Federal WiFi projects stall on compliance questions more than on technology. An RFI answer that says the wrong acronym, a vendor that promises the wrong certification, a prime that discovers a flow-down too late — each one costs a procurement cycle. And the rules changed materially in 2026, so much of what teams remember is now out of date.

Here is the current map: what FedRAMP looks like after the Consolidated Rules, where DFARS 7012 and CMMC actually sit, and what DoD impact levels mean for anyone buying or building WiFi authentication.

FedRAMP After the 2026 Consolidated Rules

FedRAMP retired the old Ready / In Process / Authorized ladder in July 2026. Cloud services now pursue progressive Certification Classes:

Class Replaces What it takes
Class A FedRAMP Ready Entry point; a current SOC 2 Type II can qualify a provider to submit (pipeline opened Aug 3, 2026)
Class B Low impact level Pipeline opened Aug 31, 2026
Class C Moderate impact level Where most civilian-agency SaaS purchases land; automated Key Security Indicator evidence required
Class D High-tier workloads Piloting late 2026

Two practical consequences

First, no agency sponsor is required to get certified and listed anymore, which removes the biggest historical bottleneck for smaller vendors. Second, the classes are progressive: a vendor can enter at Class A and is expected to move up within 12 months of landing a federal customer. The right question for a vendor is no longer "are you FedRAMP authorized" but "which Class, and what is your timeline to the Class my data requires."

DFARS 252.204-7012 and "FedRAMP Moderate Equivalency"

Defense contractors handling Controlled Unclassified Information flow DFARS 7012 down to their cloud vendors. The clause requires FedRAMP Moderate or equivalent, and equivalency is a distinct, documentation-heavy assessment — not the same thing as a 20x certification. If you are a contractor, ask your cloud vendor which path they are on before you promise your contracting officer anything.

The DoD's own memo accepts FedRAMP Moderate Authorized services in lieu of equivalency. How the new Class C maps to that language is still being clarified, so get it in writing for your specific contract.

CMMC Is About You, Not Your Cloud Vendor

The most common confusion in federal WiFi procurement

CMMC certifies the contractor's cybersecurity. FedRAMP certifies the cloud service. They are orthogonal and both can apply to the same contract. A SaaS vendor cannot lend you CMMC status, and your CMMC level does not accredit your cloud stack.

For WiFi projects on DoD installations — dorm and barracks internet, base guest networks — primes typically need CMMC flow-down from their subcontractors. A segregated commercial SaaS authentication layer keeps that flow-down clean.

DoD Impact Levels Are a Different Game

IL4 and IL5 authorization requires a DoD Provisional Authorization on top of a FedRAMP baseline, isolated infrastructure, and US-persons staffing. Very few SaaS vendors carry it directly. The realistic pattern for specialized software is deployment inside a prime's or OEM's authorization boundary, with documented inheritance assessed by their 3PAO. If a vendor tells you their commercial FedRAMP work covers IL4/IL5, be skeptical.

What This Means for WiFi Authentication Buyers

  1. Civilian agency, moderate-sensitivity data: look for FedRAMP Class C, or a credible path to it, on the vendor's part.
  2. Public-facing guest WiFi, dorm internet, low-sensitivity: Class A or B may genuinely be enough. Do not over-specify and pay Moderate prices for guest portal traffic.
  3. Defense contractor networks with CUI: DFARS 7012 equivalency or Moderate authorization for the cloud layer, CMMC for your own house.
  4. On-installation DoD networks: plan around a prime's authorization boundary, not a vendor's marketplace listing.

Where IronWiFi Fits

IronWiFi is a cloud RADIUS, 802.1X/EAP-TLS, captive portal, and WiFi identity threat detection SaaS. Today we hold a SOC 2 Type II report (unqualified opinion, May 2026), an active SAM.gov registration (UEI TB1XW4HNNUG9), and public listings on the AWS, Cisco, and Oracle marketplaces. We are pursuing FedRAMP 20x certification under the 2026 rules. We support Microsoft Entra ID including GCC High tenants, and we work under primes and ISPs on military housing WiFi bids as the authentication layer.

Scoping a federal WiFi requirement?

Email us your requirement, RFI, or sources-sought notice and we will tell you plainly whether we fit and which certification level your procurement actually needs.

Start Free Trial Government Solutions Have Questions?

Trusted by 1,000+ organizations in 108 countries

Conclusion

The 2026 rules lowered the drawbridge: no sponsor requirement, a SOC 2-based entry class, and a progressive path upward. That is good news for agencies that want modern SaaS and for the vendors building it. The remaining failure mode is vocabulary — buying Moderate when Class B would do, or assuming a marketplace listing covers a CUI flow-down. Match the certification to the data, put equivalency questions in writing, and the compliance conversation stops being the long pole in your WiFi project.

Daniel Konecny

Daniel Konecny

Blog Writer, IronWiFi

Daniel writes about enterprise WiFi authentication and identity security at IronWiFi. With deep expertise in RADIUS, 802.1X, and cloud infrastructure, he covers practical network security for IT teams managing thousands of devices.

About the author