Skip to main content

FedRAMP 20x Class A: Separate Reporting from the Audit Cycle

Class A incorporates an Ongoing Certification Report every three months and publication of the next report target date. A synchronous Quarterly Review is optional. Keep those tasks separate from the assessment expectations of the underlying alternative security framework.

Written by Boundera Team|October 10, 2026|5 min read

Main question

How should a FedRAMP 20x Class A provider organize its reporting and assessment calendar?

For your FedRAMP 20x Class A reporting calendar, start with separate entries for the Ongoing Certification Report, the next public report date, and your underlying framework's assessment milestones. Then decide whether a review meeting would help your agency customers.

The distinction matters: Class A incorporates a report every three months, while its synchronous Quarterly Review is optional. Its independent-assessment rule points to the expectations of the underlying alternative security framework. Those are separate obligations and choices, even when the same compliance team coordinates them. FedRAMP Class A rules

Identify the Class A rules before scheduling work

FRC-CLA-MFR explicitly includes CCM-OCR-AVL, CCM-OCR-NRD and IVV-CSX-AIA among the additional rules Class A providers must address. This cross-reference is the basis for applying the reporting and assessment requirements here. The report is one part of the Class A package; FRC-CLA-MFR lists other responsibilities too. FedRAMP Certification

Use the following distinction when assigning calendar owners:

Calendar itemClass A ruleWhat to schedule
Ongoing Certification ReportCCM-OCR-AVL: MUSTSupply a report every three months, covering the entire period since the previous summary.
Next report target dateCCM-OCR-NRD: MUSTSupply the next report's target date with other public Certification Data.
Synchronous Quarterly ReviewCCM-QTR-MTG: MAYIf you choose to hold the review, plan the three-month cycle and invite all necessary parties.
Underlying framework assessmentIVV-CSX-AIA: MUSTMeet the underlying alternative framework's assessment expectations.

The Class A variants and mandatory/optional groupings appear in the official related-rules reference. Do not use the title “Annual Independent Assessments for 20x” alone to decide what the Class A variant requires.

Build the report around a continuous coverage period

CCM-OCR-AVL requires a consistent, human-readable Ongoing Certification Report supplied to all necessary parties every three months. It covers the entire period since the previous summary. The required high-level contents apply where relevant to the certification type or class. Report Availability

The rule's list covers these areas, if applicable:

  • Changes to Certification Data and planned changes during at least the next three months.
  • Accepted vulnerabilities and transformative changes.
  • Updated recommendations for security, configuration, usage or similar aspects of the offering.
  • Agencies directly using the product.
  • FedRAMP Reportable Incidents, or an attestation that none occurred, plus lessons learned and resulting changes when incidents did occur.

These are summaries of the contents specified in CCM-OCR-AVL. Keep the applicability qualifier when preparing the report; avoid filling a section with invented activity just to make the document look complete.

As an operating practice, give each report a coverage start, coverage end, delivery date, owner and link to the preceding report. Before release, compare adjacent coverage periods for gaps. Keep references to the records behind each summary so a reviewer can follow the explanation without restarting the research.

For example, a team could use an internal worksheet with one row per reporting period, another field for the next target date, and a separate preparation deadline for contributors. This is a suggested workflow, not a FedRAMP template or an additional mandated lead time. Pick preparation deadlines that fit your review process while preserving the rule's three-month reporting cadence.

Keep the next public date separate from report delivery

CCM-OCR-NRD requires the target date of the next Ongoing Certification Report to accompany other public FedRAMP Certification Data. Supplying the report and supplying that public date are both included in the mandatory Class A cross-reference. Class A related rules

Assign an owner to check that the public date and the team's internal schedule agree. As a release check, open the public data surface and compare its next-report date with the approved schedule. Retain the check result alongside the report's delivery record. These are suggested coordination steps; the rule does not prescribe this particular checklist.

If you are organizing the broader package delivery process, the authorization data sharing workflow provides related operational context.

Decide on the meeting without changing the report obligation

For Class A, CCM-QTR-MTG uses MAY for a synchronous Quarterly Review every three months, open to all necessary parties. FRC-CLA-OFR also places that meeting rule among the optional Class A rules. The mandatory report remains separately listed in FRC-CLA-MFR. Class A certification rules and Quarterly Review Meeting

Choose a meeting when discussion would help customers understand a meaningful change or resolve questions. Keep the decision to host it separate from the report-delivery task. An internal calendar can mark the meeting as an optional customer discussion while keeping report preparation and delivery assigned to named owners.

Maintain a separate assessment schedule

The Class A variant of IVV-CSX-AIA requires providers to meet their underlying alternative security framework's expectations as part of persistent independent verification and validation. It does not state a universal SOC 2 or GovRAMP renewal interval. The separate IVV-CSO-FIA Class A variant makes a FedRAMP independent assessment at least once per year optional. Independent Verification and Validation

For SOC 2-based Class A applications, FRC-CLA-EAM includes an estimated schedule for the upcoming report among the external assessment materials, alongside the complete report, verified audit engagement documentation and applicable bridge/gap letters and supplemental evidence. That schedule is distinct from the next Ongoing Certification Report date. External Assessment Materials

As a practical step, review the assessment milestones with the people responsible for the underlying framework. Record the expected report date, preparation work and evidence owners in separate calendar entries. Our SOC 2-to-Class A and GovRAMP-to-Class A articles address entry-package questions; this calendar addresses the ongoing coordination work.

Record the applicable adoption dates

As checked on October 10, 2026, the FRC, CCM and IVV rulesets list July 4, 2026 for optional adoption and obtaining initial 20x certification, and January 1, 2027 for maintaining ongoing 20x certification. Their published grace language ends the grace period at the first FedRAMP independent assessment started after January 1, 2027. These are ruleset applicability dates, not a substitute for the recurring report schedule. FRC dates, CCM dates, IVV dates

Record the applicable adoption basis in your operating calendar and recheck the current official rules when circumstances change. Avoid interpreting grace language as a blanket permission to postpone every Class A duty until an unspecified future audit.

Frequently asked questions

Does Class A require an Ongoing Certification Report every three months?

Yes. FRC-CLA-MFR incorporates CCM-OCR-AVL, which requires a report every three months covering the entire period since the previous summary, with applicable high-level contents. CCM-OCR-NRD also requires the next target date with public Certification Data.

Is a synchronous Quarterly Review mandatory for Class A?

No. The Class A variant of CCM-QTR-MTG uses MAY, and FRC-CLA-OFR lists the rule as optional. The Ongoing Certification Report is a separate mandatory Class A rule.

Does Class A impose a universal annual SOC 2 or GovRAMP audit schedule?

IVV-CSX-AIA requires Class A providers to meet the expectations of their underlying alternative security framework; it does not specify one common renewal interval. Keep that assessment schedule separate from the three-month Ongoing Certification Report.

Next step

If you want to turn this guidance into an execution plan, the product side handles control mapping, SSP drafting, and evidence collection.