FedRAMP Class B & C Intake Is Now Live | FedRAMP 20x 3PAO

Native FedRAMP Class B/C intake is now live. Learn how Lazarus Alliance helps cloud service providers streamline assessment, reduce risk, and advance FedRAMP authorization.

Native FedRAMP Class B & C Intake Is Now Live

The FedRAMP 20x Class B and Class C pipelines opened on August 31, 2026. Lazarus Alliance is now accepting native intake for both classes.

That is not a small process change. It is the point at which Low and Moderate work stops being treated as a retrofit of Rev5 paperwork and starts being treated as a 20x certification path: Key Security Indicators, machine-readable packages, and continuous validation.

If your offering belongs on the federal marketplace at Low or Moderate assurance, the window to enter on the new rules is open.

What Just Opened

Under the Consolidated Rules for 2026, FedRAMP replaced the familiar Low / Moderate / High labels with Certification Classes A through D. Class A opened August 3. Class B and Class C opened together on August 31.

  • Class B is the updated Low path. It consolidates the old Low and Li-SaaS tracks. Providers must meet 51 KSIs.
  • Class C is the updated Moderate path. This remains the center of the federal cloud market. Providers must meet 56 KSIs.
  • Class D (High) is still in the later phase. FedRAMP expects a late-2026 pilot and a formal option in early 2027.

Program certification on the 20x path is now required for Classes A, B, and C. Providers pick one path. FedRAMP will not issue program certifications for both 20x and Rev5 on the same offering.

Rev5 is not gone yet. Limited Rev5 Class B/C program pipelines opened August 10 for Ready Conversion and Lost Sponsor cases, and new Rev5 submissions end June 11, 2027. January 1, 2027 is mandatory CR26 adoption. Those dates matter. They are not a reason to keep assembling a Moderate package the old way if 20x Class B or C is the destination.

Why “Native” Intake Matters

Most CSPs still approach FedRAMP as a document project: Word SSPs, spreadsheet POA&Ms, narrative control statements, and a late conversion to OSCAL. That model does not survive Class B or Class C.

Native intake means the engagement starts in the 20x shape:

  • Class selected first (B or C), not after a year of Moderate-shaped artifacts
  • Authorization boundary, data flows, and inherited services scoped to the class
  • KSIs mapped to NIST SP 800-53 outcomes instead of one narrative per control
  • OSCAL as the working package, not an export after the fact
  • Evidence collected from running systems, scans, identity, logging, and configuration state
  • Continuous monitoring designed for the 20x cadence, including the aggressive automated validation cycle expected at Class C

Class C is not “Moderate with a new name.” The class tells an agency how much assurance information they have. The proof is expected to be live, machine-readable, and repeatable. Spreadsheet GRC and consultant-assembled PDFs will not keep pace.

FedRAMP Class B vs. Class C

FedRAMP’s class model is progressive. Investment and assurance scale with agency demand.

ClassLegacy analogWhat agencies can generally use it for20x bar
AFedRAMP ReadyEntry listing; many non-sensitive use casesSix federal mandates; then 12 months after a federal customer to start moving to B or higher
BLow / Li-SaaSMost Low objectives; some Moderate or High with agency compensating controls51 KSIs
CModerateMost Low and Moderate objectives; some High56 KSIs; tighter continuous validation
DHighMost unclassified use casesLater phase
Do not default to Class C because “everyone used to do Moderate.” FedRAMP has been explicit: do not jump straight to C or D unless a government contract actually requires that level of commitment. Start at the class you can defend, then climb.

If you already hold a mature Rev5 Moderate package, Class C is often the logical conversion. If you are a new SaaS provider with a SOC 2 Type II or a completed RAR, Class A may still be the right first listing, with a planned Class B or C transition once a federal customer is on the service.

What We Are Taking In Now

Lazarus Alliance, an A2LA-accredited FedRAMP 3PAO, is open for native Class B and Class C intake. That includes:

  1. Class decision and path selection — 20x Program Certification versus the limited Rev5 pipelines, and B versus C based on data, customers, and inheritance.
  2. Boundary and inheritance design — what sits in the CSO, what is inherited from a FedRAMP-authorized IaaS/PaaS/MSP, and whether that provider’s class actually supports yours.
  3. KSI and control mapping — 51 or 56 indicators tied to implemented NIST 800-53 outcomes, not recycled Rev5 narratives.
  4. OSCAL package build — SSP, assessment results, and POA&M in machine-readable form from the first working draft.
  5. Evidence and ConMon architecture — automated collection, three-day validation expectations at Class C, vulnerability SLAs, FIPS-validated crypto, MFA, and operational logging.
  6. 3PAO assessment — independent testing, demonstrations, SAR, and submission support through Marketplace listing and continuous monitoring.

Continuum GRC / A.ITAM is the working system for that intake. It is a FedRAMP-authorized GRC platform, which means Class B/C work can be scoped, evidenced, scored, and reported in an environment already accepted for federal use. AITAMBot and Cybervisor® advisory sit on top of that stack so the package is built once and reused across FedRAMP, GovRAMP, NIST, CMMC, SOC 2, and related baselines instead of rebuilt for every auditor.

