In This Article

If your company holds a SOC 2 Type II, a Legacy FedRAMP Rev 5 authorization (including FedRAMP Ready), or a GovRAMP assessment completed in the past 12 months, you can start pursuing a FedRAMP 20x Class A Certification today. The pipeline opened August 3, 2026.
Getting there takes two moves: submit the FedRAMP Marketplace Listing Request Form to get an in-process listing, and assemble a Class A certification package that maps your existing assessment to FedRAMP's Class A ruleset.
Here is what qualifies, what FedRAMP requires beyond your existing framework, and how to fill out the form.
Executive Summary
- Class A lets you build on work you've done. A SOC 2 Type II, FedRAMP Rev5 (any historical impact level, including Ready), or GovRAMP assessment from the past 12 months satisfies the alternative security framework requirement (FRC-CLA-ASF).
- Your existing report is not enough on its own. Class A adds a mandatory subset of FedRAMP rules (FRC-CLA-MFR), including seven Key Security Indicators, incident reporting, vulnerability detection, and a machine-readable certification package hosted on a trust center.
- The pipeline is open now. The Marketplace Listing Request Form went live July 6, 2026; August 3, 2026 was the first day a completed Class A certification could appear on the FedRAMP Marketplace.
- Reviewers want summaries, not pointers. "See SOC 2 report" does not satisfy the Class A package requirements; each FedRAMP rule needs a summary detailed enough to stand on its own.
What is a FedRAMP 20x Class A Certification?
Class A is a FedRAMP 20x certification path for providers who have completed a recognized security assessment under another framework.
Instead of starting a federal authorization from zero, you bring your existing assessment, map it to a defined subset of FedRAMP rules, and publish the results in a machine-readable certification package.
Three rulesets apply:
- FedRAMP Certification
- Marketplace Listing
- Certification Package Overview.
The full requirements live in the FedRAMP 20x Class A ruleset published at fedramp.gov.
For a CISO, the calculus is straightforward: the assessment work your team bled for last year now counts toward a federal marketplace listing, and the gap you have to close is a defined, finite rule subset rather than an open-ended 12 to 18 month slog.
→ For a deeper look at how 20x certification differs from a traditional authorization, see Why FedRAMP Authorization is Now Certification.
Do You Already Qualify for Class A?
Rule FRC-CLA-ASF sets the entry bar. You must have completed a certification or equivalent process, including an independent assessment if applicable, from one of these frameworks within the past 12 months:
If your most recent report is older than 12 months, you do not qualify until your next assessment cycle completes. That makes the timing decision an agenda item now: if your SOC 2 renewal lands in Q4, your Class A window opens with it.
What Materials Do You Need From Your Existing Assessment?
Rule FRC-CLA-EAM requires you to supply your framework's assessment materials to all necessary parties. What you hand over depends on which door you walked in through:
One instruction from FedRAMP deserves a highlight, because it is where packages will die in review: for each FedRAMP requirement, include a summary detailed enough that reviewers do not need to dig into your framework materials to understand the decision.
Ex: "See SOC 2 report" is not an answer. It is a homework assignment for a reviewer, and reviewers do not do homework.
Which FedRAMP Rules Still Apply on Top of Your Framework?
This separates Class A from a rubber stamp. Rule FRC-CLA-MFR requires providers to address the full FRC-CLA subset plus a defined list of additional FedRAMP rules, with artifacts or information mapping supplied in the FedRAMP Certification Package.
FedRAMP's own note is candid: some of these rules have no counterpart in SOC 2 or GovRAMP, and providers will need to implement new processes to satisfy them.
Two things a security leader should read out of this table. First, the seven Key Security Indicators are required for both Rev5 and 20x Class A certifications, so KSI work is not throwaway effort if your roadmap includes a fuller FedRAMP path later.
If KSIs are new territory for your team, start with KSI vs. Control. Second, the operational rules (a monitored FedRAMP security inbox, incident reportability evaluation, vulnerability detection, continuous monitoring report availability) are standing processes, not documents. They need owners on your org chart before they need words in a package.
How Do You Get Listed on the FedRAMP Marketplace?
The Marketplace Listing ruleset (MKT) includes step MKT-CSO-PML: notify FedRAMP via the FedRAMP Marketplace Provider Listing Request Form to begin the listing process and start working toward Class A certification. The form went live July 6, 2026, and you can submit at any time.
Here is how to fill it out:
FYI: The machine-readable package URL is the field that trips teams up, because it assumes you have a trust center and an SDR already. If those words map to nothing in your current stack, read FedRAMP 20x and Trust Centers before you touch the form.
What Does the Class A Timeline Look Like?
