FedRAMP Is Replacing Impact Levels with Certification Classes — and Every Cloud Provider Has a Deadline

FedRAMP is retiring the Low/Moderate/High certification labels it has used for more than a decade and replacing them with Certification Classes A through D. This is happening now, not next year. FedRAMP Ready went legacy on July 28, 2026, the Class A pipeline opened August 3, and Classes B and C open August 31. The new rules become mandatory for all stakeholders on January 1, 2027, and FedRAMP stops accepting new Rev5 certifications on June 11, 2027.

The part most people will get wrong is what a class actually is. FedRAMP’s own guidance is blunter than I expected from a compliance agency: “FedRAMP Certification Classes are not aligned to how secure a cloud service offering is.” A class is not a security rating and not a stand-in for an impact level. It measures the depth, frequency, and quality of FedRAMP Certification Data a provider commits to supplying to agencies. Impact levels are not going away on the agency side, which still has to categorize systems as Low, Moderate, or High under FIPS-199 and FIPS-200. What changes is the FedRAMP label a cloud provider holds.

That distinction matters because of how the tiers map. Class B is an updated version of what people called Low, and Class C replaces Moderate. Class A is the new front door, replacing FedRAMP Ready: a completed Readiness Assessment Report or a SOC 2 Type II gets you in, and once a federal customer adopts your service you have 12 months to start moving to Class B or higher. Class D, the High equivalent, does not exist yet. FedRAMP plans to develop it in Phase 4, pilot it late 2026, and make it a formal option early 2027.

The hole in the lineup is Class D. If you sell cloud into High-impact federal workloads, the tier you need is the one that has not been written. Its ruleset page is not live, and FedRAMP labels the Phase 4 timing an estimate, the kind it says will shift as real-world conditions change. Providers at the High end are being asked to plan against a target that is still being drafted.

FedRAMP is not pretending the optics are easy. Its July 30 blog opens by conceding the exact worry: “At first glance, retiring familiar designations may feel like options are disappearing.” The rebuttal is that classes let providers scale their investment and level of assurance as agency interest and customer needs grow. What the rebuttal skips is the cost of re-mapping a decade of existing Moderate authorizations onto a Class C target, while FedRAMP elsewhere calls certification a heavy investment that plenty of competent security teams deliberately cap at Class A or B to keep government pricing in line with commercial pricing. I have some sympathy for the scaling argument. I have less for the framing that this is optionality with no transition bill attached.

The adequacy map FedRAMP publishes is where the practical effect shows up. It presumes Class A is fine for pilots, testing, and negligible-risk systems; Class B for most Low-impact systems; Class C for most Low and Moderate systems, plus some High with compensating controls; and Class D for most systems regardless of impact level. That map, not the labels, is the actual decision surface for a provider deciding how far to climb.

Two other things land on top of this. The first is CMMC, which still recognizes cloud providers through two paths: FedRAMP Authorized at Moderate or higher, or equivalent to the FedRAMP Moderate baseline under DoD policy. That equivalency language is codified in DFARS 252.204-7012, which requires a contractor using an external cloud to ensure the provider meets requirements equivalent to the FedRAMP Moderate baseline. The FedRAMP re-label does not erase it. The bar is tied to the Moderate baseline, not SOC 2 or ISO 27001, and it wants 100% compliance through a FedRAMP-recognized 3PAO with no open POA&Ms from the assessment.

The second is a FAR rule on Controlled Unclassified Information, and the dates are easy to conflate. The CUI-specific proposal is FAR Case 2017-016, proposed January 15, 2025, and it would add a standardized CUI contract clause across federal acquisitions. That is separate from FedRAMP and from CMMC. It is also separate from the June 2026 FAR action, the Revolutionary Federal Acquisition Regulation Overhaul (FAR Case 2026-001), a broad deregulatory rewrite of FAR Parts 1, 2, 4, 33, 39, 40, and 53 that is not a CUI rule. If a summary tells you there was a June 2026 FAR CUI proposed rule, it has merged two documents that do not belong together.

There is a narrow Rev5 escape hatch for providers who want to move under the old regime. Two temporary Rev5 Program Certification pipelines, Lost Sponsor and Ready Conversion, open August 10, 2026 for Classes B and C and close when Rev5 applications end on June 11, 2027. The path structure overall: Program Certification is FedRAMP-granted with no agency sponsor and is mostly the 20x route, while Agency Certification needs a sponsoring agency and is Rev5 only. 20x Classes A, B, and C require the Program path; 20x Class D is listed as coming in 2027.

For most readers the headline is simpler than all of that. The labels change, the deadlines are real, and the High tier is not ready. Providers holding Moderate authorizations today are re-mapping onto Class C. Providers who want the High path are waiting on a definition FedRAMP has not published. Rev5 has a long tail, so there is roughly a year of coexistence before new Rev5 certifications stop on June 11, 2027. Nobody has to migrate tomorrow, but the taxonomy is not static.

Bottom line

FedRAMP is doing something defensible and something unfinished at the same time. Replacing a blunt Low/Moderate/High label with classes that scale assurance investment is reasonable, and FedRAMP deserves credit for saying out loud that a class is not a security rating. But Class D is the tier providers serving High-impact workloads actually need, and it does not exist yet. The dates are firm through June 2027. The High-end target is not. Providers should treat the re-label as a re-mapping exercise with real dates, and treat Class D as an open question FedRAMP has not answered.

Sources

  1. FedRAMP Certification Paths are Heating Up — FedRAMP blog, July 30, 2026
  2. FedRAMP Consolidated Rules for 2026
  3. Important Dates for the Consolidated Rules for 2026 — FedRAMP timeline
  4. FedRAMP Certification Classes — guidance for agencies
  5. FedRAMP Moderate Equivalency After the 2026 Rules — AARC-360
  6. FedRAMP 20x — phases and class descriptions
  7. Choosing a Certification Path — FedRAMP
  8. FAR Case 2017-016: Controlled Unclassified Information — proposed rule, January 15, 2025
  9. FAR Case 2026-001: Revolutionary FAR Overhaul — proposed rule, June 23, 2026
  10. CMMC Program final rule (32 CFR 170) — October 15, 2024
  11. DFARS 252.204-7012: Safeguarding Covered Defense Information — eCFR