For a long time, when someone has asked me if they should get FedRAMP, my answer has been the same:

No!
FedRAMP has been a challenging compliance regime for small and midsize businesses. It’s frighteningly expensive to earn, requires large security capability, and offers a low return on the investment, unless they do a lot of government work.
Maybe the folks at FedRAMP have been listening because on June 24 this year, they announced changes that will make it all start working.
FedRAMP’s new Consolidated Rules includes an entry-level tier called Class A. It lets a cloud service provider get FedRAMP Certified using a SOC 2 Type II report the company already holds, with no agency sponsor and no independent assessment of the FedRAMP package itself. The rules went into effect on July 4 for early adopters, and the application pipeline for Class A opens August 3, 2026.
While FedRAMP used to be unreasonably expensive for midsize companies, it’s now easily within reach. Beyond the SOC 2 Type II requirement, FedRAMP Class A provides an additional 23 mandatory rules, a quarterly reporting commitment that never ends, and a two-year expiration date. Let’s take a look at what you would actually be signing up for.
What FedRAMP Class A Actually Is
Class A is the lowest of four new certification classes. The 2026 rules retired the old Low, Moderate, and High impact-level labels in favor of Class A through Class D, defined as increasing categories of assurance from minimal at Class A to significant at Class D.
Two things make Class A different from everything that came before it.
First, it runs on the Program Certification path. FedRAMP certifies you directly, and no federal agency has to sponsor you first. That single change matters more than everything else combined. The sponsor requirement is what killed most of my FedRAMP conversations with mid-size companies, because you cannot get a sponsor without a federal customer and you cannot get a federal customer without a certification. FedRAMP used to have a “chicken or the egg” problem, but not anymore.
Does your company’s ICP include government agencies? Get FedRAMP Class A first!
Second, it builds on your existing cybersecurity compliance program. To qualify, you must have completed a certification or equivalent process, including an independent assessment where applicable, under one of three frameworks within the past 12 months: FedRAMP Rev5 (including the old FedRAMP Ready status) at any historical impact level, SOC 2 Type II, or GovRAMP, also at any impact level.
The inclusion of SOC 2 is the real win here. SOC 2 is much more affordable for midsize companies. Many already have one. Or, new companies can choose the path of getting FedRAMP Class A through SOC 2, rather than immediately pursuing FedRAMP directly.
What Your SOC 2 Report Has to Include
Not just any SOC 2 report is enough. FedRAMP wants to see a SOC 2 Type II with some additions.
Specifically, you need to provide your complete report, a bridge or gap letter if you have one, verified audit engagement documentation, the estimated schedule for your next report, and supplemental compliance evidence where applicable.
“Verified audit engagement documentation” is the phrase to pay attention to. FedRAMP is checking who signed your report, what the engagement actually covered, and whether that scope matches what you plan to sell to the government. A SOC 2 drawn narrowly around one product line will not carry a certification for your whole platform. Likewise, FedRAMP may reject reports from unreputable auditors.
FedRAMP also tells providers, in plain language, that pointing at the report is not an answer. Reviewers should not have to dig through your framework materials to understand your decisions, and “see SOC 2 report” does not count as a response.
That translation work is the real labor in a Class A package. It is also where the rule count starts to matter.
The 23 Mandatory Rules
Class A is not “submit your SOC 2 and wait for a FedRAMP certificate.” Beyond the Class A rules themselves, FedRAMP names a set of additional mandatory rules you must address, with the appropriate artifacts or information mapping supplied for every one of them in your certification package.
FedRAMP’s enumerated list runs to 25 items, but two of them fall away for a company coming in through SOC 2. One is a rule about annual assessments under Rev5, which does not apply if you are not a Rev5 provider. The other is availability reporting, which FedRAMP lists as mandatory in one place and as recommended in another, and the rule text itself says “should.”
FedRAMP’s own generated rule list for Class A drops both.
That leaves 23 that actually apply to you, and I would still do the availability one. (I counted three times and then had someone else count. This is what compliance work is really like.)
The 23 sort into three practical groups. The first covers the package and its format:
- FRC-CSO-PKG (the package). Your certification package includes a Certification Package Overview, a Security Decision Record, and either a real or an example Ongoing Certification Report.
- FRC-CSO-JSN (machine-readable everything). Wherever a rule has a FedRAMP JSON schema, you supply valid JSON (JavaScript Object Notation, a structured data format machines can parse) against it.
- FRC-CSO-POP (pick one). You cannot pursue both Rev5 and 20x Program Certification for the same offering. Choose.
- MAS-CSO-IIR (identify your information resources). You define the set of resources that are likely to handle federal customer data or affect its confidentiality, integrity, or availability. That set becomes your cloud service offering for FedRAMP purposes.
