FedRAMP 20x: into the Marketplace, deterministically
FedRAMP rewrote its rules in 2026. No agency sponsor. Machine-readable evidence. A published rulebook anyone can validate against. ACTA generates your entire certification package deterministically from your live environment, so the same environment always produces the same package.
Class A applications open August 3. Class B and C open August 31. The Marketplace listing that starts your journey is open now.
Class selected to Marketplace-submitted
Select a certification class, watch the Key Security Indicators validate, and generate the Security Decision Record and Certification Package Overview as schema-valid JSON: the actual ACTA+ Certifications workflow.
This process is new, confusing, and subject to change
We are not going to pretend otherwise. The Consolidated Rules for 2026 launched in June 2026, the certification pipelines are opening in stages through August, and the federal compliance landscape around them is actively shifting:
- โธThe Department of War suspended CMMC Phase II and its third-party assessor mandate in July 2026, pending a 60-day reform review. Active solicitations are being amended to remove C3PAO requirements.
- โธThe role of independent assessors across federal compliance programs is being rethought in real time. FedRAMP has already retired the term "3PAO" and made assessors optional for its entry-level certification class.
- โธFedRAMP publishes its rules as versioned, machine-readable JSON and updates them with a public changelog. What is true today can be amended tomorrow.
ACTA reads the published rules directly from FedRAMP's machine-readable repository. When the rules change, our engine changes with them, and your artifacts regenerate against the current ruleset. That is what deterministic compliance is for.
What actually changed with FedRAMP 20x
Correction we owe you: a lot of vendors (including, previously, this page) have described 20x loosely. Here is the precise version. Certification classes run from Class A (entry, minimal assurance) up to Class D (maximum assurance). Class A is the fast door into the Marketplace. Classes B, C, and D require an annual independent assessment by a FedRAMP Recognized assessor. FedRAMP itself, not your agency customer, is the final assessor for every 20x certification. Agencies then use your live certification data to make their own authorization decisions.
The four classes, and where the auditors actually are
| Class A | Class B | Class C | Class D | |
|---|---|---|---|---|
| Assurance level | Entry | Standard | Elevated | Maximum |
| Independent assessor | Optional | Required for initial certification; annual reviews lean on your automated KSI validation evidence | Required for initial certification; annual reviews lean on your automated KSI validation evidence | Required for initial certification; annual reviews lean on your automated KSI validation evidence |
| Basis of trust | Existing framework: SOC 2 Type II, GovRAMP, or legacy FedRAMP Rev5/Ready (within 12 months) | FedRAMP Recognized assessment of all Key Security Indicators | Assessment plus 2 automated validation methods per KSI and 6 months of historical metrics | Assessment plus 4 automated validation methods per KSI and 18 months of historical metrics |
| Applications open | August 3, 2026 | August 31, 2026 | August 31, 2026 | Not yet announced |
| Typical fit | Commercial SaaS entering the federal market | Providers with Low-impact agency workloads | Providers with Moderate-impact agency workloads | Mission-critical services |
Three rules worth knowing verbatim:
- 01
Marketplace listing comes first. Every provider must obtain an Initial Implementation Phase Marketplace listing before applying for any certification. Getting listed requires no assessor: a public use case, published certification data, and quarterly progress updates on your Trust Center.
- 02
You apply. Nobody applies for you. FedRAMP prohibits third parties, including assessors and tools like ACTA, from submitting on your behalf. ACTA prepares everything; you press the button and you own the package.
- 03
Freshness is enforced. Your initial package must reflect the verified state of your environment within the previous 7 days of application. Classes B through D also need an independent assessment completed within the previous 3 months.
FedRAMP wrote our architecture into its definitions
The Consolidated Rules define Deterministic Telemetry as verifiable data collected directly from an authoritative source that represents a factual and reproducible observation of a system's state, configuration, or behavior. The definition then adds, in FedRAMP's own words, that probabilistic inferences and generative outputs such as those produced by generative AI models do not constitute a factual record of system state and must not be used to generate deterministic telemetry.
That is not our marketing. That is the rulebook.
ACTA runs on goRapide, BMD's causal event decision language. No LLMs, no agents, no MCP, no probabilistic components anywhere in the compliance path. The same environment produces the same artifacts, the same scores, and the same hashes, every run. When a reviewer or assessor asks why a control passed, we replay the causal chain and show them.
| ACTA (deterministic) | LLM + MCP pipelines (probabilistic) | |
|---|---|---|
| Generation | Causal engine, same inputs produce same outputs | Tokenized generation, sampled output |
| Repeatability | Identical artifacts, scores, and evidence every run | Small differences run to run: a different compliance package every time |
| Failure mode | Inspectable causal chain behind every decision | Hallucination, misreads, silent drift |
| Evidence handling | Read and parsed deterministically inside your boundary | Fetched via MCP into a model that may misinterpret it |
| Auditability | Replay the journey, get the same answer | Cannot reproduce yesterday's output |
How you actually get into the FedRAMP Marketplace
- 01
Step 1: Get listed (no assessor required).