What CSPs Should Do This Week

The pipeline is live. The pipeline is live. CSPs pursuing Class B or Class C can now align their assessment and certification strategy with the new 20x model rather than treating it as a future transition.

  • Confirm the target class. B and C are different commitments.
  • Decide 20x versus the temporary Rev5 program lanes before you spend another month on the wrong package format.
  • Inventory inheritance. A Class B platform cannot carry a Class C offering.
  • Move evidence off shared drives and into automated collection.
  • Put OSCAL in the critical path now. January 1, 2027 is not a soft reminder.
  • Engage an accredited 3PAO before the first federal RFP asks which class you hold.

Lazarus Alliance has historically compressed FedRAMP assessment cycles by roughly 40–50% against traditional 3PAO timelines when the CSP is prepared and the package is automation-first. Native Class B/C intake is how that advantage is applied to 20x instead of to a dying Rev5 workflow.

Start Native Class B or Class C Intake

Do not wait for an agency to ask whether you are “still Moderate” or “already Class C.” The marketplace language has already changed. The intake path should match it.

To open a native FedRAMP 20x Class B or Class C engagement with Lazarus Alliance, contact us or call +1-888-896-7580.

Lazarus Alliance is a veteran-owned small business, A2LA-accredited FedRAMP 3PAO, authorized CMMC C3PAO, PCI DSS QSA, and Delaware CPA firm. Continuum GRC is the only FedRAMP-authorized AI GRC platform purpose-built for this work.

Frequently Asked Questions

FedRAMP Class C is the mid-level FedRAMP 20x certification class and replaces the former FedRAMP Moderate impact level. It is intended for cloud service offerings that require a higher level of security assurance than Class B and must satisfy the applicable Class C requirements established in FedRAMP's Consolidated Rules.

FedRAMP Class B updates what stakeholders previously referred to as the FedRAMP Low impact level. Organizations familiar with the legacy Low authorization model should not assume Class B is simply a renamed baseline; the FedRAMP 20x model introduces a substantially different approach to security evidence, verification, validation, and ongoing assurance.

FedRAMP Class C replaces the former FedRAMP Moderate impact level as the mid-level certification class under FedRAMP 20x. CSPs that historically would have pursued a Moderate authorization should evaluate whether Class C is the appropriate certification target under the new FedRAMP model.

The FedRAMP 20x Class B and Class C certification pipelines officially opened on August 31, 2026. FedRAMP began accepting applications for both certification classes on that date as part of its implementation of the Consolidated Rules for 2026.

Yes. FedRAMP Rev5 remains available during the transition period. FedRAMP states that it will stop accepting applications for new FedRAMP Rev5 Certifications on June 11, 2027. CSPs considering Rev5 should therefore evaluate the remaining certification window and the advantages of moving directly to the newer FedRAMP 20x model before investing in a legacy certification path.

FedRAMP Class B and Class C require independent assessment activities under the applicable FedRAMP certification rules. FedRAMP's rules establish independent verification and validation requirements and recognize FedRAMP Recognized independent assessment services, which include recognized Third Party Assessment Organizations (3PAOs). The specific assessment requirements depend on the certification class and path being pursued.

For a CSP, engaging a FedRAMP-recognized 3PAO early can also help ensure that system scope, security evidence, testing, verification, and validation are aligned with the targeted certification class before formal assessment begins.

A CSP should choose FedRAMP Class B or Class C based on the security requirements, information types, risk profile, federal customer requirements, and intended use of its cloud service offering. Class B corresponds to the lower-impact certification path, while Class C replaces the former Moderate impact level and provides a higher level of assurance.

The decision should be made early because the selected certification class affects the applicable FedRAMP requirements, security architecture, evidence, verification and validation activities, assessment scope, and ongoing compliance obligations. FedRAMP also permits providers to change certification classes, but upgrading requires a new certification application and satisfaction of the requirements for the target class.

About Lazarus Alliance

To learn more about how Lazarus Alliance can help, contact us.

                        • And dozens more!

                        Download our company brochure.

                        Lazarus Alliance

                        Website:

                        Michael Peters is a prominent cybersecurity expert and entrepreneur, serving as the CEO and founder of Lazarus Alliance, a proactive cybersecurity firm established in 2000, and Continuum GRC, a leading governance, risk, and compliance (GRC) software platform he launched in 2015.A U.S. Air Force veteran with early experience in defensive fire control systems, Peters holds an Executive Juris Doctor in Cyberspace Law, an MBA in IT Management, and numerous certifications including CISSP, CISM, CRISC, and QSA.Recognized as an industry disruptor, he has authored books, thousands of articles, and innovative tools like the IT Audit Machine, helping organizations worldwide achieve compliance and mitigate cyber risks. Based in Scottsdale, Arizona, Peters is also an ISSA Hall of Fame recipient dedicated to advancing information security excellence.