RFC-0033 20x Phase 4 Development Tracks for 20x Class D
Summary & Motivation
FedRAMP 20x Phase 4 is focused on the expansion of FedRAMP 20x Certifications to Class D and to services that are not primarily cloud-hosted. This RFC proposes the general approach that FedRAMP will take during Phase 4 to develop and test these new 20x requirements, along with expectations with industry and agency partners. The actual specifics, timelines, and details will shift based on public comment but the approach and requirements proposed in this RFC will also provide interested parties with an initial framework to prepare for participation in Phase 4.
Phase 4 will evaluate new requirements and assurance expectations to ensure FedRAMP 20x Class D Certified cloud service providers supply an appropriate level of assurance to be used in federal workloads where threats to confidentiality, integrity, or availability of federal customer data may lead to catastrophic harm, including loss of life.
We anticipate that the requirements for FedRAMP 20x Class D, when finalized, will provide a greater level of assurance than a legacy FedRAMP Rev5 Class D. Unlike other FedRAMP 20x Certifications, Class D will also require considerable additional investment to meet government-specific use cases compared to commercial ones, and we anticipate that few commercial services will invest fully in the necessary assurance.
This RFC proposes the following:
- Formal definitions for cloud-hosted, self-hosted, and hybrid-hosted to provide clarity on applicability
- High-level initial expectations for 20x Class D
- 3 separate FedRAMP 20x engagement and improvement tracks that will run simultaneously during Phase 4, including:
- Track 1: The requirements and approach for the 20x Class D Pilot for cloud-hosted services
- Track 2: Plans for direct engagement with cloud service providers who are currently Rev5 Class C and Class D self-hosted to develop FedRAMP 20x self-hosted requirements
- Track 3: Plans for direct engagement with independent assessors familiar with Rev5 Class C and Class D self-hosted services to develop FedRAMP 20x self-hosted assessment requirements
This RFC will close in 30 days due to the urgent need to finalize and open the FedRAMP 20x Phase 4 pilot. Additional specifics may be provided in follow-on RFCs. This RFC has been posted simultaneously with RFC-0034 FedRAMP 20x Phase 4 Technical Advisory Group Changes as both proposals are strongly related.
The final Rules that are developed during Phase 4 will be incorporated into the FedRAMP Consolidated Rules for 2027.
Feedback Requested
All feedback from the public is welcome, though FedRAMP prefers explicit targeted feedback rather than general commentary.
New FedRAMP Definitions
This RFC proposes the following new FedRAMP Definitions to be used in FedRAMP materials:
Cloud-Hosted (Cloud Service Offering)
A cloud service offering where machine-based information resources primarily run on third-party cloud service offerings and the cloud service provider is not responsible for the physical infrastructure used.
Self-Hosted (Cloud Service Offering)
A cloud service offering where machine-based information resources primarily run on physical infrastructure operated by the cloud service provider, either directly or through an agreement with a third party. This includes fully self-managed infrastructure as well as infrastructure running in a colocated facility or fully managed by a third party where the cloud service provider itself takes full responsibility for the physical infrastructure.
Hybrid-Hosted (Cloud Service Offering)
A cloud service offering where some machine-based information resources are cloud-hosted and others are self-hosted.
Overall Anticipated 20x Class D Requirements
FedRAMP 20x Class D is intended to be significantly more robust than FedRAMP 20x Class C or FedRAMP Rev5 Class D. Detailed proposed requirements will be released during the pilot, but this section provides a high-level overview of the direction FedRAMP plans to take FedRAMP 20x Class D for initial feedback.
FedRAMP 20x Class D will be a significant jump over FedRAMP 20x Class C, and will introduce at least the following additional expectations:
- Service offerings must obtain and maintain a 20x Class C Certification without corrective action for 6 months to become eligible for 20x Class D Certification after the Phase 4 pilot.
- Cloud-hosted or hybrid-hosted Class D services must be deployed on a Class D Certified IaaS/PaaS.
