FedRAMP no longer "authorizes" cloud services. It certifies them, in Class A through D, under the Consolidated Rules for 2026 published on June 24, 2026. Those rules become mandatory January 1, 2027, and FedRAMP stops taking new Rev5 applications on June 11, 2027. If you sell cloud or SaaS on GSA MAS SIN 518210C, your federal buyers will start asking for your Class.
I spent 18 years as a Contracting Specialist and Contracting Officer at GSA, IRS, DoD, DOI, HHS, FTC, and Energy. What trips up Schedule holders is rarely the security program. It is the gap between the new rules and the buyer's RFQ language.
What did FedRAMP change in the Consolidated Rules for 2026?
FedRAMP replaced its labels, not its purpose. "Authorization" is now "Certification," the Low/Moderate/High baselines are now Certification Classes A through D, FedRAMP 20x is a full certification path instead of a pilot, FedRAMP Ready is retired, and certified providers owe a quarterly Ongoing Certification Report.
| Old term | New term under the 2026 rules |
|---|---|
| FedRAMP Authorization / Authorized | FedRAMP Certification / Certified |
| Third-Party Assessment Organization (3PAO) | Independent assessor (FedRAMP Recognized) |
| Impact levels (Low, Moderate, High) | Certification Classes (A, B, C, D) |
| FedRAMP Ready | Legacy FedRAMP Ready; new entrants go to 20x Class A |
| Continuous monitoring (ConMon) | Collaborative Continuous Monitoring, with an Ongoing Certification Report every 3 months |
FedRAMP defines a Certified offering as one that "meets the legal requirement to be FedRAMP authorized" under the FedRAMP Authorization Act, 44 U.S.C. 3607(b)(8) and 3608. An RFQ demanding "FedRAMP authorized" is satisfied by "FedRAMP Certified." Per NTC-0004, these rules run through December 31, 2028.
Do Classes A through D map one-for-one to Low, Moderate, and High?
Not exactly, and that nuance matters in a quote. For Rev5, FedRAMP said Class B covers the old LI-SaaS and Low baselines, Class C covers Moderate, and Class D covers High. Class A is new. FedRAMP also says a Class measures how much assurance evidence you supply, not how secure you are.
| Class | Rev5 equivalent | FedRAMP's presumption for agency use |
|---|---|---|
| Class A | New (20x only; replaces Ready on the Marketplace) | Pilots, configuration and testing, or negligible-risk use such as public information |
| Class B | LI-SaaS and Low | Most Low impact systems; some Moderate or High with compensating controls |
| Class C | Moderate | Most Low or Moderate systems; some High with compensating controls |
| Class D | High | Most agency systems regardless of impact level |
FedRAMP's Certification Classes guidance tells agencies to categorize their own system under FIPS 199 first, then judge whether your package is enough. For the next year, write both labels in every quote: "FedRAMP Class C Certified (formerly Moderate)."
What are the FedRAMP deadlines cloud Schedule holders need on the calendar?
The two dates that drive decisions are January 1, 2027, when the rules become mandatory for everyone, and June 11, 2027, when FedRAMP stops accepting new Rev5 applications. Dates below come from FedRAMP's official timeline.
| Date | Milestone | Status |
|---|---|---|
| July 28, 2026 | FedRAMP Ready goes Legacy; no new Ready submissions | Passed |
| August 3, 2026 | 20x Class A pipeline opens | Open |
| August 10, 2026 | Temporary Rev5 Program Certification (Ready Conversion, Lost Sponsor) opens for Class B and C | Open |
| August 31, 2026 | 20x Class B and C pipelines open | Open |
| January 1, 2027 | Mandatory adoption for all stakeholders | Upcoming |
| February 19, 2027 | Ready Conversion and Lost Sponsor applicants must follow updated Rev5 rules | Upcoming |
| April 2, 2027 | Rev5 Collaborative Continuous Monitoring rules apply to maintaining certification | Upcoming |
| June 11, 2027 | No new Rev5 Certification applications accepted | Upcoming |
| October 1, 2027 | Rev5 grace period for Collaborative Continuous Monitoring ends | Upcoming |
Most summaries stop at January 1, 2027, but FedRAMP makes that date subject to area-specific effective dates. The Rev5 continuous monitoring rule carries its own April 2, 2027 date and October 1, 2027 grace period. No date has moved since launch.
