 1 through 5 don't need an assessor involved. Bring one in once your evidence pipeline and package materials are far enough along that setting an assessment date makes sense.
What happens after I'm ready?
You apply directly to FedRAMP, with your assessor's independent assessment attached to the package. From there, you're in FedRAMP's review process, aimed at a 30-day initial decision.
