Two Programs, One Vocabulary Gap
If a company handles Controlled Unclassified Information under Department of Defense contracts, every cloud service that stores, processes, or transmits that data must meet a specific FedRAMP standard, and a C3PAO will verify it during the CMMC assessment. A cloud service that falls short is a finding, and a finding in this area puts the certification itself at risk. The requirement predates CMMC. It has been in DFARS 252.204-7012 since 2016, and CMMC is simply the mechanism that now verifies it.
The difficulty is that the regulation and the marketplace no longer speak the same language. The cloud requirement in 32 CFR Part 170 is written in terms of FedRAMP Moderate, a label the program that issues it is now retiring. For the next several years, contractors will be evaluating cloud vendors whose certifications speak one vocabulary against a regulation that speaks another. The translation is manageable, but it has to be done deliberately.
What the Rule Requires
The requirement has two paths. Either the specific cloud service offering is FedRAMP Authorized at the Moderate baseline or higher and listed on the FedRAMP Marketplace, or the offering meets equivalency as the Department defined it in a memorandum dated December 21, 2023. The equivalency definition is demanding: 100 percent compliance with the FedRAMP Moderate security control baseline, validated by a FedRAMP recognized 3PAO, with no open POA&Ms for any security control and a complete Body of Evidence produced on request. The memorandum also states that equivalency does not confer an actual FedRAMP authorization. Both paths are defined by name against the Moderate baseline.
What Changed at FedRAMP
The Consolidated Rules for 2026, published June 25, opened for optional early adoption on July 4, 2026 and take mandatory effect for all stakeholders on January 1, 2027. They replace the baseline labels with Certification Classes and establish FedRAMP Certified as the single official authorization label, while the Marketplace separately identifies each service's certification type and baseline, with class labels phasing in as the transition proceeds.
The class mapping. Class B includes the former Low baseline. Class C includes the former Moderate baseline. Class D includes the former High baseline. Class A is new and has no predecessor among the baselines.
The transition dates. FedRAMP Ready stops accepting submissions on July 28, 2026. The Class A pipeline opens on August 3, 2026, and the Class B and Class C pipelines open on August 31, 2026. New applications under the legacy Rev5 process end on June 11, 2027. No existing authorization is stripped by the transition.
Class A Is the Claim to Watch
Class A is a transitional designation that FedRAMP designed deliberately as an entry path into the federal market. A provider qualifies on the strength of an external framework assessment, initially a SOC 2 Type II report, then has a window of two years to complete a full FedRAMP assessment and obtain a Class B, C, or D certification. It absorbs the role of the retired FedRAMP Ready designation, which never satisfied the CMMC cloud requirement, and its successor occupies the same preparatory ground. None of this is a defect in the program, and a provider holding a Class A certification has done nothing wrong by saying so. The issue is what the statement does and does not establish, because FedRAMP Certified now covers every class, and a Class A certification carries no information about the Moderate baseline.
The Equivalency Measurement Problem
FedRAMP has stated that it does not adjudicate equivalency and that questions about how its certifications map to CMMC belong to the Department of Defense. The Department has not yet issued guidance connecting the new classes or the 20x assessment model to the CMMC cloud requirement. The December 2023 memorandum defines equivalency against a specific list of several hundred security controls, while 20x assessments are organized around a streamlined set of measures called Key Security Indicators. Both approaches aim at security, but they do not measure in the same units, and there is no published crosswalk between the two. Until the Department speaks, the memorandum means exactly what it says.
How the consequence arrives. There will be no announcement and no deadline. The question surfaces during a C3PAO assessment as an ordinary document request, when the assessor asks which cloud services handle CUI and what the FedRAMP status of each one is. At that moment the answer is either in the Marketplace record or in the Body of Evidence, or the company has a finding.
The discipline is unchanged. Treat every FedRAMP claim as a question about a specific service offering, a specific class, and a specific evidence package. That was already the correct practice before July 4. The new vocabulary only raises the cost of skipping it.
Five Questions for the Executive
An executive does not need to master the control baselines to manage this exposure. The paper closes with five questions to put to the compliance team in writing: which cloud services touch CUI, including services embedded inside other services; the exact offering name and Marketplace status of each, stated by class or legacy baseline; whether the Body of Evidence has actually been examined for any equivalency claim; whether the assessed boundary covers the components the company actually uses; and whether all of it is recorded in the System Security Plan before an assessor asks.
Download the Full White Paper
The full paper walks through the class structure and transition dates, the Class A mechanics and the FedRAMP Ready lineage, the December 2023 equivalency memorandum, the measurement gap between Key Security Indicators and the Moderate control baseline, a table mapping nine vendor claims to the requirement, and the five verification questions. Every regulatory claim is supported by a citation to 32 CFR Part 170, DFARS 252.204-7012, the DoD CIO memorandum, and FedRAMP's published rules and notices.
The CMMC Decision, Second Edition
Strategic guide for CEOs and senior executives of small and mid-sized defense contractors. Level determination, enforcement timelines, certification economics, and the governance questions executives cannot delegate to the IT organization.
Read More →