FedRAMP 20x now covers three of its four certification classes. Class A applications open August 3, 2026, Classes B and C open August 31, and the FedRAMP Consolidated Rules for 2026 behind them officially launched on June 24. The class that is still missing is the one that matters most to high-assurance buyers: Class D, the successor to FedRAMP High.
FedRAMP has said plainly that "Class D Certifications will be developed during FedRAMP 20x Phase 4," and its published roadmap estimates Phase 4 for FY27 Q1–Q2. Translated out of federal fiscal time, that window runs from October 1, 2026 through March 31, 2027 — and if the pilot lands in the first quarter, it begins between October and December 2026. That is months away, not years. At the June 2026 meeting of the Federal Secure Cloud Advisory Committee, FedRAMP Director Pete Waterman described Class D as the "expected future high-impact equivalent" and confirmed the program plans to pilot a high-impact 20x path now that the 2026 consolidated rules are final.
What nobody outside the program knows is what Class D will actually require. Will it follow the same open-ended, outcome-based structure as Classes A through C, or will the High tier stay more prescriptive? FedRAMP has not published the answer, which leaves cloud providers with High ambitions planning against a blank page. We spend our days helping teams run IAL3 identity programs for FedRAMP High boundaries, so we are publishing our predictions — clearly labeled as predictions, not FedRAMP guidance — along with the preparation steps that make sense no matter how the details land.
The short version: The Class D (High) pilot window is estimated at October 2026 – March 2027. The 20x model replaces control-by-control assessment with Key Security Indicators and Security Decision Records, and the consolidated rules already telegraph one Class D requirement: 18 months of persistent validation history. Nothing in today's KSI catalog covers identity proofing or personnel vetting — Class D has to fill that gap, because the insider threat it defends against is documented in five years of FBI advisories and a growing stack of DOJ convictions.
Where FedRAMP 20x Actually Stands in July 2026
FedRAMP 20x replaced the document-heavy authorization process with a model the program describes bluntly: it works "by asking cloud service providers to demonstrate desired security capabilities instead of telling them to meet specific security requirements." Capabilities are expressed as Key Security Indicators (KSIs) — ten families covering identity and access management, change management, cloud-native architecture, monitoring, incident response, supply chain, and more — validated with automated, machine-readable evidence instead of narrative paperwork.
The results so far are real. The Phase One (Low) pilot received 26 complete packages in its first months and GSA reported authorization timeframes falling "from over one year to approximately five weeks." Phase Two extended the model to Moderate, with the first pilot certifications issued in March 2026. Phase Three — wide-scale adoption — is active now.
The 2026 rules also renamed the tiers. Under FedRAMP's designation decision, authorizations are now FedRAMP Certifications, organized into classes:
| Class | Legacy equivalent | 20x status (July 2026) |
|---|---|---|
| Class A | New pilot baseline | Applications open August 3, 2026 |
| Class B | LI-SaaS and Low | Applications open August 31, 2026 |
| Class C | Moderate | Applications open August 31, 2026 |
| Class D | High | Not released — Phase 4, estimated FY27 Q1–Q2 |
One date makes the missing class urgent: FedRAMP stops accepting new Rev5 certifications on June 11, 2027. Today, High exists only on the Rev5 track as Rev5 Class D. If 20x Class D slips while the Rev5 door closes, the on-ramp for new High offerings gets narrow. Teams targeting High should be watching Phase 4 announcements the way they once watched baseline updates.
The Control IDs Did Not Disappear — the Assessment Model Did
A common oversimplification says FedRAMP "deleted the controls." The reality is more precise, and more interesting. The 2026 reference site still publishes the full NIST SP 800-53 catalog — the identification and authentication family alone lists 59 controls and enhancements, including IA-12 identity proofing — but those control-by-control listings now apply to Rev5-based certifications only. The 20x track never touches them. It assesses KSIs.
