How Do You Get a FedRAMP 20x Class A Certification? A Step-by-Step Guide

Convert your existing SOC 2, FedRAMP Ready, and GovRAMP assessment into a FedRAMP Class A Certification. Find out who qualifies, the FedRAMP rules you still have to add, and how to fill out the Marketplace listing form.

Isaac Teuscher
|
53
min read

In This Article

If your company holds a SOC 2 Type II, a Legacy FedRAMP Rev 5 authorization (including FedRAMP Ready), or a GovRAMP assessment completed in the past 12 months, you can start pursuing a FedRAMP 20x Class A Certification today. The pipeline opened August 3, 2026. 

Getting there takes two moves: submit the FedRAMP Marketplace Listing Request Form to get an in-process listing, and assemble a Class A certification package that maps your existing assessment to FedRAMP's Class A ruleset. 

Here is what qualifies, what FedRAMP requires beyond your existing framework, and how to fill out the form.

Executive Summary

  • Class A lets you build on work you've done. A SOC 2 Type II, FedRAMP Rev5 (any historical impact level, including Ready), or GovRAMP assessment from the past 12 months satisfies the alternative security framework requirement (FRC-CLA-ASF).
  • Your existing report is not enough on its own. Class A adds a mandatory subset of FedRAMP rules (FRC-CLA-MFR), including seven Key Security Indicators, incident reporting, vulnerability detection, and a machine-readable certification package hosted on a trust center.
  • The pipeline is open now. The Marketplace Listing Request Form went live July 6, 2026; August 3, 2026 was the first day a completed Class A certification could appear on the FedRAMP Marketplace.
  • Reviewers want summaries, not pointers. "See SOC 2 report" does not satisfy the Class A package requirements; each FedRAMP rule needs a summary detailed enough to stand on its own.

What is a FedRAMP 20x Class A Certification?

Class A is a FedRAMP 20x certification path for providers who have completed a recognized security assessment under another framework. 

Instead of starting a federal authorization from zero, you bring your existing assessment, map it to a defined subset of FedRAMP rules, and publish the results in a machine-readable certification package. 

Three rulesets apply: 

  1. FedRAMP Certification
  2. Marketplace Listing
  3. Certification Package Overview. 

The full requirements live in the FedRAMP 20x Class A ruleset published at fedramp.gov.

For a CISO, the calculus is straightforward: the assessment work your team bled for last year now counts toward a federal marketplace listing, and the gap you have to close is a defined, finite rule subset rather than an open-ended 12 to 18 month slog. 

→ For a deeper look at how 20x certification differs from a traditional authorization, see Why FedRAMP Authorization is Now Certification.

Do You Already Qualify for Class A?

Rule FRC-CLA-ASF sets the entry bar. You must have completed a certification or equivalent process, including an independent assessment if applicable, from one of these frameworks within the past 12 months:

Qualifying framework Accepted scope
FedRAMP Rev5 (including FedRAMP Ready) Any historical impact level
SOC 2 Type II Complete, current report
GovRAMP Any impact level

If your most recent report is older than 12 months, you do not qualify until your next assessment cycle completes. That makes the timing decision an agenda item now: if your SOC 2 renewal lands in Q4, your Class A window opens with it.

What Materials Do You Need From Your Existing Assessment?

Rule FRC-CLA-EAM requires you to supply your framework's assessment materials to all necessary parties. What you hand over depends on which door you walked in through:

Your framework Required Materials
SOC 2 Type II The complete report, a bridge or gap letter if applicable, verified audit engagement documentation, the estimated schedule for your upcoming report, and supplemental compliance evidence if applicable.
FedRAMP Ready The Readiness Assessment Report, the Security Assessment Plan, and any other materials FedRAMP requires.
GovRAMP The Readiness Assessment Report, the Security Assessment Plan, and any other materials GovRAMP requires.

One instruction from FedRAMP deserves a highlight, because it is where packages will die in review: for each FedRAMP requirement, include a summary detailed enough that reviewers do not need to dig into your framework materials to understand the decision. 

Ex: "See SOC 2 report" is not an answer. It is a homework assignment for a reviewer, and reviewers do not do homework.

Which FedRAMP Rules Still Apply on Top of Your Framework?

This separates Class A from a rubber stamp. Rule FRC-CLA-MFR requires providers to address the full FRC-CLA subset plus a defined list of additional FedRAMP rules, with artifacts or information mapping supplied in the FedRAMP Certification Package. 

FedRAMP's own note is candid: some of these rules have no counterpart in SOC 2 or GovRAMP, and providers will need to implement new processes to satisfy them.

