Fortinetics Book a call →
Menu
03 — FedRAMP & DoD CC SRG

FedRAMP certification and the CR26 rules that become mandatory January 1, 2027.

For cloud service providers serving federal agencies and the Department of Defense. FedRAMP is the federal-wide baseline; the DoD Cloud Computing SRG layers DoD-specific controls on top for workloads handling CUI and mission-critical data.

You might be here because
  • You hold a Rev 5 authorization and just learned the rules consolidated underneath you.
  • Your ConMon program is built around monthly scanning, which VDR/VER retires on December 7, 2026.
  • A federal deal is blocked on certification and you need a realistic date, not a hopeful one.
  • You are deciding between the 20x path and a Rev 5 package that stops being accepted in 2027.

Cloud Authorization

FedRAMP changed more in 2026 than in the prior five years. On May 4, 2026 'Authorization' became 'Certification', and CR26 introduced Certification Classes A through D. The classes are not the impact levels renamed. FedRAMP says so directly: agencies should not treat them as one-for-one replacements for Low, Moderate, or High, and there is no direct correlation between the two. A class describes how much assurance information you commit to supplying; FIPS 199 categorization still describes the data, agencies are still required to perform it, and FedRAMP is emphatic that a class is not a statement about how secure a service is. The classes also arrive on their own schedule — the Class A pipeline opened August 3, 2026, Classes B and C on August 31, and Class D is piloting late in the year for formal availability in early 2027.

CR26 itself landed on June 24, 2026: one versioned, machine-readable ruleset that governs how every submission is reviewed, and it becomes mandatory for all stakeholders on January 1, 2027. New Rev 5 applications stop being accepted June 11, 2027.

Underneath CR26 sit three changes with their own clocks: the Rev 5 baselines were rebuilt so providers now set and justify their own control parameters (NTC-0013); vulnerability management moved off flat monthly scanning to an exposure- and threat-based model that is mandatory December 7, 2026 with certifications revoked after March 7, 2027 (NTC-0014); and incident communications were rebuilt with reporting windows as tight as 15 minutes (NTC-0012).

We prepare the certification package, work with a 3PAO for independent assessment, coordinate the agency relationship, and design continuous monitoring up front rather than retrofitting it. For DoD work we sequence FedRAMP so it directly accelerates the CC SRG authorization (IL4, IL5, and IL6) with no duplicated effort.

What we actually deliver
  • Path selection: 20x Certification vs Rev 5, and what each costs you in time
  • Certification boundary definition and the machine-readable Certification Package
  • Control parameter selection and justification under the rebuilt NTC-0013 baselines
  • 3PAO selection, coordination, and assessment support
  • Agency sponsor coordination — the widest schedule variable in the whole engagement
  • VDR/VER vulnerability program built to the exposure-based model before it binds
  • Incident communications runbook rebuilt to the NTC-0012 timeframes
  • DoD CC SRG IL4/IL5/IL6 overlay sequenced onto the FedRAMP work
We have done this before

All engagements are anonymized. We do not publish client names.

Next step

Start with a scoping conversation.

No obligation and no pitch deck. We will tell you what the engagement actually involves, what it depends on, and whether we are the right firm for it — including when we are not.

Other services