These dates have passed, which means there is no structural reason to wait. A provider with a current SOC 2 Type II can hold an in-process Marketplace listing this month and work the FRC-CLA-MFR gap in parallel.
Where Does Paramify Fit in a Class A Push?
Paramify is a risk management platform, and Class A is at its core a risk-mapping exercise: take the security decisions your existing assessment validated, map them to FedRAMP's rule subset, and publish the result in a form a reviewer and a machine can both read.
That is the work Paramify automates.
Paramify generates the SDR and the FedRAMP Certification Overview Package (FRC-CSO-PKG) as machine-readable files, and manages the FedRAMP-compliant trust center that hosts them, which covers the Marketplace form's hardest field and the CDS trust center rules in one motion.
The Class A rule requirements described in this article are included in Paramify's FedRAMP 20x Class A program.
More CSPs have used Paramify to get on the FedRAMP marketplace than any other GRC platform: the mapping patterns between commercial frameworks and FedRAMP rules are not theory to us. We have watched where packages stall, and it is almost never the security. It is the documentation that fails to explain the security.
Class A's summary requirement makes that failure mode explicit, and it is the failure mode a decision-based documentation model exists to prevent.
The Bottom Line on Getting Started With Class A
You came here asking whether the assessment your team completed can carry weight in the federal market, and what it takes to convert it. The answer: a SOC 2 Type II, Legacy FedRAMP Rev 5, or GovRAMP assessment from the past 12 months qualifies you for the Class A path. The pipeline is open and the real work is the FRC-CLA-MFR rule subset, seven KSIs included, delivered as reviewer-ready summaries in a machine-readable package on a trust center.
Paramify, a risk management platform built around decision-based compliance documentation, generates the SDR and Certification Overview Package as machine-readable files and runs the trust center that hosts them, so the gap between your existing assessment and a Class A package is mapping work, not a second assessment.
Request a demo video or schedule a live demo below to see Paramify in action:
Next steps:
- Read FedRAMP Rev5 vs. FedRAMP 20x to confirm Class A is the right path for your offering.
- See how Paramify's Trust Center hosts the SDR and Certification Overview Package.
- Review Paramify's FedRAMP 20x approach, then request a demo to see a Class A package built from your existing assessment.
Frequently Asked Questions
What is a FedRAMP 20x Class A Certification? A FedRAMP 20x certification path for providers who completed a qualifying assessment under another security framework (FedRAMP Rev5, SOC 2 Type II, or GovRAMP) within the past 12 months, plus a defined subset of additional FedRAMP rules.
Can I use my SOC 2 Type II to get FedRAMP certified? Yes. A SOC 2 Type II completed within the past 12 months satisfies the alternative security framework requirement (FRC-CLA-ASF) for Class A. You still must address the mandatory FedRAMP rule subset on top of it.
My SOC 2 report is 14 months old. Do I qualify? No. The qualifying assessment must have been completed within the past 12 months. Your window reopens when your next report completes.
Does FedRAMP Ready count, even at a low impact level? Yes. FedRAMP Rev5, including FedRAMP Ready, qualifies at any historical impact level. GovRAMP qualifies at any impact level as well. If GovRAMP is your path, start with Paramify's GovRAMP overview.
When can I submit the Marketplace Listing Request Form? Now. The form went live July 6, 2026.
When did the Class A pipeline open? August 3, 2026 was the first possible day for a completed Class A FedRAMP Certification to appear on the FedRAMP Marketplace.
What is an SDR? The security decision record: a machine-readable file that includes the implementation, evidence, and assessment results of your system. You host it on your trust center and link to it in the Marketplace form's machine-readable package URL field.
What goes in the "machine-readable package URL" field if my package isn't done? Include your trust center link and explain the status in the Optional Additional Information field.
Do Key Security Indicators apply to Class A? Yes. Seven KSIs are in the mandatory Class A rule subset, and per FedRAMP's notes, KSI information is required for both Rev5 and 20x Class A certifications.
Can I just point reviewers to my SOC 2 report for each requirement? No. FedRAMP's guidance is explicit: each rule needs a summary detailed enough that reviewers do not have to dig into your framework materials. "See SOC 2 report" is called out as unhelpful.
Is Class A the same as a FedRAMP Rev5 authorization? No. Class A is a certification built on a qualifying alternative framework plus a defined FedRAMP rule subset. For how the two paths compare, see FedRAMP Rev5 vs. FedRAMP 20x.
Will I need new processes my SOC 2 never required? Plan on it. FedRAMP notes that some Class A rules have no counterpart in external frameworks: a monitored FedRAMP security inbox, FedRAMP incident reportability evaluation, and continuous monitoring report availability are standing operational obligations, not report sections.



