Skip to main content

FedRAMP's Consolidated Rules for 2026: What Box Customers Need to Know

  • August 24, 2026
  • 0 replies
  • 13 views

As part of our ongoing commitment to transparency and security, Box is helping our customers navigate the recent updates introduced by the Federal Risk and Authorization Management Program (FedRAMP).

 

As part of the FedRAMP 2026 Consolidated Rules, FedRAMP has introduced significant updates, including new terminology, that affect how federal agencies and cloud providers describe and pursue FedRAMP status.

 

If you use Box to secure and manage your regulated content, this article explains what is changing, why these updates are being made, and what they mean for your organization.

Why is the Terminology Changing?

The FedRAMP Program Management Office (PMO) updated its language to clarify the distinct roles of Cloud Service Providers (CSPs) and federal agencies under federal security guidelines:

  1. Avoiding Confusion with Agency ATOs: The law defines a FedRAMP authorization as "a certification that a cloud computing product or service has completed a FedRAMP authorization process." Transitioning to "FedRAMP Certification" avoids conflating a provider's program-level status with an individual federal agency's "Authorization to Operate" (ATO).

  2. Clarifying System Impact Levels: Federal agencies use cloud services as third-party resources within their broader federal information systems. Under FIPS-199 and FIPS-200, agencies are separately required to uniquely identify the target Impact Level and control baselines for each of their own federal information systems. Switching to "Certification Classes" ensures both providers and agencies understand how agencies must implement OMB Circular A-130 requirements in their use of cloud services the agency doesn't itself operate.

Key Terminology Mapping

To help you transition your documentation and discussions, here is a direct mapping of a few legacy terms to the new FedRAMP consolidated rules for 2026 terminology:

Previous/Legacy Term

New FedRAMP Term

Description / Context

FedRAMP Authorized

FedRAMP Certified

The status of a specific cloud service offering that has completed FedRAMP's assessment process and meets the requirement to be "FedRAMP Certified."

Authorization

Certification

The process by which a cloud service offering completes FedRAMP's assessment requirements and obtains (or maintains) its certified status.

Authorization Package

Certification Package

The collection of security and compliance information a provider supplies to FedRAMP and agencies that agencies use to decide whether to authorize use of the cloud service.

Low, Moderate, High (Impact Level)

Class A, B, C, D (Certification Class)

This is not a direct renaming. Certification Classes describe assurance level, not risk impact.

System Security Plan (SSP)

Security Decision Record (SDR)

A continuously maintained record of the actual security decisions a provider has made for its cloud service rather than a forward-looking plan of intended controls. FedRAMP shifted to this because certification is meant to reflect real outcomes, not documented intentions.

Third Party Assessor (3PAO)

Independent Assessor

The independent organization that performs assessment, verification, or validation activities for a cloud service seeking to obtain or maintain FedRAMP Certification.

 

Understanding Certification Classes vs. Impact Levels

If your agency is evaluating Box's FedRAMP status for use within your own environment, it's important to understand that Certification Classes and Impact Levels are two separate concepts under the 2026 Consolidated Rules. Neither is a substitute for the other.

 

What a Certification Class tells you

A Certification Class describes the level of assurance information a cloud service provider (Box) supplies through FedRAMP for a cloud service offering. Certification Classes are about the depth, frequency, and quality of FedRAMP Certification Data available to agencies. They are not a direct label for how sensitive an agency system is. In short: it reflects how much assurance information Box has committed to providing, not a rating of how secure Box's service is.

 

What an Impact Level tells you

Agencies are required by FIPS-199 and FIPS-200 to categorize their information systems based on the risk of a potential adverse impact to the confidentiality, integrity, or availability of the information they will put into that system. Then agencies must categorize the information system itself with an overall impact level of low, moderate, or high. This categorization is your agency's own responsibility and is entirely independent of Box's Certification Class.

