Fast FedRAMP Authorization

Fast FedRAMP Authorization

Book a rapid FedRAMP demo—get authorized in six months or less.

FedRAMP Without an Agency Sponsor: Program Certification

FedRAMP Without an Agency Sponsor Program Certification
Facebook
Twitter
Pinterest
LinkedIn

FedRAMP as a program has been through a lot over the years it has existed. Different authorization paths, different requirements and standards, multiple rounds of streamlining and changes; it's been a rocky road.

Things are starting to smooth out now that FedRAMP 20x is broadly available, but there's still a lot to learn or to question before you can be fully up to speed. So, let's talk about authorization and where we stand today.

BLUF - Bottom Line Up Front

FedRAMP moved from agency ATO and JAB/P-ATO to FedRAMP 20x, which removed the JAB and favors program certification to speed authorization. Two parallel paths run now: Rev5 (older, agency focus) and 20x (new, program focus). Certification classes A–D replace impact levels; most CSPs will be Class C. Class D pilot starts Q1 2027. Steps: pick path, pick class, list on the marketplace, implement controls and get assessed.

ATO, P-ATO, JAB, and 20x; Tracing the History of Authorization

When it was first created, FedRAMP was meant to be a way for government agencies to identify and pick interested service providers, and guide their path to secure operations so they could work with the agency.

ATO P ATO JAB And 20x Tracing The History Of Authorization

As the program expanded and more and more businesses sought FedRAMP authorization, this model started to chafe.

An organization seeking authorization to operate with the federal government had a significant roadblock to overcome before they could even begin. They would need to find a government agency, department, or other entity that wanted to use their service, and get that government agency to sponsor their application through FedRAMP.

Well, despite the immense size of the federal government, there are only so many departments, so many agencies, and so many operations that need a secure, third-party contractor to handle them. With lengthy contracts on top, competition was fierce, and the process became very long and drawn out. Many Cloud Service Providers (CSPs) that wanted to join FedRAMP simply couldn't because they couldn't get agency sponsors.

The solution at the time was the JAB process.

The JAB was the Joint Authorization Board, one of the authority groups in charge of FedRAMP. The JAB offered a parallel authorization path. The Agency Authorization to Operate was the ATO process; the JAB offered the P-ATO, or Provisional Authorization to Operate, process.

The P-ATO process basically did all of the groundwork for an agency ATO, without an agency sponsor. The JAB acted as the sponsor for promising and potential CSPs, getting them ready for when an agency wanted to use their services without the lengthy (often 8-12-month process) of authorization from scratch.

Then, all this changed. In 2024, the shift towards the new paradigm of FedRAMP began with the "FedRAMP memo", M-24-15. This dismantled the JAB, eliminated the P-ATO process, and issued the directive that would eventually become what we have today: FedRAMP 20x.

The New Route to Authorization

Right now, near the end of 2026, we're in a period of transition.

The New Route To Authorization

The older, slower, more cumbersome FedRAMP version is FedRAMP Rev5, the fifth major revision of the FedRAMP program. The newer, more streamlined version is FedRAMP 20x. We're in the process of FedRAMP 20x replacing FedRAMP Rev5.

However, due to how slow Rev5 is and how different 20x is, the government has chosen to make the transition somewhat "soft" for the benefit of CSPs that have already been working on a FedRAMP Rev5 authorization. Just imagine if you were 8 months into a 12-month process of authorization, and the government changed the process and rules out from under you!

So, right now, there are two parallel authorization paths.

This is made more complicated by the two authorization paths within those two paths, and by the phased roll-out of FedRAMP 20x. Buckle up; this is going to get a little complicated.

Program vs Agency Certification

First up is the sub-selection: program certification or agency certification.

This is a mirror of the ATO and P-ATO distinction.

Program Vs Agency Certification

Program certification is a certification path working directly with the FedRAMP organization, which does not require an agency to sponsor the CSP before the CSP can get started.

Agency certification is the path that requires an agency sponsor for the CSP to get working on their authorization.

In the past, under FedRAMP Rev4 and Rev5, the program certification (P-ATO) was very limited and only offered to a relatively small handful of CSPs. With FedRAMP 20x, the Program Certification path is the preferred path.

Rev5 Certification vs 20x Certification

Rev5 is the older certification path, while 20x is the new certification path. There are a lot of changes with how 20x handles security and certification, with a heavier emphasis on organizationally-defined parameters, machine-readable artifacts and proof, and much more besides.

When it comes to the core path, it's a matter of outlook.

Rev5 Certification Vs 20x Certification

Rev5 focuses on the Agency path, with a very small number of CSPs qualifying for the Rev5 version of the Program path, the P-ATO equivalent (since the actual P-ATO died with the JAB).

20x, meanwhile, focuses entirely on the Program path. One of the huge goals of 20x at the most basic level is streamlining the speed of the authorization process, and eliminating the need to find an agency sponsor and work with them was a big way they accomplished this goal.

Determining Your Authorization Path

If all of this is sounding confusing, don't worry; it's actually a lot easier than it seems when you're just reading documentation. Basically, you just have to follow a flowchart. Answer these questions, and we'll help guide you to the right answer.

Determining Your Authorization Path

1: Have you started your authorization path yet?

If you're already in progress and have been for more than a few months, there's a pretty good chance you're on the Rev5 path and most likely working with an agency sponsor. If you're on Rev5 and have a Program certification in progress, you already know, and you probably aren't even reading this post.

