Ramping into FedRAMP 20X Continuous Authorization - What it means for documentation and evidence collection.
Insight Assurance
58:27
June 17 | 1:00 PM ET
FedRAMP 20X represents the most significant evolution of the FedRAMP program in years. The shift toward continuous authorization moves away from periodic point-in-time assessment toward ongoing, automated evidence collection and real-time control validation — and it raises immediate questions for cloud service providers: What does the new documentation framework actually require? How is evidence expected to be structured? And what does continuous authorization mean for how a Third Party Assessment Organization (3PAO) evaluates your environment?
Join Insight Assurance and Paramify for a practical conversation on what FedRAMP 20X means for your documentation and evidence collection practices.
Topics we'll explore:
- What continuous authorization looks like under FedRAMP 20X — and how it differs from the traditional model
- How documentation standards and evidence expectations are evolving
- What cloud service providers should be thinking about now as the program matures
- How independent 3PAO assessments evaluate evidence in a continuous authorization environment
This session is designed for compliance leads, security practitioners, and technical teams at cloud service providers pursuing FedRAMP authorization, maintaining an existing ATO, or planning their path forward under the new framework.
Speakers
Dillard Trapp
Senior Manager of Federal Cloud Compliance & Assessments | Insight Assurance
Dillard Trapp is a Senior Manager of Federal Cloud Compliance & Assessments at Insight Assurance and a U.S. Marine Corps veteran with over a decade of experience in cybersecurity, governance, risk, and compliance. He has supported both federal and commercial organizations across cloud security, FedRAMP, DoD, NIST RMF, and CMMC initiatives, helping organizations strengthen their security posture while navigating complex regulatory and authorization requirements.
Dillard's experience spans security architecture, federal cloud compliance strategy, assessment readiness, continuous monitoring, and risk management across highly regulated environments. His work focuses on bridging technical operations with practical compliance execution, helping organizations build scalable and defensible security programs aligned to evolving federal standards.
Isaac Teuscher
FedRAMP 20x Moderate Security Engineer - Paramify
Isaac is a Senior Security Engineer at Paramify, leading the technical implementation of cloud and AI-driven security initiatives. Isaac led FedRAMP 20x pilot programs leading to one of the first FedRAMP 20x Moderate authorizations. His approach prioritizes real security over checkbox compliance by applying risk-based hardening, threat modeling, and automation to ensure systems are both secure and audit-ready.
Ramping into FedRAMP 20X Continuous Authorization - What it means for documentation and evidence collection.
58:27