Native FedRAMP Class B & C Intake Is Now Live
The FedRAMP 20x Class B and Class C pipelines opened on August 31, 2026. Lazarus Alliance is now accepting native intake for both classes.
That is not a small process change. It is the point at which Low and Moderate work stops being treated as a retrofit of Rev5 paperwork and starts being treated as a 20x certification path: Key Security Indicators, machine-readable packages, and continuous validation.
If your offering belongs on the federal marketplace at Low or Moderate assurance, the window to enter on the new rules is open.
What Just Opened
Under the Consolidated Rules for 2026, FedRAMP replaced the familiar Low / Moderate / High labels with Certification Classes A through D. Class A opened August 3. Class B and Class C opened together on August 31.
- Class B is the updated Low path. It consolidates the old Low and Li-SaaS tracks. Providers must meet 51 KSIs.
- Class C is the updated Moderate path. This remains the center of the federal cloud market. Providers must meet 56 KSIs.
- Class D (High) is still in the later phase. FedRAMP expects a late-2026 pilot and a formal option in early 2027.
Program certification on the 20x path is now required for Classes A, B, and C. Providers pick one path. FedRAMP will not issue program certifications for both 20x and Rev5 on the same offering.
Rev5 is not gone yet. Limited Rev5 Class B/C program pipelines opened August 10 for Ready Conversion and Lost Sponsor cases, and new Rev5 submissions end June 11, 2027. January 1, 2027 is mandatory CR26 adoption. Those dates matter. They are not a reason to keep assembling a Moderate package the old way if 20x Class B or C is the destination.
Why “Native” Intake Matters
Most CSPs still approach FedRAMP as a document project: Word SSPs, spreadsheet POA&Ms, narrative control statements, and a late conversion to OSCAL. That model does not survive Class B or Class C.
Native intake means the engagement starts in the 20x shape:
- Class selected first (B or C), not after a year of Moderate-shaped artifacts
- Authorization boundary, data flows, and inherited services scoped to the class
- KSIs mapped to NIST SP 800-53 outcomes instead of one narrative per control
- OSCAL as the working package, not an export after the fact
- Evidence collected from running systems, scans, identity, logging, and configuration state
- Continuous monitoring designed for the 20x cadence, including the aggressive automated validation cycle expected at Class C
Class C is not “Moderate with a new name.” The class tells an agency how much assurance information they have. The proof is expected to be live, machine-readable, and repeatable. Spreadsheet GRC and consultant-assembled PDFs will not keep pace.
FedRAMP Class B vs. Class C
FedRAMP’s class model is progressive. Investment and assurance scale with agency demand.
| Class | Legacy analog | What agencies can generally use it for | 20x bar |
|---|---|---|---|
| A | FedRAMP Ready | Entry listing; many non-sensitive use cases | Six federal mandates; then 12 months after a federal customer to start moving to B or higher |
| B | Low / Li-SaaS | Most Low objectives; some Moderate or High with agency compensating controls | 51 KSIs |
| C | Moderate | Most Low and Moderate objectives; some High | 56 KSIs; tighter continuous validation |
| D | High | Most unclassified use cases | Later phase |
If you already hold a mature Rev5 Moderate package, Class C is often the logical conversion. If you are a new SaaS provider with a SOC 2 Type II or a completed RAR, Class A may still be the right first listing, with a planned Class B or C transition once a federal customer is on the service.
What We Are Taking In Now
Lazarus Alliance, an A2LA-accredited FedRAMP 3PAO, is open for native Class B and Class C intake. That includes:
- Class decision and path selection — 20x Program Certification versus the limited Rev5 pipelines, and B versus C based on data, customers, and inheritance.
- Boundary and inheritance design — what sits in the CSO, what is inherited from a FedRAMP-authorized IaaS/PaaS/MSP, and whether that provider’s class actually supports yours.
- KSI and control mapping — 51 or 56 indicators tied to implemented NIST 800-53 outcomes, not recycled Rev5 narratives.
- OSCAL package build — SSP, assessment results, and POA&M in machine-readable form from the first working draft.
- Evidence and ConMon architecture — automated collection, three-day validation expectations at Class C, vulnerability SLAs, FIPS-validated crypto, MFA, and operational logging.
- 3PAO assessment — independent testing, demonstrations, SAR, and submission support through Marketplace listing and continuous monitoring.
Continuum GRC / A.ITAM is the working system for that intake. It is a FedRAMP-authorized GRC platform, which means Class B/C work can be scoped, evidenced, scored, and reported in an environment already accepted for federal use. AITAMBot and Cybervisor® advisory sit on top of that stack so the package is built once and reused across FedRAMP, GovRAMP, NIST, CMMC, SOC 2, and related baselines instead of rebuilt for every auditor.
