Plans of Action and Milestones no longer exist. The Consolidated Rules for 2026 replaced them with Accepted Weaknesses, renamed Authorization to Certification, turned impact levels into Classes A to D, and replaced the System Security Plan with the Security Decision Record.
This assessment is written to CR26, which took effect on 4 July 2026. It scores 60 questions across the Key Security Indicators and the ruleset obligations around them, including the four notification clocks on transformative change that catch most providers out. It is free, it saves as you go, and you can stop and come back to it.
What this is
If your FedRAMP material still says 3PAO, JAB, POA&M and impact level, it predates the rules that now apply. Under CR26 the assessor is an Independent Assessor who must be FedRAMP Recognized and A2LA accredited; the JAB was replaced by the FedRAMP Board; and the package is three documents — the Certification Package Overview, the Secure Configuration Guide and the Security Decision Record — supplied in JSON valid against the FedRAMP schema alongside the human-readable version.
The dates that matter: mandatory adoption of CR26 on 1 January 2027, and no new Rev5 certifications after 11 June 2027. Rev5 is not dead, but it runs in parallel on a published run-off, and a provider cannot pursue both Rev5 and 20x for the same offering at once.
The background is elsewhere — how authorisation works, the ATO, the system security plan, the boundary, the checklist, continuous monitoring, what it costs and against GovRAMP. Come here when you want a score.
What it covers
60 questions, about 45 minutes.
| Section | Questions |
|---|---|
| Start – path, class and type | 5 |
| Scope and certification package | 6 |
| Architecture and service configuration | 10 |
| Identity, logging and monitoring | 7 |
| Policy, inventory and change management | 8 |
| Recovery, incident, supply chain and training | 8 |
| Independent verification and validation | 6 |
| Continuous monitoring and data sharing | 10 |
How the scoring works
| Status | Weight | Means |
|---|---|---|
| Not started | 0% | No policy, process or activity exists |
| Planned | 25% | Agreed and scheduled, nothing in place yet |
| Partially implemented | 50% | In place for part of the scope, or applied inconsistently |
| Implemented, not evidenced | 75% | Operating as intended, but you could not prove it today |
| Implemented and evidenced | 100% | Operating as intended, with records someone could sample |
| Not applicable | — | A justified exclusion, removed from the score |
Note how often the Key Security Indicators use the word persistently. FedRAMP is asking about continuous review and automated enforcement, not point-in-time evidence, so a quarterly manual check usually scores as partial however well documented it is.
Free score, or the full report
The assessment and your overall score are free. The full report is a one-off $39 and gives you every question with your status and notes, the score broken down by section, a prioritised gap list, and the documents from the FedRAMP Toolkit that close each gap — as a PDF and a working Excel file.
How long does it take?
About 45 minutes. Cloud native architecture and service configuration are 16 of the 46 Key Security Indicators between them and take the longest.
What to do with your score
Below 40% — start with the path, class and type decisions. They determine which rulesets apply to you, and a gap assessment against the wrong class measures the wrong thing.
40–70% — the usual shape for a provider with a SOC 2 Type II. The security controls are largely there; the CR26 machinery — trust centre, programmatic access, machine-readable package, notification clocks — is not.
Above 70% — rehearse the significant change path. Four notifications on a transformative change, one of them 30 business days before you start, is a process that has to exist before you need it.
Frequently asked questions
Is this assessment really free?
Yes. All 60 questions, the breakdown by section and your overall score cost nothing. The $39 report is optional.
Do I have to address the Key Security Indicators?
Classes B, C and D must address all of them, assessed at minimum annually. Class A may, and can instead satisfy an underlying framework such as SOC 2 Type II.
Is Rev5 finished?
Not yet. Rev5 runs in parallel as a certification type under CR26, but no new Rev5 certifications are granted after 11 June 2027.
What about Class D?
Class D is the highest assurance class and is still in development under Phase Four. 20x currently offers Classes A, B and C.
Can I use this for a client?
Yes. Run one assessment per client organisation.
What happens to my answers?
They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.