FedRAMP 20x Readiness and Independent Assessments
FedRAMP 20x modernizes federal cloud security certification through measurable security outcomes, persistent verification, machine-readable information, and greater reliance on automation.
The FedRAMP Consolidated Rules for 2026 establish the applicable requirements. Cloud service providers should use those rules, rather than assumptions carried over from legacy FedRAMP processes, to select a certification class and prepare their cloud service offering.
Understanding FedRAMP 20x
FedRAMP 20x organizes certification requirements around Key Security Indicators, or KSIs. KSIs describe security capabilities that providers must address through documented measures, evidence, verification, validation, and applicable historical metrics.
Automation is central to this model, but FedRAMP 20x does not prescribe a single tool, implementation, or compliance platform for every provider. The required evidence and validation approach depend on the certification class and the provider’s cloud architecture.
FedRAMP currently supports:
- Class A: An entry point for services with mature security and compliance programs based on an eligible alternative security framework.
- Class B: Intended for common, smaller-scale, or lighter-use cloud services.
- Class C: Intended for common enterprise services and services supporting important government functions.
- Class D: Planned for higher-assurance services, with detailed requirements being developed through the Phase 4 pilot.
Providers should confirm current availability and requirements directly through FedRAMP because the program continues to evolve.
Defining the Assessment Scope
A provider must identify the information resources included within its FedRAMP Minimum Assessment Scope. This scope includes resources likely to:
- Handle federal customer data.
- Affect the confidentiality, integrity, or availability of federal customer data.
- Provide security functions for the cloud service offering.
- Support connections or dependencies relevant to the offering’s security.
A clear boundary is essential. Omitting relevant services, inherited capabilities, administrative systems, or third-party resources can make the certification package incomplete. An unnecessarily broad boundary can increase assessment complexity without improving assurance.
Security Decision Records
For Classes B and C, the Security Decision Record replaces the traditional narrative-heavy system security plan with a persistently maintained record of the provider’s security decisions.
For each applicable KSI, the record should explain:
- The measures used to demonstrate the required security capability.
- The objectives of those measures.
- How frequently persistent measures operate.
- How the provider verifies the measures and supporting automation.
- How the provider validates that the measures work as intended.
- Any accepted exceptions, limitations, or residual risks.
The record must remain accurate as the service, architecture, dependencies, and security measures change.
Persistent Validation and Metrics
FedRAMP 20x expects providers to produce evidence that reflects the service’s current security posture rather than relying entirely on point-in-time documentation.
Class B and Class C providers must maintain historical KSI metrics. Class C applicants must also supply at least six months of historical metrics from persistent validation and implement the automated verification and validation methods required by the applicable rules.
This does not create a universal requirement for 24-hour scanning under CA-7, nor does it mean every security activity must occur on the same schedule. Providers must follow the specific FedRAMP rule, KSI, frequency, and reporting requirement applicable to their certification class.
Independent Assessment Requirements
Providers seeking Class B or Class C certification must submit an initial independent assessment completed by a FedRAMP Recognized independent assessment service within the period specified by FedRAMP. The current certification rules require that assessment to have been completed within the previous three months.
Class B and Class C providers must also include all applicable KSIs in a FedRAMP independent assessment at least annually.
Independent assessors must:
- Verify that implemented measures match the provider’s documented measures.
- Validate that those measures produce the intended security outcomes.
- Examine relevant technical evidence rather than relying only on narratives or screenshots.
- Document assessment results, failures, and areas of dispute.
- Verify that assessment information is included accurately in the certification package.
The cloud service provider remains responsible for applying for certification. An independent assessor cannot submit the application on the provider’s behalf.
Relationship to Other Frameworks
Existing evidence from NIST SP 800-53, SOC 2, ISO 27001, CMMC, NIST SP 800-171, or other programs may help a provider understand its security environment. However, those frameworks do not automatically satisfy FedRAMP 20x.
FedRAMP 20x does not universally require explicit CMMC Level 2 or NIST SP 800-171 mappings. Any cross-framework mapping should be presented as an efficiency opportunity, not as a FedRAMP requirement unless the official rules or a separate contractual obligation establish it.
How Lazarus Alliance Can Help
Lazarus Alliance is listed in the official FedRAMP Marketplace as a FedRAMP Recognized independent assessment service.
Within the bounds of assessor independence, Lazarus Alliance can perform the verification and validation activities required for an eligible FedRAMP assessment. Assessment scope, timing, certification class, evidence expectations, and independence considerations should be confirmed before the engagement begins.
FedRAMP rules prohibit an assessor from assessing the same cloud service offering within two years after providing advisory or consulting services to that offering, unless FedRAMP publishes a specific exception. Organizations should therefore distinguish readiness consulting from independent assessment services when selecting service providers.
Authoritative Sources
- FedRAMP 20x overview
- FedRAMP Consolidated Rules for 2026
- Security Decision Record requirements
- Independent verification and validation
- FedRAMP certification requirements
- Lazarus Alliance’s FedRAMP Marketplace listing
About Lazarus Alliance
To learn more about how Lazarus Alliance can help, contact us.
- FedRAMP
- GovRAMP
- NIST 800-53
- DFARS NIST 800-171
- CMMC
- SOC 1 & SOC 2
- C5
- HIPAA, HITECH, & Meaningful Use
- PCI DSS RoC & SAQ
- IRS 1075 & 4812
- CJIS
- LA DMF
- ISO 27001, ISO 27002, ISO 27005, ISO 27017, ISO 27018, ISO 27701, ISO 22301, ISO 17020, ISO 17021, ISO 17025, ISO 17065, ISO 9001, & ISO 90003
- And dozens more!




Related Posts