- Class D services must only use Class B, C, or D Certified Third-Party Information Resources in their Minimum Assessment Scope.
- Class D services will be expected to demonstrate they can provide additional assurance engineering resources to agencies, including more active support with agency review of the FedRAMP Certification Package and ongoing support for integrating assurance data into agency GRC systems.
- Class D services will be required to address new Key Security Indicators related to assurance engineering, automation capabilities, and availability, along with a new KSI theme related to Foreign Ownership, Control, or Influence (FOCI).
Similar to FedRAMP Rev5, many Rules will have stricter timelines and other expectations for 20x Class D services. Some of these have been previewed in the Consolidated Rules for 2026 and others will be added during the pilot.
FedRAMP will publish the full requirements as an RFC on October 14, shortly after this RFC closes. If you have targeted feedback on the proposed requirements mentioned above, please submit them early if possible.
Phase 4 Track 1: 20x Class D Cloud-Hosted Pilot
The Phase 4 pilot will take place during FY27 Q1 and Q2, with final review eating into the beginning of FY27 Q3.
There will be a single requirement to apply for participation in the Phase 4 pilot: You must receive a CR26-compliant FedRAMP 20x Class C Certification before December 1, 2026.
If you apply for a FedRAMP 20x Class C Certification before November 13, 2026, and intend to participate in the Phase 4 pilot, please reach out directly to the FedRAMP Director (pete@fedramp.gov) with a notice of intent after your Class C application has been submitted. Phase 2 pilot participants, including AI Prioritized participants, will not be eligible for participation in the Phase 4 pilot unless they have received a full CR26-compliant FedRAMP 20x Class C Certification before December 1.
The following target dates assume no unexpected bumps in the road:
- October 14: RFC with full FedRAMP 20x Class D Certification pilot requirements.
- November 18: Final FedRAMP 20x Class D Certification pilot requirements are published.
- December 1 - 4: Application window.
- December 7 - 18: Initial discussions with participants.
- February 17, 2027: Mandatory draft package submission and initial progress review.
- March 17, 2027: Final pilot package submission deadline.
- March 23, 2027: Tentative FedRAMP Day
The Phase 4 pilot will follow a similar approach to the Phase 2 pilot:
- The goal of the Phase 4 pilot is for participants to earn a FedRAMP 20x Class D Pilot Certification during the pilot.
- It will be strictly limited to participants that have already demonstrated the capability to meet FedRAMP 20x requirements.
- Qualified and interested providers will need to apply for participation and demonstrate their ability to achieve Class D assurance.
- Participants will be expected to engage a FedRAMP Recognized Independent Assessment Service during the pilot.
- Participants will be expected to engage with the FedRAMP PMO to discuss plans and approach in the early pilot phase.
FedRAMP will also be adding an additional agency engagement component to the Phase 4 pilot; participants should expect to engage with FedRAMP’s Technical Advisory Group, the FedRAMP Board, and certain interested agency stakeholders during the Phase 4 pilot.
Finally, FedRAMP will establish a firm maximum of 10 participants in the Phase 4 pilot.
Phase 4 Track 2: Expanding 20x to Self-Hosted or Hybrid-Hosted Services
To enable maximum speed and widest adoption, FedRAMP 20x Phase 1-3 focused exclusively on developing an updated path for cloud services that were hosted on infrastructure or platforms that were already FedRAMP Rev5 Certified. This provided a path for the majority of cloud services, but deprioritized a path for the rare services that operate their own physical infrastructure.
FedRAMP plans to remedy this in the Consolidated Rules for 2027 by offering an expanded set of criteria for self-hosted or hybrid-hosted services to qualify for a FedRAMP 20x Certification of any Class. We understand that most companies who are responsible for their own infrastructure are already expected or required to meet stringent government regulations and commercial guidelines to operate datacenters safely. We anticipate leveraging those existing investments to the maximum extent possible.
