From SOC 2 to FedRAMP: The Class A Sponsorless Path Is Open
By Kenio Shirley · · 8 min read
FedRAMP Class A is the first genuinely sponsorless route into the federal market. If you have a mature SOC 2 program, you are closer than you think — and further than the marketing suggests.
On August 3, 2026, FedRAMP opened applications for Class A Certification — a path into the FedRAMP Marketplace that does not require an agency sponsor. The qualifying signal, for many applicants, is a current SOC 2 Type II report. The first certifications landed within weeks: Files.com listed on August 27 as one of the first two cloud services through the Class A path. Coalfire, Have SOC 2? FedRAMP Class A Just Opened the Federal Door Files.com, Files.com Is Now FedRAMP Certified
If you run a commercial SaaS platform and federal customers have ever asked “are you FedRAMP authorized?” in a procurement questionnaire, this is the first time the honest answer can be “we can be, on our own timeline.” But the bridge from SOC 2 to Class A is shorter than the bridge from SOC 2 to Moderate — and it is not zero. Here is how I would think about it.
What the sponsor requirement actually cost
The sponsor model never appeared on a budget line, but it priced most commercial providers out of the market. Finding an agency willing to shepherd your authorization meant eighteen months of relationship building before the security work even started, and the sponsor’s priorities — not yours — set the schedule. I led a FedRAMP Moderate authorization through an Agency ATO on Azure Government, and the sponsor dynamic shaped everything: which controls got attention, when evidence was due, what the system was allowed to become while the package was in review.
Class A removes that dependency for a defined tier of low-risk SaaS. The program office has been candid about the intent: the marketplace has 534 certified services and agencies still can’t find authorized options for routine commercial software. The bottleneck was never assessor capacity. It was sponsorship scarcity. FedRAMP Marketplace
What your SOC 2 program actually buys you
A current SOC 2 Type II is the entry ticket, but the useful inheritance is more specific than the report itself. Three things carry over directly:
- An operating control environment with history. Class A assessors are looking for the same thing SOC 2 auditors learned to look for: evidence generated by systems over an observation window, not artifacts assembled for the assessment. If your change management, access review, and incident response controls produce machine-generated records across a full year, that population is your foundation.
- A discipline of scoped systems. If you have maintained a real SOC 2 system description — one where the scope statement matches the architecture — you have already done the hardest conceptual work in any federal authorization: deciding what is inside the boundary and defending that decision. I have written about this separately; the boundary is an architecture decision, and it is the same decision in every framework.
- An organization that has survived an audit. This sounds soft. It isn’t. Teams that have been through two or three Type II cycles know how to answer an assessor, how to remediate an exception without panic, and how to keep evidence flowing while shipping product. That muscle is the difference between a certification that takes four months and one that stalls.
SOC 2 proves your controls operated. Class A asks whether they operate at a federal bar — and whether your evidence is structured well enough for the government to check continuously, not once a year.
What it doesn’t buy you
The gaps are predictable, and they are the same gaps I see when SOC 2 shops walk into any federal framework:
- FIPS-validated cryptography. SOC 2 says “encrypt it.” Federal says “encrypt it with validated modules, and show me the certificate numbers.” Cloud provider managed services usually get you there; anything you built yourself with a general-purpose TLS library needs a module review. This is the single most common technical surprise.
- Structured, machine-readable evidence. Class A sits inside the FedRAMP 20x model, which means authorization data is submitted in structured formats, not as a binder of PDFs. If your GRC tooling produces polished PDF exports and nothing else, budget time for the translation layer.
- Vulnerability management at federal tempo. The remediation clocks are stricter than anything a SOC 2 auditor enforces, and your scanner output flows through to the government with less editorial intervention than you are used to. Raw scan data is the report.
- Continuous monitoring as an obligation, not a posture. A Type II report is an annual snapshot of a year-long window. Class A expects the window to stay open — monthly cadence on the things that matter. Teams that treat the audit as a season will feel this as a culture change.
The gap assessment to run before you apply
Before paying an assessor, spend two weeks answering five questions with evidence, not opinions:
- Is every cryptographic module in the data path FIPS-validated, with certificate numbers on file?
- Can you produce a machine-readable control implementation statement for your top thirty controls, generated from your GRC platform rather than written in a document?
- What is your real — not policy — remediation time for high vulnerabilities, measured from the last four quarters of scanner data?
- Does every production change trace to a record in your change system, including the emergency path? Run the population reconciliation, don’t guess.
- Who owns continuous monitoring when the certification is done? If the answer is “the consultant,” you don’t have a program yet.
Most mature SOC 2 shops I would expect to pass three of the five on the first pass. The two they fail tell them exactly where the certification budget goes.
Who should move, and who should wait
Class A is scoped to low-impact SaaS — the program is explicit that it is not a stepping stone that converts automatically into Moderate. If your federal prospects handle CUI or anything above low baseline, the Class A listing will not satisfy them, and the effort is better aimed at a sponsored or agency path at the right impact level. But if your pipeline is full of agencies and primes asking for some federal signal — the collaboration tools, the workflow software, the research platforms like NORC’s enclave that certified on September 9 — the sponsorless path is the first time the math works for a mid-size SaaS company. NORC, Data Enclave Gov Earns FedRAMP Certification
The pattern I would not repeat from the Rev 5 era: treating certification as a document project. The providers moving fastest through Class A are the ones whose SOC 2 programs were already evidence pipelines. The certification is just the first external consumer of a stream they already produce.