What FedRAMP genuinely removed is the scaffolding that used to sit on top of the catalog. Notice 0013 (June 2026) is blunt: FedRAMP is "removing the vast majority of FedRAMP-assigned control parameter values" and "nearly all FedRAMP-specific control guidance" from the Rev5 baselines. The SSP and SAR's control-implementation content is replaced by the Security Decision Record; the Control Implementation Summary and Customer Responsibility Matrix are replaced by a provider Secure Configuration Guide. Vendors now make and document their own security decisions rather than transcribing FedRAMP's.
That freedom comes with a gap that matters enormously for High. Walk the current KSI catalog and you will find that KSI-IAM's indicators are strong on the account: automated account lifecycle management, "secure passwordless methods... otherwise strong passwords with phishing-resistant MFA," least-privilege and just-in-time authorization, disabling privileged accounts on suspicious activity. None of them verifies the human behind the account. There is no KSI for identity proofing, personnel screening, or background vetting anywhere in the catalog — the closest family, cybersecurity education, is training only. Under Rev5, the High baseline handles this with IA-12 identity proofing (including IA-12(4), which appears only in the High baseline) and PS-3 personnel screening. Under 20x as written today, that entire dimension of assurance has no home.
That absence is, in our view, the single most consequential open question for Class D.

Our Five Predictions for 20x Class D (High)
FedRAMP has released no Class D requirements. What follows is informed opinion — ours, not theirs — based on the published rules, the Rev5 High baseline, and the threat environment High systems exist to resist.
1. Class D will stay KSI-based, not return to control-by-control assessment
The program has called the 20x proof of concept a success at every phase gate, and the consolidated rules already define Class D's certification mechanics in KSI terms. We expect the open-ended structure to hold: capability outcomes, machine-readable evidence, persistent validation. Teams hoping the High tier will hand back a familiar 370-control checklist should not plan on it.
2. The rigor will come from validation depth — and the 18-month clock is already running
The certification rules escalate by class: Class B expects at least one automated validation method per KSI, Class C at least two plus six months of historical metrics. For Class D, the rule is already published: providers seeking 20x Class D certification must provide historical metrics from persistent validation covering at least the past 18 months for all KSIs. Read that against the calendar. A provider hoping for 20x Class D in mid-2028 needs persistent validation running by the end of 2026. You cannot backfill telemetry, which makes this the rare compliance requirement where waiting for the standard to be finished is itself the compliance failure.
3. Identity and personnel assurance will be named requirements — possibly risk-scoped instead of blanket
FedRAMP's current Rev5 guidance associates Class D with NIST digital identity assurance level 3, and FedRAMP has mapped High to IAL3 since 2018. Given the KSI gap described above, we predict Class D introduces an identity-assurance and personnel-assurance outcome — the human-verification counterpart to KSI-IAM — rather than silently dropping a control family that exists specifically because High systems attract nation-state interest.
The more interesting question is scope. Today's Rev5 High practice puts essentially everyone with logical access to the boundary in scope for identity proofing, because IA-12 covers "users that require accounts for logical access to systems." Population size is the main cost driver of an IAL3 program. An outcome-based Class D could allow providers to scope proofing rigor case by case, by the risk of each employee's duties — full IAL3 for production access, administrative rights, and remote hires; lighter assurance for roles that never touch federal data. That flexibility would reduce cost for large providers. It would also transfer the burden of defending the scoping decision onto the provider, which brings us to the next prediction.
4. Security Decision Records will be where flexibility meets accountability
The consolidated rules define the Security Decision Record as "a persistently maintained, verified, and validated record of the security decisions made by a provider over the lifecycle of a cloud service offering." The SDR rules require, for each applicable FedRAMP rule, an explanation of how it is followed — or "the reason and resulting risk to customers for not following the rule," accepted by a senior official, with independent verification and validation on top.
This is the answer to the obvious worry about outcome-based standards: that some vendors will attempt the bare minimum needed to pass an assessment. If FedRAMP leaves specific controls out, the bare-minimum path does get wider — and industry voices have warned that without standard guidance, agencies may sidestep 20x-certified offerings entirely. Congress raised the same concern when the overhaul launched, with the FedRAMP Authorization Act's author demanding "clear assurance that it will result in effective and rigorous security outcomes." The SDR is the mechanism that makes minimalism expensive: every omission becomes a written, named, senior-official-accepted risk statement that an assessor, an agency, and eventually a plaintiff's counsel can read. Under Rev5 you could hide a weak program inside 400 pages of narrative. Under 20x you have to sign your shortcuts.
