FedRAMP Marketplace Designations

For commercial businesses listed on the FedRAMP Marketplace
FedRAMP recently released new certification designations to minimize confusion and to provide greater transparency of where cloud providers are in the authorization pipeline. The designations also work to address long-standing issues with the FedRAMP certification or review of a cloud provider’s submitted security package, and federal agencies granting an Authorization to Operate (ATO) after adopting a certified cloud solution. Combined, these new designations align with the FedRAMP Act, OMB Memorandum 24-15, and the NIST Risk Management Framework.

FedRAMP Certification Labels

FedRAMP Certified (Rev5)
This designation indicates a service has completed a point-in-time assessment based primarily on a review of filed paperwork, meeting legacy FedRAMP Revision 5 (Rev5) requirements.

FedRAMP Validated (20x)
This designation indicates a service has demonstrated the ability to persistently validate their security posture, meaning the validation package always accurately reflects the service's current status.

Determining Your Certification Profile

Your final certification status is a result of three distinct variables:

  • Type: Specifies the assessment standard (FedRAMP Rev5 or FedRAMP 20x).
  • Class: Indicates the depth of assessment coverage and requirements (Classes A through D).
  • Path: Defines the entry method:
    • Program Certification: Direct submission to FedRAMP.
    • Agency Certification: Traditional path requiring an initial review by a federal agency sponsor.

FedRAMP Certification Levels

The legacy FIPS 199 security categories (Low, Moderate, High) have transitioned to a number-based level system for both new designations:

Here are the new FedRAMP Certified (Rev5) Levels, along with their historical FedRAMP Rev5 categorization and a description of the assessment coverage.

FedRAMP certification classes
ClassLevel / PurposeHistorical Rev5 CategorizationBest For…
Class AStarterFedRAMP ReadyOrganizations new to the federal space. Uses existing, alternative security reports (like SOC 2 or GovRAMP) to kickstart your journey.
Class BFoundationLowOrganizations with some federal experience; suitable for initial production-level needs.
Class CAdvancedModerateMature organizations requiring deeper assessment coverage and greater detail for agency decision-makers.
Class DHigh AssuranceHighHigh-stakes systems. Requires the deepest level of assessment; limited to agency-sponsored paths only.

Important Context for Certification Profiles

  • Progressive Growth: These classes are designed to scale with you. You don't need to start at the top; you can begin at Class A and "uplift" to higher classes as your organization's federal experience and requirements grow.
  • Depth, Not Risk: These classes indicate the depth of information provided in your certification package, not the "security level" of your product. They help agencies make risk-based decisions faster.
  • Requirement Stacking: Rules stack as you level up. For example, a Class C certification incorporates all the requirements of Class B, plus additional process and documentation adherence.
  • Rev5 Program (Non-Agency Sponsored) Certifications will be limited in both time and eligibility. For more information, review the Rev5 Lost Sponsor/Ready Conversion Rules in the FedRAMP Consolidated Rules for 2026.

Learn more about FedRAMP Certification Classes.