FedRAMP 20x Phase 4 Is Open: Class D Pilot and RFC Window | Lazarus Alliance

Lazarus Alliance FedRAMP 20x Phase 4 graphic announcing the Class D pilot and RFC-0033 and RFC-0034 comment window closing October 9, 2026.

On September 9, 2026, FedRAMP opened two Requests for Comment that start Phase 4:

  • RFC-0033 — 20x Phase 4 Development Tracks for 20x Class D
  • RFC-0034 — Technical Advisory Group Changes

Both close October 9, 2026.

This is not a Marketplace listing day. It is the planning window for High. Class B and Class C pipelines opened August 31. Phase 4 is how FedRAMP takes 20x to Class D — the former High baseline — and how it starts writing rules for self-hosted and hybrid-hosted services that Phase 1–3 left behind.

Providers who want a seat in the Class D pilot have one hard gate: a CR26-compliant FedRAMP 20x Class C Certification before December 1, 2026.

Read More

FedRAMP Class B & C Intake Is Now Live | FedRAMP 20x 3PAO

Native FedRAMP Class B/C intake is now live. Learn how Lazarus Alliance helps cloud service providers streamline assessment, reduce risk, and advance FedRAMP authorization.

Native FedRAMP Class B & C Intake Is Now Live

The FedRAMP 20x Class B and Class C pipelines opened on August 31, 2026. Lazarus Alliance is now accepting native intake for both classes.

That is not a small process change. It is the point at which Low and Moderate work stops being treated as a retrofit of Rev5 paperwork and starts being treated as a 20x certification path: Key Security Indicators, machine-readable packages, and continuous validation.

If your offering belongs on the federal marketplace at Low or Moderate assurance, the window to enter on the new rules is open.

Read More

FedRAMP 20x Class A Is Now Open: What It Means for Cloud Providers and Federal Cybersecurity

FedRAMP 20x Class A Is Now Open—square promotional graphic featuring secure cloud infrastructure, a federal government building, cybersecurity shield, encrypted cloud, and compliance dashboard. The image highlights FedRAMP 20x Class A authorization, continuous compliance, accelerated federal cloud security, risk-based authorization, transparency, and cybersecurity modernization for cloud service providers supporting U.S. government agencies.

The federal cloud compliance landscape has reached another significant milestone. As of August 3, 2026, the FedRAMP 20x Class A submission pipeline is officially open, marking the first widely available entry point into the new FedRAMP 20x certification model. This isn’t simply a process update—it’s a fundamental shift toward a faster, more automated, and evidence-driven approach to cloud security authorization.

For cloud service providers (CSPs), particularly SaaS companies that have historically viewed FedRAMP as expensive and time-consuming, this represents a new opportunity. For cybersecurity advisors and assessment organizations like Lazarus Alliance, it signals a transformation in how organizations prepare for federal market entry.

Read More