3PAO · FedRAMP Recognized independent assessor
FedRAMP 3PAO Assessments: Rev5 and 20x
Independent FedRAMP assessments from an ISO/IEC 17020 accredited assessor.
Anthony Timbers LLC is a FedRAMP 3PAO listed on the FedRAMP Marketplace, with FedRAMP in our ISO/IEC 17020 accreditation scope through A2LA. Under FedRAMP’s Consolidated Rules for 2026, 3PAOs are now called independent assessors. We perform both FedRAMP Rev5 assessments and FedRAMP 20x assessments for cloud service providers.
Rev5
NIST SP 800-53 Rev 5 assessments
20x
Key Security Indicator assessments
17020
ISO/IEC 17020 accredited inspection body
A2LA
Accreditation body
Two paths
Two paths to FedRAMP Certification
FedRAMP now offers two ways for a cloud service offering to earn FedRAMP Certification. Rev5 is the established, control-by-control path built on NIST SP 800-53 Rev 5. FedRAMP 20x is the newer, outcome-based path built on Key Security Indicators and automated, machine-readable validation. We assess both, and we’ll tell you plainly which one fits your system.
What we assess
FedRAMP assessment services
FedRAMP 20x Assessments
We verify that your Key Security Indicators are described honestly, implemented as described and proven to work. That means testing the security capability and the automation that reports on it: data sources and scope, collection and transformation, queries and thresholds, failure handling, and whether validation runs at the stated cadence across the full scope. We favor live demonstrations, direct queries and machine-readable results over static documents.
FedRAMP Rev5 Assessments
A control-by-control assessment of your system against its NIST SP 800-53 Rev 5 baseline, with testing, interviews, evidence review and penetration testing. For agency-sponsored assessments we deliver the Security Assessment Plan and Security Assessment Report. For Rev5 program certification we follow FedRAMP’s independent verification and validation rules.
Annual and Significant Change Assessments
Ongoing assessment work for systems already certified under Rev5, including annual assessments and significant change reviews, so your certification stays current while you plan your path forward.
Compare
Rev5 vs. 20x at a glance
| FedRAMP Rev5 | FedRAMP 20x | |
|---|---|---|
| Built on | NIST SP 800-53 Rev 5 control baselines | Key Security Indicators (KSIs): outcome-based security claims |
| Evidence | Documentation, interviews, configuration review and testing for each control | Living evidence: live demonstrations, direct queries and machine-readable results |
| What we validate | That each control is implemented as documented and operating as intended | That each KSI claim is accurate, and that the automated validation behind it runs on schedule, across the full scope, and gives consistent results |
| Deliverables | Security Assessment Plan and Security Assessment Report for agency-sponsored assessments; FedRAMP independent verification and validation for program certification | A clear record of what was tested, how it was tested, what the evidence showed, and where risk remains |
| Certification classes | Existing Low, Moderate and High authorizations map to Classes B, C and D | Class A pipeline opened August 3, 2026; Classes B and C opened August 31, 2026 |
| Timeline | New Rev5 certifications end June 11, 2027 | The path FedRAMP is moving the program toward |
| Often a good fit for | Systems with an agency sponsor or a Rev5 package already underway | Cloud-native systems with strong automation and infrastructure as code |
Based on FedRAMP’s Consolidated Rules for 2026 as of September 2026. FedRAMP updates these rules, so check fedramp.gov for the latest dates.
Independence
We assess. We don’t build what we assess.
FedRAMP’s rules say an assessor should not design a provider’s solution and then certify their own work. We keep our assessment work independent, so our results carry weight with FedRAMP and with your agency customers.
FAQ
FedRAMP assessment FAQ
Is a 3PAO the same as an independent assessor?
Yes. FedRAMP’s Consolidated Rules for 2026 use the term independent assessor for what used to be called a Third Party Assessment Organization (3PAO). FedRAMP only accepts assessments performed by FedRAMP Recognized independent assessment services, which are listed in the FedRAMP Marketplace.
Should we pursue FedRAMP 20x or Rev5?
If your system is cloud-native and you can produce security evidence automatically, 20x can be faster and is where FedRAMP is heading. Rev5 still makes sense if you already have an agency sponsor or a Rev5 package underway. New Rev5 certifications end on June 11, 2027, so plan any new Rev5 effort around that date. We’re glad to talk it through before you commit.
What are Key Security Indicators (KSIs)?
KSIs are the security outcomes a cloud service provider claims and measures under FedRAMP 20x. Instead of documenting every control, you show with automated, machine-readable evidence that each outcome is met and keeps being met. Our job is to confirm those claims are true and that the automation behind them works.
What happens to our existing Rev5 authorization?
FedRAMP has said existing Rev5 authorizations carry forward as FedRAMP Certifications under the new class system, and that Rev5 providers should plan a move to 20x over time. We can keep assessing your Rev5 system while you plan that transition.
Is FedRAMP Certification the same as an agency ATO?
Not exactly. FedRAMP Certification shows that a cloud service meets FedRAMP’s requirements. Each agency still decides whether the service’s risk fits its own use before it authorizes it.
Can you also help us prepare for the assessment?
Not for a system we will assess. To stay independent, we don’t design or build the security program we certify. We can explain FedRAMP’s requirements and how our assessment works, so there are no surprises.
News
Our FedRAMP milestones
Ready to plan your FedRAMP assessment?
Call us at +1 804-596-0596 or fill out the form. We’ll set up an introductory call about your system, your target class and your timeline.
How can we help?
Whether you need immediate help with an IT issue or want to discuss your long-term IT strategy, our team is here to help.
Call us at +1 804-596-0596 or complete the form below and we'll help in any way we can.
One firm. Four authorizations.
MSSP
CMMC Level 2 Certified MSSP
24/7 security monitoring and incident response for small to mid-sized businesses and DoD contractors.
C3PAO
Authorized CMMC C3PAO
Official CMMC Level 2 certification assessments, authorized by the Cyber AB.
3PAO
FedRAMP 3PAO
FedRAMP Rev5 and 20x assessments as a FedRAMP Recognized independent assessor, accredited to ISO/IEC 17020.
QSA
PCI Qualified Security Assessors
PCI DSS assessments and consulting, listed as QSAs on the PCI SSC website.
Team credentials




ISO/IEC 17020 accredited
