
TLDR:
- The new FedRAMP Consolidated Rules were finalized on June 25, 2026, and took effect July 4, 2026; FedRAMP Ready is no longer accepting new submissions as of July 28, 2026.
- FedRAMP 20x introduces four new Certification Classes (A, B, C, and D), which sit alongside the legacy Rev5 process for now.
- Five things to look for in a readiness tool built for the current FedRAMP process, from cross-framework reuse to persistent validation.
FedRAMP, or the Federal Risk and Authorization Management Program, is a U.S. government framework that standardizes security requirements for cloud service providers (CSPs) working with federal agencies. If you searched for a FedRAMP readiness tool a year ago, you were probably shopping for something that helped you prepare for a FedRAMP Ready designation.
For years, the FedRAMP framework ran almost entirely through a process called Rev5, built around an agency sponsor and a lengthy, narrative-heavy assessment, with a third-party assessment organization (3PAO) conducting these evaluations on FedRAMP's behalf. Specifically, FedRAMP Ready is retiring and had already stopped accepting new submissions as of July 28, 2026. Existing holders are now working under what FedRAMP calls “Legacy FedRAMP Ready.”
FedRAMP 20x is the modernized replacement, and the certification model FedRAMP Ready fed into has also changed. FedRAMP's Consolidated Rules for 2026 (CR26) introduced Certification Classes A through D, and the native 20x paths (Class B and Class C) no longer require a readiness assessment report (RAR). So "readiness" itself means something different depending on which path a cloud service provider (CSP) is on, and a tool built for the old process won't necessarily help with the new one.
Read on to find out what FedRAMP Ready’s retirement means for your certification path, how the underlying controls changed under 20x, and what to actually look for in a readiness tool built for the process as it stands today.
What is a FedRAMP readiness tool?
A FedRAMP readiness tool is software that helps a CSP prepare for and track progress toward FedRAMP certification. It maps your existing security controls, organizes evidence, and flags gaps before you're in front of an assessor. But a lot has changed in the last year with the move to FedRAMP 20x. Readiness used to mean building toward a single designation and a single, static package. Now it means something specific to whichever certification path you've chosen, since 20x's native Class B and Class C flow doesn't lean on a readiness assessment report the way the legacy process did.
Does a FedRAMP readiness assessment report guarantee certification?
No, on either path. Even under legacy Rev5, a RAR never guaranteed authorization. It documented that a cloud service had a reasonable shot at passing a full FedRAMP assessment, nothing more. Under 20x, a prior RAR is now just one accepted form of evidence toward Class A eligibility, alongside a security assessment plan—and it’s not even a required checkpoint in the native Class B or C process. FedRAMP's own guidance for the legacy readiness assessment report process makes clear that a positive readiness assessment report only meant an assessor believed the cloud service provider was prepared to pursue a full FedRAMP assessment, not that authorization was assured.
FedRAMP Ready is retired. Here's what replaced it
FedRAMP Ready stopped accepting new submissions on July 28, 2026. Any CSP holding a Legacy FedRAMP Ready designation will remain in that status until November 17, 2026, or the expiration of their most recent yearly assessment. After that date, the Legacy FedRAMP Ready designation lapses.
Understanding the new Certification Classes A, B, C, and D
What replaced it depends on where you're starting from. On June 25, 2026, FedRAMP 20x finalized the CR26 and provided a formal pathway for Certification Classes A through D. It’s important to note that FedRAMP now refers to CSPs the program office has approved as “FedRAMP certified” rather than “FedRAMP authorized,” a change confirmed directly by FedRAMP's own leadership during a May 2026 public discussion on clearing up authorization confusion.
Certification Class A
Class A is the simplest option for anyone who was pursuing FedRAMP Ready. It allows a CSP to leverage an existing commercial attestation, such as a completed SOC 2 Type II report, a GovRAMP certification at any impact level, or prior FedRAMP Rev5 history, including FedRAMP Ready, so long as that prior work was completed within the past 12 months. From there, a provider addresses 23 additional mandatory FedRAMP rules, including seven specific Key Security Indicators (KSIs) covering areas such as account management automation, adopting passwordless methods, and incident response procedures. No agency sponsor is required for this path. And you can already pursue this path. The FedRAMP 20x Class A pipeline opened on August 3, 2026.
Certification Class B
Class B follows FedRAMP 20x's native path more directly, built around 56 KSIs rather than an external attestation, and those pipelines open on August 31, 2026.
Certification Class C
Like Class B, Class C also follows FedRAMP’s native path, but uses 61 KSIs instead of an external attestation. The pipeline for Class C opens on August 31, 2026, at the same time as Class B.
