FedRAMP, done in the open.
FedM8 is not FedRAMP authorized today, and nothing on this page says otherwise. This is the public roadmap: the certification we are aiming for, every item on the checklist, and exactly where we stand. It updates as work lands.
Which certification, and why
FedRAMP is the single security certification a cloud product needs before federal agencies can use it with government data. In 2026 FedRAMP consolidated everything into new rules ("CR26") with four classes. FedM8 handles publicly released contract data and account information — a limited-harm profile that maps to Class B, the class that replaced the old Low and LI-SaaS baselines.
Two things make this the right moment to plan. First, the old requirement to find a federal agency sponsor is gone — the Program Certification path lets FedRAMP itself review and certify Class B services. Second, the Class B submission pipeline opened on August 31, 2026. The path is open; the work is real.
| Certification target | FedRAMP 20x Certification, Class B (formerly "Low" / "LI-SaaS") |
|---|---|
| Route | Program Certification (sponsor-free) under the FedRAMP Consolidated Rules for 2026 (CR26, finalized June 25, 2026) |
| What it requires | ~56 Key Security Indicators (KSIs) implemented and validated, with at least 70% validated by automated checks; evidence in both human-readable and machine-readable form |
| Independent assessment | A FedRAMP-recognized independent assessor must complete a fresh assessment within 3 months before submission |
| After certification | Continuous reporting: persistent automated validation, quarterly reviews, annual reassessment, and federal incident reporting |
| Who needs it | Only required when federal agencies use FedM8 with government data. Veteran and small-business users never need us to have it — for them it is simply proof we hold ourselves to the government's own bar. |
The checklist
Seven phases, from decision to continuous reporting. Click a phase to expand it.
What this costs
Published 2026 market ranges for a small SaaS at Class B / Low. We show them so nobody mistakes this roadmap for a press release.
Independent assessment
Roughly $50K–$150K for a Low/Class B boundary, depending on scope and readiness. The single largest required outside spend.
Engineering & hosting
Migration to FedRAMP-authorized infrastructure, FIPS-validated encryption, logging, and evidence automation. Months of engineering; hosting costs rise meaningfully.
Advisory (optional)
Readiness consultants typically $25K–$100K. Optional — the 20x rules are public and machine-readable, and we build our own tooling.
Keeping it
Continuous monitoring, quarterly reviews, and annual reassessment: plan on a recurring five-figure annual cost after certification.
Questions a contracting officer would ask
| Are you FedRAMP authorized? | No. Planning phase. This page is the honest state of the effort. |
|---|---|
| Do you handle government data? | FedM8 works from publicly released federal contracting data (SAM.gov and related public sources) plus our users' own account data. No agency data lives in FedM8 today. |
| Why pursue it at all? | Agencies, PTACs/APEX Accelerators, and veteran-service organizations are natural future users of FedM8. Certification is the door to those customers — and the discipline improves security for every user now. |
| What security work exists today? | See our SOC 2 practice board — the same do-it-in-the-open approach: real controls, drills, and evidence habits, no purchased badge. |