The Security Decision Record replaces the traditional System Security Plan, and it is more demanding than it sounds.
For each applicable rule, you must document
- How you follow it (or why you don’t and what risk that creates for customers)
- Your own verification and validation
- Independent verification and validation (where applicable)
- Any responses to assessor comments
- The supporting artifacts.
If your compliance program currently lives in spreadsheets, word documents, cloud drives, or an external compliance automation tool, the JSON requirement is your biggest surprise. Plan time to translate everything into the right format!
The Seven Key Security Indicators
Key Security Indicators (KSIs) are FedRAMP 20x’s replacement for control narratives. Instead of writing prose about hundreds of individual NIST controls, you demonstrate outcomes. Class A requires seven of them:
- Logging changes (KSI-CMT-LMC). Modifications to your cloud service offering are logged and monitored.
- Restricting network traffic (KSI-CNA-RNT). Machine-based resources are persistently reviewed to confirm they are configured to limit inbound and outbound traffic.
- Reviewing all training (KSI-CED-RAT). You review the effectiveness of your security training, including general training for everyone, role-specific training for high-risk roles, secure software delivery training for engineering staff, and training for anyone involved in incident response or disaster recovery.
- Automating account management (KSI-IAM-AAM). The lifecycle and privileges of all accounts, roles, and groups are securely managed using automation.
- Adopting passwordless methods (KSI-IAM-APM). Secure passwordless authentication where feasible, and strong passwords with phishing-resistant multi-factor authentication everywhere else.
- Reviewing incident response procedures (KSI-INR-RIR). You review the effectiveness of your documented incident response procedures.
- Securing information (KSI-SVC-SIN). Information is encrypted or otherwise protected from unwanted access or modification.
There are two specific requirements here stricter than SOC 2, so companies coming from SOC 2 must improve their program to meet them.
Account management is the first. A quarterly access review spreadsheet passes a SOC 2 audit all day long, but FedRAMP expects automated controls.
The second is passwordless and phishing-resistant multi-factor authentication. SMS one-time codes and push notifications are not considered phishing-resistant! You need to use stronger multi-factor authentication methods, such as an authenticator app.
The Publishing, Reachability, and Reporting Rules
The remaining 12 mandatory rules aren’t about how secure your product or environment is. Instead, they are about how you publish your security information, how reachable you are for the government, and how you report incidents.
You have to publish. CDS-CSO-PUB requires 16 specific data points about your offering to be publicly available in both human-readable and JSON formats, including your UEI number from SAM.gov, a detailed list of your individual services with their security categories, a link to your secure configuration guidance, and the date of your next Ongoing Certification Report. CDS-CSO-UTC requires a FedRAMP-compatible trust center to store and share your certification data. CDS-UTC-AAD gives you five business days to notify FedRAMP if you deny an agency’s request for access to that data.
Separately, FedRAMP recommends an availability status page covering at least the past 30 days, in both human-readable and machine-readable form, ideally hosted so it stays up when your product goes down. That one is a “should” rather than a “must,” but it’s worth building anyways.
You have to be reachable. The three Addressing FedRAMP Communication rules require:
- A dedicated FedRAMP Security Inbox
- The ability to receive and act on FedRAMP email without any extra steps on their end
- Completion of required actions in Emergency or Emergency Test messages within the stated timeframe
No CAPTCHAs, no support portal logins, no ticketing system that swallows the message. FedRAMP wants to be able to reach you directly, without a hassle. Note: don’t use an individual’s email inbox even if they own the process. Personnel change!
For reporting, you of course have to report incidents. You must promptly evaluate whether an incident affects, or is likely to affect, the confidentiality or integrity of federal customer data.
If it affects federal customer data, then it’s a FedRAMP Reportable Incident. Class A providers owe a Final Incident Report within three business days of recovery at every severity level.
Initial reports (within six hours at the higher severity ratings) and ongoing reports are recommended rather than required at Class A. If you will eventually need a higher Class of FedRAMP authorization, you should build the initial reporting muscle now.
You also have to hunt for vulnerabilities broadly. VDR-CSO-DET expects systematic, persistent, prompt discovery through whatever combination of scanning, threat intelligence, disclosure programs, penetration testing, and automated control testing fits your environment. FedRAMP is explicit that this reaches past software vulnerabilities: an out-of-date control statement in your Security Decision Record counts as a vulnerability that must be found and fixed.
The reporting never stops. Every three months an Ongoing Certification Report goes to all necessary parties, covering eight required topics: recent changes, planned changes, transformative changes, accepted vulnerabilities, updated security recommendations, the agencies using your product, reportable incidents (or an attestation that you had none), and the target date of the next report.
