What FedRAMP 20x - Modernized US Federal Cloud Security Assessment and Authorization (Key Security Indicators) requires
FedRAMP 20x is the FedRAMP program office modernization of US federal cloud security assessment and authorization, described by the program as a new approach to cloud security assessment and authorization that moves beyond traditional compliance to focus on the security decisions that matter most. Instead of static yearly audits, FedRAMP 20x is built on Key Security Indicators (KSIs): the Phase 1 pilot demonstrated that KSIs can provide near real time security posture validation, and the program position is that once security goals and measures are defined, status, progress, and outcomes should be automatically enforced and validated whenever possible. FedRAMP 20x authorization is organized into certification classes: Class A for mature providers entering the federal marketplace, Class B for small-scale or light-use services, and Class C for common enterprise services are available now, while Class D remains under development for Phase 4. As of mid 2026 the program is in Phase 3, focused on formalizing requirements and wide-scale adoption, with the submission pipeline planned to open in the July to September 2026 window; Phase 2 completed in March 2026. FedRAMP 20x operates alongside the traditional NIST SP 800-53 Rev 5 baseline path, and the statutory footing for FedRAMP is the FedRAMP Authorization Act codified in title 44 of the United States Code. Cloud service providers selling to US federal agencies should map their continuous-monitoring architecture to KSIs and choose between the 20x path and the Rev 5 baseline path based on service maturity and agency demand.
Pillar: Cloud & SaaS · Authority: FedRAMP Program Management Office (US General Services Administration); FedRAMP 20x program published at fedramp.gov/20x; statutory basis in the FedRAMP Authorization Act, title 44 United States Code · Version: 1.0.0 · Last updated:
Primary source: https://www.fedramp.gov/20x/
SHA-256 integrity: 58e39ee623823397edcc47a191585c9ccb7d08209a1b2c6edb25804421c4786d
Primary Citations — 6 traced to source
- FedRAMP 20x program, US General Services Administration, at https://www.fedramp.gov/20x/ - a new approach to cloud security assessment and authorization that moves beyond traditional compliance to focus on the security decisions that matter most
- FedRAMP 20x Key Security Indicators: the Phase 1 pilot demonstrated that KSIs can provide near real time security posture validation, replacing static yearly audits
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/us-fedramp-20x-cloud-authorization-modernization.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/us-fedramp-20x-cloud-authorization-modernization.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/us-fedramp-20x-cloud-authorization-modernization
- Back to registry: Browse all 10,085 compliance nodes