About GSA
The General Services Administration (GSA) is a federal agency that is the engine for the federal government. GSA is responsible for providing centralized procurement services, real estate management, technology solutions, and administrative support across the government.
Across the government, the Federal Risk and Authorization Management Program (FedRAMP) is responsible for standardizing the security assessment process for cloud services used by federal agencies, establishing baseline security requirements for cloud service providers serving the federal government, and maintaining a marketplace of FedRAMP-certified cloud services that agencies can leverage.
The challenge
For years, FedRAMP has served as the government’s security gatekeeper for cloud services; however, the FedRAMP certification process was widely seen as difficult to navigate. Cloud service providers faced lengthy timelines, high costs, extensive documentation requirements, recurring assessments, and uncertainty about how long certification would take. The legacy process, known as Rev5, had become a bottleneck that slowed adoption and innovation within government.
Under Rev5, a single certification review could take years and require hundreds of pages of static documentation. This often created “compliance theater,” where cloud service providers implemented controls to satisfy paperwork rather than genuinely reduce cybersecurity risk.
While this documentation provided evidence of compliance at a point in time, it did not continuously demonstrate that a cloud service remained secure. The legacy Low/Moderate/High impact model offered little flexibility for cloud service providers to tailor security to their actual environment, and gave agencies no assurance that a provider’s posture hadn’t changed since their last review.
FedRAMP’s own staffing also reflected the need to address the bigger issue. With a small staff of federal employees supporting a government-wide program responsible for assessing the risk of cloud services, the program office needed to reinforce its policies and rethink its delivery model.
The challenge was clear: replace a slow, paperwork-heavy, point-in-time compliance model with something faster, more transparent, and rooted in continuous, real-time assurance without compromising security.
The approach
Enter FedRAMP 20x. As a complement to redesigning the FedRAMP website and marketplace, multiple U.S. Digital Corps Cybersecurity Fellows helped develop 20x, refine requirements for different security classes, and draft consolidated rules. They have been embedded in every phase of the 20x initiative:
- Piloting 20x, working directly with cloud service providers to test the new continuous-monitoring-based framework in real-world conditions
- Refining security requirements for different classes of systems, moving away from the static Low/Moderate/High impact categories toward a more dynamic classification model that is formally referred to as Class A, B, C, and D. The new requirements are designed to better differentiate risk tolerance and monitoring cadence based on a system’s actual operating environment and use case, rather than a fixed impact rating alone.
- Drafting the Consolidated Rules for 2026, translating the philosophy of 20x into concrete, actionable requirements that providers and assessors can implement
FedRAMP 20x represents a shift from static, documentation-heavy compliance toward continuous monitoring, automation, transparency, and machine-readable data. Rather than relying primarily on documentation that describes a provider’s security posture at a single point in time, the 20x approach is designed to continuously demonstrate that posture.
This new model can significantly reduce the burden on cloud service providers while giving the government more timely insight into security.
The impact
The results from 20x represent one of the most significant update efforts in FedRAMP’s history:
| Legacy Rev5 | 20x | |
|---|---|---|
| Review timeline | Up to 2 years | ~3 weeks |
| Security posture | Point-in-time snapshot | Real-time, continuously verified |
| Documentation | Hundreds of pages, manually reviewed | Light on documentation, machine-readable |
| Flexibility | Fixed control checklists | Cloud service providers define Key Security Indicator metrics for their use case |
| Risk model | Static Low/Moderate/High impact tiers | New Class A/B/C/D model with nuanced, use-case-driven risk differentiation |
The work of U.S. Digital Corps Fellows helped advance FedRAMP toward a faster, more automated, and more transparent model for cloud security certification.
FedRAMP 20x has dramatically shortened the expected certification timeline compared with the legacy process: a Rev5 review could take up to two years, while a 20x review averages about three weeks. Its continuous and machine-readable approach also creates opportunities to reduce documentation burdens and focus compliance efforts on demonstrating meaningful security outcomes.
By compressing certification timelines from years to weeks, 20x removes one of the most persistent barriers to cloud adoption and reuse in government. This enables agencies to access secure, modern cloud services far faster than before. Just as importantly, the shift from static documentation to real-time verification means agencies can trust that a provider’s security posture reflects today’s reality, not a snapshot from two years ago.
Industry observers have described the shift to 20x as a game changer not just for federal compliance, but for the broader governance, risk, and compliance (GRC) sector. The work of U.S. Digital Corps Fellows helped advance FedRAMP toward a faster, more automated, and more transparent model for cloud security authorization, currently in phase 3 of a five-phase plan.
digitalcorps.gsa.gov
An official website of GSA’s Technology Transformation Services