Part 2: The Hard Part May Be What Comes Next
The CSP side of FedRAMP 20x is moving quickly. What I heard at FedRAMP Day reinforces that the next challenge may be on the agency side.
Continuous, machine-readable evidence sounds great. But agencies have to be able to accept it, consume it and use it to make risk decisions.
That starts with policy. If an agency wants to use a 20x package as part of its authorization process, its internal policies need to allow for it. That matters when the OIG is evaluating whether the agency followed its own policies. Agencies may need to formally update what they recognize as acceptable assessment evidence rather than trying to fit 20x into an existing Rev. 5 process.
Then there is the practical side.
One agency representative pointed out that their GRC can’t currently consume the new machine-readable information and that replacing it could be several budget cycles away.
That’s a real problem.
We don’t want to create continuous security evidence and then flatten it back into spreadsheets and traditional authorization packages because that’s what the existing process can handle.
The promise of 20x isn’t just a smaller SSP. It’s giving agencies better, more current information about the security of the services they’re actually using.
CSPs, 3PAOs and FedRAMP can change how we produce and validate that information relatively quickly.
Now agencies need the policy, processes and tools to use it.
That’s where I think the next phase of 20x gets really interesting.