Apply that to identity. A Security Decision Record that waives identity verification for remote employees with privileged access — in 2026, with five years of FBI advisories on record — is a document nobody should want to sign. For a remote workforce, skipping an in-person or equivalent identity check is at this point difficult to describe as anything but negligent, and under 20x that negligence would be self-documented.
5. Agency and Department of War trust will keep Class D conservative
FedRAMP 20x is a genuine improvement — GSA calls it a shift "from process-driven compliance to outcome-focused security", and we agree with the direction. But Class D only works if the buyers of High assurance trust it as much as they trusted the Rev5 High baseline. The Department of War (DoW) floors Impact Level 5 on FedRAMP High under the DISA cloud computing SRG, and as of mid-2026 there is no announced DoW pathway for accepting 20x certifications at all. High systems carry the government's most sensitive unclassified data; the agencies and military components buying at that tier will not accept "trust our KSIs" without hard floors. We expect Class D to be the most prescriptive of the 20x classes — explicit minimums for cryptography, incident reporting, personnel and identity assurance — even if those minimums are written in outcome language. If FedRAMP under-specifies, agencies will bolt on their own requirements, and a fragmented "hydra of compliance" would be a worse outcome for providers than a clear baseline.
IAL3 Is an Insider-Threat Capability, Not a Checkbox
Whatever form Class D takes, the underlying security problem does not move: you cannot claim a hardened boundary while taking the identity of the people inside it on faith.
Under the final NIST SP 800-63A-4 (July 2025), IAL3 identity proofing "SHALL only be delivered as on-site attended" — a trained proofing agent participates in the session, either co-located with the applicant or attending remotely while the applicant uses a CSP-controlled kiosk or device. The CSP must collect and retain a biometric, validate evidence against authoritative sources, and staff the session with agents trained to spot manipulation, coercion, and social engineering. Knowledge-based verification is now banned outright for identity verification. An ordinary video call over an employee's own webcam does not qualify — which is precisely the point, because an ordinary video call is exactly what nation-state operators have learned to beat.
This is why we push back on treating IAL3 as a compliance checkbox to minimize. It is a critical, interwoven cybersecurity capability — the control that defends the hiring and enrollment pipeline the way phishing-resistant MFA defends the login. Our FedRAMP High Rev5 IAL3 requirements guide covers the current-state obligations, and our pre-hire identity proofing playbook covers the highest-leverage moment to apply them.
The Government Already Published the Threat
When the government publishes notices about a specific risk under active exploitation, a vendor should expect to have the control already in place before an assessor — or an incident — asks about it. On remote-workforce identity fraud, the notices are not subtle, and they have been accumulating for five years:
- May 2022: The FBI, State, and Treasury jointly warned that the DPRK "dispatches thousands of highly skilled IT workers around the world" to fund its weapons programs, and told employers to conduct video identity verification and use "fingerprint/biometric log-in to verify identity and claimed location."
- October 2023: Updated US–South Korea guidance recommended notarized proofs of identity, making interviewees physically hold their ID documents up to the camera, insider-threat monitoring, and geolocation of company laptops.
- January 2025: The FBI warned that DPRK IT workers had escalated to data extortion and told companies to "implement identity-verification processes during interviewing, onboarding, and throughout the employment of any remote worker" and to complete as much of hiring as possible in person — while flagging AI face-swapping in live video interviews.
- 2025–2026 enforcement: DOJ's coordinated nationwide action hit 29 laptop farms across 16 states. Christina Chapman was sentenced to 102 months for a scheme that used 68 stolen identities to place operatives at 309 U.S. businesses, including Fortune 500 companies, generating over $17 million. By May 2026, DOJ was announcing its seventh and eighth laptop-farmer sentences in five months. Treasury's March 2026 sanctions put DPRK IT-worker fraud revenue at nearly $800 million in 2024 alone.

