The Consolidated Rules for 2026 replace the FedRAMP program cloud service providers have known for a decade — new Certification Classes, a new approach to scoping, and Key Security Indicators validated through machine-readable evidence. This session answers the three questions providers are asking most:
- What is FedRAMP 20x, and what does CR26 actually change? What the new program structure looks like — how Certification Classes A–D replace the Low/Moderate/High baselines and what Minimum Assessment Scope means for how systems are evaluated.
- What are the Rev 5 transition deadlines? 20x submissions are open for Classes A-C, the Ready Conversion window opens August 10, 2026, and Rev 5 retires at the end of 2027. We’ll lay out each authorization path and its milestones so you can plan with accurate information.
- How do KSIs and machine-readable evidence work? How roughly 61 KSIs replace 325+ control narratives, how automated validation works, and how evidence from existing programs like SOC 2 relates to 20x expectations.
Can’t make it live? Register anyway and we’ll send the replay.
Who should attend: Compliance, security, and engineering leaders at cloud service providers pursuing or maintaining FedRAMP authorization — and anyone responsible for understanding how the 2026 changes affect their organization’s federal roadmap.
Speakers