 

Certification Classes are not a one-for-one replacement for Impact Levels

FedRAMP guidance is direct on this point: Agencies should not treat Certification Classes as one-for-one replacements for Low, Moderate, or High impact levels. Your agency should categorize your own system first, then review Box's FedRAMP Certification Package to determine whether it provides sufficient protections for your specific use case, configuration, and data.

 

General guidance by class

FedRAMP provides broad guidance to help agencies gauge the presumption of adequacy for each Certification Class:

  • Class A — adequate for pilots, configuration/testing, or negligible-risk use cases such as public information.

  • Class B — adequate for most Low-impact systems, and some Moderate or High-impact systems with appropriate compensating controls.

  • Class C — adequate for most Low or Moderate-impact systems, and some High-impact systems with appropriate compensating controls.

  • Class D — adequate for most agency information systems regardless of impact level, particularly with appropriate compensating controls.

 

Box's FedRAMP Marketplace listing currently shows Box as FedRAMP Certified, Class D (High). This designation reflects the terminology update under CR26. Box, like other FedRAMP Rev5 certified providers, is still working to adopt the full set of substantive Consolidated Rules for 2026 requirements ahead of the mandatory adoption deadlines. Even so, your agency must independently categorize its own system's impact level under FIPS-199/FIPS-200, then determine whether this certification adequately supports your specific use case.

 

More details about FedRAMP Certification Classes for agencies can be found at: https://www.fedramp.gov/2026/agencies/use/classes/#fedramp-certification-classes

 

What This Means for Box's Certification Status

It is important to note that the naming of Box's certification has changed, not the boundary of what has been assessed. Box's certified system boundary and its FedRAMP-certified status are unaffected by this rename. Separately and independent of the terminology update, FedRAMP's 2026 rules introduce new program-wide requirements, including updates to certification packaging, vulnerability detection and response, and ongoing certification reporting. Box is adopting these changes on FedRAMP's published timeline, consistent with every other FedRAMP Rev5 certified provider.

 

The following aspects of Box's FedRAMP offering remain completely unchanged:

  • Our Certification Status: Box continues to meet the highest standards for securing federal workloads. Under the consolidated rules for 2026, Box is officially designated as FedRAMP Certified, Class D (High) which was formerly referred to as FedRAMP High Authorized.

  • Marketplace Listing & Package ID: Our listing on the FedRAMP Marketplace remains active and valid.

  • Existing Customer Deployments: There is no impact on your current Box environments or configurations.

  • Sponsoring Agency & Annual Assessment: Box continues its annual assessment cadence with its sponsoring agency, while adopting FedRAMP's updated ongoing certification methodology on FedRAMP's published timeline. Our annual audit is currently underway, with our Security Assessment Report (SAR) on track for delivery in September 2026.

Frequently Asked Questions (FAQs)

Q: Is Box still "FedRAMP High"?
A: Yes. Box's existing High-baseline authorization carries forward as a FedRAMP Certification at Class D (High), with no gap in status. Separately, FedRAMP's 2026 rules introduce new ongoing assurance requirements that all certified providers, including Box, are adopting on FedRAMP's published timeline, independent of this terminology change.

 

Q: Is Box transitioning to FedRAMP 20x?
A: No, not immediately. Because Box already holds an authorization with an agency sponsor, we are continuing on our agency-sponsored (Revision 5) certification path under the legacy process governed by the 2026 Consolidated Rules. We will monitor the transition timelines closely as existing Rev 5 certifications are expected to migrate to 20x after 2028.

 

Q: Are GovRAMP (formerly StateRAMP) terms changing as well?
A: No. GovRAMP is a separate program and is not adopting these changes. GovRAMP will continue to use the "Low, Medium, High" impact levels and the "Authorization" terminology.

 

Q: Where can I find more information?
A: For a deeper dive into these framework updates, you can review the official guidance published by the FedRAMP PMO at fedramp.gov/2026 (https://www.fedramp.gov/2026). You may also review the Box FedRAMP website at www.box.com/fedramp.