FedRAMP®
FedRAMP 20x Class B and Class C Pipelines Are Open: Which Path Fits Your Cloud Service?
On Monday, August 31, 2026, FedRAMP opened its certification pipelines for FedRAMP 20x Class B and Class C. Cloud service providers will have two new ways to pursue formal certification under the modernized program, without the requirement for an agency sponsor
The important decision is not who can submit first. It is which class matches the federal customers you want to serve, the data your service handles, and the assurance your buyers will expect.
Class B is the updated FedRAMP 20x path for what many stakeholders previously called FedRAMP Low. Class C replaces the Moderate impact level. Both are meaningful certification targets. They serve different use cases and demand different levels of preparation.
The short version
Choose Class B when your service supports a lower-risk, lighter-use, or more limited federal deployment and the buyer does not need Moderate-aligned assurance.
Choose Class C when an agency, procurement opportunity, or product strategy calls for deeper assurance, validation, reporting, and ongoing visibility.
Before you choose, CSPs should be able to:
- Connect the class decision to a real customer, agency requirement, or procurement opportunity
- Define the cloud service offering and its boundary
- Map current controls and evidence to the selected 20x rules and applicable Key Security Indicators (KSIs)
- Automate evidence gathering, internal control validation, metric reporting, and vulnerability management to stay current as the environment changes.
- Maintain human readable and machine-readable program summaries within a trust center
- Support the work after certification, not only the work that leads to it
The letter should follow the use case. It should not lead the decision.
FedRAMP 20x is moving fast!
Meet with Coalfire’s FedRAMP team to talk through your current state, target certification path, and highest-priority FedRAMP 20x gaps.
Book a strategy meeting with Coalfire's FedRAMP teamWhat Class B means
FedRAMP describes Class B as an updated version of what stakeholders previously associated with the FedRAMP Low impact level.
It fits services used in lower-risk or narrower federal deployments. An agency may use the service for a limited purpose, a small user population, or workloads where a security incident would have a limited adverse impact. The exact fit still depends on the agency, the system, the data, and the applicable FedRAMP requirements.
Class B is a formal certification target. It can be the right long-term destination when customer demand and data sensitivity do not call for a higher security program, such as one that can process moderate impact data. It also gives providers a way to build an operating model for federal compliance without taking on requirements their buyers do not need.
What Class C means
Class C is the mid-level certification baseline under FedRAMP 20x and replaces the familiar Moderate impact level.
It is a strong fit for cloud services that will support more sensitive information, broader agency use, or enterprise federal workloads. It also fits opportunities where the agency or procurement language calls for Moderate-aligned assurance.
Class C asks more of the provider - in addition to a clear system boundary, measurable controls, automated current evidence, reliable validation, a larger set of KSIs and longer retention of historic data within a trust center raise the bar over Class B. The provider thus needs an operating model that can maintain the certification posture over time, and critically, demonstrate to stakeholders in real time!
How the FedRAMP 20x classes fit together
Think of the classes as different assurance and reporting commitments, not a ranking of which cloud service is “more secure.” A higher class means the provider must be prepared to supply more certification data, validation, reporting, and ongoing visibility to federal customers.
Class | Best fit | What it signals | Watchout |
| Class A | Providers with a mature commercial security program that want a sponsorless entry into the federal market. | A lighter entry point through Program Certification, with the potential to reuse qualifying assessment work. | It is designed for limited-risk or pilot-oriented use cases and has a transition clock. |
| Class B | Lower-risk, lighter-use, or more limited federal services. | A full certification path without the Moderate-aligned scope of Class C. | It may not meet the needs of an agency-wide platform or more demanding workload. |
| Class C | Services and federal opportunities that require Moderate-aligned assurance. | A deeper commitment to certification data, validation, reporting, and continuous assurance. | It requires stronger preparation and more disciplined post-certification operations. |
| Class D (under planning) | High-assurance agency use cases that require the greatest certification commitment. | The highest class in the 20x structure, planned for 2027 go live | Pursue it only when the agency requirement and operating model justify the investment. |
Choose the lowest class that meets the agency need and business case. If customer demand, service criticality, or assurance expectations grow, the certification investment can grow with them.
Where Class A fits
Class A is the lightest FedRAMP certification class and a sponsorless entry point through Program Certification. FedRAMP’s Class A pipeline opened August 3, 2026. A complete Readiness Assessment Report (RAR) or a SOC 2 Type II can support a Class A submission, subject to the program’s eligibility and submission requirements. Class A is a practical fit for providers with a mature commercial security program, recent qualifying assurance work, and a civilian-first federal strategy. Qualifying work may include SOC 2 Type II, GovRAMP, or prior FedRAMP work. Existing assurance can provide a head start, but it does not equal FedRAMP certification. Providers still need to address FedRAMP-specific rules, evidence, documentation, and ongoing obligations.
Class A can make sense when the first federal use case is a low-risk pilot, the provider wants Marketplace visibility sooner, and the team has a plan for the next class. FedRAMP gives providers 12 months to begin transitioning to Class B or higher once a cloud service offering has been authorized for use by a federal agency.