Industry telemetry says the same thing. CrowdStrike responded to 304 incidents from the DPRK's "Famous Chollima" operation in 2024 — nearly 40% involving insider activity — and tracked 320+ infiltrated companies the following year. Mandiant's CTO has described hundreds of Fortune 500 organizations that unknowingly hired North Korean IT workers. Even security company KnowBe4 publicly documented hiring one: the operative passed four video interviews and a background check on a stolen identity, and was caught only when the company workstation started loading malware. The lesson is not that detection failed — theirs worked in minutes. It is that interviews and background checks alone are beatable at the hiring step, which is the step identity proofing exists to harden. U.S. Attorney Jeanine Pirro put the government's expectation plainly at the Chapman sentencing: "Corporations failing to verify virtual employees pose a security risk for all. You are the first line of defense against the North Korean threat."
To be clear about base rates: a true malicious insider is still a rare event at any single company, precisely because sophisticated actors work around weak identity and background checks quietly. But rare is not the same as ignorable — see our guide to detecting insider threats and fake IT workers for what the early signals look like. And a company that finds and manages the threat itself has a very different story to tell federal buyers than one that learned about its insider from an FBI notification.
Why "Legal Will Handle It" Is Not a Plan
None of this is meant as a scare tactic. It is meant as guidance about a specific, common planning error: assuming that if an insider incident happens, the legal system will make the company whole. The real-world track record says otherwise.
Insider and trade-secret litigation is slow, expensive, and unpredictable even when you win. Appian won a $2.036 billion verdict against Pegasystems in 2022 over a planted contractor "spy" — the largest in Virginia history. The award was reversed on appeal in 2024, and in January 2026 the Virginia Supreme Court confirmed the case must be retried. Six years after filing: zero dollars collected, damages to be proven again from scratch. Motorola Solutions won its trade-secret case against Hytera in 2020; nine years after filing, the award has been cut, appealed, and remanded, and courts were still finding Hytera in contempt in late 2025 over more than $70 million in unpaid royalties. Google's engineer-turned-defector Anthony Levandowski was criminally convicted — then pardoned, and the $179 million arbitration award against him landed on a bankrupt estate. Years of forensics, discovery, and fees are guaranteed; the verdict you hoped for is not.
And those are only the disputes you can read about. Most insider cases never reach a courtroom or a headline, because it is in nearly every organization's interest to keep them quiet: the standard playbook is a discreet termination, a confidential settlement or private arbitration, and an NDA, since publicizing an insider invites customer churn, contract scrutiny, and shareholder questions. Even the government's own releases keep victims anonymous — the 309 companies in the Chapman prosecution appear only as descriptions like "a top-five major television network" and "an aerospace manufacturer." And the government often has little incentive to expose an individual incident at all: prosecutors surface a few representative cases while others sit under seal inside broader investigations, and naming a victim company is rarely worth compromising a larger national-security matter. Calibrate accordingly — the public record is the visible tip, not the base rate, which means neither the precedents nor the deterrence you might infer from headlines are actually there.
Against nation-state IT workers, even that uncertain path mostly does not exist. The North Korean defendants in DOJ's indictments "remain at large"; their wages are appropriated by a sanctioned state; the State Department offers rewards of up to $5 million because arrests are not realistic. The Chapman forfeiture recovered roughly $285,000 against a $17 million scheme — the remediation costs stayed with the victim companies. The Ponemon Institute's 2025 insider-risk study puts the average annualized cost of insider risk at $17.4 million per organization, with malicious-insider incidents averaging over $715,000 each and 81 days to contain. The consequences for the attackers are low and the actors are far from the reach of U.S. courts. Prevention is not just cheaper than litigation — for this threat, it is effectively the only remedy that exists.
What to Do Between Now and the Pilot
Preparing for an unreleased standard sounds speculative. It is not, because everything below is already required, already published, or robust to any plausible version of Class D:
- Treat the Rev5 Class D (High) baseline as your floor. It is the only High that exists today, new Rev5 certifications end June 11, 2027, and every published signal says 20x will demand equivalent-or-better assurance, not less. Nothing you build against Rev5 High identity requirements is wasted.
