FedRAMP
Landers and Company guides Cloud Service Providers through every stage of the FedRAMP journey — from readiness assessments and gap analysis through full certification, including documentation development, JSON schema implementation, and 3PAO coordination. Certified isn't the finish line. Our ongoing support keeps you there: vulnerability detection and response, vulnerability evaluation and reporting, Security Decision Record (SDR) maintenance, quarterly Ongoing Certification Reports, and everything else the 2026 rules require.
FedRAMP Is Changing — Is Your Cloud Service Ready?
The federal government's framework for cloud security authorization has undergone its most significant transformation in a decade. The FedRAMP Consolidated Rules for 2026 fundamentally change how Cloud Service Providers (CSPs) earn and maintain FedRAMP Certification — and the clock is already running.
Whether you currently hold a Rev5 authorization, are working toward your first FedRAMP certification, or are evaluating the new FedRAMP 20x path, Landers and Company is ready to guide you through every stage of the transition. We have already completed a thorough analysis of the 2026 rules across all 15 rulesets and 198 individual requirements, and we are helping CSPs plan and execute their path to compliance before the critical deadlines arrive.
Not sure where you stand? Contact us for a free consultation and a FedRAMP 2026 readiness assessment.
Two Paths Forward
Under the 2026 rules, CSPs must choose one of two certification types:
FedRAMP Rev5 — the established path, modernized. Rev5 continues to use the NIST SP 800-53 Rev.5 control baseline, but the 2026 rules bring significant changes to how Rev5 certifications are documented, assessed, and maintained. This path is available for existing authorizations and new applications filed before June 11, 2027, after which no new Rev5 applications will be accepted.
FedRAMP 20x — the new modern path. Built around Key Security Indicators (KSIs), automated evidence, and machine-readable certification data, 20x is designed for cloud-native providers who can demonstrate security outcomes through continuous, automated validation. 20x certifications do not use a traditional SSP and do not require a 3PAO annual assessment in the traditional sense.
Both paths are governed by the same 15 rulesets. The difference is in the underlying security framework and how compliance is demonstrated — not whether compliance is required
What Both Paths Have in Common
Regardless of which path you are on, every CSP must now:
- Eliminate the POA&M and transition to the Vulnerability Detection and Response (VDR) and Vulnerability Evaluation and Reporting (VER) programs – with outputs in machine-readable JSON formats.
- Replace the SSP with a Certification Package Overview (CPO) and Security Decision Record (SDR) in JSON-compatible formats — Word documents are no longer the standard.
- Publish and maintain a FedRAMP-Compatible Trust Center with machine-readable certification data
- Conduct Quarterly Review meetings open to all agency customers
- Publish Ongoing Certification Reports (OCRs) every three months
- Deliver Significant Change Notifications with defined timeframes (not the old SCR process)
Mandatory by December 7, 2026
Grace period ends March 7, 2027 for existing certifications.
These two rulesets represent the largest operational shift for most CSPs and require the most lead time to implement properly:
Vulnerability Detection and Response (VDR) — Monthly scans and uploading a POA&M are no longer sufficient. The 2026 rules require a persistent, automated vulnerability detection program covering all information resources, with remediation timeframes driven by a new risk rating system. The new timeframes are based on the newly developed PAIN (Potential Agency Impact N rating), internet reachability, and exploitability. Vulnerability Evaluation and Reporting (VER) - Every detected vulnerability must be evaluated for exploitability, internet reachability, and Potential Agency Impact before being reported. Reports must be machine-readable JSON, continuously available to all agency customers through your Trust Center. The old monthly Continuous Monitoring submission process does not satisfy these requirements.
Considering FedRAMP 20x? Here's What You Need to Know
FedRAMP 20x is designed for cloud-native providers that can demonstrate security outcomes through automation and continuous measurement rather than through documentation and periodic assessments. If your engineering team already runs continuous integration pipelines, automated configuration management, and real-time security monitoring, 20x may be a more efficient path than Rev5.
Key Security Indicators (KSIs) replace the NIST 800-53 control baseline as the primary expression of security requirements. There are 12 KSI areas covering encryption, vulnerability management, access control, audit logging, incident response, and more. Each KSI must be addressed with implementation statements, validation evidence, assessment methodology, automated test results, and machine-readable evidence streams.
Automated evidence replaces annual assessments. Rather than a 3PAO conducting periodic point in-time assessments, 20x relies on continuous, machine-generated evidence that the KSIs are being met. Independent verification focuses on validating that the automation itself is working correctly.
The Certification Package is fully machine-readable. The CPO, SDR, vulnerability reports, and all other certification data must be available in JSON format through a FedRAMP-compatible Trust Center with programmatic API access.