Category Rules
FedRAMP Certification FRC-CSO-PKG (Certification Package), FRC-CSO-JSN (FedRAMP JSON Schemas), FRC-CSO-POP (Pick One Program Certification Type)
Minimum Assessment Scope MAS-CSO-IIR (Identify Information Resources)
Certification Data Sharing CDS-CSO-PUB (Public Information), CDS-CSO-UTC (Use Trust Centers), CDS-UTC-AAD (Agency Access Denial)
Addressing FedRAMP Communication AFC-CSO-INB (Maintain a FedRAMP Security Inbox), AFC-CSO-RCV (Receive Email Without Disruption), AFC-CSO-CRA (Complete Required Actions)
Incident Evaluation and Communication IEC-CSO-EFR (Evaluate FedRAMP Reportability), IEC-CSO-FIR (Final Incident Report)
Vulnerability Detection and Response VDR-CSO-DET (Vulnerability Detection)
Collaborative Continuous Monitoring CCM-OCR-AVL (Report Availability), CCM-OCR-NRD (Next Report Date)
Independent Verification and Validation IVV-CSX-AIA (Annual Independent Assessments for 20x)
Key Security Indicators KSI-CMT-LMC (Logging Changes), KSI-CNA-RNT (Restricting Network Traffic), KSI-CED-RAT (Reviewing All Training), KSI-IAM-AAM (Automating Account Management), KSI-IAM-APM (Adopting Passwordless Methods), KSI-INR-RIR (Reviewing Incident Response Procedures), KSI-SVC-SIN (Securing Information)

Two things a security leader should read out of this table. First, the seven Key Security Indicators are required for both Rev5 and 20x Class A certifications, so KSI work is not throwaway effort if your roadmap includes a fuller FedRAMP path later.

If KSIs are new territory for your team, start with KSI vs. Control. Second, the operational rules (a monitored FedRAMP security inbox, incident reportability evaluation, vulnerability detection, continuous monitoring report availability) are standing processes, not documents. They need owners on your org chart before they need words in a package.

Your SOC 2 got you to the door. Paramify builds the Class A package that gets you through it.

See how Paramify handles 20x

How Do You Get Listed on the FedRAMP Marketplace?

The Marketplace Listing ruleset (MKT) includes step MKT-CSO-PML: notify FedRAMP via the FedRAMP Marketplace Provider Listing Request Form to begin the listing process and start working toward Class A certification. The form went live July 6, 2026, and you can submit at any time. 

Here is how to fill it out:

Form field What to enter
Form dropdown [For CSPs] Marketplace Listing Request Form
Your email address A group or shared inbox for the team that will communicate with the FedRAMP PMO. Not one person's inbox; people take vacations and change jobs, and rule AFC-CSO-RCV expects you to receive email without disruption.
Provider-CSP Name Your company's name (e.g., Paramify)
Provider-CSO Name Your product's name, matching how you market it to federal agencies (e.g., Paramify Cloud)
Certification Type 20x
Machine-readable package URL The link to your trust center hosting your SDR (security decision record), the machine-readable file covering your system's implementation, evidence, and assessment results. Your FedRAMP Certification Overview Package (FRC-CSO-PKG) is hosted there too. If the package is still in progress, include the trust center link and explain the status in the additional information field.
Optional Additional Information Anything else FedRAMP should know; enter "N/A" if nothing applies.

FYI: The machine-readable package URL is the field that trips teams up, because it assumes you have a trust center and an SDR already. If those words map to nothing in your current stack, read FedRAMP 20x and Trust Centers before you touch the form.

What Does the Class A Timeline Look Like?

Date Milestone
July 6, 2026 Marketplace Listing Request Form went live; submissions open
July 6 to August 3, 2026 Preparation window: in-process Marketplace listing while assembling the Class A package
August 3, 2026 Class A certification pipeline opened; first possible day for a completed Class A FedRAMP Certification on the Marketplace

These dates have passed, which means there is no structural reason to wait. A provider with a current SOC 2 Type II can hold an in-process Marketplace listing this month and work the FRC-CLA-MFR gap in parallel.

Where Does Paramify Fit in a Class A Push?

Paramify is a risk management platform, and Class A is at its core a risk-mapping exercise: take the security decisions your existing assessment validated, map them to FedRAMP's rule subset, and publish the result in a form a reviewer and a machine can both read. 

That is the work Paramify automates. 

Paramify generates the SDR and the FedRAMP Certification Overview Package (FRC-CSO-PKG) as machine-readable files, and manages the FedRAMP-compliant trust center that hosts them, which covers the Marketplace form's hardest field and the CDS trust center rules in one motion. 

The Class A rule requirements described in this article are included in Paramify's FedRAMP 20x Class A program.

