Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

FedRAMP compliance checklist: Rev5 and 20x paths and key dates

FedRAMP Compliance Checklist: The Best 8 Steps for 2027

A FedRAMP compliance checklist written before 2026 is now actively misleading. The Consolidated Rules changed the authorization paths, retired deliverables that every older checklist still tells you to write, and put dates on the end of Rev5.

This is the checklist as it stands in September 2026: what you actually have to do, in the order you have to do it, and the five dates that decide which path you are on.

FedRAMP compliance checklist: the Rev5 and 20x paths and the dates that separate them
Same control baseline. Different validation model, and different deadlines.

First decide which path you are on

This is the step every outdated checklist skips, and getting it wrong wastes months.

FedRAMP 20x is no longer a pilot limited to a handful of participants. With the Consolidated Rules it became a generally available path. It uses the same NIST SP 800-53 Rev5 control baseline, so the security requirements are not lighter. What changes is validation: continuous, machine-readable attestation instead of an annual point-in-time audit.

Rev5 remains available, but on a clock, and the Consolidated Rules changed it substantially rather than leaving it alone. The terminology moved to FedRAMP Certification, and Continuous Monitoring became Ongoing Certification with a wider scope.

Date What it means for you
4 July 2026 The Consolidated Rules took effect. All new FedRAMP 20x applications must follow them from this date.
1 January 2027 All new Rev5 applications must follow the Consolidated Rules, and active 20x certified offerings must comply or face a corrective action request.
11 June 2027 Last day to submit a new Rev5 certification application. Nothing is accepted after this.
1 February 2028 All grace periods expire. Offerings not following the rules lose their FedRAMP Certification, and FedRAMP states there will be no extensions.
31 December 2028 The 2026 Consolidated Rules themselves expire and are replaced by the next set.

The FedRAMP compliance checklist, step by step

A FedRAMP compliance checklist is only useful if it is ordered, and these steps genuinely are sequential. Each step produces the input the next one needs, which is why providers who run them in parallel end up redoing the categorisation.

1. Categorise the system under FIPS 199. Low, Moderate or High, derived from the impact of losing confidentiality, integrity or availability. Everything downstream scales from this, and a categorisation set too high is the most expensive avoidable mistake in the programme.

2. Draw the authorization boundary. What is inside, what is external, and where the interconnections are. Boundary disputes are the most common cause of assessment delay, and we cover the mechanics in the guide to the authorization boundary.

3. Complete the digital identity determination. Assurance levels under SP 800-63, recorded as a worksheet. Small document, and assessors ask for it early.

4. Write the policies and procedures behind the control families. Access control, audit and accountability, configuration management, incident response, personnel security, risk assessment, system and information integrity and the rest. This is the bulk of the documentation effort and the part a template set genuinely shortens.

5. Produce the system documentation your path requires. Here is where old checklists go wrong. The traditional System Security Plan and Plan of Action and Milestones are being retired under the Consolidated Rules in favour of a different deliverable set. Our guide to the FedRAMP SSP and the two documents that replaced it covers what to produce instead.

6. Secure an authorization path. Agency sponsorship remains the common route, and the steps are set out in the guide to the FedRAMP ATO. The wider sequence is in FedRAMP authorization.

7. Engage a 3PAO and run the assessment. A security assessment plan first, then testing, then the assessment report. The plan is a negotiation about scope and sampling, so treat it as one rather than a formality.

8. Stand up continuous monitoring before you are authorized, not after. Scanning cadence, reporting, availability reporting and incident notification. Under the Consolidated Rules the reporting triggers are broader and the incident thresholds more complex than most providers expect.

What most FedRAMP compliance checklists get wrong

Categorising high to be safe. It is not safer. It multiplies the control count, the assessment effort and the ongoing monitoring burden, and an assessor will ask you to justify it against the FIPS 199 analysis rather than against your comfort.

Treating the boundary as a network diagram. It is a scoping decision with contractual consequences, and external services inside it inherit your obligations.

Writing documentation for the old deliverable set. A checklist telling you to produce an SSP and a POA&M and stop there is describing a programme that is being phased out. Confirm which deliverables your path requires before you start writing.

What is in our FedRAMP toolkit

The pack is built around this FedRAMP compliance checklist rather than around a raw control list. It ships the FIPS 199 categorisation record, the digital identity worksheet, the security assessment plan, the annual assessment plan, and the policy set across the control families including access control, audit and accountability, personnel security, risk assessment, supply chain risk management and system and information integrity.

Programme documents are published by FedRAMP. The editable document set is in the FedRAMP Toolkit, or start with the free templates.

Dates and path descriptions reflect the FedRAMP Consolidated Rules position as at 6 September 2026. FedRAMP is changing quickly; verify against fedramp.gov before committing to a timetable.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.