Start with the service and the government use case
A FedRAMP plan starts with the specific cloud service offering, its intended federal use, and the systems and people that operate it. Write down what customers will buy, which data and workflows it supports, the outside services it depends on, and who owns the operating evidence. Avoid budgeting against a generic company-wide claim of “FedRAMP compliance.”
The 2026 provider guidance describes direct or indirect government-wide use as the basis for Marketplace listing and certification eligibility. It also distinguishes FedRAMP’s program from defense-specific CMMC questions. A CMMC obligation and a FedRAMP certification objective are not interchangeable; establish which requirement your actual customer is asking you to satisfy. [1]
Separate certification type, class, and path
As of this article’s October 10, 2026 update, the consolidated guidance distinguishes 20x and Rev5 certification types. It generally directs cloud-native offerings built on certified infrastructure or platforms toward 20x; Rev5 remains relevant to services operating their own infrastructure and current Class D needs. Confirm your architecture and eligibility against the official type guidance before selecting a work plan. [2]
Certification class reflects the assurance needed for intended agency use. The current guidance uses Classes A through D and warns against treating them as a direct renaming of the Low, Moderate, and High impact levels used for federal information systems. Choose with the intended customer’s use case and required assurance in view. [3]
The Program Certification path is handled directly by FedRAMP and is the required route for 20x. Agency Certification uses agency authorization and sponsorship for Rev5. Limited Rev5 Program exceptions have specific eligibility criteria; they are not a general sponsor-free alternative for any applicant. [4]
Use the current transition dates for your situation
FedRAMP’s published timeline sets January 1, 2027 as the mandatory adoption date for the consolidated rules, subject to specific applicability and effective dates. It also states that new Rev5 certification applications will no longer be accepted after June 11, 2027. Existing certifications, transition applicants, and new submissions can have different obligations; check the relevant provider guidance instead of applying one deadline to every organization. [5]
Record the guidance version, eligibility assumptions, and dates used in your decision. Before a major commitment, confirm that the relevant intake is available and that your service qualifies. An anticipated future option should be a planning dependency, not a representation that the option is already available.
Budget for an operating capability, not only a package
Our suggested readiness output is a decision brief that connects the proposed route to the architecture, evidence gaps, engineering work, independent assessment needs, and ongoing operating responsibilities. Identify who can produce each required record and what happens when a control changes or fails. A document repository cannot compensate for a control that is not operating.
Keep advisory support, implementation, independent assessment, and the government’s decision roles explicit. Readiness consulting can help you prepare and resolve gaps; it cannot promise certification, an agency authorization, or a federal contract. Agree on milestones that your team can demonstrate rather than a guaranteed outcome outside the engagement’s control.
- Identify the service offering, boundary, dependencies, and intended agency use.
- Document the proposed type, class, and path with the current eligibility basis.
- Record applicable transition dates and unresolved assumptions.
- Assign owners for implementation, assessment evidence, and ongoing operations.
- Recheck the official rules before procurement or submission.
