Released June 24, 2026. FedRAMP published the Consolidated Rules for 2026 (CR26) — one stable ruleset that brings the FedRAMP 20x requirements together and resets the expectations FedRAMP uses to review every submission, Rev 5 included. CR26 is the umbrella over the year’s major changes: the Authorization→Certification rename and Classes A–D, the NTC-0012 incident-communications overhaul, the NTC-0013 Rev 5 baseline rebuild, and the NTC-0014 vulnerability-management regime — and it moves the whole package to machine-readable rules. It becomes mandatory January 1, 2027. This is the map of what changed and the dated path through it.
For most of 2026 the FedRAMP changes arrived as a stream of separate public notices, and it was easy to track each one without seeing the whole. CR26 is the moment they become a single system. It is the ruleset FedRAMP will apply to every submission going forward, the place the individual notices now live, and the format — structured data — the program is built on from here. If you hold a FedRAMP certification or you are mid-application, this is the document that governs the next eighteen months, and the changes underneath it land on specific dates rather than all at once.
This is a practitioner read of what CR26 actually consolidates, the four changes that matter most, and the dated path through the transition.
What CR26 is
In FedRAMP’s words, the Consolidated Rules for 2026 “bring the requirements for FedRAMP 20x into one stable ruleset and establish the expectation FedRAMP will use to review submissions going forward.” Two things are doing work in that sentence.
First, consolidation. The 20x program — the automation-first path built on Key Security Indicators — had been accumulating rules across a series of RFCs and notices. CR26 collects them into one place and pairs them with reset expectations for the Rev 5 world. One ruleset now governs both.
Second, a single review standard. CR26 is what FedRAMP measures every submission against from here. That is why it matters even to providers who never touched 20x: a Rev 5 certification is now reviewed against CR26’s expectations, not the prior patchwork.
CR26 is also the point at which FedRAMP commits to structured data. The rules are published as JSON at github.com/FedRAMP/rules, with an AI-agent-oriented markdown reference at github.com/FedRAMP/2026-markdown, and the certification package itself becomes machine-readable. The retired Rev 5 and 20x-pilot materials are preserved at fedramp.gov/legacy.
The four changes underneath CR26
CR26 is the umbrella; the substance is four changes, each with its own scope and its own clock.
1. Authorization became Certification, and impact levels became Classes A–D
The most visible change is terminology, and it is also the easiest to underestimate. “FedRAMP Authorization” is now “FedRAMP Certification,” and the Low / Moderate / High impact levels are now Certification Classes — Class B (Low), Class C (Moderate), and Class D (High), with Class A as the Pilot tier. The control baselines did not change with the rename; what changed is every place the old terms appear. SSP cover sheets, marketplace listings, customer-facing trust-center language, and contract clauses that say “FedRAMP Authorization” or “Moderate” now read as dated. This is a sweep-and-update job across your documentation and your sales surface, not a control change — but an agency reviewer reading “Authorization” in a 2027 package is reading a program that has not kept current. We cover the mechanics of the rename in the 20x deep-dive.
2. Incident communications were rebuilt — NTC-0012
The first operational notice, NTC-0012, rebuilt how every certified service reports incidents: reporting timeframes tiered by Certification Class and a renamed Potential Agency Impact (PAIN) rating, with an initial-report window as tight as 15 minutes for a Class D service at the most severe rating; impact estimation made optional with a fast-path default; a new requirement to name the likely-affected agencies; and the removal of the requirement to report agency-customer incidents directly to CISA. If your incident-response runbook still references the old “Potential Adverse Impact” terminology or assumes a CISA report, it is out of date.
3. The Rev 5 baselines were rebuilt — NTC-0013
The structural change. NTC-0013 removes most of the control parameter values FedRAMP used to assign — cloud providers now set and justify their own organization-defined parameters per NIST — relocates FedRAMP-specific guidance into a separate “FedRAMP Rules” construct, and replaces the SSP / SAR / Control Implementation Summary / Customer Responsibility Matrix templates with a machine-readable Certification Package (Certification Package Overview, Security Decision Record, Secure Configuration Guide). The controls themselves are unchanged; the way you author the package is not. This is the change most likely to surprise a team that built a Rev 5 package before.
4. Vulnerability management was reset — NTC-0014
The firmest-enforced piece. NTC-0014 adopts CISA’s BOD 26-04 risk model for certified CSPs through two rulesets — Vulnerability Detection and Response (VDR) and Vulnerability Evaluation and Reporting (VER) — moving providers off the flat monthly-scan cadence to an exposure- and threat-based model that prioritizes internet-reachable, exploitable, and Known-Exploited vulnerabilities. A binding operational directive does not reach a private company; NTC-0014 is what makes the model bind a certified CSP, with a hard consequence: it is mandatory December 7, 2026, and a non-compliant certification is revoked after March 7, 2027.
The dated path through the transition
The single most useful thing to take from CR26 is the calendar. The changes do not land together; they land on specific dates across late 2026 and into 2027:
- June 24, 2026 — CR26 is released; the rename and Classes A–D take effect in FedRAMP’s language and marketplace. (The blog post announcing it is dated June 25, which is why some coverage gives that date; FedRAMP’s own changelog files the release under June 24, and NTC-0015 refers to “the other CR26 important deadlines that went into effect June 24, 2026.”)