More CSPs have used Paramify to get on the FedRAMP marketplace than any other GRC platform: the mapping patterns between commercial frameworks and FedRAMP rules are not theory to us. We have watched where packages stall, and it is almost never the security. It is the documentation that fails to explain the security. 

Class A's summary requirement makes that failure mode explicit, and it is the failure mode a decision-based documentation model exists to prevent.

FEDRAMP 20X CLASS A

Your last audit was the hard part.

Paramify turns your SOC 2, Rev5, or GovRAMP assessment into a machine-readable Class A package: SDR, Certification Overview Package, and a FedRAMP-compliant trust center to host it all.

Request a demo

The Bottom Line on Getting Started With Class A

You came here asking whether the assessment your team completed can carry weight in the federal market, and what it takes to convert it. The answer: a SOC 2 Type II, Legacy FedRAMP Rev 5, or GovRAMP assessment from the past 12 months qualifies you for the Class A path. The pipeline is open and the real work is the FRC-CLA-MFR rule subset, seven KSIs included, delivered as reviewer-ready summaries in a machine-readable package on a trust center.

Paramify, a risk management platform built around decision-based compliance documentation, generates the SDR and Certification Overview Package as machine-readable files and runs the trust center that hosts them, so the gap between your existing assessment and a Class A package is mapping work, not a second assessment.

Request a demo video or schedule a live demo below to see Paramify in action:

Next steps:

Frequently Asked Questions

What is a FedRAMP 20x Class A Certification? A FedRAMP 20x certification path for providers who completed a qualifying assessment under another security framework (FedRAMP Rev5, SOC 2 Type II, or GovRAMP) within the past 12 months, plus a defined subset of additional FedRAMP rules.

Can I use my SOC 2 Type II to get FedRAMP certified? Yes. A SOC 2 Type II completed within the past 12 months satisfies the alternative security framework requirement (FRC-CLA-ASF) for Class A. You still must address the mandatory FedRAMP rule subset on top of it.

My SOC 2 report is 14 months old. Do I qualify? No. The qualifying assessment must have been completed within the past 12 months. Your window reopens when your next report completes.

Does FedRAMP Ready count, even at a low impact level? Yes. FedRAMP Rev5, including FedRAMP Ready, qualifies at any historical impact level. GovRAMP qualifies at any impact level as well. If GovRAMP is your path, start with Paramify's GovRAMP overview.

When can I submit the Marketplace Listing Request Form? Now. The form went live July 6, 2026.

When did the Class A pipeline open? August 3, 2026 was the first possible day for a completed Class A FedRAMP Certification to appear on the FedRAMP Marketplace.

What is an SDR? The security decision record: a machine-readable file that includes the implementation, evidence, and assessment results of your system. You host it on your trust center and link to it in the Marketplace form's machine-readable package URL field.

What goes in the "machine-readable package URL" field if my package isn't done? Include your trust center link and explain the status in the Optional Additional Information field.

Do Key Security Indicators apply to Class A? Yes. Seven KSIs are in the mandatory Class A rule subset, and per FedRAMP's notes, KSI information is required for both Rev5 and 20x Class A certifications.

Can I just point reviewers to my SOC 2 report for each requirement? No. FedRAMP's guidance is explicit: each rule needs a summary detailed enough that reviewers do not have to dig into your framework materials. "See SOC 2 report" is called out as unhelpful.

Is Class A the same as a FedRAMP Rev5 authorization? No. Class A is a certification built on a qualifying alternative framework plus a defined FedRAMP rule subset. For how the two paths compare, see FedRAMP Rev5 vs. FedRAMP 20x.

Will I need new processes my SOC 2 never required? Plan on it. FedRAMP notes that some Class A rules have no counterpart in external frameworks: a monitored FedRAMP security inbox, FedRAMP incident reportability evaluation, and continuous monitoring report availability are standing operational obligations, not report sections.

Isaac Teuscher
A Security Engineer leading the technical implementation of cloud and AI-driven security. With experience in NIST 800-53 and FedRAMP, Isaac collaborates with executive teams to build scalable security programs that meet the highest federal compliance standards.
Aug 2026
Related posts

Paramify blog

Interviews, tips, guides, industry best practices, and news.

