FedRAMP 20x
FedRAMP 20x gap assessment
Find your certification path and class, your Marketplace listing gaps, and your readiness across all 10 KSI families — in about five minutes, grounded in the FedRAMP 20x rules, not guesses.
- 1Route triage — your certification type, path, and suggested class
- 2Marketplace checkpoint — the listing facts that actually matter (UEI, service list, agency use)
- 3KSI readiness — one question per family across all 10 Key Security Indicators
- 4A readiness snapshot — top gaps mapped to NIST controls, with next steps
What the assessment covers
Your readiness is rated across all ten FedRAMP 20x Key Security Indicator families — the capabilities FedRAMP validates for Class A, B, and C certifications:
- CEDCybersecurity Education
- CMTChange Management
- CNACloud Native Architecture
- IAMIdentity and Access Management
- INRIncident Response
- MLAMonitoring, Logging, and Auditing
- PIYPolicy and Inventory
- RPLRecovery Planning
- SCRSupply Chain Risk
- SVCService Configuration
Plus your certification path and suggested class, and a Marketplace listing checkpoint (UEI, public service list, agency use case, quarterly progress). Explore the underlying requirements in the 2026 Rules Explorer or the FedRAMP 20x implementation explorer.
Frequently asked
- What is a FedRAMP 20x gap assessment?
- A structured check of where you stand against the FedRAMP 20x requirements before you commit to the certification process: which certification path and class fit you, what your FedRAMP Marketplace listing still needs, and how ready you are on each Key Security Indicator (KSI) family. This one is grounded in the official FedRAMP Consolidated Rules for 2026, so every question maps to a real rule.
- Is this a real FedRAMP assessment?
- No. It's an indicative, self-reported snapshot grounded in the FedRAMP 20x rules — not a verified assessment or authorization. Connect your systems for the evidence-backed evaluation.
- Which FedRAMP certification class do I need — A, B, or C?
- It depends on your service and what you already hold: Class A leverages a completed alternative framework assessment (such as SOC 2 Type II, GovRAMP, or FedRAMP Rev5), while Classes B and C are assessed by a FedRAMP-recognized independent assessor. The assessment's route triage suggests a class from your answers, grounded in the certification rules.
- What are the Key Security Indicators (KSIs)?
- KSIs are the security capabilities FedRAMP 20x validates instead of the Rev5 control-by-control review — 46 indicators across 10 families, from Cloud Native Architecture to Incident Response. You rate your readiness per family and get your top gaps mapped to NIST controls.
- What does it cover?
- Your certification type, path and class, a Marketplace listing checkpoint, and a readiness score across all 10 Key Security Indicator (KSI) families.
- How long does it take?
- About five minutes. No login required; your work email unlocks the KSI readiness journey and the snapshot.
This is an indicative, self-reported snapshot — not a verified assessment or FedRAMP authorization.