← All articles Compliance

FedRAMP Certification 2026: What Changes for GSA Schedule Cloud Sellers and When?

FedRAMP no longer "authorizes" cloud services. It certifies them, in Class A through D, under the Consolidated Rules for 2026 published on June 24, 2026. Those rules become mandatory January 1, 2027, and FedRAMP stops taking new Rev5 applications on June 11, 2027. If you sell cloud or SaaS on GSA MAS SIN 518210C, your federal buyers will start asking for your Class.

I spent 18 years as a Contracting Specialist and Contracting Officer at GSA, IRS, DoD, DOI, HHS, FTC, and Energy. What trips up Schedule holders is rarely the security program. It is the gap between the new rules and the buyer's RFQ language.

What did FedRAMP change in the Consolidated Rules for 2026?

FedRAMP replaced its labels, not its purpose. "Authorization" is now "Certification," the Low/Moderate/High baselines are now Certification Classes A through D, FedRAMP 20x is a full certification path instead of a pilot, FedRAMP Ready is retired, and certified providers owe a quarterly Ongoing Certification Report.

Old termNew term under the 2026 rules
FedRAMP Authorization / AuthorizedFedRAMP Certification / Certified
Third-Party Assessment Organization (3PAO)Independent assessor (FedRAMP Recognized)
Impact levels (Low, Moderate, High)Certification Classes (A, B, C, D)
FedRAMP ReadyLegacy FedRAMP Ready; new entrants go to 20x Class A
Continuous monitoring (ConMon)Collaborative Continuous Monitoring, with an Ongoing Certification Report every 3 months

FedRAMP defines a Certified offering as one that "meets the legal requirement to be FedRAMP authorized" under the FedRAMP Authorization Act, 44 U.S.C. 3607(b)(8) and 3608. An RFQ demanding "FedRAMP authorized" is satisfied by "FedRAMP Certified." Per NTC-0004, these rules run through December 31, 2028.

Do Classes A through D map one-for-one to Low, Moderate, and High?

Not exactly, and that nuance matters in a quote. For Rev5, FedRAMP said Class B covers the old LI-SaaS and Low baselines, Class C covers Moderate, and Class D covers High. Class A is new. FedRAMP also says a Class measures how much assurance evidence you supply, not how secure you are.

ClassRev5 equivalentFedRAMP's presumption for agency use
Class ANew (20x only; replaces Ready on the Marketplace)Pilots, configuration and testing, or negligible-risk use such as public information
Class BLI-SaaS and LowMost Low impact systems; some Moderate or High with compensating controls
Class CModerateMost Low or Moderate systems; some High with compensating controls
Class DHighMost agency systems regardless of impact level

FedRAMP's Certification Classes guidance tells agencies to categorize their own system under FIPS 199 first, then judge whether your package is enough. For the next year, write both labels in every quote: "FedRAMP Class C Certified (formerly Moderate)."

What are the FedRAMP deadlines cloud Schedule holders need on the calendar?

The two dates that drive decisions are January 1, 2027, when the rules become mandatory for everyone, and June 11, 2027, when FedRAMP stops accepting new Rev5 applications. Dates below come from FedRAMP's official timeline.

DateMilestoneStatus
July 28, 2026FedRAMP Ready goes Legacy; no new Ready submissionsPassed
August 3, 202620x Class A pipeline opensOpen
August 10, 2026Temporary Rev5 Program Certification (Ready Conversion, Lost Sponsor) opens for Class B and COpen
August 31, 202620x Class B and C pipelines openOpen
January 1, 2027Mandatory adoption for all stakeholdersUpcoming
February 19, 2027Ready Conversion and Lost Sponsor applicants must follow updated Rev5 rulesUpcoming
April 2, 2027Rev5 Collaborative Continuous Monitoring rules apply to maintaining certificationUpcoming
June 11, 2027No new Rev5 Certification applications acceptedUpcoming
October 1, 2027Rev5 grace period for Collaborative Continuous Monitoring endsUpcoming

Most summaries stop at January 1, 2027, but FedRAMP makes that date subject to area-specific effective dates. The Rev5 continuous monitoring rule carries its own April 2, 2027 date and October 1, 2027 grace period. No date has moved since launch.

What must a Rev5-certified provider on SIN 518210C do before January 1, 2027?

If you hold a Rev5 authorization at Low, Moderate, or High, you keep it. You now operate under the new rulebook: adopt the updated Rev5 rules, relabel your offering by Class, and issue an Ongoing Certification Report every three months.

  1. Confirm your Class on the FedRAMP Marketplace.
  2. Build the OCR. Every 3 months: changes and planned changes, accepted vulnerabilities, transformative changes, updated security recommendations, every agency directly using the product, and reportable incidents or an attestation of none.
  3. Schedule Quarterly Reviews. Class C and D providers MUST host one every 3 months. Class B SHOULD. Class A MAY. You must publish the next report date and the next review date.
  4. Update your sales materials. Capability statements, GSA Advantage descriptions, and quote templates should show the Class and legacy label side by side.

Your OCR agency list should reconcile with your Transactional Data Reporting, mandatory on SIN 518210C.