During Phase 4, FedRAMP will gather data and perspectives directly from current FedRAMP Certified cloud service providers with self-hosted or hybrid-hosted services. We will focus on industry standard certifications that are most widely used by these providers, and the deltas between those certifications and the requirements from existing FedRAMP Rev5. Our goal, where possible, will be to identify existing reusable certifications and classifications that can be included directly in a FedRAMP 20x Certification to address infrastructure-related controls.
FedRAMP will establish a direct engagement track where we will offer the opportunity to discuss this with us directly to a targeted subset of cloud service providers. In compliance with federal law and regulations, FedRAMP has identified the following criteria for providers to participate in this engagement track, to ensure a wide range of FedRAMP Certified cloud service providers will be able to contribute to this effort fairly:
- Must be FedRAMP Rev5 Class C or Class D Certified
- Must have at least 15 agency uses on record
- Must be primarily self-hosted or hybrid-hosted
- Cloud service providers with multiple qualifying cloud service offerings will only count once
FedRAMP will identify qualifying cloud service providers based on the information available on the FedRAMP Marketplace. All qualifying providers will receive a non-emergency notification in their FedRAMP Security Inbox with instructions on how to apply to participate in the direct engagement track and the expectations of that track.
At the same time, FedRAMP will publish RFCs with related questions then proposed rules so that all other parties can participate.
The following target dates for expanding 20x to self-hosted or hybrid-hosted services assume no unexpected bumps in the road:
- October 12: Qualifying cloud service offerings will receive a notification with instructions on how to opt-in to the direct engagement track.
- October 16: Deadline for responding to the opt-in notification.
- November 4: Publish RFC with general questions of existing certifications and managing self-hosted or hybrid-hosted services.
- November 4 - 20: Round 1 meetings with cloud service providers to set initial scope, intentions, questions, etc.
- January 4 - 15, 2027: Round 2 meetings with cloud service providers to discuss answers, responses, impact, etc.
- February 10, 2027: Publish RFC on FedRAMP 20x self-hosted or hybrid-hosted service rules.
- March 15 - 26, 2027: Round 3 meetings with cloud service providers to discuss final rules.
Phase 4 Track 3: Independent Assessment Service Engagement
The final component of Phase 4 will be a direct engagement track with FedRAMP Recognized independent assessment services (FRR-IAS) on self-hosted or hybrid-hosted rules. Many FRR-IAS have deep experience in auditing and assessing complex physical infrastructure environments for certifications that go well beyond the NIST SP 800-53 in commercial engagements and we plan to tap their expertise and knowledge.
In compliance with federal law and regulations, FedRAMP has identified the following criteria for assessors to participate in this engagement track, to ensure a wide range of FedRAMP Recognized independent assessment services will be able to contribute to this effort fairly:
- Must be the current assessor of record OR primary assessor within the last 3 years for any cloud service provider that qualifies for the direct engagement track
FedRAMP will identify qualifying assessment services based on the information available to us and the FedRAMP Marketplace. All qualifying assessors will be notified via an email to the public email address on record in their FedRAMP Marketplace Listing.
Unlike cloud service providers, FedRAMP plans to meet with small groups of assessment services at the same time to increase efficiency. Assessment services will receive the same general questions and information as cloud service providers but will be expected to respond from their unique perspective.
All assessment services will also be able to participate in the same public comment processes on the RFCs released regarding these requirements.
The following target dates for engaging with assessment services assume no unexpected bumps in the road:
- October 12: Qualifying FedRAMP Recognized independent assessment services receive a notification with how to opt-in to the direct engagement track.
- October 16: Deadline for responding to the opt-in notification.
- October 19-23: Round 1 meetings with independent assessment services to set initial scope, intentions, questions, etc.
- January 19-22, 2027: Round 2 meetings with independent assessment services to discuss answers, responses, impact, etc.
- March 8-12, 2027: Round 3 meetings with independent assessment services to discuss final rules.