BLOG
September 14, 2026
decorative
Travis Good

How to Transition From FedRAMP Rev 5 to FedRAMP 20x

Moving from FedRAMP Rev 5 to 20x means building a new complaince program in parallel. Here are the transition steps, deadlines, and tooling changes to plan for.

You can't just flip a switch and move from FedRAMP Rev 5 to 20x. It takes a significant amount of work.

Whereas Rev 5 is built on a narrative-driven, document-heavy structure, 20x leans on continuous compliance, machine-readable data, and Key Security Indicators (KSIs).

If you're currently Rev 5 authorized and want to figure out what the journey to 20x certification looks like, we've got you covered.

How to Plan for FedRAMP 20x Alongside Rev 5

My approach to 20x would be to treat it as its own standalone compliance project. Assign 20x preparation its own owner and engineering time, running alongside the work to keep your current Rev 5 responsibilities flowing (control maintenance, POA&M updates, vulnerability management, monitoring).

Even if you're not transitioning to FedRAMP 20x right away, there are still some changes from FedRAMP's Consolidated Rules for 2026 (CR26) you need to be aware of:

  1. New documentation: Organizations will need a Certification Package Overview, which replaces the traditional System Security Plan (SSP), plus a Security Decision Record to document how you meet FedRAMP requirements and controls. Both need to be human-readable and available as JSON.
  2. Certification reports: The Ongoing Certification Report needs to be delivered every three months. It must summarize changes and planned changes to your systems, any incidents, and accepted vulnerabilities.
  3. A different way to track weaknesses: POA&Ms are being phased out by FedRAMP's Accepted Weaknesses/Accepted Vulnerabilities approach.

If you have an existing Rev 5 authorization, the CR26 dates you need to know are:

Legacy Rev 5Narrative FedRAMP 20xMachine-readable
Evidence form Narrative written for a human to read Machine-readable data (e.g., OSCAL)
Production cadence Once per assessment, point-in-time Continuous, generated by your systems
How controls are proven An SSP describing each control KSIs validated automatically against NIST 800-53
Audit work Manual evidence collection at audit time Ongoing automated validation, faster assessments

Transitioning from Rev 5 to 20x Means Rebuilding Your FedRAMP Program

If I were running security at a Rev 5–authorized company, here's how I'd approach the transition to 20x. First, don't try to retrofit your Rev 5 work into 20x. It needs to be a parallel program, and you need to design your 20x compliance from first principles.

FedRAMP 20x operates on top of the same NIST controls as Rev 5. The fundamental change between the two is how you document and prove compliance. So you can't just bolt 20x onto your existing Rev 5 work. It's something you have to build from the ground up.

The best approach is to treat 20x as a new, separate compliance program that's built on the same foundation (controls, tools, and principles) as Rev 5.

Here's a breakdown of the key differences between Rev 5 and 20x:

Requirement Maintain date Grace period ends
Vulnerability detection & response; evaluation & reporting December 7, 2026 March 7, 2027
Significant change notification January 1, 2027 June 1, 2027
Collaborative continuous monitoring April 2, 2027 October 1, 2027

Applies to existing Rev 5 authorizations under FedRAMP's Consolidated Rules for 2026 (CR26). Dates are FedRAMP targets and can shift — check the FedRAMP roadmap before you plan around them.

The main shift is how you actually prove compliance. Rev 5 relies on narrative-driven compliance (via an SSP), whereas 20x is driven by continuous, machine-readable compliance via Key Security Indicators (KSIs). KSIs deliver evidence directly from your systems, so compliance can be checked continuously.

KSIs layer on top of the same NIST 800-53 controls Rev 5 is built on, and each KSI maps to multiple controls, with 46 KSIs in the Class B and Class C framework (41 are required for Class B, with five optional, while all 46 are required for Class C).

To give you an example of how the two differ: under Rev 5, you might write about your employee access policy and provide offboarding tickets as evidence. Under 20x, if your policy says access will be removed within 24 hours of an employee leaving, your systems need to show what accounts someone had and when access was removed.

It essentially flips the process, so instead of spending your time assembling evidence and writing your SSP, you're designing systems and implementing KSIs that monitor and validate your controls in real time.