What if you are on the Schedule but not FedRAMP certified yet?

Start with 20x Class A. FedRAMP designed it for commercial products that already hold a SOC 2 Type II and a mature security program, and it requires no agency sponsor. Once a federal customer is using your service, you have 12 months to begin moving to Class B or higher.

FedRAMP will not issue Program Certifications for both 20x and Rev5, so pick one lane. It also warns against starting at Class C or D unless an agency contract already requires it.

How will agencies buying cloud through the Schedule treat the new Classes?

Ordering agencies still decide what they accept. The ordering Contracting Officer sets security requirements in the RFQ, and the agency's authorizing official decides whether your Certification Package fits its system. Expect Class A for pilots and low-risk work, and Class C or higher for most Moderate systems.

Here is the transition problem. GSA's Cloud SIN ordering guidance, last updated August 7, 2026, still tells buyers to verify an active FedRAMP authorization "at the required impact level (Low, Moderate, or High)." It also names the FedRAMP Marketplace as the final authority. Expect RFQs asking for "FedRAMP Moderate" while the Marketplace shows "Class C." Your quote has to bridge that gap.

When I sat in the Contracting Officer seat evaluating cloud quotes, the first thing I verified was Marketplace status, not the vendor's marketing language. As a Contracting Specialist, I watched evaluation panels lose days on one terminology mismatch between quote and requirement. Do not make the government translate for you.

Agencies now MUST review each Ongoing Certification Report against the risk accepted in their Authorization to Operate. Write your OCR like a deliverable, not a formality.

What should software resellers on SIN 511210 and SIN 518210C do?

Resellers do not hold the FedRAMP Certification; the manufacturer's cloud service offering does. Your job is to prove the product and edition you quote is the certified one, at the Class the buyer needs, and to keep that evidence current through 2027.

From the Contracting Officer side, reseller quotes usually failed on proof, not price: the quote never showed that the specific product and edition matched the Marketplace listing.

Does the Class you choose affect your GSA pricing?

It can. FedRAMP says lower-Class offerings are cheaper to procure and operate, and that many providers with strong security programs stop at Class A or B to keep government pricing aligned with commercial pricing. Higher Classes add recurring federal-only costs.

My take: do not buy a higher Class to win one order. Buy the Class your federal customers require. New to the Schedule? Read can SaaS and PaaS companies get on the GSA Schedule.

What should you do now?

Across 70+ GSA contract awards, the cloud contractors who win steady task orders are the ones whose paperwork matches the buyer's checklist on the first read. I hold a FAC-C Level III and a Harvard Master of Liberal Arts. If you want your Schedule catalog, pricing, and compliance calendar kept aligned with FedRAMP's new rules, our GSA Schedule maintenance program handles the modifications and reporting so your team can keep selling.

Frequently Asked Questions

Is a FedRAMP Certification the same as a FedRAMP authorization?

Yes. Under the Consolidated Rules for 2026, FedRAMP defines a FedRAMP Certified offering as one that meets the legal requirement to be FedRAMP authorized under 44 U.S.C. 3608. An RFQ requiring FedRAMP authorization is satisfied by a FedRAMP Certification.

When do the FedRAMP Consolidated Rules for 2026 become mandatory?

The rules become mandatory for all stakeholders on January 1, 2027. Some areas carry their own effective dates; for example, the Rev5 Collaborative Continuous Monitoring rules apply to maintaining certification on April 2, 2027, with a grace period ending October 1, 2027.

What is the last day to apply for a new FedRAMP Rev5 Certification?

FedRAMP will stop accepting applications for new Rev5 Certifications on June 11, 2027. The temporary Ready Conversion and Lost Sponsor pipelines close the same day.

Does FedRAMP Class C mean the same thing as FedRAMP Moderate?

For Rev5, FedRAMP said Class C includes the current Moderate baseline, so the requirements are essentially the same. FedRAMP also tells agencies not to treat Classes as one-for-one replacements for impact levels, because a Class measures assurance evidence rather than overall security. List both labels in your quotes during the transition.

What is an Ongoing Certification Report?

It is a human-readable report a FedRAMP Certified provider must deliver every three months. It summarizes changes, accepted vulnerabilities, the agencies using the product, and any reportable incidents or an attestation that none occurred.

Can a SaaS company on GSA MAS get FedRAMP certified without an agency sponsor?

Yes. FedRAMP 20x Class A, B, and C use Program Certification directly through FedRAMP, with no agency sponsor. Class A is designed for commercial products that already have a SOC 2 Type II, and once a federal customer uses the service, the provider has 12 months to begin moving to Class B or higher.

Does a GSA MAS contract require FedRAMP certification?

Security requirements are set by the ordering agency at the task order level. GSA's Cloud SIN ordering guidance tells buyers to prioritize FedRAMP solutions and confirm status on the FedRAMP Marketplace, so most production cloud orders will require it.

Work With a Former CO Who's Been There

Navigating GSA Schedule strategy doesn't have to be a guessing game. Book a free strategy call with Pedro and let's talk about where you stand.

Book a Free Consultation →