No new 20x applications under the Rev5 path. A CSP cannot hold both a Rev5 Program Certification and a 20x Program Certification for the same CSO. If you are currently on Rev5 and want to move to 20x, you must apply for a new FedRAMP Certification.
FedRAMP is accepting 20x certifications now. Contact us for guidance on whether 20x is the right path for your organization and what a realistic transition timeline looks like.
Already certified? The work isn't over.
The FedRAMP 2026 rules require a persistent, automated vulnerability program that operates every day — not just at assessment time. Whether you're building this capability from scratch or updating an existing program to meet the new requirements, we can help design it, run it, and keep it current. Let's talk.
We offer a variety of support levels to meet your needs. The following services can be applied to establish a comprehensive program or to support existing staff:
Vulnerability Program Transformation
We help CSPs design and implement a VDR/VER-compliant vulnerability program that satisfies the new requirements without rebuilding your entire security operations from scratch:
- Detection gap analysis: Assessment of your current detection coverage against VDR frequency requirements for drift-prone vs. stable resources, sample detection, and non-machine verification
- Remediation timeframe implementation: Building the evaluation workflows needed to apply FedRAMP's new due date system — assessing each vulnerability's PAIN rating, internet reachability, and exploitability together to determine the correct mitigation or remediation timeframe under VDR-TFR-PVR.
- Vulnerability Detail Report setup: Replacing your POA&M with a properly structured, automated program that can turn your vulnerability information into the FedRAMP required deliverables.
- Accepted Vulnerability Info setup: Setting up a properly structured Accepted Vulnerabilities list meeting FedRAMP requirements, to include handling false positives and internal reporting.
- Incorporating the KEV process: Building an automated process to check the CISA Known Exploited Vulnerability (KEV) catalog and incorporate KEV due dates into your remediation and reporting workflows.
- Automated reporting design: Designing machine-readable vulnerability reports in the FedRAMP JSON schema format, integrated with your Trust Center for continuous agency access.
- Incident escalation integration: Connecting your vulnerability program to incident reporting procedures for PAIN-5/4 internet reachable vulnerabilities that trigger Incident Evaluation and Communication (IEC) obligations.
- Trust Center establishment: Designing or procuring a FedRAMP-compatible Trust Center that meets the 2026 data-sharing requirements— including programmatic API access, access logging, and machine-readable certification data delivery.
Ongoing Vulnerability Program Support
For CSPs that need a long-term partner rather than a one-time engagement, we provide ongoing program support — including:
- Ongoing VER/AVI report preparation: Creating and publishing vulnerability detection and response activity and accepted vulnerability reports in FedRAMP-compliant format.
- Scanning tool and automation maintenance: Keeping your vulnerability scanning tools configured correctly and all automation logic current — so your reports continue to meet FedRAMP requirements as your environment changes.
- Trust Center data currency: Ensuring your machine-readable and human readable vulnerability data is updated at the frequencies required by FedRAMP.
- Comprehensive detection coverage: FedRAMP requires vulnerability detection to go beyond scanning tools. We help you build and maintain coverage across assessments, threat intelligence, vulnerability disclosure programs, penetration testing, incident response, automated control testing, and supply chain monitoring — all sources explicitly listed in rule VDR-CSO-DET.
DISA/DOD IL4, 5, 6
Landers and Company provides support to Cloud Service Providers (CSPs) as they go through the Defense Information Systems Agency (DISA) cloud computing security authorization process. Our experts provide guidance to CSPs on how to meet the requirements of the Cloud Computing (CC) Security Requirements Guide (SRG), in order to provide their Cloud Service Offering (CSO) to the Department of Defense (DoD). This program, known as FedRAMP+, outlines specific requirements beyond the FedRAMP requirements in order for CSOs to be used by the DoD.
L&C can guide you through the DoD authorization process by providing any of the following:
- Gap Analysis to determine what additional cybersecurity controls and safeguards must be implemented to meet FedRAMP+ requirements
- Advisory consulting for either existing FedRAMP-authorized CSOs or for CSPs seeking FedRAMP+ authorization
- Completion of the majority of the required documentation
- Support with continuous monitoring
- Preparation for penetration tests, assessments, vulnerability scans, and incident response
- Rev. 5 Uplift - Updates needed for security packages in order to comply with the updated Rev. 5 requirements
GovRAMP
For Cloud Service Providers (CSPs) with primarily state and local government customers, L&C also has experience supporting the GovRAMP process.
GovRAMP adopts policies and procedures to standardize the security requirements for Cloud Service Providers (CSPs), then ensures Cloud Service Offerings (CSOs) utilized by state and local governments satisfy those security requirements through independent audits and continuous monitoring.
