If you already hold a Federal Risk and Authorization Management Program (FedRAMP) authorization, the question we hear most is a direct one: what has changed and how do the changes apply to my organization? FedRAMP published CR26, the Consolidated Rules for 2026, on June 24, 2026, and a meaningful share of what changes for a Rev5 Provider comes from the program rules directly, not from adopting FedRAMP 20x.
This means, even if you’re on the Rev 5 path and not the 20x path, there are program rules that apply now. CR26 renames FedRAMP Authorization to FedRAMP Certification, replaces the Low, Moderate, and High categorization levels with Certification Classes B, C, and D, and adds a new Class A. It also moves vulnerability scanning from monthly to near continuous, tightens incident reporting windows, and eventually rebuilds your documentation stack around automated evidence. None of these waits for a decision about 20x.
Our FedRAMP assessment services team built this guide to present security, compliance, and engineering leaders at certified CSPs a clear picture: the new vocabulary mapped term by term, Certification Classes A through D, what applies to you if you stay on Rev5, minimum assessment scope and significant change notification, how your assessment changes under Independent Verification and Validation (IV&V), and dated deadlines from January 2026 through 2028.
Rev5 is not retiring at the end of 2027 for already certified cloud solutions. It remains available on an ongoing basis through December 31, 2028. But CR26 introduces new rules that will impact your system, posture, package, and assessment going forward. Take advantage to plan and transition meaningfully.
Download the guide below for a practical reference as you plan ahead.