Native FedRAMP Class B & C Intake Is Now Live
The FedRAMP 20x Class B and Class C pipelines opened on August 31, 2026. Lazarus Alliance is now accepting native intake for both classes.
That is not a small process change. It is the point at which Low and Moderate work stops being treated as a retrofit of Rev5 paperwork and starts being treated as a 20x certification path: Key Security Indicators, machine-readable packages, and continuous validation.
If your offering belongs on the federal marketplace at Low or Moderate assurance, the window to enter on the new rules is open.
What Just Opened
Under the Consolidated Rules for 2026, FedRAMP replaced the familiar Low / Moderate / High labels with Certification Classes A through D. Class A opened August 3. Class B and Class C opened together on August 31.
- Class B is the updated Low path. It consolidates the old Low and Li-SaaS tracks. Providers must meet 51 KSIs.
- Class C is the updated Moderate path. This remains the center of the federal cloud market. Providers must meet 56 KSIs.
- Class D (High) is still in the later phase. FedRAMP expects a late-2026 pilot and a formal option in early 2027.
Program certification on the 20x path is now required for Classes A, B, and C. Providers pick one path. FedRAMP will not issue program certifications for both 20x and Rev5 on the same offering.
Rev5 is not gone yet. Limited Rev5 Class B/C program pipelines opened August 10 for Ready Conversion and Lost Sponsor cases, and new Rev5 submissions end June 11, 2027. January 1, 2027 is mandatory CR26 adoption. Those dates matter. They are not a reason to keep assembling a Moderate package the old way if 20x Class B or C is the destination.
Why “Native” Intake Matters
Most CSPs still approach FedRAMP as a document project: Word SSPs, spreadsheet POA&Ms, narrative control statements, and a late conversion to OSCAL. That model does not survive Class B or Class C.
Native intake means the engagement starts in the 20x shape:
- Class selected first (B or C), not after a year of Moderate-shaped artifacts
- Authorization boundary, data flows, and inherited services scoped to the class
- KSIs mapped to NIST SP 800-53 outcomes instead of one narrative per control
- OSCAL as the working package, not an export after the fact
- Evidence collected from running systems, scans, identity, logging, and configuration state
- Continuous monitoring designed for the 20x cadence, including the aggressive automated validation cycle expected at Class C
Class C is not “Moderate with a new name.” The class tells an agency how much assurance information they have. The proof is expected to be live, machine-readable, and repeatable. Spreadsheet GRC and consultant-assembled PDFs will not keep pace.
FedRAMP Class B vs. Class C
FedRAMP’s class model is progressive. Investment and assurance scale with agency demand.
| Class | Legacy analog | What agencies can generally use it for | 20x bar |
|---|---|---|---|
| A | FedRAMP Ready | Entry listing; many non-sensitive use cases | Six federal mandates; then 12 months after a federal customer to start moving to B or higher |
| B | Low / Li-SaaS | Most Low objectives; some Moderate or High with agency compensating controls | 51 KSIs |
| C | Moderate | Most Low and Moderate objectives; some High | 56 KSIs; tighter continuous validation |
| D | High | Most unclassified use cases | Later phase |
If you already hold a mature Rev5 Moderate package, Class C is often the logical conversion. If you are a new SaaS provider with a SOC 2 Type II or a completed RAR, Class A may still be the right first listing, with a planned Class B or C transition once a federal customer is on the service.
What We Are Taking In Now
Lazarus Alliance, an A2LA-accredited FedRAMP 3PAO, is open for native Class B and Class C intake. That includes:
- Class decision and path selection — 20x Program Certification versus the limited Rev5 pipelines, and B versus C based on data, customers, and inheritance.
- Boundary and inheritance design — what sits in the CSO, what is inherited from a FedRAMP-authorized IaaS/PaaS/MSP, and whether that provider’s class actually supports yours.
- KSI and control mapping — 51 or 56 indicators tied to implemented NIST 800-53 outcomes, not recycled Rev5 narratives.
- OSCAL package build — SSP, assessment results, and POA&M in machine-readable form from the first working draft.
- Evidence and ConMon architecture — automated collection, three-day validation expectations at Class C, vulnerability SLAs, FIPS-validated crypto, MFA, and operational logging.
- 3PAO assessment — independent testing, demonstrations, SAR, and submission support through Marketplace listing and continuous monitoring.
Continuum GRC / A.ITAM is the working system for that intake. It is a FedRAMP-authorized GRC platform, which means Class B/C work can be scoped, evidenced, scored, and reported in an environment already accepted for federal use. AITAMBot and Cybervisor® advisory sit on top of that stack so the package is built once and reused across FedRAMP, GovRAMP, NIST, CMMC, SOC 2, and related baselines instead of rebuilt for every auditor.
What CSPs Should Do This Week
The pipeline is live. The pipeline is live. CSPs pursuing Class B or Class C can now align their assessment and certification strategy with the new 20x model rather than treating it as a future transition.
- Confirm the target class. B and C are different commitments.
- Decide 20x versus the temporary Rev5 program lanes before you spend another month on the wrong package format.
- Inventory inheritance. A Class B platform cannot carry a Class C offering.
- Move evidence off shared drives and into automated collection.
- Put OSCAL in the critical path now. January 1, 2027 is not a soft reminder.
- Engage an accredited 3PAO before the first federal RFP asks which class you hold.
Lazarus Alliance has historically compressed FedRAMP assessment cycles by roughly 40–50% against traditional 3PAO timelines when the CSP is prepared and the package is automation-first. Native Class B/C intake is how that advantage is applied to 20x instead of to a dying Rev5 workflow.
Start Native Class B or Class C Intake
Do not wait for an agency to ask whether you are “still Moderate” or “already Class C.” The marketplace language has already changed. The intake path should match it.
To open a native FedRAMP 20x Class B or Class C engagement with Lazarus Alliance, contact us or call +1-888-896-7580.
Lazarus Alliance is a veteran-owned small business, A2LA-accredited FedRAMP 3PAO, authorized CMMC C3PAO, PCI DSS QSA, and Delaware CPA firm. Continuum GRC is the only FedRAMP-authorized AI GRC platform purpose-built for this work.
About Lazarus Alliance
To learn more about how Lazarus Alliance can help, contact us.
- ISO 27001, ISO 27002, ISO 27005, ISO 27017, ISO 27018, ISO 27701, ISO 22301, ISO 17020, ISO 17021, ISO 17025, ISO 17065, ISO 9001, & ISO 90003
- And dozens more!
[wpforms id=”137574″]