Landers and Company can support your GovRAMP journey with any of the following services:
- Gap Analysis to help you determine what additional cybersecurity controls and safeguards you may need to implement prior to meeting the GovRAMP requirements
- Completion of all required documentation
- Advisory consulting as you transition through the GovRAMP statuses of Ready, Provisional, and Authorized
- Support with continuous monitoring
- Preparation for penetration tests, assessments, vulnerability scans, and incident response
- Rev. 5 Uplift - Updates needed for security packages in order to comply with the updated Rev. 5 requirements
Updated GovRAMP Standards
Did you know GovRAMP has selected the NIST 800-53, Rev. 5 framework as the foundation for all GovRAMP standards? L&C has completed a thorough analysis of all Rev. 5 changes and has updated templates and questionnaires available to support you with any Rev. 5-related requirements and updates.
Contact us to learn more, or to request a free consultation
Cybersecurity Maturity Model Certification (CMMC)
The Department of Defense (DoD) developed CMMC 2.0, a new security requirements framework that will be implemented through contracts with DoD contractors that handle sensitive, unclassified DoD information. This certification is designed to validate the security posture of DoD suppliers to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). While these requirements may continue to evolve, DoD suppliers and vendors should be planning for compliance now.
L&C provides advisory consulting for CMMC, including helping to define the CMMC/CUI boundary as well as the development of documentation to support the effort. Contact us for help with any of the following:
- CMMC advisory consulting
- Help to define the CMMC/CUI boundary
- Support documentation development
When the DoD implemented the CMMC 2.0 program, there were three key changes introduced as refinements from the original (CMMC Model 1.0) program requirements, including the following:
- Streamlined & Aligned Model: the updated CMMC Model 2.0 now includes three (3) compliance levels (as opposed to five (5) levels in CMMC Model 1.0), which are aligned with National Institute of Standards and Technology (NIST) cybersecurity standards.
- Reliable & Reduced-Cost Assessments: in the updated 2.0 model, some companies (depending on the compliance level appropriate for their type and sensitivity of information) may complete self-assessments to demonstrate compliance, and the model increased oversight of standards for third-party assessors.
- Flexible Implementation: some companies may now make Plans of Action & Milestones (POA&Ms) to achieve the initial certification, and there are additional circumstances under which the government is now allowed to waive the inclusion of CMMC requirements.
Cybersecurity Maturity Model Certification (CMMC)
The Department of Defense (DoD) developed CMMC 2.0, a new security requirements framework that will be implemented through contracts with DoD contractors that handle sensitive, unclassified DoD information. This certification is designed to validate the security posture of DoD suppliers to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). While these requirements may continue to evolve, DoD suppliers and vendors should be planning for compliance now.
L&C provides advisory consulting for CMMC, including helping to define the CMMC/CUI boundary as well as the development of documentation to support the effort. Contact us for help with any of the following:
- CMMC advisory consulting
- Help to define the CMMC/CUI boundary
- Support documentation development
When the DoD implemented the CMMC 2.0 program, there were three key changes introduced as refinements from the original (CMMC Model 1.0) program requirements, including the following:
- Streamlined & Aligned Model: the updated CMMC Model 2.0 now includes three (3) compliance levels (as opposed to five (5) levels in CMMC Model 1.0), which are aligned with National Institute of Standards and Technology (NIST) cybersecurity standards.
- Reliable & Reduced-Cost Assessments: in the updated 2.0 model, some companies (depending on the compliance level appropriate for their type and sensitivity of information) may complete self-assessments to demonstrate compliance, and the model increased oversight of standards for third-party assessors.
- Flexible Implementation: some companies may now make Plans of Action & Milestones (POA&Ms) to achieve the initial certification, and there are additional circumstances under which the government is now allowed to waive the inclusion of CMMC requirements.
The CMMC Model 2.0 - announced in November 2021 - is the next iteration of the DoD's CMMC cybersecurity model. Key elements of the CMMC 2.0 program include the following details for the three (3) tier model:
- Level 3:
- The model includes 110+ requirements based on NIST SP 800-171 and NIST SP 800-172; as new versions of these documents are developed and released, suppliers will be expected to meet these changes as well
- Requires triennial government-led assessments and annual affirmations
- Level 2:
- The model includes 110 requirements aligned with NIST SP 800-171
- Requires triennial third-party assessments and annual affirmations. Some programs allow triennial self-assessments, in addition to annual affirmations
- Level 1:
- Model includes 15 requirements
- Requires an annual self-assessment and annual affirmations
CMMC CERTIFICATION
Landers and Company can help you with all stages of the CMMC Certification process, including:
- CMMC advisory consulting
- Gap Analysis
- Determination of the CMMC/CUI boundary
- Development of a full documentation package
- Development of the System Security Plan (SSP)
- Development of a Plan of Action & Milestones (POA&M)
Contact us to learn more about our services, or to request a free consultation as you embark on the CMMC certification process.




