FedRAMP 20x Retired the Binder — and Handed You a Data Platform to Run
Under the Consolidated Rules for 2026, certification data has to be published continuously, in human-readable and machine-readable form, with uninterrupted, logged access for agency people and agency systems alike. That is no longer a documentation problem. It is an engineering problem — and it is the one we already solved for our customers.
In June we mapped the vocabulary change — authorization becoming certification, Low/Moderate/High becoming Classes A through D — and closed on the point that mattered most: the providers who win under 20x are the ones whose evidence is already continuous and machine-readable. That sentence has since grown teeth. FedRAMP's certification data sharing rules now spell out what "continuous and machine-readable" means in practice, and the answer surprises most engineering teams the first time they read it.
Short version: you are no longer expected to write a package. You are expected to operate one — a live, always-available, access-controlled data service that federal customers and their automated tooling can query on demand. Here is what that actually requires, and where the burden disappears.
The Package Became a Platform
The old model had a physical shape to it. You assembled a System Security Plan, a Security Assessment Report, a POA&M and a stack of supporting artifacts, dropped them into a secure folder, and agencies requested access one at a time. Documents were the deliverable, and a document is a thing you finish.
FedRAMP 20x replaces that with a trust center: a provider-operated location where FedRAMP Certification Data lives and is shared under FedRAMP's access, accuracy and transparency rules. Some of that data has to be public — published openly in both human-readable and JSON form, and kept accurate. The rest is shared with agencies on request, but through a mechanism that has to stay available continuously rather than a folder someone grants you into.
Notably, the data is treated as the provider's intellectual property rather than federal information — which is precisely why the obligation to publish, maintain and log it lands squarely on you.
46 KSIs, Reported Continuously
The telemetry your trust center carries is anchored to the Key Security Indicators. There are 46 KSIs in the 2026 ruleset, organized into ten families — and the count is worth stating plainly, because draft-era numbers from the 2025 phase-one materials are still circulating in vendor blogs and RFP language.
Forty-six is not a frightening number on its own — the underlying expectations map to NIST 800-53 controls you already recognize. What changes the workload is the word persistently. A KSI is not a paragraph you write once; it is an assertion your systems keep making, with evidence, on a schedule that never stops. Multiply that across every service in your Minimum Assessment Scope, hold the output accurate in two formats at once, and the shape of the problem becomes clear.
A handful of indicators also shift by class — several that are optional at Class B become required at Class C, including automated configuration assessment and authorized log access. Know your class before you build your evidence pipeline; the rework cycle is one you cannot afford inside a certification window.
The Requirement Teams Underestimate: Access
Most providers read the publication rules, nod, and hand them to a compliance manager. Then they hit the trust center rules and discover they have been handed a product requirements document. Sharing the data is the easy half; governing who reached it, when, and how is where the engineering lives.
Read that list as an architecture brief and the scope lands: federated identity for two very different consumer types, just-in-time authorization, a documented API, immutable access logging with retention, a self-service admin console, an availability endpoint that survives your own outage, and automation keeping every JSON payload in lockstep with the page a human reads. That is a product — and most software companies pursuing certification are not staffed to ship one alongside the application they actually sell.
The trust center is not a one-time build. Every rule above carries an operational tail — logs to retain, inventories to reconcile, snapshots to preserve for the life of the certification, an availability service that has to stay up precisely when everything else is down. Teams that budget for the build and not the tail are the ones that fail their first Ongoing Certification Report.
We Already Built It
This is the part where the burden goes away. GovDataHosting has built a Trust Center into our Cloud Technology Platform, and it is available to our hosting customers as part of the service. Your service publishes its telemetry and certification data into it securely; the platform handles the rest of the specification — the dual-format publication, the programmatic access layer, the just-in-time provisioning, the access inventory and retained logs, the historical snapshots, and the independent availability reporting that has to keep answering when your application cannot.
The value proposition for a FedRAMP-certified software company is straightforward: you stop diverting engineers into compliance infrastructure and put them back on the product your customers are buying. For a company pursuing its first certification, the effect is larger still — the trust center is the one part of 20x that looks nothing like the security work a young company has already done. Inheriting it removes an entire workstream from the critical path, the same way you already inherit physical, environmental and boundary controls from the platform underneath you.
It is a natural progression of what we already do. GovDataHosting has spent 25 years making complicated federal compliance easy — inheriting controls, running a 24/7 U.S.-based SOC, carrying a FedRAMP High (Class D) certification so our customers do not have to carry the whole weight of one themselves. FedRAMP 20x moved part of that weight from paper into software. So we built the software.
Publish your evidence. We'll run the platform under it.
Our customers publish certification data and KSI telemetry into a Trust Center that is already built for continuous, logged, dual-format access by agency reviewers and agency machines. You own your application layer and your evidence. We own the infrastructure that makes sharing it a solved problem — continuously monitored, on FedRAMP High (Class D) certified infrastructure.
What You Should Do Now
The clock is no longer theoretical. The 20x rulesets opened for optional adoption on July 4, 2026 — the same date they began applying to obtaining a 20x certification. Maintaining one falls under them on January 1, 2027, with the grace period closing at the first independent assessment started after that date. The Rev5 path runs longer — obtain from January 1, 2027, maintain from August 1, 2027, grace ending February 1, 2028 — but longer is not the same as generous.
Three moves. First, inventory what you would have to publish today and be honest about how much of it exists only in a document. Second, treat the access requirements as an engineering scope item, not a compliance checkbox — if nobody on your team can name who would build the programmatic access layer, you do not have a plan. Third, decide deliberately whether operating a trust center is a business you want to be in, or a dependency you would rather inherit from your platform.
"FedRAMP 20x didn't reduce the compliance burden — it converted it from writing into operating. The providers who feel relief are the ones who never had to build the operating part themselves."
GovDataHosting Compliance Team
Our mission has not changed in 25 years: make complicated federal compliance easy. The rules changed shape this year, so the way we deliver on that changed shape with them. The binder is gone. The platform is running. You are welcome to build on it.
Your Trust Center Is Already Built
Whether you are maintaining a certification into the January 2027 deadline or pursuing your first one, our compliance team can map your certification data sharing obligations and show you the Trust Center that already meets them.
Schedule Your Free FedRAMP Consult →
Ask us for a walkthrough of the Trust Center portal while you are there.