Photo of Kate GrowleyPhoto of Jacob HarrisonPhoto of Ajan JayantPhoto of Bryan Dewan

On June 25, 2026, the Federal Risk & Authorization Management Program (FedRAMP) launched its Consolidated Rules for 2026, marking a significant turning point in how the U.S. government administers security authorizations of private sector cloud offerings. The Consolidated Rules apply to all variants of the FedRAMP ecosystem, including legacy “Rev5” authorization holders, as well as future certifications under the new 20x program. Importantly, the Rules are intended in part to transition Rev5 authorizations over to 20x, with the Rev5 authorization status expected to terminate by the end of 2028. 

What Are the Consolidated Rules?

Over the past several months, FedRAMP has worked to revamp and modernize its rules and processes applicable to cloud service offerings authorized to house federal data. The release of the Consolidated Rules for 2026 marks the culmination of that work.

Major Emphases Include:

  • Conciseness. The Consolidated Rules focus on replacing long, narrative-based controls and documentation requirements with concise, declarative, plain-language statements. 
  • Outcome-based security. Providers are largely expected to define and justify their own security methods, rather than follow precise prescriptions from FedRAMP.
  • Tiered certification classes with scaled obligations. Instead of the legacy “Low, Moderate, High” impact levels, the Consolidated Rules organize cloud service offerings and related security requirements by certification classes A-D, with each class requiring progressively greater expectations. 
  • Transparency and structured data sharing. Multiple changes aim to increase and standardize the level of information shared with FedRAMP and agency customers, with an emphasis on sharing data in both human-readable and machine-readable JSON formats.
  • Transition away from Rev5. FedRAMP will stop accepting any new FedRAMP Rev5 applications on June 11, 2027, and plans to sunset existing FedRAMP Rev5 authorizations by December 31, 2028. FedRAMP says Rev5 providers should consider transitioning to 20x “as quickly as possible.”
  • Changes for Rev5-authorized providers. The Consolidated Rules introduce several substantive changes for Rev5 providers continuing to operate before their sunset, including more complex incident reporting triggers, the retirement of System Security Plans (SSP) and Plans of Action & Milestones (POA&Ms), broader continuous monitoring requirements, new availability reporting, and the creation of configuration guides.

Critical Deadlines:

The Consolidated Rules take mandatory effect for all stakeholders on January 1, 2027, subject to specific effective dates and grace periods within certain rulesets. Other key dates to note include:

  • December 7, 2026: Providers must have adopted the Vulnerability Detection & Response and Vulnerability Evaluation & Reporting rulesets.
  • June 11, 2027: FedRAMP will no longer accept new applications for FedRAMP Rev5.
  • February 1, 2028: All grace periods for the Consolidated Rules expire; noncompliant offerings will lose FedRAMP certification.
  • December 31, 2028: Existing FedRAMP Rev5 authorizations will sunset.

For a more detailed analysis or questions about how the Consolidated Rules could affect your organization, please contact Crowell & Moring.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Kate Growley Kate Growley

Kate M. Growley (CIPP/US, CIPP/G) is a director with Crowell & Moring International and based in Hong Kong. Drawing from over a decade of experience as a practicing attorney in the United States, Kate helps her clients understand, navigate, and shape the policy…

Kate M. Growley (CIPP/US, CIPP/G) is a director with Crowell & Moring International and based in Hong Kong. Drawing from over a decade of experience as a practicing attorney in the United States, Kate helps her clients understand, navigate, and shape the policy and regulatory environment for some of the most complex data issues facing multinational companies, including cybersecurity, privacy, and digital transformation. Kate has worked with clients across every major sector, with particular experience in technology, health care, manufacturing, and aerospace and defense. Kate is a Certified Information Privacy Professional (CIPP) in both the U.S. private and government sectors by the International Association of Privacy Professionals (IAPP). She is also a Registered Practitioner with the U.S. Cybersecurity Maturity Model Certification (CMMC) Cyber Accreditation Body (AB).

Photo of Jacob Harrison Jacob Harrison

Jacob Harrison helps his clients navigate both domestic and international legal challenges.

Jake advises U.S. government contractors on internal investigations and state and federal regulatory compliance. His compliance practice focuses on counseling clients operating at the intersection of government contracts and cybersecurity, including

Jacob Harrison helps his clients navigate both domestic and international legal challenges.

Jake advises U.S. government contractors on internal investigations and state and federal regulatory compliance. His compliance practice focuses on counseling clients operating at the intersection of government contracts and cybersecurity, including for cybersecurity compliance reviews, risk assessments, and data breaches.

In his international practice, Jake represents foreign and domestic clients in Foreign Sovereign Immunities Act and Anti-Terrorism Act litigation. He also has experience advising clients involved in cross-border commercial arbitration proceedings.

During law school, Jake served as an associate editor of the Emory Law Journal and interned at the Supreme Court of Georgia and the Georgia House Democratic Caucus. Before attending law school, Jake worked in politics and state government.