You can learn more about how KSIs relate to NIST controls here.

How to Rebuild Your Evidence Pipeline Around KSIs

The switch from narrative to machine-readable, continuously monitored evidence is at the core of the transition to 20x. You need to get to a place where your evidence pipeline validates each KSI automatically.

Start by auditing your existing evidence, looking at which system produces the evidence currently. For example, log and event management might be a SIEM like Datadog or AWS CloudTrail, and identity might be Okta for MFA. Then you can build a plan to create automated, machine-readable validations.

The "continuous" element is also key. Under 20x, compliance is always-on and any drift should be spotted in real time. If a misconfiguration ships on a Tuesday afternoon, your code should spot it and trigger an alert almost immediately.

What Does Your FedRAMP 20x Certification Package Need?

Alongside building out your KSI validations, FedRAMP 20x also requires a certification package. This includes:

  • The Certification Package Overview (CPO): a human-readable and machine-readable JSON file that replaces the old SSP. It needs to include your logo, a description of your service, Unique Entity Identifier (UEI), FedRAMP ID, and key company contact information.
  • The Security Decision Record (SDR): this explains how you address the 20x requirements, supported by verification, validation, and independent assessment information. It should also explain how you address the KSIs. Like the CPO, it needs human-readable and JSON versions.

Your JSON files must match the specified schema. And once a FedRAMP 20x certification package is in use, it must be kept up to date. Class B packages must be kept current at least monthly, and Class C at least every two weeks.

How Do You Choose Your FedRAMP 20x Class and Scope?

The Class you require will have a big say in the amount of work required and the budget needed to achieve 20x. Before scoping the work, you should agree on which Class you're aiming for: Class A (a new entry-level class), B (Low), C (Moderate), and D (High).

The vast majority of FedRAMP Rev 5 authorizations were at the Moderate level (now Class C), and that will likely continue with 20x. However, 20x has also opened up Class A, offering a route into the federal marketplace for organizations coming from a consumer-compliance background. Generally, the decision between Class B and C will come down to the requirements of the customers you're serving.

Check Your Tools for FedRAMP 20x Readiness

Many of the tools you're currently using will likely be able to support the switch to FedRAMP 20x. However, getting continuous, machine-readable evidence out of certain tools may mean paying for a higher tier, something many companies don't budget for as they cost out the switch.

Basic logging might pipe events somewhere fine for a point-in-time check. But to get the API or programmatic access that produces machine-readable validation, you need more advanced features. The same goes for device management and endpoint detection and response (EDR), which become far more relevant as you climb from Class B to Class C.

When Can You Retire Duplicate Rev 5 Work?

Retire duplicate Rev 5 work only after confirming your FedRAMP 20x certification and what your customers still need. Though the 20x deadline and the sunset of Rev 5 are looming, different agencies might want to switch over at different times.

I'd review the transition arrangements with FedRAMP and the agencies you're working with, or expecting to work with, over the next couple of years.

It's Best to Get Started Early

If you have Rev 5 in place already, the transition to 20x is on the horizon, and the best time to start looking at how your organization can transition is now. Start by looking at your current setup, understanding where you stand, and thinking about how you can implement KSIs and continuous monitoring.

If you'd like to know what it'll take to transition at your organization, or would like an outside perspective, our public sector practice runs both Rev 5 and 20x programs. We can help you figure out the best path forward and take on as much of the technical and implementation work as required to help you meet 20x standards on your own timeline.

Want to learn more about our FedRAMP work? Book a call with our team.

Turn compliance into a growth engine: Workstreet delivers full-stack solutions that transform security and compliance into growth accelerators. Talk to an expert →
Build trust, accelerate growth.
Workstreet offers Al-first security solutions that help high growth technology companies get compliant, scale securely, and close bigger deals.
Get started
Ready to Transform Security into a Growth Advantage
Schedule a consultation with our trust solutions experts to see how we can accelerate your security program and compliance journey.
Talk to an engineer
Travis Good

Architect of security and privacy programs for 1,000+ hypergrowth companies. Author of "Complete Cloud Compliance," HITRUST 3rd Party Council member, and recognized speaker on startup security.