FedRAMP Resources
Selling cloud software to the United States federal government requires a FedRAMP Certified designation. What has changed, and changed substantially, is how a provider obtains one.
What 20x changes for a smaller provider
The traditional route required an agency sponsor before the security work began, which left small providers with no federal relationship stuck: agencies wanted vendors already in the program, and getting into the program required an agency. FedRAMP 20x removes that dependency. A provider can pursue the designation, appear on the Marketplace, and approach agencies with a package already in hand.
The second change is an engineering one. 20x is built around key security indicators with heavy emphasis on automated, machine-verifiable validation, so strong technical writing no longer compensates for weak automation. Producing reliable evidence directly from your environment is not overhead alongside the compliance work. Increasingly it is the compliance work.
Two things to hold onto. Rev5 and 20x are separate paths, chosen one per cloud service offering, and the Certification Classes are split across them rather than forming one ladder. And a program listing is not an agency Authorization to Operate: every agency still issues its own. Requirements here change, so confirm the current ones directly with FedRAMP before committing to a plan.

FedRAMP 20x for Small Businesses
A 50-page booklet for small and mid-size cloud service providers weighing whether and how to enter the federal market. Free, and delivered as a PDF.
What is inside
- How the 20x path works end to end, and where it differs from the sponsored route
- What a security package has to contain, and what evidence has to stand behind each claim
- Where the automation requirements bite hardest for a small engineering team
- The decisions that determine cost and schedule, including boundary definition and categorization
- What continues after a listing is granted, and why continuous monitoring is an operating state rather than a project
Get your copy
Worth reading first
Primary sources and one explainer of our own. Useful whether or not you request the booklet.
The FedRAMP 20x program page
The program’s own description of 20x, including how it is being phased in. Requirements here have changed more than once, and this is the source that changes with them. Check it before committing to a plan rather than relying on a summary written months ago.
The FedRAMP Marketplace
The public list of cloud service offerings and their current status, along with the assessors and advisors working in the program. It is the fastest way to see what a comparable provider in your category has done and how their listing is described.
NIST SP 800-53 Revision 5
The control catalog every federal security baseline draws from. You do not implement all of it. Reading the control families relevant to your architecture is the cheapest way to understand what a security package will actually ask you to evidence.
FedRAMP Certification Paths: Agency Sponsorship and the Alternatives
Our own explainer on how the sponsored route compares to 20x, why an agency Authorization to Operate is a separate thing from a program listing, and what holds true whichever path you take.
Verdict FedRAMP advisory services
What we do for clients across federal authorization, commercial assurance, and AI governance, the specific documents and records we produce and maintain, and where our work stops and an independent assessor’s begins.