FedRAMP Compliance Hub

FedRAMP CR26 modernization: Class A-D replacing Low/Mod/High, SCN and Vulnerability Evaluation rules finalized

FedRAMP CR26 modernization: Class A-D replacing Low/Mod/High, SCN and Vulnerability Evaluation rules finalized

Key Questions

What are the key deadlines for CR26 implementation?

CR26 final rules were released June 25, 2026, with public preview ending June 30. FedRAMP Ready retires July 28, 2026, Rev5 new certs end June 2027, and mandatory transition begins January 2027. The marketplace opens July 6 and the pipeline starts in August.

How do the new Class A-D levels replace previous impact levels?

Class A-D replace Low/Mod/High, with Class A now live allowing SOC 2 holders to enter the federal market without sponsorship using 25 mandatory rules plus KSIs. Class is not a security grade and should not be equated with DoD IL. CSPs must update marketing copy from Authorization to Certification and Impact Levels to Classes A-D.

What replaces monthly scans under CR26?

Monthly scans are retired and replaced by Vulnerability Detection and Response (VDR) and Vulnerability Evaluation Rules (VER) using risk-based context over CVSS per BOD 26-04. SCN is now mandatory for 20x/Rev5 with opt-in by July 4. Certification packages require human-readable plus JSON formats across 9 rule subsets.

How does CMMC interact with FedRAMP requirements for DoD contracts?

The CMMC final rule clarifies external service providers no longer need their own CMMC certification, but CSPs handling CUI still trigger FedRAMP. This is critical for scoping cloud vendors under DFARS 7012. A new article explains FedRAMP Authorized vs Equivalent for CMMC compliance.

What guidance exists for CSPs transitioning under CR26?

CSPs must plan transition immediately, run Rev5 and 20x tracks in parallel, and build automated evidence pipelines within 18 months. 20x requires real-time asset inventory, exploitability prioritization, and incident response beyond GRC automation. The SSP is replaced by the SDR with machine-readable KSIs on a 3-day cadence.

CR26 final rules released June 25, 2026. Public preview ends June 30; FedRAMP Ready retires July 28, 2026; Rev5 new certs end June 2027. Key timelines: July 6 marketplace open, August pipeline start, January 2027 mandatory. Provisions confirmed: SCN mandatory for 20x/Rev5 (opt-in by July 4), elimination of agency sponsorship for Class A, Class C IV&V rules, Vulnerability Evaluation rules (risk-based context over CVSS per BOD 26-04). Monthly scan retired, replaced by VDR/VER. Certification package guidance: human-readable + JSON, 9 rule subsets. Class A is live today: SOC 2 holders enter federal market without sponsor, 25 mandatory rules plus KSIs, two-year upgrade clock. CMMC final rule clarifies that external service providers no longer need own CMMC cert, but CSPs handling CUI still trigger FedRAMP—critical for DoD contract scoping. A new article from Second Front provides a practical guide for CSPs to update marketing copy: 'Authorization' → 'Certification', Impact Levels → Classes A-D, 'FedRAMP Ready' retiring July 28. Clarifies Class is not a security grade and warns against equating with DoD IL. CSPs must plan transition immediately. A new article 'FedRAMP for CMMC: Authorized vs Equivalent Explained' offers a clear, practical breakdown of FedRAMP Authorized vs Equivalent for CMMC/DFARS 7012, with Marketplace verification steps – essential for CSPs scoping cloud vendors for CUI under defense contracts. A new practical guide 'FedRAMP 20x Class B vs Class C: Which Is the Right Fit?' helps CSPs navigate the new class decision under 20x, clarifying that the real difference is in validation depth, not just KSI count. FSCAC meeting on July 27, 2026, will focus on agency adoption and reuse, relevant to High supply crisis and CR26 implementation. Reviewed a paywalled PubKGroup article on CR26 as a new operating model; no new actionable information extracted. A new article 'FedRAMP 20x Takes More Than Compliance Automation' reinforces that 20x is an operating model shift requiring real-time asset inventory, exploitability prioritization, and incident response beyond GRC automation. Also reviewed an article on SDR vs SSP: practical breakdown of FedRAMP's shift from narrative docs to machine-readable evidence, aligning with CR26/20x automation and OSCAL adoption. FAR Council proposed CUI rule (June 2026) mandates FedRAMP Moderate for cloud CUI, comment deadline July 23. New details from recent article: 72-hour incident reporting, FedRAMP incident reporting exception, NIST 800-171 Rev 3 alignment. Also noted: CMMC pause/transition to Rev 3, FOCI expansion, quantum EO add long-term planning pressure. A NIST SP 800-171r2 to r3 crosswalk is available as a reference for dual-compliance shops. ProShop completed independent FedRAMP Moderate assessment, reinforcing DFARS 7012 compliance for defense contractors amid CMMC Phase II pause. Second Front Systems launched an ATO Accelerator for Azure Government, offering managed ATO paths across FedRAMP Classes B/C/D and DoD IL2-IL6, reducing barriers for CSPs transitioning under CR26. A new article 'Prepare for Rev 5 FedRAMP Sunset' provides a solid refresher on deadlines and practical advice for running both tracks in parallel and building automated evidence pipelines. Coalfire published 'FedRAMP 20x: 6 Key Takeaways' reinforcing shift to continuous evidence, KSIs, independent assessment, real-time dashboards – practical framing for CSPs. A Schellman blog article 'FedRAMP CR26: Why the SSP Is Being Replaced' provides the clearest articulation yet of why narrative artifacts fail under CR26. The SSP is replaced by the SDR with machine-readable KSIs on a 3-day cadence. Timeline pressure is real—18 months for Rev5 CSPs to rebuild evidence pipelines. The compliance industry's moat is evaporating; infrastructure capability becomes the differentiator. CSPs must internalize this shift now, not wait for mandatory transition.

Sources (5)
Updated Jul 28, 2026