You've maintained SOC 2 Type II for commercial customers. Now federal agencies are asking about FedRAMP, and you're wondering if it's worth the investment. The new Class A certification path eliminates the agency sponsor requirement and builds directly on your existing SOC 2 foundation. Submissions open in August 2026. If you start now, you'll be ready.
Why This Matters
Your SOC 2 Type II report demonstrates security controls to commercial customers. But federal agencies can't use it to authorize your cloud service. They need FedRAMP certification, which used to mean a lengthy authorization process, high costs, and the challenge of finding a federal agency sponsor.
The FedRAMP 20x framework, introduced in 2025, changes this. Class A certification is issued directly by the FedRAMP PMO, with no sponsor required. It builds on frameworks you already have, focusing on continuous validation through Key Security Indicators (KSIs) instead of extensive documentation. You'll be listed on the FedRAMP Marketplace, which federal procurement teams use to shortlist vendors.
If you're already maintaining SOC 2 Type II, you've addressed most baseline security requirements. The gap to Class A is about 35-55 additional FedRAMP-specific requirements, many of which extend controls you already operate.
What You Need Before Starting
Required Foundation:
- Active SOC 2 Type II report (must be current)
- Documented ISMS covering your cloud service boundary
- Configuration management database (CMDB) or asset inventory system
- Centralized logging infrastructure (SIEM or equivalent)
- Incident response plan and runbook
Access and Tooling:
- Administrative access to your cloud infrastructure (AWS GovCloud, Azure Government, or Google Cloud)
- Vulnerability scanning tools with API access for automated reporting
- Identity and access management system with audit logging
- Backup and disaster recovery solution with documented RTOs/RPOs
Team Roles:
- Compliance lead (owns gap analysis and submission package)
- Security engineer (implements Technological Controls and KSI reporting)
- System owner (maintains system security plan documentation)
- Legal or contracts representative (reviews federal-specific terms)
Before you write a single control narrative, pull your most recent SOC 2 Type II report and map it against the FedRAMP Class A baseline. Identify controls you've already implemented and documented, and gaps where FedRAMP requires capabilities your SOC 2 scope didn't address.
Step-by-Step Implementation
Phase 1: Gap Identification (Weeks 1-2)
Start with the controls your SOC 2 didn't fully cover. Common gaps include:
- Federal incident reporting requirements (72-hour notification to US-CERT)
- FIPS-Validated Cryptography for data at rest and in transit
- Continuous monitoring and automated security reporting (KSIs)
- Configuration baselines aligned to NIST SP 800-53 instead of just CIS Benchmarks
- Media sanitization procedures meeting NIST SP 800-88 standards
Document each gap with the control requirement, your current state, and the action needed to close it. Don't write narratives yet. You're building a work plan.
Phase 2: Technical Remediation (Weeks 3-8)
Address technical gaps before documentation. If you're missing FIPS-Validated Cryptography, you can't document a control that doesn't exist.
Priority order:
- Cryptography: Verify all encryption modules are FIPS 140-2 or 140-3 validated. If using cloud-native encryption (AWS KMS, Azure Key Vault), confirm the service is operating in a FedRAMP-authorized region.
- Continuous Monitoring: Implement automated collection of security metrics. FedRAMP Class A requires demonstrable KSIs. Set up dashboards that pull real-time data from your SIEM, vulnerability scanner, and configuration management tools.
- Incident Response: Update your IR plan to include federal reporting workflows. Document the 72-hour US-CERT notification process and assign responsibility for federal incident coordination.
- Access Controls: If your SOC 2 used role-based access control (RBAC), verify it meets the principle of least privilege at the granularity FedRAMP expects. Document your Segregation of Duties Policy explicitly.
Phase 3: Documentation and Evidence Assembly (Weeks 9-12)
Build your System Security Plan (SSP) by extending your SOC 2 control narratives. For each FedRAMP control:
- Reference the corresponding SOC 2 control if applicable
- Describe the implementation specific to your system boundary
- Cite the evidence artifact (policy document, configuration screenshot, log query)
Your SOC 2 Type II report already contains control descriptions and test results. Reuse them. Don't rewrite what you've already documented unless the FedRAMP requirement demands additional specificity.
Create a Control Implementation Summary (CIS) matrix that maps every FedRAMP Class A control to either:
- Your SOC 2 report (with section reference)
- New documentation you've created
- Inherited controls from your cloud infrastructure provider (if they're FedRAMP-authorized)
Phase 4: Package Assembly and Submission (Weeks 13-16)
The Class A submission package includes:
- System Security Plan (SSP)
- Control Implementation Summary (CIS)
- Policies and procedures referenced in your SSP
- Architecture diagrams showing data flows and system boundaries
- Continuous monitoring plan describing your KSI collection and reporting
Review the FedRAMP PMO's submission checklist before you upload. Incomplete packages get rejected, which resets your timeline by weeks.
Submit through the FedRAMP portal when the August 2026 window opens. The PMO reviews submissions on a rolling basis.
Validation: How to Verify It Works
Before Submission:
- Run a tabletop exercise simulating a federal incident. Can your team execute the 72-hour reporting requirement?
- Query your SIEM for the security metrics you've designated as KSIs. Can you generate the reports automatically, or are you still doing manual data collection?
- Ask a colleague unfamiliar with your system to read your SSP and identify the system boundary. If they can't, your architecture diagrams need work.
After Certification:
- Verify your listing appears on the FedRAMP Marketplace with accurate system details
- Test your KSI reporting pipeline by generating a monthly security posture report
- Confirm your monitoring tools are alerting on the thresholds you documented in your continuous monitoring plan
Maintenance and Ongoing Tasks
Class A certification requires continuous monitoring, not just annual audits. Set up these recurring tasks:
Monthly:
- Generate and review KSI reports (vulnerability scan results, access review completion, configuration drift)
- Update your asset inventory if you've added infrastructure
Quarterly:
- Review and update your risk register
- Conduct access reviews for privileged accounts
- Test backup restoration procedures
Annually:
- Update your System Security Plan if your architecture changes
- Refresh policies and procedures
- Conduct tabletop exercises for incident response and business continuity
Event-Driven:
- Report significant security incidents to US-CERT within 72 hours
- Notify the FedRAMP PMO of major system changes before implementation
- Update your SSP within 30 days of any change affecting your system boundary or control implementation
If you're already running a mature SOC 2 program, you're doing most of this work already. The difference is that FedRAMP requires you to report it to the PMO and maintain it as evidence of continuous authorization.
You're not starting from scratch. You're extending a foundation you've already built.