What CSPs Should Do This Week
The pipeline is live. The pipeline is live. CSPs pursuing Class B or Class C can now align their assessment and certification strategy with the new 20x model rather than treating it as a future transition.
- Confirm the target class. B and C are different commitments.
- Decide 20x versus the temporary Rev5 program lanes before you spend another month on the wrong package format.
- Inventory inheritance. A Class B platform cannot carry a Class C offering.
- Move evidence off shared drives and into automated collection.
- Put OSCAL in the critical path now. January 1, 2027 is not a soft reminder.
- Engage an accredited 3PAO before the first federal RFP asks which class you hold.
Lazarus Alliance has historically compressed FedRAMP assessment cycles by roughly 40–50% against traditional 3PAO timelines when the CSP is prepared and the package is automation-first. Native Class B/C intake is how that advantage is applied to 20x instead of to a dying Rev5 workflow.
Start Native Class B or Class C Intake
Do not wait for an agency to ask whether you are “still Moderate” or “already Class C.” The marketplace language has already changed. The intake path should match it.
To open a native FedRAMP 20x Class B or Class C engagement with Lazarus Alliance, contact us or call +1-888-896-7580.
Lazarus Alliance is a veteran-owned small business, A2LA-accredited FedRAMP 3PAO, authorized CMMC C3PAO, PCI DSS QSA, and Delaware CPA firm. Continuum GRC is the only FedRAMP-authorized AI GRC platform purpose-built for this work.
Frequently Asked Questions
What is FedRAMP Class C?
FedRAMP Class C is the mid-level FedRAMP 20x certification class and replaces the former FedRAMP Moderate impact level. It is intended for cloud service offerings that require a higher level of security assurance than Class B and must satisfy the applicable Class C requirements established in FedRAMP's Consolidated Rules.
What did FedRAMP Class B replace?
FedRAMP Class B updates what stakeholders previously referred to as the FedRAMP Low impact level. Organizations familiar with the legacy Low authorization model should not assume Class B is simply a renamed baseline; the FedRAMP 20x model introduces a substantially different approach to security evidence, verification, validation, and ongoing assurance.
What did FedRAMP Class C replace?
FedRAMP Class C replaces the former FedRAMP Moderate impact level as the mid-level certification class under FedRAMP 20x. CSPs that historically would have pursued a Moderate authorization should evaluate whether Class C is the appropriate certification target under the new FedRAMP model.
When did FedRAMP Class B and Class C open?
The FedRAMP 20x Class B and Class C certification pipelines officially opened on August 31, 2026. FedRAMP began accepting applications for both certification classes on that date as part of its implementation of the Consolidated Rules for 2026.
Is FedRAMP Rev5 still available?
Yes. FedRAMP Rev5 remains available during the transition period. FedRAMP states that it will stop accepting applications for new FedRAMP Rev5 Certifications on June 11, 2027. CSPs considering Rev5 should therefore evaluate the remaining certification window and the advantages of moving directly to the newer FedRAMP 20x model before investing in a legacy certification path.
Does FedRAMP Class B or Class C require a 3PAO assessment?
FedRAMP Class B and Class C require independent assessment activities under the applicable FedRAMP certification rules. FedRAMP's rules establish independent verification and validation requirements and recognize FedRAMP Recognized independent assessment services, which include recognized Third Party Assessment Organizations (3PAOs). The specific assessment requirements depend on the certification class and path being pursued.
For a CSP, engaging a FedRAMP-recognized 3PAO early can also help ensure that system scope, security evidence, testing, verification, and validation are aligned with the targeted certification class before formal assessment begins.
Should a CSP choose FedRAMP Class B or Class C?
A CSP should choose FedRAMP Class B or Class C based on the security requirements, information types, risk profile, federal customer requirements, and intended use of its cloud service offering. Class B corresponds to the lower-impact certification path, while Class C replaces the former Moderate impact level and provides a higher level of assurance.
The decision should be made early because the selected certification class affects the applicable FedRAMP requirements, security architecture, evidence, verification and validation activities, assessment scope, and ongoing compliance obligations. FedRAMP also permits providers to change certification classes, but upgrading requires a new certification application and satisfaction of the requirements for the target class.
About Lazarus Alliance
To learn more about how Lazarus Alliance can help, contact us.
- FedRAMP
- GovRAMP
- NIST 800-53
- DFARS NIST 800-171
- CMMC
- SOC 1 & SOC 2
- C5
- HIPAA, HITECH, & Meaningful Use
- PCI DSS RoC & SAQ
- IRS 1075 & 4812
- CJIS
- LA DMF
- ISO 27001, ISO 27002, ISO 27005, ISO 27017, ISO 27018, ISO 27701, ISO 22301, ISO 17020, ISO 17021, ISO 17025, ISO 17065, ISO 9001, & ISO 90003




Related Posts