What must a Rev5-certified provider on SIN 518210C do before January 1, 2027?
If you hold a Rev5 authorization at Low, Moderate, or High, you keep it. You now operate under the new rulebook: adopt the updated Rev5 rules, relabel your offering by Class, and issue an Ongoing Certification Report every three months.
- Confirm your Class on the FedRAMP Marketplace.
- Build the OCR. Every 3 months: changes and planned changes, accepted vulnerabilities, transformative changes, updated security recommendations, every agency directly using the product, and reportable incidents or an attestation of none.
- Schedule Quarterly Reviews. Class C and D providers MUST host one every 3 months. Class B SHOULD. Class A MAY. You must publish the next report date and the next review date.
- Update your sales materials. Capability statements, GSA Advantage descriptions, and quote templates should show the Class and legacy label side by side.
Your OCR agency list should reconcile with your Transactional Data Reporting, mandatory on SIN 518210C.
What if you are on the Schedule but not FedRAMP certified yet?
Start with 20x Class A. FedRAMP designed it for commercial products that already hold a SOC 2 Type II and a mature security program, and it requires no agency sponsor. Once a federal customer is using your service, you have 12 months to begin moving to Class B or higher.
- 20x Class A, B, C: Program Certification directly from FedRAMP, no sponsor. Class A accepts a completed Readiness Assessment Report or a SOC 2 Type II.
- 20x Class D: FedRAMP expects a pilot in late 2026 and formal availability in early 2027.
- Rev5 Agency Certification: Still generally requires a sponsoring agency. File before June 11, 2027, or plan on 20x.
- Rev5 Ready Conversion or Lost Sponsor: Only for providers that achieved Ready, completed a RAR, or lost an In Process sponsor between January 2025 and March 2026. Closes June 11, 2027.
FedRAMP will not issue Program Certifications for both 20x and Rev5, so pick one lane. It also warns against starting at Class C or D unless an agency contract already requires it.
How will agencies buying cloud through the Schedule treat the new Classes?
Ordering agencies still decide what they accept. The ordering Contracting Officer sets security requirements in the RFQ, and the agency's authorizing official decides whether your Certification Package fits its system. Expect Class A for pilots and low-risk work, and Class C or higher for most Moderate systems.
Here is the transition problem. GSA's Cloud SIN ordering guidance, last updated August 7, 2026, still tells buyers to verify an active FedRAMP authorization "at the required impact level (Low, Moderate, or High)." It also names the FedRAMP Marketplace as the final authority. Expect RFQs asking for "FedRAMP Moderate" while the Marketplace shows "Class C." Your quote has to bridge that gap.
When I sat in the Contracting Officer seat evaluating cloud quotes, the first thing I verified was Marketplace status, not the vendor's marketing language. As a Contracting Specialist, I watched evaluation panels lose days on one terminology mismatch between quote and requirement. Do not make the government translate for you.
Agencies now MUST review each Ongoing Certification Report against the risk accepted in their Authorization to Operate. Write your OCR like a deliverable, not a formality.
What should software resellers on SIN 511210 and SIN 518210C do?
Resellers do not hold the FedRAMP Certification; the manufacturer's cloud service offering does. Your job is to prove the product and edition you quote is the certified one, at the Class the buyer needs, and to keep that evidence current through 2027.
- Know which SIN fits. SIN 511210 (NAICS 513210) covers software licenses and maintenance. GSA encourages offering SaaS on SIN 518210C; see our breakdown of 518210C vs. 511210 vs. 54151S.
- Keep a Marketplace record per product. Save the listing, the Class, and the legacy baseline for every cloud offering on your price list.
- Get OEM confirmation in writing on its Class and its 20x-versus-Rev5 plan.
