The FedRAMP 20x Phase 2 pilot closes March 31. The findings from that pilot — what KSI automation worked in practice, where gaps emerged, how agency validators adapted to evidence-based authorization — will shape Phase 3, which is expected to open continuous authorization to all Low and Moderate baseline cloud service providers in Q3-Q4 2026.
For every cloud provider that serves or wants to serve the federal market, and for every federal agency procurement team evaluating cloud options, the Phase 3 opening represents the most significant structural change to the FedRAMP process since the program launched in 2011.
Here’s what the practical implications look like for both sides of that equation.
What Phase 2 Was Testing
Phase 2 wasn’t just about demonstrating that KSIs could be automated — it was about validating the entire authorization workflow end-to-end under realistic conditions.
The pilot cohort included cloud service providers across different size tiers, different service categories (IaaS, PaaS, SaaS), and different existing authorization statuses (some already authorized, some pursuing initial authorization). Agency validators — staff from FedRAMP PMO, participating agency ISSOs, and in some cases 3PAOs in an evolved role — reviewed continuous evidence streams rather than static package documentation.
The specific questions Phase 2 was designed to answer:
- Can automated KSI evidence be reliably generated at the frequency and structure required for meaningful continuous authorization?
- Can agency validators make authorization decisions based on dynamic evidence without the documentation scaffolding they’ve historically relied on?
- Where do gaps in automated evidence create situations where documentation still adds value?
- What does the boundary between automated and human-verified evidence look like in practice?
The Phase 2 findings aren’t fully public yet, but the direction based on FedRAMP PMO communications suggests the core KSI automation concept is working, with refinements needed around evidence schema standardization and the process for handling KSI anomalies during authorization maintenance.
What Phase 3 Will Change for Cloud Providers
The shift from Phase 2 (pilot cohort) to Phase 3 (broad availability) has specific implications for CSPs at different stages:
For providers currently authorized under the existing process:
Your existing ATO doesn’t disappear. Phase 3 will include a transition pathway for currently authorized CSPs to migrate to continuous authorization. The likely structure is that providers who want to maintain their authorization under the new framework begin generating and submitting KSI evidence, while their existing ATO remains valid during a transition period.
This is important because the continuous authorization model requires investment. Building the automated evidence pipelines, configuring the reporting, and integrating with FedRAMP’s evidence intake systems is non-trivial engineering work. Providers that wait until Phase 3 launches to start that work will find themselves behind the timeline.
The recommendation for currently authorized providers: begin your KSI architecture work now, using the publicly available KSI schema from the Phase 2 pilot. You don’t have a compliance obligation yet, but you’ll have a better implementation when the obligation arrives.
For providers currently in the authorization process:
If you’re mid-way through a traditional authorization process, you have a decision to make. Depending on your timeline to ATO, you may be able to complete the existing process and then migrate. Or you may be in a position to engage FedRAMP PMO about whether a hybrid approach makes sense for your situation.
What you shouldn’t do is stop your current process on the assumption that Phase 3 will be faster and easier. Phase 3 opening is Q3-Q4 2026 at earliest. If your existing process can close before then, close it.
For providers pursuing initial authorization for the first time:
Phase 3’s broad availability changes the math for providers who have avoided FedRAMP authorization because of the cost and timeline. If continuous authorization through KSI evidence genuinely compresses the authorization timeline to weeks rather than months — the aspiration the FedRAMP PMO has articulated — then the cost-benefit analysis for initial authorization shifts significantly.
This is particularly relevant for mid-market SaaS providers that have federal government customers who have been using them without FedRAMP authorization, relying on agency-specific Authority to Operate (ATO) decisions. Phase 3 may make formal FedRAMP authorization achievable enough that it becomes the better path versus managing multiple agency-specific ATOs.
What Phase 3 Changes for Federal Agency Buyers
The continuous authorization model changes how federal cloud procurement should work.
Under the existing model, the question is: “Is this provider authorized?” The answer is binary. An agency reviews the existing ATO, the 3PAO assessment reports, and the CSP’s ConMon posture — all of which are point-in-time snapshots.
Under continuous authorization, the question becomes: “What is this provider’s current security posture?” The Marketplace will surface real-time KSI data for authorized providers. Agency procurement teams and AOs that know how to interpret that data will make better authorization decisions than those relying on document review.
This requires capability investment on the agency side. Federal AOs and ISSOs need to understand what KSIs mean, how to read an evidence dashboard, and how to evaluate KSI anomalies against acceptable risk thresholds. Agencies that are building that capability now — even before Phase 3 launches — will be better positioned to move quickly when continuous authorization becomes available.
It also changes the ongoing oversight responsibility. Under continuous authorization, the agency AO relationship with an authorized CSP becomes more like a monitoring relationship than a periodic review relationship. The tools and skills for that monitoring need to be in place.
The 3PAO Role Evolution
One of the unresolved questions heading into Phase 3 is what happens to the Third-Party Assessment Organization role in a continuous authorization world.
The existing model puts 3PAOs at the center of the initial authorization assessment and the annual assessment for maintained authorizations. If KSI automation handles the continuous verification function, the 3PAO’s periodic assessment role diminishes.
The likely evolution is toward 3PAOs providing validation and quality assurance for KSI architectures — verifying that a CSP’s automated evidence pipeline is actually measuring what it claims to measure — rather than performing the substantive security assessment themselves. Some 3PAOs are already positioning for this evolution. Others are betting that the existing assessment model persists longer than FedRAMP PMO’s timeline suggests.
For CSPs planning their 3PAO relationships, it’s worth understanding where your assessor stands on the evolution question. A 3PAO that helps you build a compliant KSI architecture is more valuable over a 5-year horizon than one that’s optimized for the existing assessment process.
March 31 closes Phase 2. Q3-Q4 opens Phase 3. The preparation window is now.