Finally, the Independent Verification and Validation rule means something specific at Class A: your underlying framework is your ongoing assessment. Let your SOC 2 lapse and the foundation of your certification goes with it.
The Application Process and the Timing
Here is the sequence, in order:
1. Get listed on the Marketplace first. Initial Implementation Phase listings opened July 6, 2026. You request one through the Marketplace Provider Listing Request Form.
2. Demonstrate an agency use case. Either direct use, where an agency integrates your product into a federal information system that will receive an Authorization to Operate. Or indirect use, where you sit inside another provider’s certified offering. Services that private companies buy to satisfy other regimes like CMMC do not qualify.
3. Demonstrate continuous progress. You document your goals and milestones in your trust center or on your website and update them at least quarterly.
4. Apply yourself. The FedRAMP Certification Application Form must be completed in full, and you must submit it. Assessors and advisors cannot apply on your behalf. They can absolutely help you prepare the materials.
5. Submit a fresh package. Your package has to reflect the current status of your offering as verified and validated by you within the previous seven days. Do not let a finished submission sit in someone’s inbox for two weeks!
6. Decide whether you want an independent review. Class A providers may have the package independently verified and validated by a FedRAMP Recognized assessor before submission, and may supply a fresh FedRAMP independent assessment completed within the previous three months.
You probably don’t want the independent review. The reviews are expensive and keeping them optional is what makes Class A affordable. But you do want to make sure your FedRAMP Class A Package is accurate, so it’s worth getting an experienced compliance person to work on your package.
Then you wait, but not long. FedRAMP describes itself as “a small tight-knit team of gentle humans” and states an internal goal of an initial decision within 30 days of receiving an application. There is no service level agreement, and the clock stops whenever they are waiting on you. Expect a deep dive call on your Certification Package Overview and Security Decision Record, and make your team available quickly when they ask!
FedRAMP Class A Cost
What should you budget? Nobody knows yet. The pipeline opens next week, so anyone quoting you a confident Class A number is guessing.
Here is what we can say. Your SOC 2 Type II keeps costing what it costs, which for a 150-person company typically runs $25,000 plus or minus $5,000 for the audit itself. The Class A work sits on top of that, and it is likely a five-figure number rather than a six- or seven-figure one.
Where you land inside those five figures depends almost entirely on how good your existing cybersecurity program already is. A company that automates account provisioning, uses phishing-resistant multi-factor authentication, and already publishes a status page is mostly doing paperwork.
A company that has to do an initial buildout will of course cost more. Figure low six figures for your first SOC 2 Type II, then the cost for FedRAMP on top of it. Still cheaper than it used to be!
The Two-Year Catch
Class A is temporary by design.
The program said during the public comment process that Class A certifications are intended to be transitory and replaced by a Class B, C, or D certification that addresses all relevant FedRAMP rules. At that point, no reciprocity from your external framework is intended or will be granted.
The Marketplace rules put a deadline on it: you must show that an assessment for Class B, C, or D has been scheduled within two years of your initial Initial Implementation Phase listing, or FedRAMP removes your listing until you produce evidence of a scheduled assessment.
That window was originally one year, and FedRAMP extended it to two in response to public comment, with some flexibility around assessor scheduling.
So the obvious objection: is Class A just a two-year trial that dumps you back into the seven-figure project you were trying to avoid?
Roughly, yes. And it is still worth doing, for two reasons:
First, you get to find out whether federal revenue is real for your company before you spend significant money. Two years of agency sales conversations is a far better basis for that decision than vibes about a market you have never sold into.
Second, nothing you build for Class A gets thrown away. The trust center, the JSON artifacts, the Security Decision Record, the quarterly reporting rhythm, the seven Key Security Indicators: all of it is the foundation of a Class B or Class C package. You are not renting the work. You are paying for the first phase of it, and finding out early whether phase two is worth funding.
Who Should Pursue FedRAMP Class A
Do you have a cloud service you want to sell into federal government agencies? Class A is a great place to start. Especially if you already have a SOC 2 Type II, as long as your SOC 2 boundary covers what you would actually sell to a federal agency.
If you don’t have a SOC 2 yet or the boundary doesn’t cover it, you should prepare for a SOC 2 audit that covers the service you want to sell to the government. Then go for Class A on the back of your new SOC 2 report.
I expect that FedRAMP Class A will change the game for FedRAMP. It is going to become much more common.
___
Curious about taking the first step for FedRAMP or SOC 2? The Fractional CISO Team and I are here to help! Learn more about our FedRAMP and SOC 2 services at those links. And reach out if you have questions about the process.