On March 24, 2025, the General Services Administration (GSA) announced FedRAMP 20x, a plan to rebuild how cloud services get authorized for federal use. The stated aims are to automate most of the validation work, replace long narrative documents with machine-readable evidence, cut authorization times from months or years to weeks, and remove the need for an agency sponsor for simple, low-impact services. For now, though, the existing Rev. 5 agency authorization path remains the only active route, and many details of 20x are still being worked out in public.

Here's what has actually been announced, what's still forming, and how cloud providers should plan around it.

What is FedRAMP 20x?

FedRAMP 20x is GSA's initiative to create a new, cloud-native authorization process alongside the current one. In its announcement, GSA described the goal as making automated authorization "simpler, easier, and cheaper while continuously improving security."

The headline commitments from the announcement were:

  • Authorizations measured in weeks rather than months or years
  • No federal agency sponsor needed for simple, low-impact service offerings
  • Less unnecessary or duplicative paperwork
  • Security requirements that engineers can actually implement
  • Public working groups to shape the program with industry

This builds on earlier direction. The FedRAMP Authorization Act, enacted in December 2022, put the program into law, and OMB Memorandum M-24-15, issued in July 2024, pushed FedRAMP toward automation and machine-readable authorization packages. FedRAMP 20x is the most aggressive step so far in that direction.

What are the goals of FedRAMP 20x?

FedRAMP has organized 20x around five goals:

Goal What FedRAMP says it wants
Simplification through automation Automate validation of at least 80 percent of FedRAMP's security requirements
Leveraging existing commercial security frameworks Let providers build on the commercial security programs they already run
Hands-off approach to continuous monitoring Standardize, simplify and automate assessment and monitoring
Building trust through collaboration More direct interaction between providers and the agencies that use them
Enabling rapid improvements Remove the need for FedRAMP approval of "significant changes" to a service

These are statements of direction, not finished requirements. The mechanics behind each one are still being designed.

How will FedRAMP 20x change authorizations?

From narrative documents to machine-readable evidence

Under the current process, a cloud provider describes how it implements each control in a long System Security Plan, and an assessor reviews evidence largely by hand. FedRAMP 20x aims to flip that model. Instead of written explanations, providers would supply evidence that machines can check, and most requirements would be validated automatically.

FedRAMP has supported machine-readable authorization packages in NIST's Open Security Controls Assessment Language (OSCAL) for several years. What's new is the ambition: automated validation as the default, rather than an optional format for the same narrative content.

Less reliance on agency sponsorship

Today, a provider generally needs a federal agency willing to sponsor its authorization. That's a real barrier for smaller providers and newer services. GSA's announcement said simple, low-impact services won't need an agency sponsor under 20x.

FedRAMP leadership has been candid that the path without a sponsor is still being built. Until it exists, the sponsored agency path is how you get authorized.

Key Security Indicators

FedRAMP has said it will move away from a checklist of individual controls toward Key Security Indicators (KSIs). The idea is to express the intent of traditional controls as a smaller set of measurable, comparable indicators that can be validated automatically.

The specific indicators haven't been published yet. Expect them to be proposed publicly and refined with industry input before they're used in any authorization.

Continuous monitoring and change management

Two of the five goals target the ongoing burden after authorization. FedRAMP wants continuous monitoring to rely on automated reporting that providers generate from their own systems, rather than manual monthly packages. It also wants providers to be able to ship significant changes without waiting for FedRAMP approval.

Both would be a big shift for providers who currently plan releases around the significant change process. Neither has a published standard behind it yet.

What is Phase One of FedRAMP 20x?

FedRAMP has described a Phase One focused on a simplified, cloud-native, continuous assessment process for certain software-as-a-service offerings, run as a pilot. Together with GSA's statement about simple, low-impact services, that suggests the early work is aimed at the lower end of the risk spectrum rather than Moderate or High systems.

