Federal Practice

FedRAMP

FedRAMP authorization for cloud service providers. 20x initiative, baselines, 3PAO assessment, and continuous monitoring.

All FISMA & NIST RMF FedRAMP CMMC Federal AI Governance GovCon Compliance Federal Cybersecurity Federal Zero Trust Federal GRC Engineering AI Governance GRC Engineering Cybersecurity Cloud Security HIPAA SOC 2
FedRAMP

FedRAMP Moderate vs High Cost: The 87-Control Delta and the Re-baseline Economics Most Vendors Miss

FedRAMP Moderate has 324 controls. FedRAMP High has 411. The delta is 87 controls and control enhancements spanning 15 of 20 control families. That number, 87, is the headline every comparison article cites. The number...

Read the Guide
FedRAMP

FedRAMP 20x First-Shell Submission Walkthrough: Eight Artifacts and Four Gating Questions

FedRAMP 20x Phase 2 concluded in late March 2026 after two pilot cohorts. The Program Management Office's review window ran through March 31. Phase 3, the wide-adoption phase that opens 20x to general submission, is...

Read the Guide
FedRAMP

DoD Impact Level 5: The 175-Control Delta from FedRAMP High and the Four Architecture Changes That Matter More

Department of Defense Impact Level 5 is FedRAMP High plus 170 to 175 additional controls, depending on how you count the Committee on National Security Systems Instruction 1253 National Security System overlays. The control count...

Read the Guide
FedRAMP

FedRAMP 3PAO Assessment: What to Expect and How to Prepare

The kickoff call goes well. The Third Party Assessment Organization (3PAO) sounds prepared. The Cloud Service Provider's compliance lead has run SOC 2 audits for years and treats this as a familiar exercise. Six months...

Read the Guide
FedRAMP

FedRAMP 20x: What Changes for Cloud Service Providers in 2026

FedRAMP has been running essentially the same authorization process for fifteen years. Cloud service providers submit narrative security packages, assessors review documentation, the Program Management Office (PMO) validates controls, and an agency issues an Authorization...

Read the Guide
FedRAMP

RFC-0024 Machine-Readable Compliance: FedRAMP’s Phased OSCAL Deadline Guide

In 2025, FedRAMP processed more than 100 Rev5 authorizations without a single Open Security Controls Assessment Language (OSCAL) submission, a figure RFC-0024 itself cites in its background section to justify the machine-readable mandate (FedRAMP RFC-0024,...

Read the Guide
The Authority Brief

One compliance analysis per week from Josef Kamara, CPA, CISSP, CISA. Federal and private compliance, written for practitioners.