SAM.gov: Active SBA: SDVOSB UEI: SVPSJ52ZGAY9
Veteran-led · Arlington, VA · [email protected]
Roadmap · Not FedRAMP authorized

FedRAMP, done in the open.

FedM8 is not FedRAMP authorized today, and nothing on this page says otherwise. This is the public roadmap: the certification we are aiming for, every item on the checklist, and exactly where we stand. It updates as work lands.

TargetFedRAMP 20x · Class B (Low)
PathProgram Certification — no agency sponsor
Current phase
Items complete
0%Certification
Straight talk: this is a planning-stage roadmap. Progress shown here reflects real, verifiable work — nothing is checked off to look good. FedRAMP® is a registered mark of the U.S. Government; FedM8 claims no authorization until it appears on the official FedRAMP Marketplace.

Which certification, and why

FedRAMP is the single security certification a cloud product needs before federal agencies can use it with government data. In 2026 FedRAMP consolidated everything into new rules ("CR26") with four classes. FedM8 handles publicly released contract data and account information — a limited-harm profile that maps to Class B, the class that replaced the old Low and LI-SaaS baselines.

Two things make this the right moment to plan. First, the old requirement to find a federal agency sponsor is gone — the Program Certification path lets FedRAMP itself review and certify Class B services. Second, the Class B submission pipeline opened on August 31, 2026. The path is open; the work is real.

Certification targetFedRAMP 20x Certification, Class B (formerly "Low" / "LI-SaaS")
RouteProgram Certification (sponsor-free) under the FedRAMP Consolidated Rules for 2026 (CR26, finalized June 25, 2026)
What it requires~56 Key Security Indicators (KSIs) implemented and validated, with at least 70% validated by automated checks; evidence in both human-readable and machine-readable form
Independent assessmentA FedRAMP-recognized independent assessor must complete a fresh assessment within 3 months before submission
After certificationContinuous reporting: persistent automated validation, quarterly reviews, annual reassessment, and federal incident reporting
Who needs itOnly required when federal agencies use FedM8 with government data. Veteran and small-business users never need us to have it — for them it is simply proof we hold ourselves to the government's own bar.

The checklist

Seven phases, from decision to continuous reporting. Click a phase to expand it.

What this costs

Published 2026 market ranges for a small SaaS at Class B / Low. We show them so nobody mistakes this roadmap for a press release.

Independent assessment

Roughly $50K–$150K for a Low/Class B boundary, depending on scope and readiness. The single largest required outside spend.

Engineering & hosting

Migration to FedRAMP-authorized infrastructure, FIPS-validated encryption, logging, and evidence automation. Months of engineering; hosting costs rise meaningfully.

Advisory (optional)

Readiness consultants typically $25K–$100K. Optional — the 20x rules are public and machine-readable, and we build our own tooling.

Keeping it

Continuous monitoring, quarterly reviews, and annual reassessment: plan on a recurring five-figure annual cost after certification.

Questions a contracting officer would ask

Are you FedRAMP authorized?No. Planning phase. This page is the honest state of the effort.
Do you handle government data?FedM8 works from publicly released federal contracting data (SAM.gov and related public sources) plus our users' own account data. No agency data lives in FedM8 today.
Why pursue it at all?Agencies, PTACs/APEX Accelerators, and veteran-service organizations are natural future users of FedM8. Certification is the door to those customers — and the discipline improves security for every user now.
What security work exists today?See our SOC 2 practice board — the same do-it-in-the-open approach: real controls, drills, and evidence habits, no purchased badge.