cloud

FedRAMP 20x Reaches 538 Certified Cloud Services on a $10 Million Budget, While Europe Still Has No Common Cloud Certification

FedRAMP is the US government’s security approval for cloud services. If a federal agency wants to run its work on someone’s cloud, the service generally needs FedRAMP clearance first. In fiscal 2026, which ended on 30 September, the programme issued 92 new certifications, bringing the total to 538 cloud offerings. Agencies issued 760 new authorisations to use them.

It did that with 17 federal employees, 15 contractors and a budget of $10 million, of which it spent just under $9 million.

Those numbers come from FedRAMP’s own year-end review, published on 8 October. They describe a programme in the middle of a rebuild, and a contrast with Europe, which has spent six years failing to agree on a single cloud certification of its own.

What 20x changes

For most of its history FedRAMP was slow. Getting authorised could take a year or more of documentation and reviews. In March 2025 the programme launched FedRAMP 20x, a redesign meant to automate much of the work and accept machine-readable evidence instead of long written packages.

It’s been rolled out in phases. The first produced 12 low-risk pilot authorisations by September 2025. The second, from November 2025 to March 2026 and slowed by the shutdown, produced eight at the moderate level. The third began in April 2026.

New consolidated rules, known as CR26, could be adopted early from July 2026. They replace the old Low, Moderate and High levels with classes A to D and rename authorisation as certification. Class A is a new entry tier. The rules become mandatory for every provider on 1 January 2027. FedRAMP stops accepting new certifications under the old process in June 2027. Its plan for fiscal 2027 includes a high-security class D pilot and moving existing services, the big cloud providers included, onto 20x.

Europe’s patchwork

The EU has tried to build its own cloud certification, called EUCS, since 2020, when the EU cybersecurity agency ENISA published a first draft. It stalled over one question: should the highest level require providers to be headquartered in Europe and immune from foreign laws like the US CLOUD Act? A vote planned for April 2024 was postponed. The Commission proposed a revised Cybersecurity Act in January 2026 to speed up certification schemes. EUCS still has no final text.

So Europe’s big economies run their own systems. Germany’s C5, set by its federal cyber agency BSI, has required the more demanding Type 2 audit since July 2025 and is mandatory for cloud processing of health data. France’s SecNumCloud, run by ANSSI, is the strictest on sovereignty. It took the Thales-controlled S3NS, which runs Google technology, 17 months to qualify, by December 2025. Bleu, a joint venture of Capgemini and Orange running Microsoft technology, now aims for qualification by the end of 2026. Britain has no national certification; its cyber agency gives buyers a set of cloud security principles and leaves the judgement to them.

Two different problems

The comparison shows two separate questions often treated as one. FedRAMP answers whether a cloud service is secure enough. It doesn’t ask who owns the provider, since the providers are mostly American. Europe’s schemes try to answer both security and sovereignty, whether the provider can be forced to hand data to a foreign government.

Sovereignty is the hard part, and it’s why EUCS has stalled while C5 and SecNumCloud went ahead nationally. It ties straight into the fight over EU-US data transfers and the EU’s proposed Cloud and AI Development Act.

For providers, the result is a strange map. One certification covers the whole US federal market and is getting faster. Europe needs several, each slower, and the EU-wide one still doesn’t exist. FedRAMP’s small team and budget make a pointed comparison. Speed in certification has less to do with money than with agreeing what you’re certifying.