There's also a separate, temporary option available to Class B and C for CSPs who are already too deep into the legacy Rev5 process and have lost their agency sponsor along the way. Sponsorless Rev5 Program Certification pipelines opened on August 10, 2026, through what FedRAMP calls “Lost Sponsor/Ready Conversion,” giving providers stuck in limbo a way to finish what they started rather than starting over. It's worth understanding this option even if you're not directly affected, since it signals how seriously the FedRAMP program is treating the agency-sponsor bottleneck that has held up authorizations for years.
Certification Class D
Class D remains tied to the legacy Rev5 process and the full NIST Special Publication 800-53 control catalog, generally for high-impact systems where the more automated 20x approach isn't yet available. However, it’s slated for the Phase 4 rollout of FedRAMP 20x, estimated for late 2026 through mid-2027 (i.e., Q1 and Q2 of FY27).
One more date worth knowing if you're thinking in terms of your full FedRAMP journey rather than just this year: FedRAMP will stop accepting new Rev5 certification applications entirely after June 11, 2027. Rev5 isn't gone yet, but it now has an expiration date, too.
How controls changed under FedRAMP 20x
The control landscape shifted alongside the certification classes. Under the legacy Rev5 path, a cloud service provider documents its security posture against the full NIST Special Publication 800-53 control catalog, narrative by narrative. Under 20x, that narrative documentation is being replaced by Key Security Indicators (KSIs), which map to clusters of the same underlying controls but are expressed as automated, continuously validated capability outcomes rather than long-form write-ups.
This is a meaningful change to what "identify gaps" actually means day-to-day. Instead of writing a paragraph explaining how you handle account management, a Key Security Indicator asks whether that process is automated and verifiable in near real time. For a deeper look at how these control families match to KSIs, see this piece on the FedRAMP security controls baseline.
| Certification | Class A | Class B | Class C | Class D |
|---|---|---|---|---|
| Best fit for | CSPs that want to build on an existing commercial attestation rather than start from scratch | Lighter-use cloud services unlikely to see agency-wide adoption | Common enterprise services likely to be used agency-wide | High-impact systems, still tied to the legacy Rev5 process. |
| Eligibility evidence | Readiness assessment report, Security assessment plan, or Commercial attestation (SOC 2 Type II, GovRAMP, prior FedRAMP Rev5/FedRAMP ready) | KSI-based certification package (no external attestation required) | KSI-based certification package (no external attestation required) | Full System Security Plan (SSP) and Security Assessment Report via 3PAO assessment (legacy Rev5 process) |
| KSIs controls | 7 | 56 | 61 | N/A - still uses full NIST 800-53 catalog |
| Important dates | Pipeline open: August 3, 2026 | Pipeline open: August 31, 2026 | Pipeline open: August 31, 2026 | Pipeline not open: Phase 4 is estimated late 2026–mid-2027 |
Where a readiness tool fits in your FedRAMP journey
The shift from Rev5's narrative documentation model to 20x's machine-readable evidence changes what a readiness tool must do. A static spreadsheet or a folder of Word documents was never a great way to track FedRAMP readiness, but it could limp along under the old model. It can't keep up with a system built around continuously validated evidence.
The two paths now diverge in a way they didn't before:
- The 20x path (Classes A-C): Pre-certification preparation → A KSI-based certification package → Certification through Class A, B, or C → Persistent validation via robust continuous monitoring program
- The Rev5 (Class D) path: Pre-certification preparation → A readiness assessment report (RAR) → Formal FedRAMP certification → Periodic continuous monitoring reporting
A readiness tool earns its keep differently depending on which of these you're on. On the 20x path, it needs to help a CSP continuously generate and maintain evidence. On the Rev5 path, it's still mostly about closing gaps before the RAR and the formal assessment that follows.
This is where having the right platform matters more than having any platform. For example, Wisedocs, a Mycroft customer already serving federal agencies, credited Mycroft with providing strategic guidance on complex compliance questions, ranging from SOC 2 implementation to planning for future certifications such as ISO 27001 and FedRAMP. That kind of forward planning (i.e., mapping today's security posture against tomorrow's certification target) is exactly what a readiness tool should be doing regardless of which FedRAMP path a CSP eventually chooses.
