FedRAMP 20x Automation: Lazarus Alliance Cybersecurity Audits

FedRAMP 20x Automation: Lazarus Alliance Cybersecurity Audits

FedRAMP 20x Automation, Evidence and Independent Assessments

FedRAMP 20x changes how cloud service providers document, measure, and demonstrate security. Its emphasis is on measurable outcomes, current evidence, persistent verification and validation, and machine-readable certification information.

Automation can make evidence more timely and repeatable, but it does not replace governance, risk decisions, human oversight, or independent assessment. Providers remain responsible for explaining their security measures and demonstrating that those measures work as intended.

Key Security Indicators

FedRAMP 20x uses Key Security Indicators, or KSIs, to describe the security capabilities applicable to a cloud service offering.

For each applicable KSI, a provider should identify:

  • The security objective.
  • The measures used to demonstrate the capability.
  • The systems and resources covered by those measures.
  • The frequency at which persistent measures operate.
  • The evidence produced by the measures.
  • How the measures and evidence are verified.
  • How their effectiveness is validated.
  • Any exceptions, limitations, or residual risks.

KSIs are associated with relevant NIST SP 800-53 controls, but FedRAMP 20x evaluates the provider’s security capabilities and outcomes rather than requiring only a control-by-control narrative.

The Security Decision Record

For applicable certification classes, the Security Decision Record replaces a traditional narrative-heavy system security plan with a record that is maintained throughout the cloud service offering’s lifecycle.

FedRAMP requires the Security Decision Record in human-readable and JSON formats. When a rule identifies a FedRAMP JSON schema, the machine-readable information must validate against that schema unless the rule provides an exception.

The record should remain synchronized with the provider’s actual architecture, security measures, dependencies, and assessment results.

Machine-Readable Does Not Always Mean OSCAL

OSCAL is a NIST-developed standard for expressing security controls and assessment information in machine-readable formats. It can be useful for exchanging structured security data.

However, FedRAMP 20x does not universally require every provider to deliver an OSCAL catalog, component definition, assessment plan, or assessment-results file. The Consolidated Rules for 2026 establish specific FedRAMP JSON schemas for required 20x information.

Providers may use OSCAL or other structured formats where supported and appropriate, but the controlling requirement is compliance with the current FedRAMP rule and associated schema. OSCAL should therefore be described as a potentially useful implementation standard, not as the sole required format for FedRAMP 20x.

Class-Specific Automation

Automation expectations differ by certification class:

  • Class A: Providers may use automated methods to verify and validate KSIs.
  • Class B: Providers should implement automated verification and validation where applicable, including at least one automated method for each KSI under the current certification rules.
  • Class C: Providers must implement at least two automated methods for each KSI and supply the required historical metrics from persistent validation.

Class C applicants must provide at least six months of historical KSI metrics, subject to the qualifications in the current FedRAMP rules for services that have not operated long enough to possess the complete history.

Providers should verify current effective dates, transition provisions, and class-specific requirements before designing their automation program.

Building Reliable Evidence Pipelines

An effective evidence pipeline should produce accurate, attributable, and reproducible information. Depending on the service architecture, this can include:

  • Asset and service inventories.
  • Identity and access-management events.
  • Configuration and change-management records.
  • Software build and deployment evidence.
  • Vulnerability and exposure information.
  • Logging and monitoring results.
  • Incident-response evidence.
  • Backup and recovery testing results.
  • Third-party service and dependency information.

Automation should not merely collect large volumes of data. Each artifact should be connected to a defined security measure, applicable KSI, assessment scope, and responsible owner.

Evidence should also include sufficient context for an independent assessor to understand its source, time period, completeness, and relationship to the cloud service offering.

Governance and Human Oversight

Automated evidence does not eliminate the need for documented approvals, exception management, risk acceptance, or management oversight.

Providers should establish procedures for:

  • Reviewing failed or incomplete automated checks.
  • Investigating inconsistent evidence.
  • Approving security-sensitive changes.
  • Tracking corrective actions.
  • Managing exceptions and residual risk.
  • Updating the Security Decision Record.
  • Preserving evidence needed for independent assessment.
  • Confirming that automation itself remains accurate.

A successful program combines technical automation with clear accountability.

Independent Assessments

Class B and Class C providers must include all applicable KSIs in a FedRAMP independent assessment at least annually.

The independent assessor must verify that implemented measures match the provider’s descriptions and validate that those measures achieve their intended outcomes. This requires review of the underlying technical implementation and evidence, rather than reliance solely on policies, narratives, or screenshots.

Assessment results must be incorporated accurately into the provider’s certification package.

Relationship to Other Frameworks

Evidence developed for SOC 2, ISO 27001, CMMC, NIST SP 800-171, PCI DSS, HIPAA, GovRAMP, or another framework may be reusable when it addresses the same system, measure, and security objective.

Reuse must be verified rather than assumed. FedRAMP 20x does not automatically require CMMC Level 3 alignment, and evidence from another framework does not automatically satisfy a FedRAMP KSI.

Cross-framework mapping should be presented as an evidence-management opportunity, not as a guaranteed reduction in assessment time, cost, or effort.

How Lazarus Alliance Can Help

Lazarus Alliance is listed in the FedRAMP Marketplace as a FedRAMP Recognized independent assessment service.

Within applicable independence requirements, Lazarus Alliance can evaluate KSI implementation, test automated and manual security measures, validate supporting evidence, and perform independent assessment activities required by FedRAMP.

Cloud service providers remain responsible for maintaining their certification information and submitting their own FedRAMP application.

Authoritative Sources

About Lazarus Alliance

To learn more about how Lazarus Alliance can help, contact us.

Download our company brochure.

CyberVisor

Website: