FedRAMP 20x · September 2026
FedRAMP 20x asks you to prove 92 things automatically. Five of them your compliance platform structurally cannot do.
The 2026 rules require two automated validation methods for each of 46 Key Security Indicators. Five of those indicators are written with verbs — enforce, redeploy, remediate, validate throughout deployment — that a read-only platform cannot satisfy. Here is the exact text, and what it means for who you buy from.
7 September 2026 · Kenio Shirley
Start with the file, not the commentary
FedRAMP publishes its entire ruleset as one machine-readable file — fedramp-consolidated-rules.json, currently version 2026.07.14.01, at github.com/FedRAMP/rules — and explicitly instructs automation to read that file rather than scraping the site.
Read it and you find 46 Key Security Indicators across 10 families, not the 63 across 12 themes that AWS's own April 2026 public-sector blog post describes. That post counts two FedRAMP rulesets (CSX and AFR) as though they were KSI families, and cites identifiers such as KSI-AFR-VDR that do not exist in the data model. It also predates the 24 June 2026 launch of the current set.
Two other things changed that most commentary has not absorbed: KSI-TPR (Third-Party Information Resources) no longer exists — it was replaced by KSI-SCR (Supply Chain Risk) — and identifiers are mnemonic now, KSI-CNA-DFP rather than KSI-CNA-01.
Then the number
Rule FRC-CSX-VVK sets the validation obligation by Certification Class:
| Class | Requirement | Minimum methods |
|---|---|---|
| Class A | MAY implement automated methods. | — |
| Class B | SHOULD, with at least 1 automated method for each Key Security Indicator. | 46 |
| Class C | MUST, with at least 2 automated methods for each. | 92 |
| Class D | MUST, with at least 4 automated methods for each. | 184 |
At Class C — the successor to Moderate — that is 92 automated validation methods, minimum. At Class D, 184.
And two methods does not mean two Config rules. It means two independent ways of establishing the same fact. A single scanner producing 200 checks is arguably one method applied 200 times.
The five, quoted verbatim
Read the verbs. Each of these describes something being done to the estate, not something being observed about it.
KSI-CNA-EIS
“Automated services are used to persistently assess the security of all machine-based information resources and automatically enforce their intended operational state.”
KSI-SVC-ACM
“The configuration of machine-based information resources is managed using automation and persistently reviewed for drift.”
KSI-SVC-EIS
“Information resources are persistently evaluated for opportunities to improve security and those improvements are persistently made.”
KSI-CMT-RMV
“Changes to machine-based information resources are executed through the redeployment of version controlled resources rather than direct modification wherever reasonable.”
KSI-CMT-VTD
“Persistent testing and validation of changes throughout deployment is automated.”
A platform that connects over a read-only API can hold your statement that these things happen. It cannot produce the artefact, because the artefact is the run.
That is not a criticism of those platforms. Read-only is the correct architectural choice for a tool that has to be safe to connect to a thousand estates. It is a description of where the evidence has to come from instead.
Reinforce it with what SDR-CSX-KSI actually requires per indicator: an explanation of the measures, an explanation of the cycle for measures implemented persistently, verification that the measures demonstrate the KSI, verification that the automation in place is accurate and sufficient, and validation that the measures are accurately produced and working as intended. That fourth item is the one that bites — you have to prove the automation itself, not just its output.
Three things that change the shape of the work
01
FedRAMP hosts nothing
CDS-CSO-UTC requires providers to use a FedRAMP-compatible trust center, and CDS-TRC-PAC requires it to "provide documented programmatic access to all FedRAMP Certification Data, including programmatic access to human-readable materials." Access must be logged and summaries kept at least six months. There is no central FedRAMP ingestion API — the API obligation runs the other way.
02
It is FedRAMP's own JSON, not OSCAL
FRC-CSO-JSN requires documents valid against the corresponding FedRAMP JSON schema. Nine schema families, all dated 24 June 2026. OSCAL is optional and in some cases. A lot of tooling investment went into the secondary format.
03
Your documentation is in scope as a vulnerability
VDR-CSO-DET states that an out-of-date control statement in the Security Decision Record is a vulnerability that must be detected and remediated like any other, and VDR-CSO-FAV makes failures of the detection process itself into vulnerabilities. Your compliance pipeline has to monitor its own health as a finding.
The practical note: Class A is the way in
Class A is new, it has no legacy equivalent, and FRC-CLA-ASF lets you qualify off a SOC 2 Type II completed within the past 12 months. FRC-CLA-IVV makes independent assessment optional at Class A. The pipeline opened 3 August 2026; B and C opened 31 August. FedRAMP Ready stopped accepting submissions on 28 July, and FedRAMP's own guidance says the simplest conversion is to Class A.
The catch, stated plainly: KSI-CNA-EIS is one of five indicators not defined at Class A at all, and FRC-CSX-VVK at Class A is only a MAY. Class A is where you get in. Class C is where the automation requirement actually lands.
What Keystone does, and what it does not
Keystone runs Terraform and Ansible against your own accounts, evaluates every Terraform plan with tfsec and Checkov, detects drift and converges it, gates changes behind role-separated approval, and writes a hash-chained evidence record for each one. Those are first-party artefacts for the five indicators above and for four more — CMT-LMC, MLA-EVC, CNA-IBP and PIY-GIV.
Nine of 46. Keystone is not a FedRAMP 20x platform and will not tell you it is. It does not collect IAM, CloudTrail or log data, it has no incident or recovery-testing workflow, and it emits no FedRAMP JSON today.
What it does is the part where somebody has to actually change the infrastructure and prove it — which is the part a read-only tool leaves for you.
Kenio Shirley is the founder of Keystone and runs hireken.io. CISSP, CISM. Seventeen years in enterprise technology across 50+ audits covering SOC 2, HITRUST, FedRAMP, PCI DSS, SOX and IRAP.
See what Keystone evidences
Nine indicators, first-party, hash-chained. Not a FedRAMP platform — the part where the infrastructure actually changes.