FedRAMP Marketplace Designations
For commercial businesses listed on the FedRAMP Marketplace
FedRAMP recently released new certification
designations to minimize confusion and to provide greater transparency of where cloud providers are in the authorization pipeline. The designations also
work to address long-standing issues with the FedRAMP certification or review of a cloud provider’s submitted security package, and federal agencies
granting an Authorization to Operate (ATO) after adopting a certified cloud solution. Combined, these new designations align with the FedRAMP Act, OMB
Memorandum 24-15, and the NIST Risk Management Framework.
FedRAMP Certification Labels
FedRAMP Certified (Rev5)
This designation indicates a service has completed a point-in-time assessment based primarily on a
review of filed paperwork, meeting legacy FedRAMP Revision 5 (Rev5) requirements.
FedRAMP Validated (20x)
This designation indicates a service has demonstrated the ability to persistently validate their
security posture, meaning the validation package always accurately reflects the service's current status.
Determining Your Certification Profile
Your final certification status is a result of three distinct variables:
- Type: Specifies the assessment standard (FedRAMP Rev5 or FedRAMP 20x).
- Class: Indicates the depth of assessment coverage and requirements (Classes A through D).
- Path: Defines the entry method:
- Program Certification: Direct submission to FedRAMP.
- Agency Certification: Traditional path requiring an initial review by a federal agency sponsor.
FedRAMP Certification Levels
The legacy FIPS 199 security categories (Low, Moderate, High) have transitioned to a number-based level system for both new designations:
Here are the new FedRAMP Certified (Rev5) Levels, along with their historical FedRAMP Rev5 categorization and a description of the assessment coverage.
| Class | Level / Purpose | Historical Rev5 Categorization | Best For… |
|---|---|---|---|
| Class A | Starter | FedRAMP Ready | Organizations new to the federal space. Uses existing, alternative security reports (like SOC 2 or GovRAMP) to kickstart your journey. |
| Class B | Foundation | Low | Organizations with some federal experience; suitable for initial production-level needs. |
| Class C | Advanced | Moderate | Mature organizations requiring deeper assessment coverage and greater detail for agency decision-makers. |
| Class D | High Assurance | High | High-stakes systems. Requires the deepest level of assessment; limited to agency-sponsored paths only. |
Important Context for Certification Profiles
- Progressive Growth: These classes are designed to scale with you. You don't need to start at the top; you can begin at Class A and "uplift" to higher classes as your organization's federal experience and requirements grow.
- Depth, Not Risk: These classes indicate the depth of information provided in your certification package, not the "security level" of your product. They help agencies make risk-based decisions faster.
- Requirement Stacking: Rules stack as you level up. For example, a Class C certification incorporates all the requirements of Class B, plus additional process and documentation adherence.
- Rev5 Program (Non-Agency Sponsored) Certifications will be limited in both time and eligibility. For more information, review the Rev5 Lost Sponsor/Ready Conversion Rules in the FedRAMP Consolidated Rules for 2026.
Learn more about FedRAMP Certification Classes.