Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
FedRAMP CR26 Readiness: Your Pre-Certification ChecklistRegulations & Laws
6 min readFor Risk Managers

FedRAMP CR26 Readiness: Your Pre-Certification Checklist

If your cloud service interacts with federal data, you have six months to make a critical decision. CR26 takes effect December 31, 2026, and it's a complete rewrite of how you'll prove security to government agencies.

This checklist guides you through what you need to do now, before the new rules lock in. Each item has a clear completion state, references the specific CR26 change it addresses, and ends with what success looks like in practice.

Prerequisites

Before starting, ensure you have:

  • Current FedRAMP status documentation: If authorized, you'll need your impact level designation, Statement of Applicability, and recent continuous monitoring reports.
  • Technical architecture diagrams: These help determine your Certification Class and assess if your systems can produce machine-readable evidence.
  • Access to evidence collection systems: You need visibility into how your organization currently collects logs, configuration data, and security metrics.

If you're missing any of these, gather them first. This checklist assumes you can evaluate your current state against the new requirements.

Checklist Items

1. Determine your Certification Class under the new taxonomy

Map your current impact level to the new class structure:

  • FedRAMP Ready → Class A
  • Low or Li-SaaS → Class B
  • Moderate → Class C
  • High → Class D

Review the updated control baselines for your class when CR26 publishes in June 2026. Note any new controls or reporting requirements specific to your class.

Done looks like: You've documented your new Certification Class, identified any baseline control changes, and briefed your leadership on what shifts in scope or effort those changes require.

2. Choose your path: Rev5 or 20x

Evaluate which certification path fits your architecture:

  • Choose 20x if: Your systems are cloud-native, you can produce JSON-formatted evidence, and you're Class A, B, or C.
  • You must use Rev5 if: You're Class D (High), you have complex legacy systems, or your evidence collection isn't machine-readable yet.

Remember, these paths aren't interchangeable. If you certify under Rev5 and later want to switch to 20x, you start over.

Done looks like: You've made a documented decision on your certification path, with technical justification. Your GRC and engineering teams agree on the choice, and you've identified any gaps that would prevent you from using your preferred path.

3. Audit your current evidence collection for machine-readability

Review every control where you currently provide narrative evidence or manual screenshots. Ask:

  • Can this control produce JSON or another structured data format?
  • Do our logging systems export in machine-readable formats?
  • Are our configuration management tools API-accessible for automated validation?

This requirement applies to both Rev5 and 20x paths. If you're on Rev5 at Class D, you still need machine-readable data whenever possible.

Done looks like: You have a spreadsheet listing every control, its current evidence format, and whether it's machine-readable. For controls that aren't machine-readable, you've identified the tooling or process change needed to fix that.

4. Map your controls to Key Security Indicators

CR26 shifts from narrative descriptions to specific, verifiable metrics. For each control you implement, identify:

  • What measurable indicator demonstrates compliance?
  • How frequently can you measure it?
  • What threshold defines "compliant" vs. "non-compliant"?

Example: Instead of "We perform vulnerability scans regularly," your KSI becomes "Authenticated vulnerability scans run weekly, with critical findings remediated within 15 days."

Done looks like: You've translated your Statement of Applicability into a KSI framework. Each control has at least one measurable indicator, a measurement frequency, and a compliance threshold.

5. Prepare for Significant Change Notifications

Under CR26, you notify FedRAMP after implementing changes, not before. Review your change management process:

  • Can you classify changes as significant vs. non-significant?
  • Do you have a security review gate before deployment?
  • Can you document security controls for new features before they go live?

You'll need to move faster, but with better documentation. The change must be secure before you notify, not after you get permission.

Done looks like: Your change management procedure includes a "significant change" decision tree, a pre-deployment security validation step, and a notification template that matches CR26's reporting structure.

6. Update your marketplace presence

If you're listed in the FedRAMP marketplace, remove pricing information. CR26 prohibits publishing pricing details.

Review your marketplace entry for outdated terminology. Replace "authorization" language with "certification." Update your impact level references to Certification Classes once CR26 publishes.

Done looks like: Your marketplace listing reflects CR26 terminology, contains no pricing information, and accurately describes your certification status using the new class system.

7. Validate your independent assessor's activity status

If you work with a 3PAO, confirm they're performing at least two assessments every two years. CR26 requires this to maintain independent assessor status.

Ask your assessor:

  • How many FedRAMP assessments have you completed in the last 24 months?
  • Do you expect to maintain your status under the new activity requirements?

Done looks like: You've received written confirmation from your 3PAO that they meet the new activity requirements, or you've identified an alternative assessor who does.

8. Plan your transition timeline

CR26 takes effect December 31, 2026. If you're mid-authorization now, map out:

  • When does your current authorization expire?
  • Will you need to recertify under CR26 rules?
  • If you're pursuing new authorization, should you wait for CR26 or proceed under current rules?

Remember, CR26 remains the baseline through December 31, 2028. Any certification work you complete in 2027 or 2028 will be under these rules.

Done looks like: You have a Gantt chart showing your certification milestones, CR26's effective date, and any decision points where you'll need to choose between current rules and new rules.

Common Mistakes

Assuming Class equivalence is perfect: While Class C maps to Moderate, the control baselines will change. Don't assume your current controls are sufficient just because you're at the "same" level.

Treating machine-readable as optional: Some teams read "whenever possible" as "if it's convenient." Auditors won't. If a control can reasonably produce structured data, you need to make it happen.

Picking 20x because it's faster without checking eligibility: Speed doesn't matter if you have to start over. Class D CSPs can't use 20x yet. Complex systems may not qualify. Do the technical assessment first.

Ignoring the Rev5/20x incompatibility: These aren't two versions of the same thing. They're separate certification paths with different evidence requirements. Switching paths means recertification from scratch.

Next Steps

  1. Download CR26 when it publishes (end of June 2026): Read the full text. Compare it to this checklist. Identify any requirements we didn't cover here.

  2. Run a gap analysis by August 2026: You have four months between publication and effective date. Use them to identify every place where your current program doesn't meet CR26 requirements.

  3. Prioritize evidence automation: If you're still collecting screenshots and writing narratives for most controls, that's your biggest risk. Start building API integrations and automated evidence collection now.

  4. Brief your agency partners: They'll need to understand that your authorization is now a certification, and that they still need to issue their own ATO. The terminology change doesn't eliminate their responsibilities.

CR26 isn't just administrative cleanup. It's a fundamental shift in how you'll demonstrate security to federal agencies. The CSPs that treat this as a paperwork exercise will struggle. The ones that use it as an opportunity to modernize their evidence collection will find the new process faster and less painful than what came before.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like