Skip to content
Capability/Compliance Frameworks

FedRAMP

Federal cloud service authorization

01 / Overview

The Federal Risk and Authorization Management Program provides a standardized approach to security assessment and authorization for cloud services. Thalorin accelerates FedRAMP authorization with automated evidence collection, package generation, and continuous monitoring that maintains authorization status.

FedRAMP is in the middle of the largest change to its operating model since the programme began. The 20x initiative is replacing document-centric authorization with automated, continuously validated assessment, and the vocabulary changed with it: under the consolidated 2026 rules, "FedRAMP Authorized" is retired in favour of "FedRAMP Certified" as the single official label across every path.

The timeline matters more than the terminology. Rev 5 remains an active path through 2026, but document-based Rev 5 certifications end on 30 September 2027, after which 20x is the only route. A cloud service provider starting a traditional Rev 5 package in 2026 needs to know whether it will finish before that door closes.

Phase Two of 20x, piloted through the first half of 2026, introduced expectations that change how a CSP must be built rather than merely how it is documented: authorization data sharing, persistent validation and assessment, recommended secure configurations, and a substantial overhaul of vulnerability detection and response. Providers can also adopt the optional Significant Change Notification process in place of the older Significant Change Request.

Thalorin models the control state as machine-readable evidence from the outset, which is the posture 20x assumes. The same state produces a Rev 5 package for an authorization in flight and continuous validation output for the path replacing it.

02 / Challenges

Framework compliance requires sustained effort

A closing door on Rev 5

Document-based Rev 5 certifications end 30 September 2027. A package started late in the window may not complete in time, and the remediation is not a deadline extension but a different programme.

Continuous validation replaces periodic evidence

20x expects persistent validation rather than an annual assessment plus monthly ConMon uploads. Organisations whose evidence is assembled by humans on a schedule cannot simply be re-pointed at the new model.

Sponsorship and demand

An agency authorization still requires an agency willing to sponsor and review. Engineering readiness does not by itself produce a certification, and providers routinely underestimate the sponsorship path.

Vulnerability response under the new expectations

The Phase Two overhaul of vulnerability detection and response tightens what must be demonstrated continuously, not just what must be reported after the fact.

03 / Capabilities

How Thalorin helps

FedRAMPNIST 800-53FedRAMP Rev 5

FedRAMP package generation

Generate the System Security Plan and its supporting artifacts in machine-readable form from the start, which is the shape 20x continuous validation assumes rather than a later conversion project.

3PAO assessment support

Track NIST SP 800-53 Rev 5 control implementation with each control bound to the system components that satisfy it, so an assessor tests the system rather than the narrative.

Continuous monitoring automation

Maintain the boundary and data-flow model as a live artifact, so a change to the service surfaces as authorization impact rather than at the annual assessment.

ConMon reporting

Carry POA&M items with their remediation clocks and evidence of closure rather than as a static spreadsheet.

Significant change management

Support both the Significant Change Request and the newer Significant Change Notification processes as the programme transitions.

Agency authorization support

Reuse the same control state across FedRAMP, StateRAMP, and DoD authorization paths where the underlying controls overlap.

Questions

FedRAMP: common questions

Is FedRAMP Authorized still the correct term?

Not under the consolidated 2026 rules. "FedRAMP Authorization" and "FedRAMP Authorized" are retired in favour of "FedRAMP Certification" and "FedRAMP Certified" as the single official label across every path. Existing marketplace listings and contract language will take time to catch up, so both terms are in circulation.

When does the Rev 5 path close?

Document-based Rev 5 certifications end on 30 September 2027, after which 20x becomes the only path forward. Rev 5 remains active through 2026, so it is still a viable route for a package that will complete comfortably before that date.

What changed in FedRAMP 20x Phase Two?

Phase Two, piloted through the first half of 2026, added expectations for authorization data sharing, persistent validation and assessment, and recommended secure configurations, along with a substantial overhaul of vulnerability detection and response requirements. It also introduced the optional Significant Change Notification process as an alternative to Significant Change Requests.

Do I need an agency sponsor?

For an agency authorization, yes — an agency must sponsor and review the package. This remains the practical bottleneck for many providers, and it is independent of technical readiness. Providers that treat sponsorship as a business development problem rather than a compliance one generally move faster.

Does FedRAMP certification satisfy DoD requirements?

Partially, and it depends on impact level. FedRAMP Moderate is frequently a prerequisite rather than a conclusion for DoD work, with additional requirements from the DoD Cloud Computing SRG applying at higher impact levels. Reciprocity reduces duplicated effort but does not eliminate the DoD-specific overlay.

Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.

05 / Get Started

Talk to us about FedRAMP.

See how one evidence artifact satisfies FedRAMP requirements alongside every other framework you carry.