FedRAMP After the Rewrite
Last reviewed · content updated
IntermediateWhat you'll learn
~18 min- Read a post-rewrite FedRAMP certification the way an inheriting program evaluates it
- Use Certification Classes, KSIs, and Security Decision Records as evaluation instruments
- Run the check-today's-numbers discipline on a program in mid-transition
Seat change: evaluator
As promised in Lesson 1.1 — new seat. Meridian is not a cloud service provider and never will be; pretending otherwise would teach you a world that isn’t yours. But Meridian’s federal delivery depends on one: Castellan Analytics (fictional), the SaaS vendor whose telemetry platform sits in Meridian’s stack, is pursuing FedRAMP certification — and the receiving system’s ISSO has asked Meridian’s team to evaluate whether Castellan’s certification supports the interconnect’s risk story. This is the seat federal program teams, ISSOs, and DevSecOps engineers actually occupy with FedRAMP: you consume authorizations orders of magnitude more often than you pursue them. The evaluation skill is the job skill — and commercial readers will recognize it as third-party risk management, the same discipline behind every vendor security review, pointed at a federal certification instead of a SOC 2 report. The cost of skipping it is concrete. A vendor onboarded on the strength of a class letter that does not match your data’s sensitivity becomes a finding at your next assessment, a renegotiation mid-contract, or — worst — the path through which your own system’s authorization is questioned.
What the rewrite changed
FedRAMP underwent a genuine rewrite — not a revision, a rebuild — merging its fast-track experiment with its legacy baseline track into one machine-readable rulebook. The durable architecture (specifics and dates fenced below):
CERTIFICATION CLASSES the "authorization" vocabulary gives way to lettered CLASSES - roughly: an entry class with commercial-audit heritage where assessment can be optional, ascending through classes where an independent assessment is REQUIRED, up to a high-baseline class (not yet in operation). NOT the same axis as FIPS 199 impact levels (low / moderate / high) - a common briefing error worth catching in the wild.
KSIs a set of KEY SECURITY INDICATORS grouped in categories - the assessable unit of the new model: concrete, largely machine-checkable statements replacing narrative control prose.
SDR the SECURITY DECISION RECORD - a structured (JSON) artifact recording what was evaluated and decided; the package format of the new world. FedRAMP-JSON, not OSCAL (Lesson 2.3).
SCN significant-change notifications become NOTIFY-not-approve for routine change classes: providers ship and notify rather than awaiting approval (high-impact changes and authorization conditions can still require engagement) - the assessor-throughput arithmetic (Lesson 1.3) applied to change management.Lesson 1.3’s predictive tool, confirmed: every element spends fewer assessor-hours per authorized system — classes scope the assessment, KSIs mechanize it, notify-not-approve removes a queue. The rewrite is the capacity arithmetic, institutionalized.
The evaluator’s method
(Lesson 4.3 carries the companion artifact — a single evaluation sheet that scores a government platform and a commercial one on the same seven rows, so the comparison leadership will ask for is answered on one page.)
The receiving ISSO doesn’t ask “is Castellan FedRAMP certified?” — Lesson 1.1 taught you why (certification is not risk acceptance, and now you’re the one making the risk argument). The method:
Evaluate the vendor certification package (attached: their class letter,SDR, KSI results) for OUR interconnect's risk story:1) CLASS vs OUR DATA: what class is this, was independent assessment required at that class or optional - and does the data we send this vendor warrant more than their class covers? name the gap;2) KSI READ: which KSIs are relevant to how WE use the service; for each - result, evidence freshness, and whether it is machine-verified or attested;3) RESPONSIBILITY SEAM: from their customer-responsibility matrix (Lesson 2.2's split, their side), list what remains OURS - and check each item against our actual configuration of their service;4) DELTA REPORT: what our AO must accept beyond what this certification demonstrates - stated as residual risks with compensations, not as a pass/fail verdict on the vendor.Item 4 is the whole seat in one line: your output is never “vendor good/bad” — it’s the delta between what their certification establishes and what your system needs, framed for your AO’s acceptance decision.
🔍The rewrite's specifics (volatile - a program in mid-transition; verify before citing)
As of August 2026: the rewrite is CR26 (mid-2026), merging the 20x fast-track with Rev5 into one rulebook. Classes are A through D - A entry-level with SOC2-heritage and assessment optional, independent assessment mandatory from Class B up, D (High) not yet operational (expected ~FY27). 46 KSIs across 10 categories, recorded via Security Decision Record JSON. Transition dates: CR26 mandatory for new starts from January 1, 2027; in-flight Rev5 packages may still complete, with the last new Rev5 authorizations by June 2027. The assessor ecosystem was renamed (the 3PAO term retired in favor of recognized independent assessors) with roughly 50 listed - Lesson 1.3’s arithmetic in one number. Roughly 530 services hold authorizations, with the first few dozen through the fast-track lineage, on cycle times around five weeks.
Check-today’s-numbers exercise - the counts, dates, and even class definitions above are exactly the facts that will drift first. Before relying on any of them: Ask your AI CLI: search the current FedRAMP marketplace and program documentation; verify the class structure, the count of authorized services, the transition deadlines, and whether Class D exists yet. Diff against what this lesson claims and report what changed. That prompt is not a disclaimer - it is the lesson: mid-transition programs are read live, never from training material.
Castellan proudly reports it holds an entry-class certification (assessment optional at that class, self-attested KSIs). Meridian sends the vendor operational grid telemetry that the receiving federal system treats as sensitive. What is the evaluator-seat conclusion?
Practice status — among mature regulated delivery programs, commercial and federal
(a few rows carry a more specific status - principle, canon, suspended - where one of the five would mislead)
| Practice | Status | Also called |
|---|---|---|
| Certification Classes, KSIs, Security Decision Records | required (FedRAMP CR26) the program’s current rulebook; specifics volatile | — |
| evaluator method (class vs data, KSI read, seam, delta report) | common baseline | third-party risk management |
| notify-not-approve change management | FedRAMP rule routine change classes; high-impact changes may still need engagement | — |
| check-today’s-numbers discipline | strong optional for any program in mid-transition | — |
Scale: required | common baseline | strong optional | reference-shop (seen only at organizations that publish their own practice) | emerging
Key takeaway
The rewritten FedRAMP is the capacity arithmetic institutionalized: classes scope assessment, KSIs mechanize it, decision records structure it, notify-not-approve unclogs it. Read it from the evaluator seat — class letter against your data’s sensitivity, KSI results with their verification mode, the responsibility seam against your actual configuration — and deliver a delta report for your AO, never a verdict on the vendor. And a program in mid-transition is read live: check today’s numbers. Next: the DoD path, where what gets authorized might surprise you.
LEADERSHIP DECISION require a delta report for every inherited certification before data flows - and route the residual risk to the AO for written acceptance, or require the higher classPRACTITIONER ACTION run the evaluator method: class vs data sensitivity, KSI results with verification mode, the responsibility seam against actual configurationSUCCESS MEASURE every vendor in the federal delivery path has a dated delta report on file; zero class-vs-sensitivity mismatches discovered by an assessor