There are few compliance programs whose decisions ripple through the security industry quite like FedRAMP.
FedRAMP sits at the intersection of the federal government, cloud providers, security assessors, software vendors, consultants, and some of the largest technology companies in the world. Its importance to the broader compliance ecosystem is difficult to overstate.
So when FedRAMP changes how it thinks about assurance, the rest of us should pay attention.
GRC engineers should be paying particularly close attention.
FedRAMP 20x is here, and the direction it is taking looks remarkably similar to the direction GRC Engineering has been arguing the profession needs to go: away from compliance built primarily around documents, screenshots, and point-in-time evidence, and toward systems that can produce, validate, and communicate assurance continuously.
That does not mean traditional compliance disappears tomorrow. It does mean one of the most influential assurance programs in the world is giving us a pretty good glimpse of what may come next.
Making FedRAMP More Approachable
One of the most interesting changes is the introduction of certification classes.
Class A is the simplest place to see the new outcome-focused approach in action. FedRAMP describes it as a smaller reference that emphasizes essential expectations and measurable security outcomes instead of large documentation packages.
Class B goes further. Historical KSI metrics become required in the Security Decision Record, and the rules increase expectations around ongoing assurance. FedRAMP says Class B providers should implement automated methods to persistently verify and validate KSIs, with at least one automated method for each KSI.
Class C extends the model for Moderate services with still stronger persistent validation and automation requirements. Class D, the future path for High services, is planned for a later pilot.
The result is a more progressive path into the FedRAMP ecosystem. But making FedRAMP more approachable should not be confused with simply making compliance easier.
The bigger change is how assurance is demonstrated.
The Evidence Is Changing
This is where GRC engineers should really start paying attention.
A FedRAMP 20x certification package includes a maintained Security Decision Record, Key Security Indicators, ongoing certification data, and other information used to support security decisions. The Security Decision Record replaces the traditional System Security Plan with a record that is persistently maintained, verified, and validated. It must be available in both human-readable and JSON formats for the classes where it is required.
That is a very different mental model for compliance.
| Traditional Evidence Model | 20x Direction |
|---|---|
| Collect a screenshot | Query or generate current state |
| Upload evidence | Maintain certification data |
| Describe a control | Demonstrate a security outcome |
| Review periodically | Verify persistently where required |
| Human-readable documents | Human and machine-readable information |
| Point-in-time assessment | Metrics and assurance over time |
| Compliance team gathers proof | Systems increasingly produce proof |
The right side of that table requires different skills.
APIs matter. Structured data matters. Infrastructure as code matters. Version control matters. Observability matters. Understanding how systems actually produce security outcomes matters.
And increasingly, the person working in GRC needs to understand how those pieces fit together.
That sounds a lot like GRC Engineering.
From Controls to Security Signals
Another important concept in 20x is the Key Security Indicator, or KSI.
KSIs describe security capabilities that can be measured and validated while connecting those outcomes back to established controls. Current FedRAMP KSIs include expectations such as persistently evaluating and testing the configuration of machine-based information resources, especially infrastructure as code.
That is not an instruction to write a better policy.
It is an instruction to build and operate better systems, and then demonstrate that those systems continue to work.
That distinction matters.
FedRAMP Month
October is FedRAMP Month at the GRC Engineering Club, which makes this a particularly good time to start digging into what these changes mean.
On Friday, October 9 from 12:00–1:00 PM ET, the national GRC Engineering Club is hosting FedRAMP 20x, Live with Paramify.
Paramify co-founder and CEO Kenny Scott will walk through modern FedRAMP security package management, the relationship between Rev 5 and 20x, and how organizations should start thinking about their authorization programs under this new model. There will also be time for live questions.
The session is available to PRO members through the GRC Eng Academy.
And we are not stopping there.
We will be sharing more FedRAMP resources throughout the month because this is something worth learning together.
If you work in GRC Engineering, now is the time to connect, learn, experiment, and build. Companies navigating FedRAMP 20x are not just going to need people who understand what evidence to submit.
They are going to need people who can help build the systems that produce the evidence.
FedRAMP 20x Mini Fact Sheet
| Topic | Beginner Version |
|---|---|
| FedRAMP 20x | FedRAMP's outcome-focused certification model, with increasing use of measurable security outcomes, persistent assurance, machine-readable information, and automation. |
| Class A | The simplest 20x entry point and the easiest place to see the new outcome-focused model with less extra complexity. |
| Class B | Adds stronger ongoing expectations, including required historical KSI metrics in the Security Decision Record and greater emphasis on automated persistent verification and validation. |
| Class C | Supports Moderate services and increases persistent validation, historical metrics, and automation requirements. |
| Class D | The future 20x path planned for High services. |
| KSI | Key Security Indicator. A measurable security capability used to demonstrate an important security outcome. |
| Security Decision Record | A persistently maintained, verified, and validated record of security decisions. For applicable 20x classes, it replaces the traditional SSP and is supplied in human-readable and JSON formats. |
| Persistent validation | Repeatedly checking that security measures are accurately produced, in place, and working as intended. |
| Why GRC engineers should care | 20x increasingly connects compliance requirements to systems, automation, metrics, structured data, and continuously produced assurance. |
FedRAMP's Class A pipeline opened in August 2026, followed by the Class B and C pipelines later that month. The Consolidated Rules for 2026 become mandatory across the program beginning January 1, 2027, subject to individual rule effective dates. FedRAMP plans to stop accepting applications for new Rev 5 certifications on June 11, 2027.
This is not something sitting on a distant roadmap anymore.
The future of compliance is being built right now. GRC engineers should be among the people building it.