# FedRAMP Modernization: Transitioning from Rev5 to 20x & CR26 (Self-Paced) (Coming Soon)

Canonical URL: <https://www.graduateschool.edu/courses/fedramp-modernization-rev5-to-20x-and-cr26-self-paced>

## Overview

FedRAMP is undergoing its most significant change since inception. The Consolidated Rules for 2026 take mandatory effect on January 1, 2027, retiring familiar artifacts, changing core terminology, and moving the program toward the automated, data-driven FedRAMP 20x model, with Rev5 sunsetting by the end of 2028. This intermediate course explains what is changing and when, contrasts Rev5 authorization with 20x certification, and walks the modernized package approach built on Security Decision Records, structured data, and Key Security Indicators. 

Learners finish by building a practical Rev5-to-20x transition roadmap. Because the program is unusually relevant to industry, this course serves both agency staff and the cloud service providers and contractors who must meet the new requirements.

## What you'll learn

- Explain CR26 and the FedRAMP modernization timeline through 2028
- Contrast Rev5 authorization with 20x certification
- Describe the new certification classes and boundary changes
- Modernize packages using Security Decision Records and structured data
- Apply Key Security Indicators and automated validation
- Build a Rev5-to-20x transition roadmap

## Curriculum

#### Module 1: CR26 Foundations and the FedRAMP Transition Timeline

- Examine the changes introduced by CR26 and the key milestones and dates in the FedRAMP transition timeline.

#### Module 2: From Rev5 Authorization to 20x Certification

- Explore how FedRAMP 20x shifts the program from the Rev5 authorization model toward a certification-based approach.

#### Module 3: Certification Classes, Scope, and Boundary Changes

- Review the new certification classes and evaluate how changes to system scope and authorization boundaries affect certification.

#### Module 4: Modernizing Packages with Security Decision Records and Structured Data

- Use Security Decision Records and structured data to replace or modernize traditional authorization package artifacts.

#### Module 5: Key Security Indicators and Automated Validation

- Examine Key Security Indicators and the role of continuous automated validation in demonstrating security performance.

#### Module 6: Ongoing Certification, Reporting, and Agency Collaboration

- Maintain certification through continuous reporting, evidence updates, and collaboration with participating agencies.

#### Module 7: Building a Rev5-to-20x Transition Roadmap

- Develop a practical roadmap for migrating systems, documentation, processes, and stakeholders from Rev5 to FedRAMP 20x.

#### Module 8: Developing a CR26 Transition Strategy Capstone

- Produce a comprehensive CR26 transition strategy that addresses certification scope, documentation, automation, reporting, and implementation priorities.

## Instructors

### Wes Bryan — Instructor

Wes Bryan resides in Gainesville, Florida, and has built his career around technology, education, and helping others understand complex subjects. He values continuous learning, clear communication, and practical problem-solving. Outside of work, Wesley enjoys running, hiking, fishing, and spending time outdoors. He also has a strong interest in music and literature, enjoys reading both fiction and nonfiction, as well as playing guitar.

## Pricing

**Tuition:** $1049