The practical details are still settling. Exact eligibility, what a participant would submit, how validation would work and what kind of authorization would result haven't been fully published yet. If you're interested in participating, watch FedRAMP's official channels and the working groups for the specifics, and don't commit engineering roadmaps on assumptions.

What are the FedRAMP 20x community working groups?

FedRAMP launched four public Community Working Groups to develop 20x standards and guidance with industry:

  • Rev5 Continuous Monitoring: improving monitoring under the existing Rev. 5 process
  • Automating Assessments: how assessments can be automated and validated
  • Applying Existing Frameworks: how commercial security frameworks can count toward FedRAMP
  • Continuous Reporting: how providers report security status on an ongoing basis

The groups are open to the public, and GSA has said they're meant to ensure equal access to information and encourage pilot programs. This is the best place to learn early what's coming, and to influence it. If your organization has strong views on how evidence should be structured or how commercial certifications should be recognized, this is where to raise them.

What happens to the Rev. 5 authorization path?

It continues. FedRAMP's own FedRAMP in 2025 post, published the same day as the announcement, states that "the existing Agency Authorization path based on FedRAMP Rev. 5 baselines is the sole active path to FedRAMP authorization" and that "no changes to this path are planned at this time."

GSA's announcement also said FedRAMP would continue to support traditional agency authorizations. FedRAMP has said it's concentrating on clearing the existing agency authorization backlog.

If you're partway through a Rev. 5 authorization, keep going. If you're already authorized, your continuous monitoring obligations haven't changed.

What should cloud providers do now?

The direction of travel is clear even though the details aren't. The steps below make sense whichever way the specifics land:

  1. Stay on your current path. Don't pause a Rev. 5 authorization or continuous monitoring program on the expectation that 20x will replace it soon.
  2. Automate your evidence. Inventory the controls where evidence already comes from systems, such as configuration state, access reviews, vulnerability scan results and logging coverage. Build pipelines that produce that evidence on demand, in structured formats.
  3. Invest in machine-readable documentation. If you haven't worked with OSCAL, start. Even if 20x formats end up different, structured data is easier to convert than prose.
  4. Map your commercial frameworks. If you already hold a SOC 2 report, ISO/IEC 27001 certification or similar, document how those controls line up with FedRAMP requirements. One of the stated goals is to recognize that work.
  5. Treat continuous monitoring as an engineering problem. Aim for dashboards and automated reports, not monthly spreadsheets. That positions you for either model.
  6. Join a working group. Assign someone to follow the working groups, read proposals as they're published and contribute comments.
  7. Keep your agency relationships. Sponsorship may matter less in the future, but agency customers still decide whether to use your service.

Frequently asked questions

Does FedRAMP 20x replace FedRAMP Rev. 5?

Not today. FedRAMP has stated that the Rev. 5 agency authorization path is the only active path and that no changes to it are planned. 20x is being developed alongside it.

Can we get authorized without an agency sponsor now?

Not yet. GSA said simple, low-impact services won't need a sponsor under 20x, but that path is still being built. Current authorizations still go through the sponsored agency path.

What are Key Security Indicators?

They're FedRAMP's planned replacement for checking a long list of individual controls: a smaller set of measurable indicators that show security outcomes and can be validated automatically. The actual indicators haven't been published yet.

How fast will 20x authorizations be?

GSA's stated goal is weeks rather than months or years. Treat that as a target until the process has been tested in practice.

Key takeaways

  • GSA announced FedRAMP 20x on March 24, 2025, aiming for automated, cloud-native authorizations measured in weeks.
  • The goals include automated validation of at least 80 percent of requirements, reuse of commercial frameworks, automated continuous monitoring, and no agency sponsor for simple, low-impact services.
  • Key Security Indicators and Phase One details are still being defined, largely through four public working groups.
  • The Rev. 5 agency authorization path remains the only active route, with no changes planned.
  • Start automating your evidence and structuring your documentation now. That work pays off whatever the final model looks like.