What to look for in a FedRAMP readiness tool
Five evaluation criteria matter more now than they did under the old FedRAMP Ready model.
| Core capability | Why it matters |
|---|---|
| KSI and control mapping | Connects your existing controls to whichever framework, KSIs, or full NIST 800-53, your certification path actually requires. |
| Automated evidence collection | KSIs depend on continuously true evidence, so you can’t rely on a static document you update periodically. |
| Boundary and data flow diagram support | Your system architecture and authorization boundary are among the first things an assessor reviews, on any certification path. |
| Persistent validation support | Certification under 20x isn't a one-time event: Your tool needs to keep proving FedRAMP compliance even after the certification is granted. |
| Cross-framework evidence reuse | A tool that can't reuse evidence forces you to duplicate work the path was designed to let you skip. |
Map controls automatically
A readiness tool should connect your existing controls to whichever framework your certification path requires, whether that's the full NIST 800-53 catalog under Rev5 or the KSI set under 20x, without you having to manually re-map each one. That mapping is also what makes cross-framework evidence reuse possible in the first place.
Automatically collect continuous evidence
KSIs aren't a narrative you write once and file away. They're meant to be continuously true, which means a readiness tool needs to actually connect to your environment, whether that's Amazon Web Services GovCloud, Microsoft Azure Government, or Google Cloud's government-focused offerings, rather than relying on someone manually re-checking a box every quarter.
Look for boundary and data flow diagram support
Boundary and data flow diagram support matters too. A clear understanding of your system architecture and authorization boundary is foundational to any FedRAMP effort, and it's one of the first things an assessor reviews during documentation review, regardless of certification class.
Maintain persistent validation
Continuous evidence collection gets your tool connected to your environment. Persistent validation is what keeps that evidence trustworthy over time, confirming that your controls remain true today, not just on the day you generated the certification package.
Reuse evidence across frameworks
Class A's entire design depends on a CSP's existing commercial attestation, whether that's a SOC 2 Type II report or a prior Rev5 assessment. A readiness tool that can't reuse evidence across frameworks forces a provider to duplicate work that Class A was specifically designed to let them skip.
Mycroft's approach centers on exactly this kind of control mapping and evidence automation, so a CSP doesn’t have to track every rule change as FedRAMP continues to iterate manually. Learn more about how Mycroft can help you achieve FedRAMP Certification.
A readiness tool decides how much verification you still need
Independent verification isn't handled the same way across every path anymore. It's optional under Class A, where a provider may have its certification package independently verified and validated before submission, but isn't required to do so. It's still required under Classes B, C, and D, and under the legacy Rev5 process generally, where a full FedRAMP assessment from a 3PAO remains part of the formal authorization process.
That difference doesn't change what a readiness tool is actually for. Its job stays consistent across every path: Close as many security gaps as possible before anyone outside your organization looks at your environment, so that whatever formal verification is still required goes faster and finds less. Despite everything that's changed with the Consolidated Rules for 2026, that underlying job hasn't.
If your team is still deciding which certification path fits your cloud service, or you're sitting on a Legacy FedRAMP Ready designation that needs to be converted over before it lapses, see how Mycroft maps your environment against current FedRAMP requirements.
Frequently asked questions (FAQs)
Is a FedRAMP readiness tool the same as a FedRAMP readiness assessment?
No. A FedRAMP readiness tool helps you prepare for certification, while a FedRAMP readiness assessment is a formal, independent evaluation that only a third-party assessment organization (3PAO) can conduct. The tool's job is to narrow the gap before that formal assessment happens, not to replace the assessment itself.
What happened to FedRAMP Ready status?
FedRAMP Ready went legacy on July 28, 2026, and is no longer accepting new submissions. Existing holders keep their status until November 17, 2026, or their next yearly assessment expiration, whichever comes first, or their certification lapses completely. After that date, they must move to a full FedRAMP certification, pursuing Class A, B, C, or D certifications instead.
How long does it take to get FedRAMP certified?
The amount of time it takes to get FedRAMP certified depends heavily on your path. Class A can move faster since it builds on an existing SOC 2 Type II report or prior FedRAMP history, though a provider still has to address 23 additional FedRAMP-specific rules. Classes B, C, and D, along with the legacy Rev5 process, generally take longer, since they involve a full independent assessment.
Do I need a FedRAMP readiness tool if I'm already working with an assessor?
Yes. A readiness tool and an assessor serve different roles. The assessor conducts the formal, independent verification your certification path requires. A readiness tool helps you get there with fewer gaps, which usually shortens the time required for the formal review and lowers costs.
What happens if a cloud service provider doesn't pass its FedRAMP formal assessment?
A negative finding isn't the end of the road. The assessor documents each gap with a severity level and a remediation window, and the provider addresses those gaps and re-assesses once they're resolved. Many providers don't pass on their first attempt.
How does Mycroft support cloud service providers pursuing FedRAMP certification?
Mycroft streamlines FedRAMP documentation, control implementation, and evidence collection, helping cloud service providers move more quickly toward certification. Mycroft also supports the continuous monitoring program that a certified CSP needs to maintain over time.