Class A is a poor fit when buyers already require Class C or higher, the near-term opportunity is DoD-focused, or the provider wants a permanent certification target for broad federal deployment. It is a formal certification class, not a replacement for a higher class when the market requires one.
Class B or Class C? Start with the buyer
The cleanest way to choose is to work backward from the opportunity.
Class B may be the better fit when:
- The initial federal use case is limited, lower risk, or narrowly scoped.
- The service will not support agency-wide or mission-important work.
- Buyers need a full FedRAMP certification but do not require Moderate-aligned assurance.
- The provider wants a durable certification target without building for requirements its customers do not need.
Class C may be the better fit when:
- An agency customer or active procurement requires Moderate-aligned assurance.
- The service will support more sensitive information or broader agency use.
- The provider’s federal growth strategy depends on a certification position that can support more demanding buyers.
- The team is ready to maintain a deeper evidence, validation, reporting, and continuous-assurance model.
If the buyer requirement is unclear, pause before choosing a class. A higher class can add cost and complexity without helping you win the opportunity. A lower class can leave you unable to meet the requirement when procurement begins – however, requirements are incremental, and a lower-class certification can lay the foundation to achieving a higher class in the future.
Providers serving DoD buyers or the defense industrial base should also review CMMC and contract-specific requirements. A FedRAMP class decision does not answer every defense-market obligation. Some providers will need a dual-track plan.
What changes on the 20x path?
FedRAMP 20x changes how providers demonstrate that security controls work in the environment, not only how they assemble a certification package.
Evidence must stay current
Traditional compliance packages often leaned on large, static documents. FedRAMP 20x places more weight on structured, current evidence that teams can validate and reuse as systems change.
That shift connects security, engineering, compliance, and operations. The people who maintain the environment also need a practical way to produce proof about it.
Scope decisions matter early
A clear boundary and a defensible Minimum Assessment Scope (MAS) keep the effort focused on the service customers will use. A boundary that is too broad adds work without improving the certification story. A boundary that is too narrow can leave important services, dependencies, or customer commitments outside it.
KSIs need to operate in the real environment
Key Security Indicators should show up in the way the service is built, deployed, monitored, and maintained. Providers need to connect applicable rules and KSIs to measurable implementation, useful evidence, and repeatable validation.
Continuous assurance becomes part of the operating model
The 20x model emphasizes machine-readable evidence, automated validation, recurring reporting, and vulnerability detection and response. Providers need processes and tooling that can keep pace with infrastructure, code, and configuration changes.
Human and Machine readable
A significant new evolution within the FedRAMP program is that critical information including the certification package and the Security Decision Record (SDR) are required to be both human and machine readable. This enables ease of use and the ability to programmatically access data.
Five questions to answer before you submit
Use the August 31 opening as a prompt to get specific:
- What customer, agency, or procurement requirement makes Class B or Class C necessary now?
- What exact cloud service offering are you certifying, and where does its boundary begin and end?
- Which controls, tools, and evidence can support the selected 20x rules and applicable KSIs?
- Where are the gaps in automation, documentation, vulnerability response, change management, and reporting?
- What will your team need to operate and maintain after the initial assessment?
Your answers should point to a class, a scope, and a work plan. If they do not, more discovery is needed before you enter the pipeline.
What existing Rev. 5 providers should know
The August 31 opening applies to new 20x Class B and Class C submissions. Existing Rev. 5 providers are on related transition tracks under the Consolidated Rules for 2026.
If you already hold a Rev. 5 certification, separate transition planning from a new-class decision. Your next step may involve understanding how the current certification maps to the 20x structure, what evidence can be reused, and which new operating expectations your team must support.
How Coalfire can help
Coalfire’s FedRAMP 20x services help providers prepare for that shift through advisory support, boundary and scope work, KSI alignment, evidence strategy, automation planning, and continuous-compliance guidance.
FedRAMP decisions connect security, technology, compliance, and go-to-market strategy. Coalfire brings those conversations together before a provider commits to a boundary or certification class that does not fit.
Our team can help you:
- Evaluate whether Class A, B, or C fits your customers, use cases, and federal growth strategy.
- Compare 20x and Rev. 5 considerations for your offering.
- Pressure-test the boundary, inherited services, and Minimum Assessment Scope.
- Assess current capabilities against the selected ruleset and applicable KSIs.
- Build an evidence strategy for human review and machine-readable workflows.
- Develop the Security Decision Record and supporting certification documentation.
- Prioritize gaps before they slow an independent assessment.
- Design reporting and continuous-compliance processes that your team can maintain.
- Review civilian, DoD, and CMMC requirements when a dual-track plan may be necessary.
Coalfire’s role is not to steer every provider toward the same class. It is to help you choose a path that fits your buyers, your architecture, and the assurance your market requires.
Start planning your Class B or Class C path
For guidance specific to your environment, meet with Coalfire’s FedRAMP team for a strategy session. We can talk through your current state, target class, highest-priority gaps, and the next step for your federal market strategy.
Take the conversation further in New York City
FedRAMP 20x is easier to understand when you can bring your real questions to the room. Join Coalfire, Paramify, and A-LIGN in New York City on September 22 for the final stop of the FedRAMP 20x Road Show. We’ll go deeper on authorization strategy, evidence, continuous compliance, and what to tackle first.