- Start persistent KSI validation now. The published Class D certification rule requires 18 months of validation history for all KSIs. Work the math backward from your target certification date; for most High aspirants the window has already opened.
- Practice writing Security Decision Records. Map your current controls to the published KSIs and draft the "how we meet this" and "why we deviate, and the resulting customer risk" entries now. The teams that struggle under 20x will be the ones writing their first SDR during an assessment.
- Tier your workforce by risk and proof identities accordingly. Full IAL3 on-site attended proofing for privileged, production, and remote-access roles; documented, defensible scoping for everyone else. If Class D allows case-by-case scoping, you are ahead; if it requires the full population, you have the machinery running.
- Verify remote hires the way the FBI has told you to since 2022. Identity verification during interviewing, onboarding, and throughout employment — with in-person or CSP-controlled equivalent checks for sensitive roles, not an unmanaged webcam.
- Make your evidence machine-readable. The 20x model runs on automated validation and JSON artifacts, and 3PAOs already sample IAL3 records end to end. Identity evidence that exports as structured, tamper-evident records — see our approach to OSCAL and machine-readable FedRAMP evidence — slots into either track.
- Watch Phase 4 formally, not through rumor. Follow the FedRAMP 2026 timeline and the public roadmap; participate in comment periods. The predictions above are ours — the requirements will be FedRAMP's.
Frequently Asked Questions
When will FedRAMP 20x Class D (High) be released?
FedRAMP states that Class D certifications will be developed during 20x Phase 4, estimated for FY27 Q1–Q2 — October 1, 2026 through March 31, 2027 on the calendar (federal FY27 Q1 alone is October 1 – December 31, 2026). That is the development-and-pilot window, not a finished standard; dates are FedRAMP estimates and phases have slipped before.
Will 20x Class D require IAL3 identity proofing?
Unknown — Class D requirements are unpublished. What is factual today: FedRAMP's current Rev5 guidance associates Class D with NIST digital identity assurance level 3, the Rev5 High baseline includes in-person identity-evidence validation (IA-12(4)) and personnel screening (PS-3), and the current 20x KSI catalog contains no identity-proofing indicator at all. Our prediction is that Class D names identity and personnel assurance as a required outcome, potentially with risk-based scoping of who needs full IAL3.
Should we wait for 20x Class D or pursue Rev5 High now?
Do not wait. New Rev5 certifications end June 11, 2027, the 20x Class D rule already on the books demands 18 months of persistent validation history, and Rev5 High evidence — especially identity proofing, screening, and audit trails — carries forward into any plausible Class D. Waiting for the final text forfeits the one input you cannot recover: time.
What is a Security Decision Record?
FedRAMP's 2026 rules define it as "a persistently maintained, verified, and validated record of the security decisions made by a provider over the lifecycle of a cloud service offering." It replaces the control-implementation content of the SSP and SAR. For every applicable rule, the provider documents how it complies — or the reason and resulting customer risk for not complying, accepted by a senior official and subject to independent verification and validation.
Did FedRAMP delete controls like IA-12?
No. The 2026 reference site still publishes the full NIST SP 800-53 control catalog, including IA-12 and its enhancements, for Rev5-based certifications (Classes B, C, and D on the Rev5 track). What changed is that the 20x track does not assess control-by-control at all — it validates Key Security Indicators — and FedRAMP has removed most FedRAMP-specific parameters and control guidance in favor of provider-owned security decisions.
The Bottom Line
FedRAMP 20x is a genuine revamp, and we think its bet — engineering-led security over compliance theater — is the right one. But High assurance is where that bet gets stress-tested, because Class D has to satisfy the agencies and DoW components with the most to lose. Our prediction is a Class D that keeps 20x's flexibility and makes you sign for it: persistent validation, documented security decisions, and identity assurance for the humans inside the boundary. Every one of those is something you can start building today.
Preparing a FedRAMP High (Class D) identity program — or getting ahead of 20x? Talk with Trust Swiftly about IAL3 on-site attended proofing, audit-ready evidence, and workforce identity assurance built for teams pursuing FedRAMP.