- Flag Legacy Ready products. Legacy FedRAMP Ready is not a certification. Expect agencies to pass on those for production use.
From the Contracting Officer side, reseller quotes usually failed on proof, not price: the quote never showed that the specific product and edition matched the Marketplace listing.
Does the Class you choose affect your GSA pricing?
It can. FedRAMP says lower-Class offerings are cheaper to procure and operate, and that many providers with strong security programs stop at Class A or B to keep government pricing aligned with commercial pricing. Higher Classes add recurring federal-only costs.
- Document the delta. If your certified edition costs more to run than your commercial edition, show why before you negotiate with your GSA Contracting Officer.
- Know the ordering tools. GSA points buyers to Requirements Task Orders under GSAR 552.238-199 for consumption-based cloud, placed under FAR subpart 8.4.
My take: do not buy a higher Class to win one order. Buy the Class your federal customers require. New to the Schedule? Read can SaaS and PaaS companies get on the GSA Schedule.
What should you do now?
- This week: Record your Class next to your legacy baseline.
- By November 2026: Rewrite capability statements, GSA Advantage descriptions, and quote templates to show "Class X (formerly Low/Moderate/High)."
- Before January 1, 2027: Adopt the Consolidated Rules for 2026 and build your first Ongoing Certification Report and Quarterly Review schedule.
- If you are uncertified: Apply for 20x Class A using your SOC 2 Type II, or file a Rev5 package well before June 11, 2027.
- Every quarter: Reconcile your OCR agency list with TDR.
Across 70+ GSA contract awards, the cloud contractors who win steady task orders are the ones whose paperwork matches the buyer's checklist on the first read. I hold a FAC-C Level III and a Harvard Master of Liberal Arts. If you want your Schedule catalog, pricing, and compliance calendar kept aligned with FedRAMP's new rules, our GSA Schedule maintenance program handles the modifications and reporting so your team can keep selling.
Frequently Asked Questions
Is a FedRAMP Certification the same as a FedRAMP authorization?
Yes. Under the Consolidated Rules for 2026, FedRAMP defines a FedRAMP Certified offering as one that meets the legal requirement to be FedRAMP authorized under 44 U.S.C. 3608. An RFQ requiring FedRAMP authorization is satisfied by a FedRAMP Certification.
When do the FedRAMP Consolidated Rules for 2026 become mandatory?
The rules become mandatory for all stakeholders on January 1, 2027. Some areas carry their own effective dates; for example, the Rev5 Collaborative Continuous Monitoring rules apply to maintaining certification on April 2, 2027, with a grace period ending October 1, 2027.
What is the last day to apply for a new FedRAMP Rev5 Certification?
FedRAMP will stop accepting applications for new Rev5 Certifications on June 11, 2027. The temporary Ready Conversion and Lost Sponsor pipelines close the same day.
Does FedRAMP Class C mean the same thing as FedRAMP Moderate?
For Rev5, FedRAMP said Class C includes the current Moderate baseline, so the requirements are essentially the same. FedRAMP also tells agencies not to treat Classes as one-for-one replacements for impact levels, because a Class measures assurance evidence rather than overall security. List both labels in your quotes during the transition.
What is an Ongoing Certification Report?
It is a human-readable report a FedRAMP Certified provider must deliver every three months. It summarizes changes, accepted vulnerabilities, the agencies using the product, and any reportable incidents or an attestation that none occurred.
Can a SaaS company on GSA MAS get FedRAMP certified without an agency sponsor?
Yes. FedRAMP 20x Class A, B, and C use Program Certification directly through FedRAMP, with no agency sponsor. Class A is designed for commercial products that already have a SOC 2 Type II, and once a federal customer uses the service, the provider has 12 months to begin moving to Class B or higher.
Does a GSA MAS contract require FedRAMP certification?
Security requirements are set by the ordering agency at the task order level. GSA's Cloud SIN ordering guidance tells buyers to prioritize FedRAMP solutions and confirm status on the FedRAMP Marketplace, so most production cloud orders will require it.