On the other hand, if you have not yet started your authorization, your next question is about your impact level, or rather, your certification class.

2: What is your certification class?

Certification classes have replaced impact levels with FedRAMP 20x, but they aren't a simple 1:1 mapping. In fact, impact levels still exist; they're just used on the agency side instead of the CSP side now.

Instead, certification class is a measure of your risk as a CSP. They are broadly similar to impact levels, but not quite.

  • Class A: Used for pilots, testing, and extremely low risk levels, similar to FedRAMP Ready or Li-SaaS.
  • Class B: Roughly equivalent to FedRAMP Low, it's a low level baseline that might have a few higher-tier controls here and there if the need arises.
  • Class C: Roughly equivalent to FedRAMP Moderate, this is where the majority of CSPs are going to find themselves. In some cases, you might handle information that would previously have been High baseline, as long as you have compensating controls in place.
  • Class D: The highest tier, suitable for high impact level services and information.

If your CSP is Class A, B, or C, and you have not yet started authorization under a Rev5 path, you are going to go with the FedRAMP 20x Program path. But, since the Class D path does not yet exist, you can't use it.

3: What is your timeline?

If your CSP is Class D, you have two options. You can pursue certification now, which means going with the Rev5 Agency authorization path (or, in very rare cases, the Program path under Rev5). Or, you can delay until the current FedRAMP 20x pilot for Class D has concluded and the actual path is released for general use.

That Class D pilot is estimated to begin in Q1 2027, and likely won't be finalized and rolled out until Q3-4. So, you'll have around a year from this writing, give or take, to wait.

Many CSPs looking to work with the government, especially at a high impact level, aren't likely looking to wait a year. You will have to transition to FedRAMP 20x once it's available, but you can undergo the Rev5 process now just to get working sooner rather than later.

Right now, the bulk of CSPs are probably going to be aiming for FedRAMP 20x Class C Program Authorization.

4: Are you an exception to the rule?

There are two exceptions to the flowchart we've outlined above. Both are cases where a CSP would normally go through FedRAMP 20x Program Authorization, but instead will go with Rev5 authorization at Class B or Class C levels.

Exception #1: Lost Sponsor. If you're a CSP that has been working with an agency sponsor using the Rev 5 Agency process, but the government is tightening the purse strings and has cut the contract you were planning to win, you have lost your sponsor. Instead of leaving you high and dry, FedRAMP is graciously offering a conversion to the Rev5 Program Authorization Path.

To qualify for this conversion, you must have already been in process on the FedRAMP marketplace before you lost your sponsor. You can't have just been doing the work and hoping. Alternatively, you need to have already completed a full assessment, with your SAP and SAR, under an informal agreement with the agency you lost. You don't need to meet both, just one or the other.

Exception #2: Ready Conversion. If you were all set to be listed as FedRAMP Ready, you're in a tricky spot, since FedRAMP Ready was removed. If you have completed a Readiness Assessment Report, or if you were already listed as FedRAMP Ready on the FedRAMP marketplace, you can qualify for a Rev5 Program certification instead of needing to retool your entire authorization to suit FedRAMP 20x.

Both of these exception paths are already open, and close in February of 2027. It's a very limited transition period for CSPs caught in the middle.

How the Program Certification Path Works for FedRAMP 20x

One more note before we progress; we've been using the word "authorization" here to avoid causing yet more confusion, but another change in FedRAMP 20x is actually a change in terminology. FedRAMP is now actually a certification, and FedRAMP 20x authorization is actually becoming certified.

How The Program Certification Path Works For FedRAMP 20x

So, what is the path to becoming FedRAMP 20x certified with the program path?

Step 1: Choose Your Path

As outlined above, you choose your path first and foremost… except you don't actually choose this directly. It's more of a matter of the choices you've already made.

Step 1 Choose Your Path

You also verify whether you're in process with Rev5, if you're a high enough impact level to still need Rev5, or if you're good to go under the new 20x ruleset.

Step 2: Choose Your Class

While it's somewhat helpful to think of Classes in terms of impact levels, they don't map fully, so it's also good to look into the Classes in more detail.

Step 2 Choose Your Class

Class A is very limited and small in scope. Class B is for low-impact, low-responsibility, low-risk organizations. Class C is by far the most common, and Class D isn't available yet. So, you're probably Class C.

Step 3: Get a Marketplace Listing

Step 3 Get A Marketplace Listing

In the past, the marketplace was only for CSPs that were nearly done or fully finished with their authorization. Now, any CSP looking to apply to FedRAMP can apply to the marketplace for an Implementing listing, which helps inform Agencies that you exist. This helps you get an agency partner later.

Step 4: All the Work

Not to gloss over it too much, but once you're ready to get down to implementation, you have a million individual tasks. You need to review the FedRAMP rules, identify the security controls you need to implement, and implement them. You need to develop your documentation and proof in machine-readable formats. You need to find an assessor and schedule your assessment. And then, at long last, you can be certified, can seek agencies to work with, bid on contracts, and get to work.

Step 4 All The Work

Here at Ignyte, we can help you with basically all of this. As experts in FedRAMP, we can help you figure out what your class and path should be, and how to navigate your authorization process. The Ignyte Assurance Platform is also an ideal tool to help you track and implement all of your applicable security controls, while gathering the proof you'll need to submit all in one place. To see how it all works and how we can help, just book a customized demo today!

Stay up to date with everything Ignyte