Today, July 28, 2026, is the final day of the FedRAMP Ready submission model. FedRAMP, the Federal Risk and Authorization Management Program administered under the General Services Administration, is the gate through which cloud services enter federal agency use, and Ready has for years been the entry-level designation providers earned to signal they were prepared for full authorization. As of today, that designation moves to legacy status, no new Ready submissions will be accepted, and new market entrants are directed toward FedRAMP 20x certification instead. For any company that sells or plans to sell cloud services to the federal government, and for the governance, risk, and compliance teams that support them, the compliance model is changing shape, not just changing names.
What Happened
On June 25, 2026, FedRAMP published the Consolidated Rules for 2026, referred to as CR26, which bring the FedRAMP 20x framework out of its pilot phase and into a single stable ruleset with firm dates. FedRAMP 20x is the program's modernization effort, built around measurable security outcomes, machine-readable evidence, and continuous evaluation rather than the large point-in-time documentation packages that defined the legacy process. CR26 governs both the new 20x path and a modified version of the legacy Rev5 path during the transition, and it establishes the calendar now in motion:
- July 28, 2026: FedRAMP Ready becomes Legacy FedRAMP Ready. No new Ready submissions are accepted after today.
- August 3, 2026: The FedRAMP 20x Class A certification pipeline opens.
- August 10, 2026: Limited temporary Rev5 Program Certification pipelines open for eligible Class B and Class C providers through the Ready Conversion and Lost Sponsor paths.
- August 31, 2026: The FedRAMP 20x Class B and Class C pipelines open.
- January 1, 2027: The Consolidated Rules for 2026 become mandatory for all stakeholders, including currently certified Rev5 systems.
- June 11, 2027: FedRAMP stops accepting applications for new Rev5 certifications, closing the legacy path to new entrants entirely.
Two structural changes travel with the calendar. First, the new Program Certification route under 20x does not require an agency sponsor, removing what has long been the hardest gate for smaller providers to pass. Second, continuous obligations replace annual ones: certification under CR26 is maintained through ongoing certification reporting, recurring reviews with agency customers, and structured vulnerability detection and response requirements that become mandatory across certifications on December 7, 2026.
A Class Is Not a Security Grade, and Ready Did Not Become Class A
Two misreadings are already circulating. The new Classes A through D describe the scope of the assessment and the depth of information available to an agency making a use decision; they are not a ranking of how secure a service is, and the FIPS 199 impact categorization of Low, Moderate, and High still applies underneath them. Separately, FedRAMP Ready did not convert into Class A. Ready is simply retired, and Class A is a distinct certification with its own requirements on the 20x path. A provider that held Ready holds Legacy FedRAMP Ready today, nothing more, until it completes a conversion or a new certification.
Who Is Affected
The direct population is cloud service providers that hold FedRAMP Ready, are mid-pursuit of it, or planned to use it as their federal market entry point. The indirect population is larger: GSA schedule contractors and other federal suppliers whose offerings depend on FedRAMP-certified platforms, agencies evaluating services in the Marketplace, and the internal GRC teams responsible for producing and maintaining compliance evidence. Providers already holding a sponsored Rev5 authorization keep it, but they adopt the CR26 rules by January 1, 2027 and should understand that the path they came in on closes to new applicants in June 2027.
Why It Matters
The larger story here is not the retirement of a label. It is what the replacement model demands of a compliance program. The legacy process rewarded the ability to assemble a large document package once and refresh it annually. CR26 and the 20x framework reward the ability to produce structured, machine-readable evidence continuously: security claims expressed as measurable indicators, automated collection of the data behind them, and recurring validation rather than an annual scramble. A GRC program built around a shared drive of Word documents and a yearly assessment calendar can satisfy the old model. It cannot satisfy the new one, and the gap between the two is tooling, process, and ownership, none of which appear overnight.
The transition calendar also compresses decisions. A provider holding Legacy Ready has conversion options with their own eligibility rules and windows, and the temporary Rev5 pipelines opening August 10 are explicitly limited. Waiting to see how the transition settles is itself a decision, and probably the worst available one, because the options narrow with each date on the list above.
What Providers and Contractors Should Do Now
- Determine your current status precisely: Ready held before today, Ready in progress, sponsored Rev5 authorization, Rev5 in progress with a sponsor, or new entrant. The right path differs for each.
- If you held Ready, review the conversion options in CR26 and confirm eligibility with FedRAMP before assuming a path. Conversion windows and the temporary Rev5 pipelines carry their own deadlines.
- If you are a new entrant, plan against the 20x Class A pipeline opening August 3 rather than reviving a Ready strategy that no longer exists.
- If you hold a Rev5 authorization, inventory what CR26 adoption requires of your system before January 1, 2027, including the vulnerability detection and response requirements that arrive December 7, 2026.
- Assess whether your GRC tooling can produce machine-readable evidence and support continuous reporting. If your evidence lives in documents assembled by hand, this is the gap to close first.
- Assign ownership. Continuous obligations fail quietly when they belong to everyone. Someone must own the reporting calendar, the evidence pipeline, and the agency review cadence.
- If your federal revenue depends on a third-party platform's certification, ask that provider which path it is on and what its transition dates are. Their gap becomes your gap.
Questions Management Should Ask Today
- What is our exact FedRAMP status as of today, and what did it become when Ready went legacy?
- Which certification path and Class are we pursuing, and who made that decision on what basis?
- Which of the dates between August 3, 2026 and June 11, 2027 apply to us, and what must be complete before each?
- Can our current GRC systems produce structured, machine-readable evidence, or are we assembling documents by hand?
- Who owns continuous reporting once certification is no longer an annual event?
- What federal revenue depends on this transition going well, and what is the cost of a lapsed or delayed certification?
The Bottom Line
FedRAMP Ready ending is the visible event. The consequential event is the model shift underneath it: away from static, point-in-time compliance packages and toward machine-readable evidence, continuous reporting, and automated certification maintenance. Providers that treat this as a renaming exercise will discover the difference at their first submission under the new rules. Providers that treat it as a GRC capability question, and start building the evidence pipeline now, will find the new model is actually easier to live under than the old one, because the work is spread across the year instead of concentrated into an annual documentation effort. The calendar started moving today. The decision about which path to take should not wait for the next date on it.