Submit the FedRAMP Marketplace Provider Listing Request Form with your government-wide use case, publish your public certification data, and commit to quarterly progress updates. This puts you on the Marketplace in the Initial Implementation Phase, visible to agencies, before you hold any certification. You then have up to 2 years to schedule a Class B, C, or D assessment if you go beyond Class A.
- 02
Step 2: Do the work.
Implement the Key Security Indicators, build your Security Decision Record, and stand up your Trust Center. ACTA greenfields the environment or scans the one you have, runs native vulnerability assessment (Grype and Trivy with cross-engine deduplication), and maps every finding to the published rules.
- 03
Step 3: Generate the package.
ACTA emits the full certification package as JSON validated against FedRAMP's published schemas: the Certification Package Overview, the Security Decision Record with implementation and validation data for every applicable rule and KSI, and a real Ongoing Certification Report. Deterministically, from your live environment, reproducible on demand.
- 04
Step 4: Assessment, if your class requires one.
Class A: optional; your SOC 2 Type II, GovRAMP, or legacy FedRAMP assessment from the past 12 months carries the assurance. Classes B and C: a FedRAMP Recognized assessor reviews your evidence and KSI implementations. Because ACTA's artifacts carry an inspectable causal chain, assessors verify instead of excavate.
- 05
Step 5: Apply and get reviewed.
You submit the FedRAMP Certification Application Form directly. FedRAMP's stated goal is an initial decision within 30 days, including a Deep Dive session on your package with their review team. Their clock stops while they wait on you, so responsiveness matters.
- 06
Step 6: Stay certified.
Continuous monitoring, quarterly reporting cadence, incident and vulnerability communication rules, and (for B through D) the annual assessment. ACTA regenerates fresh evidence whenever your environment changes, so your package never decays between reviews.
Preparation in as little as two days
Industry tooling has proven that 20x packages can be prepared and submitted in under 30 days, with the fastest published runs landing around two weeks. That was the benchmark to beat, and it was set by teams still gathering evidence semi-manually.
ACTA compresses the provider-controlled portion of the timeline (evidence gathering, artifact generation, and submission preparation) to as little as 2 days and as long as 2 weeks, because:
- โธEvidence gathering is not a project phase. ACTA reads your environment directly and continuously; the evidence exists the moment you connect it.
- โธArtifact generation is not authorship. The package is compiled deterministically from live state, not written, reviewed, and rewritten.
- โธVulnerability posture is not a surprise. Native scanning with CVE and CISA KEV feeds means you walk into the process already knowing what stands between you and submission.
- โธResubmission is free. Mitigate, regenerate, resubmit. Same day.
ACTA range covers provider-controlled preparation with a compliant environment. Remediation of existing vulnerabilities, assessor scheduling (Classes B through D), and FedRAMP's review are additive.
The honest asterisk: the 2-day-to-2-week range covers what ACTA controls. It does not cover time spent fixing your actual security posture. If your environment carries a backlog of unmitigated vulnerabilities or unimplemented Key Security Indicators, remediation takes as long as remediation takes. ACTA will show you that gap on day one with a deterministic assessment; it will not paper over it. We generate proof of security, we do not substitute for it. FedRAMP's own review clock (a 30-day target) and any assessor scheduling are also outside any vendor's control, ours included.
- July 6, 2026Initial Implementation Marketplace listings open
- July 28, 2026FedRAMP Ready goes legacy
- August 3, 2026Class A applications opendays away
- August 31, 2026Class B and C applications open
- January 1, 2027Consolidated Rules mandatory
- June 11, 2027Last day for new Rev5 applications
Three doors, one engine
ENTERING THE MARKET: Class A through the framework you already have.
If you hold a SOC 2 Type II, a GovRAMP certification, or a legacy FedRAMP Ready designation from the past 12 months, you already carry the assurance FedRAMP accepts for Class A. No FedRAMP assessor required. ACTA maps your existing framework to the mandatory Class A rules and Key Security Indicators, generates the schema-valid package, and gets you Marketplace-listed and application-ready. This is the fastest legitimate path into federal, and it opens August 3.
MOVING UP: Class B and C for providers who have worked with an assessor.
If you have an independent assessment behind you and need into the 20x Marketplace at Class B or C, ACTA becomes your evidence engine: two or more automated validation methods per KSI (a hard Class C requirement), six months of historical KSI metrics (also required at Class C), and a package your FedRAMP Recognized assessor can verify by replaying the causal chain instead of interviewing your engineers for a month. Applications open August 31.
ALREADY AUTHORIZED: cut what you pay to stay compliant.
