Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

FedRAMP ATO agency authorization guide

FedRAMP ATO: A Clear Guide to the 5 Agency Steps in 2026

A FedRAMP ATO is a decision a single federal agency makes about a single use of a cloud service — and under the Consolidated Rules for 2026 it is deliberately no longer the same thing as being “FedRAMP authorized”. FedRAMP now certifies the service and packages the evidence; the agency still decides whether to accept the risk and issue the authorization to operate.

Confusing the two is the most expensive misunderstanding in federal cloud sales, because it is what leads a provider to tell an agency that no further work is required. This guide sets out how a FedRAMP ATO is granted in 2026, the five steps an agency actually runs, and the dates that decide which path you are on.

FedRAMP ATO: what FedRAMP certifies and what the agency decides
Two decisions, two owners: FedRAMP certifies the offering, the agency authorizes its own use of it.

What a FedRAMP ATO is, and what it is not

FedRAMP Certification is the status of a cloud service offering that has been assessed under FedRAMP practices. It produces a Certification Package that agencies may treat as presumptively adequate evidence for the provider’s part of the system. It does not authorize anything by itself.

The authorization to operate is the agency’s risk decision about its own system: the configuration it chose, the data it will put in the service, the integrations it built, and the controls it inherits versus the ones it implements. Two agencies using the same certified service will hold two different authorizations, because they made two different decisions.

  FedRAMP Certification Agency ATO
Who decides FedRAMP, on evidence validated by an independent assessor The authorizing official at the using agency
Scope The cloud service offering as the provider operates it The agency’s system, configuration and data
Output A reusable Certification Package An authorization decision with a term and conditions
Reusable? Yes — that is the point of the program No — each agency issues its own

The five steps to a FedRAMP ATO

The Consolidated Rules describe initial agency authorization as a sequence the agency owns from beginning to end.

1. Define the use and the protections it needs

The agency describes the work the service will support, who will use it, and what federal information it will handle — including features, data flows, integrations and prohibited uses. It categorizes the system under FIPS 199 and FIPS 200 and selects the control baseline from NIST SP 800-53B. Everything downstream depends on this being written down honestly; a categorization set low to make the paperwork easier is the failure that surfaces at the worst possible time.

2. Compare certified services

The agency reviews the available Certification Packages against that need: the security capabilities of each offering, the configurations the agency itself would have to apply, and the assessment results. This is where a provider’s package earns its keep or fails to.

3. Confirm the provider can support the plan

Using the provider’s Secure Configuration Guide, the agency checks that the service actually supports the intended implementation — identity integration, logging, administrative controls, data protection options. A limited pilot is encouraged where it reduces uncertainty, but a pilot does not waive any authorization requirement.

4. Configure, implement and assess

The agency configures the service, implements the controls that are its own responsibility, tests the implementation, and documents it in the agency System Security Plan. The rules are explicit that the agency does not copy the provider’s package into its own plan — inherited controls are referenced, not restated.

5. Authorize, then notify FedRAMP

The agency completes its authorization documentation, makes the decision, notifies FedRAMP and supplies the required information, and moves into ongoing authorization. Continuous monitoring is a condition of the authorization staying valid, not an afterthought.

One constraint is worth planning around: agencies are told not to authorize a FedRAMP Class A service for longer than twelve months unless the provider is pursuing a higher certification class. Class is a tiered measure of assurance, and a Class A offering supplies the least of it — so a low-class certification buys market access but leaves every customer on a short renewal cycle.

The dates that decide your FedRAMP ATO path

The Consolidated Rules for 2026 took effect on 4 July 2026 as the point at which all stakeholders should begin adopting or transitioning to them. The dates that follow are the ones to plan against:

  • 28 July 2026 — FedRAMP Ready submissions closed; providers pursue Class A certification instead.
  • 3 August 2026 — applications open for FedRAMP 20x Class A certifications.
  • 10 August 2026 — limited pipelines open for existing providers to apply for Rev5 Class B and C certifications without a sponsor.
  • 31 August 2026 — applications open for FedRAMP 20x Class B and C certifications.
  • 1 January 2027 — the new rules become mandatory; providers must comply to maintain certification.
  • 11 June 2027 — FedRAMP stops accepting applications for new Rev5 certifications.

The practical reading for a provider: 20x is now the forward path and does not require an agency sponsor, while Rev5 remains available to those already in it but is closing to newcomers in mid-2027. The practical reading for an agency: a Certification Package you are handed in 2027 may have been built under either ruleset, and the class tells you how much assurance sits behind it.

What providers get wrong about the FedRAMP ATO

Treating certification as the finish line. It is the start of the sales conversation, not the end. The agency still has to categorize, configure, test and document.

Writing a configuration guide for engineers, not authorizing officials. Step three of the agency process runs on the Secure Configuration Guide. If it does not clearly say how identity, logging and data protection are configured for federal use, the agency has to discover it by trial, and that time comes out of your sales cycle.

Assuming equivalency. FedRAMP does not support or provide “equivalency”, and it is not the route to defense contractor requirements — CMMC questions go to the Department of Defense, not to FedRAMP.

Frequently asked questions

Is a FedRAMP ATO the same as FedRAMP authorization?
Not under the 2026 rules. FedRAMP Certification is the program’s status for a cloud service offering; the ATO is the individual agency’s decision to operate its own system using that service.

Does 20x still need an agency sponsor?
No. The 20x path was designed to be available to any provider that can demonstrate government-wide use, which is what removed the sponsor bottleneck.

How long does a FedRAMP ATO last?
It is set by the authorizing official and maintained through continuous monitoring. For a Class A service, agencies are directed not to authorize for more than twelve months unless the provider is pursuing a higher class.

Do agencies still write a System Security Plan?
Yes — the agency’s own plan, covering its configuration and the controls it implements. What changed is the provider’s base system security plan, which has been replaced.

Can we reuse another agency’s ATO?
You reuse the Certification Package, not the authorization. Each agency issues its own.

Where this leaves you

The 2026 rules made explicit what was always true: FedRAMP validates evidence, agencies accept risk. If you are a provider, the fastest FedRAMP ATO is the one where your package answers the agency’s step-one questions before they are asked, and where your configuration guide survives contact with an authorizing official. If you are an agency, the five steps are yours — categorize honestly, compare packages against the actual use, pilot where uncertainty is real, and keep your own plan rather than importing the provider’s.

References

More on federal cloud authorization

The templates and registers behind an authorization package are in the FedRAMP Authorization Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.