The Consolidated Rules for 2026 replace the FedRAMP program cloud service providers have known for a decade — new Certification Classes, a new approach to scoping, and Key Security Indicators validated through machine-readable evidence. This session answers the three questions providers are asking most:

  • What is FedRAMP 20x, and what does CR26 actually change? What the new program structure looks like — how Certification Classes A–D replace the Low/Moderate/High baselines and what Minimum Assessment Scope means for how systems are evaluated.
  • What are the Rev 5 transition deadlines? 20x submissions are open for Classes A-C, the Ready Conversion window opens August 10, 2026, and Rev 5 retires at the end of 2027. We’ll lay out each authorization path and its milestones so you can plan with accurate information.
  • How do KSIs and machine-readable evidence work? How roughly 61 KSIs replace 325+ control narratives, how automated validation works, and how evidence from existing programs like SOC 2 relates to 20x expectations.

Can’t make it live? Register anyway and we’ll send the replay.

Who should attend: Compliance, security, and engineering leaders at cloud service providers pursuing or maintaining FedRAMP authorization — and anyone responsible for understanding how the 2026 changes affect their organization’s federal roadmap.

Speakers

What Is FedRAMP 20x KSIs, Rev 5 Deadlines, and the 2026 Consolidated Rules SPEAKERS