Prepare for Rev 5 FedRAMP Sunset: Important Timeline Updates 

FedRAMP Rev 5 is being phased out: existing certifications must adopt the new Consolidated Rules by January 1, 2027, and no new Rev 5 applications are accepted after June 11, 2027. CSPs need a plan to run Rev 5 and FedRAMP 20x in parallel during the transition, and Paramify supports both at once.
Read post

Compliance for AI & FedRAMP 20x: What You Need to Know About Modern Security

Why the legacy FedRAMP process failed — 1,500-page SSPs nobody could read, evidence nobody could inspect — and how FedRAMP 20x replaces it with real-time, automated evidence. Learn where AI actually helps in compliance, where it fails, and why your security expertise matters more than ever.
Read post

What is an SDR? Understanding the Security Decision Record

A Security Decision Record (SDR) replaces static, narrative-based security plans with a machine-readable format that provides continuous, evidence-based assurance of a system's security posture. By capturing actual security decisions and their implementation, it enables real-time auditing and monitoring that moves beyond the limitations of traditional, point-in-time documents.‍
Read post

Frequently Asked Questions

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Can compliance advisors or consultants work in Paramify with us, and does it help with managed-service models?

Absolutely. Paramify is used by many advisory partners, RPOs, and MSPs to guide, generate, and manage documentation, perform gap assessments, facilitate policy/procedure drafting, and oversee remediation activities. Advisors can fill out templates, manage controls, and generate client-ready documents.

We have privacy or compliance concerns, can we restrict what external reviewers can access?

Yes, you can assign role-based access controls in Paramify. Advisors or auditors can be given access only to certain programs, assessment and their related evidence.

Sensitive information can be withheld or redacted as needed, and only authorized reviewers see specific items.

Can auditors or advisory partners get direct access to our Paramify environment, or do we have to export everything for them?

Yes, Paramify allows external assessors/auditors and advisors to be invited as users, with controlled permission levels. They can review specific evidence, policies, SSPs, POA&Ms, or assessment modules without accessing broader company data. 

Documentation — such as Appendix A, SSPs, procedures, and POAMs — can also be exported in multiple standard formats (Word, Excel, OSCAL, EMASS, PDF) as needed.

Can I get matched with an Advisor based on my specific needs?

Yes. You can use the Get Matched feature on our website. We will review your specific compliance goals and connect you with the partner best suited for your industry and timeline.

How do Advisors use Paramify during a FedRAMP engagement?

Advisors use Paramify to conduct Gap Assessments, map controls, Automate SSPs, and manage POA&Ms.

Instead of spending months writing Word documents, the Advisor inputs the system architecture and control implementations into Paramify, which then generates the required NIST-formatted documentation.

Does Paramify compete with its Advisors?

No. Paramify is a software company. We do not offer independent audit or long-term consulting services. Our goal is to empower Advisors with better tools so they can serve more clients effectively.

What are the different partner tiers?

We feature Premier Partners prominently on our site. These are firms that have demonstrated a high level of proficiency with the Paramify platform and have successfully helped many clients through the authorization process using our tools.

How do I become an official Paramify Advisor Partner?

We look for firms with a proven track record in federal compliance. If you are interested in joining our network and leveraging our automation products, you can reach out via our contact page or schedule a demo to see how our tools fit into your workflow.

What is the benefit of using an Advisor who uses Paramify vs. one who doesn't?

Advisors using Paramify can accelerate your implementation and typically deliver documentation in a fraction of the time it takes without Paramify. This means:

  • Faster Implementation: An accelerated implementation roadmap keeps timelines predictable.
  • Lower Costs: Reduced manual consultant hours.
  • Higher Accuracy: Automation eliminates the "copy-paste" errors common in traditional SSPs.
  • Easier Maintenance: Your Advisor can help you manage POA&Ms and continuous monitoring within the platform.
Does working with an Advisor on this list guarantee FedRAMP or CMMC authorization?

No firm can "guarantee" authorization, as the final decision rests with the government authorizing body (e.g., the FedRAMP PMO or the DoD).

However, working with a Paramify Advisor significantly reduces the risk of documentation errors and ensures your package is built on a technically sound, automated foundation.

How do I choose the right Advisor for my organization?

Our Advisor page allows you to filter partners by their specific expertise, such as FedRAMP, CMMC, FISMA, or GovRAMP.

Why does Paramify partner with Advisors?

Paramify is an “Iron Man suit” for GRC experts. We provide automation technology to generate and manage compliance documentation (like SSPs snd POA&Ms) while Advisors provide the expert human oversight and implementation expertise.

Together, we offer a "best-of-both-worlds" solution: expert consulting powered by industry-leading automation and risk management planning.

What is the Paramify Advisor Partner Network?

The Paramify Advisor Partner Network is a curated group of cybersecurity and compliance firms — including CMMC Registered Practitioner Organizations (RPOs) and accredited Independent Assessors— that use Paramify’s platform to deliver faster, more accurate compliance outcomes for their clients.

I already have an advisor or very capable GRC team. Why do I need Paramify?

Use Paramify's Risk Solution platform to automate ATO packages, improving cost efficiency, speed, and accuracy. This frees your team to focus on more valuable efforts like security posture enhancement and compliance improvements.