If you hold an ATO today, you know the quiet number: readiness and advisory spend of $250,000 to $500,000 a year with a consultant-led or integrator-led vendor, before the assessor's own fees. That spend buys billable humans re-collecting the same evidence every cycle. ACTA replaces the re-collection with deterministic regeneration and replaces the retainer with a license, cutting annual compliance operations cost dramatically while your evidence gets more reproducible, not less. Your annual assessment gets cheaper too, because assessors bill for time and deterministic evidence takes less of it.
Own your compliance. Do not rent it.
Many competitors are integrators. They assemble other vendors' software into one dashboard and charge you to live in their hotel indefinitely.
With ACTA you manage your own cybersecurity posture, your own certifications, and your own artifacts the same way you already manage your own cloud environments, your own user roles, and your own permissions.
Compliance becomes a normal part of your business process that you own, because the people building the software should own its security posture.
FedRAMP agrees with this model. The rules require that providers, not their tools or consultants, hold responsibility and accountability for every claim in the certification package, and prohibit third parties from applying on a provider's behalf. ACTA is built for that world: you own the environment, the evidence, the package, and the submission.
The lower cost path to the marketplace
Typical competitor paths stack consultants, integrator subscriptions, and advisory retainers into $250,000 to $500,000 per year of readiness spend before the independent assessor sends an invoice. ACTA publishes its pricing openly, and the deterministic engine does the re-collection work that retainers used to bill for.
Frequently asked questions
What is FedRAMP 20x?
FedRAMP 20x is the modern certification type under FedRAMP's Consolidated Rules for 2026. Instead of sponsor-led narrative documentation, providers demonstrate measured security outcomes: Key Security Indicators, a machine-readable Security Decision Record, and JSON artifacts validated against published schemas. FedRAMP itself reviews and certifies; no agency sponsor is required.
Do I need an agency sponsor?
No. All 20x certifications run on the Program path, directly through FedRAMP. The agency sponsor path is a legacy Rev5 mechanism that closes to new applicants June 11, 2027.
Do I need an independent assessor?
Depends on your class. Class A: no FedRAMP assessment required; your SOC 2 Type II, GovRAMP, or legacy FedRAMP assessment from the past 12 months carries the assurance (an optional pre-submission verification by a FedRAMP Recognized assessor is available). Classes B, C, and D: yes, a fresh assessment by a FedRAMP Recognized assessor within 3 months of application and annually thereafter. Note that FedRAMP retired the term "3PAO"; the people are the same, the word is now "assessor."
Can my agency customer act as my auditor?
Not under 20x. FedRAMP is the final assessor and issues the certification. Your agency customers consume your live certification data through your Trust Center and continuous monitoring to make their own authorization decisions, but they do not replace the FedRAMP Recognized assessor requirement at Classes B through D.
Is this process going to change?
Probably. The rules launched in June 2026, pipelines are opening in stages, CMMC's third-party assessment mandate was suspended in July 2026 pending a reform review, and the role of independent assessors government-wide is in flux. FedRAMP publishes its rules as versioned machine-readable JSON with a public changelog; ACTA validates against the current published ruleset, so when the rules move, your artifacts move with them.
How fast can I be ready to submit?
With a compliant environment, ACTA compresses preparation to as little as 2 days and typically no more than 2 weeks: connect, assess deterministically, generate schema-valid artifacts, prepare submission. If your environment carries unmitigated vulnerabilities, remediation time is additive, and that is on purpose; ACTA proves security, it does not simulate it. FedRAMP's own review targets 30 days after you apply.
What are the machine-readable artifacts?
JSON documents validated against FedRAMP's published schemas: the Certification Package Overview, the Security Decision Record covering every applicable rule and Key Security Indicator with implementation and validation data, and an Ongoing Certification Report. ACTA generates all of them deterministically from your live environment.
How is ACTA different from AI-based compliance tools?
FedRAMP's Deterministic Telemetry definition explicitly excludes generative AI output from serving as a factual record of system state. ACTA runs on goRapide, BMD's causal event decision language, with no LLMs, agents, or MCP anywhere in the compliance path. Identical inputs produce identical artifacts, scores, and hashes, and every decision carries a replayable causal chain.
What happens when a new CVE or KEV appears in my boundary?
You know the day it is reported. ACTA's native scanning (Grype and Trivy, cross-engine deduplicated) tracks CVE and CISA KEV feeds continuously. Mitigate, regenerate deterministically, and publish fresh evidence. Compliance stays continuous instead of decaying between assessments.
How much does ACTA cost?
Seats are $5,000 per month for startups taking one product into the Marketplace. Enterprise licenses start at $250,000 per year for organizations managing several applications across federal boundaries. Compare that against the $250,000 to $500,000 per year many authorized providers currently spend on readiness retainers alone, before assessor fees.
Get listed. Get deterministic. Get certified.
The Marketplace listing that starts your journey requires no assessor and is open today. Class A applications open August 3; Class B and C open August 31. Walk in with a package that regenerates itself.