- July 4, 2026 — optional early adoption opens: “All stakeholders should begin incrementally adopting or transitioning to the Consolidated Rules for 2026.”
- July 6, 2026 — Marketplace listings open under CR26.
- July 28, 2026 — FedRAMP Ready becomes legacy; no new FedRAMP Ready submissions accepted.
- August 3, 2026 — the Class A pipeline opens.
- August 10, 2026 — the Ready Conversion and Lost Sponsor pipelines open.
- August 31, 2026 — the Class B and Class C pipelines open.
- December 7, 2026 — the NTC-0014 VDR/VER vulnerability rules become mandatory for all certifications.
- January 1, 2027 — CR26 becomes mandatory for all stakeholders; current Rev 5 certifications must have adopted the rules; the NTC-0013 baseline rebuild applies at a provider’s first independent assessment after this date.
- March 7, 2027 — end of the VDR/VER grace period; non-compliant certifications are revoked after this date.
- June 11, 2027 — FedRAMP stops accepting applications for new Rev 5 certifications.
The reading that matters: an existing certified provider is on a sequence of obligations, not a single cutover. The vulnerability rules bite first (December 2026), the broad mandate and the baseline rebuild follow (January 2027 and your next assessment), and the window to start a new Rev 5 certification closes in mid-2027.
”Stable” does not mean static — the ruleset is already moving
CR26 is described as a stable ruleset, and that is true in the sense that matters: it is the single thing FedRAMP reviews against. But it is a living document, and in the first three weeks after release FedRAMP shipped five rule releases. They are published in CR26’s own changelog at fedramp.gov/2026/changelog/ — a different page from the main site changelog, and the one to actually watch. Several of those releases carry real requirement changes, not typos:
- 2026.06.25.01 — the independent-assessment grace period changed from “on the first FedRAMP independent assessment completed after…” to “…started after…”. FedRAMP’s stated reason: “this change ensures the rules do not change during an assessment.” If you scoped your conversion against the word “completed,” your date moved.
- 2026.07.01.01 — annual independent assessments for Rev 5 were removed from the Class A requirements, and “All class a packages will use the 20x rules.” Class A is now a 20x-only tier.
- 2026.07.02.01 — terminology aligned to NTC-0012, replacing “Response” with “Communication” across the incident evaluation rules.
- 2026.07.06.01 — the separate Lost Sponsor and Ready Conversion sections were merged into a single pipeline with clarified eligibility criteria.
- 2026.07.14.01 — further rule clarifications and corrections to the FedRAMP JSON schemas, plus a display rename from “Certification Overview Package” to “Certification Package Overview.”
The practitioner takeaway is not any single item on that list. It is that a package authored against the June 24 text is already authored against a superseded revision, and the rules now ship as versioned releases with a changelog — which is exactly what you would expect once the ruleset became machine-readable. Pin the version you are building against, and read the changelog before an assessment rather than after.
What a provider should do now
- Treat CR26 as one program, not five notices. Map the rename, NTC-0012, NTC-0013, and NTC-0014 against your own service and build a single transition plan with the dates above as milestones. The failure mode is tracking each notice separately and missing how they stack.
- Sweep your documentation and sales surface for the old terms. “Authorization,” “Moderate,” “High” — update the SSP cover sheets, the marketplace listing, the trust center, and the contract language. This is low-effort and high-visibility, and it is the first thing an agency reviewer notices.
- Put December 7 on the calendar in red. The VDR/VER vulnerability rules are the first mandatory change and the one with a revocation date attached. Be operating against the exposure-based model by December 7, 2026, and use the grace period for correction, not for starting.
- Plan your Rev 5 conversion around your next assessment. The baseline rebuild — setting your own parameters and building the Certification Package — lands at your first independent assessment after January 1, 2027. Scope that work into the assessment deliberately rather than discovering it under deadline.
- Build for machine-readable from here. Whether you are converting an existing package or starting new, the Certification Package and the rules are structured data. If your package lives in prose, the conversion is an engineering task — budget for it.
When to engage
CR26 is the kind of change that is cheapest to absorb before you commit to a path. A provider deciding now whether to pursue a Class C (Moderate) certification, convert an existing Rev 5 authorization, or move toward the 20x model is making decisions that the transition calendar prices differently depending on timing — and the parameter-setting, package format, and vulnerability-management work all compound if they are left until a deadline forces them.
Our FedRAMP and DoD CC SRG practice tracks these rules as they land and helps providers turn CR26 from a stack of notices into a sequenced plan — the rename sweep, the incident runbook, the Rev 5 baseline conversion, and the VDR/VER vulnerability program, mapped to the dates that actually govern them. If you hold a FedRAMP certification or you are mid-application and just learned the rules consolidated under you, a scoping conversation will surface the order of operations quickly: which obligation bites first, what your next assessment has to carry, and what converting to the CR26 model takes before each date.
Related reading: NTC-0013 Rev 5 baseline overhaul · NTC-0014 vulnerability management (VDR & VER) · NTC-0012 incident communications overhaul · FedRAMP 20x deep-dive · FedRAMP framework overview