As a part of the recently announced FedRAMP 20x initiative, the FedRAMP Program Management Office (PMO), industry stakeholders, and agency experts are working to redesign the FedRAMP assessment process. According to the FedRAMP PMO, the goal of FedRAMP 20x is to streamline and enhance the compliance process by:
- Streamlining Continuous Monitoring: Revisiting the approach to continuous monitoring, emphasizing ongoing, automated assessments to ensure compliance is maintained effectively over time.
- Automating Assessments: Developing mechanisms to automate security requirement validations, reducing the time and resources required for manual reviews.
- Leveraging Existing Frameworks: Allowing CSPs to use existing commercial security frameworks, minimizing duplicative efforts and enhancing compatibility with federal requirements.
- Enabling Continuous Reporting: Enhancing communication between CSPs and federal agencies by providing real-time reporting and monitoring capabilities.
To facilitate these improvements, working groups have been established to discuss these topics and gather input from stakeholders. These groups will help shape the future of FedRAMP.
For more information about FedRAMP 20x, please visit the FedRAMP 20x and FedRAMP 20x Working Groups pages.