{
  "node_id": "us-fedramp-20x-cloud-authorization-modernization",
  "title": "FedRAMP 20x - Modernized US Federal Cloud Security Assessment and Authorization (Key Security Indicators)",
  "domain": "Cloud & SaaS",
  "version": "1.0.0",
  "last_updated": "2026-07-10",
  "bluf": "FedRAMP 20x is the FedRAMP program office modernization of US federal cloud security assessment and authorization, described by the program as a new approach to cloud security assessment and authorization that moves beyond traditional compliance to focus on the security decisions that matter most. Instead of static yearly audits, FedRAMP 20x is built on Key Security Indicators (KSIs): the Phase 1 pilot demonstrated that KSIs can provide near real time security posture validation, and the program position is that once security goals and measures are defined, status, progress, and outcomes should be automatically enforced and validated whenever possible. FedRAMP 20x authorization is organized into certification classes: Class A for mature providers entering the federal marketplace, Class B for small-scale or light-use services, and Class C for common enterprise services are available now, while Class D remains under development for Phase 4. As of mid 2026 the program is in Phase 3, focused on formalizing requirements and wide-scale adoption, with the submission pipeline planned to open in the July to September 2026 window; Phase 2 completed in March 2026. FedRAMP 20x operates alongside the traditional NIST SP 800-53 Rev 5 baseline path, and the statutory footing for FedRAMP is the FedRAMP Authorization Act codified in title 44 of the United States Code. Cloud service providers selling to US federal agencies should map their continuous-monitoring architecture to KSIs and choose between the 20x path and the Rev 5 baseline path based on service maturity and agency demand.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "statutory_anchor",
      "rev5_baseline_relationship",
      "ksi_continuous_monitoring",
      "certification_classes",
      "industry_mapping",
      "enforcement_anchors"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "us-44-usc-3614-fedramp-authorization-program",
    "fedramp-moderate-baseline",
    "fedramp-authorization"
  ],
  "primary_citations_count": 6
}