What Is FedRAMP 20x? KSIs, Rev 5 Deadlines, and the 2026 Consolidated Rules
15
5:00 PM - 6:00 PM
The Consolidated Rules for 2026 replace the FedRAMP program cloud service providers have known for a decade — new Certification Classes, a new approach to scoping, and Key Security Indicators validated through machine-readable evidence. This session answers the three questions providers are asking most:
- What is FedRAMP 20x, and what does CR26 actually change? What the new program structure looks like — how Certification Classes A–D replace the Low/Moderate/High baselines and what Minimum Assessment Scope means for how systems are evaluated.
- What are the Rev 5 transition deadlines? 20x submissions are open for Classes A-C, the Ready Conversion window opens August 10, 2026, and Rev 5 retires at the end of 2027. We'll lay out each authorization path and its milestones so you can plan with accurate information.
- How do KSIs and machine-readable evidence work? How roughly 61 KSIs replace 325+ control narratives, how automated validation works, and how evidence from existing programs like SOC 2 relates to 20x expectations.
Can't make it live? Register anyway and we'll send the replay.
Who should attend: Compliance, security, and engineering leaders at cloud service providers pursuing or maintaining FedRAMP authorization — and anyone responsible for understanding how the 2026 changes affect their organization's federal roadmap.
Speakers
Dillard Trapp
Senior Manager of Federal Cloud Compliance & Assessments | Insight Assurance
Dillard Trapp is a Senior Manager of Federal Cloud Compliance & Assessments at Insight Assurance and a U.S. Marine Corps veteran with over a decade of experience in cybersecurity, governance, risk, and compliance. He has supported both federal and commercial organizations across cloud security, FedRAMP, DoD, NIST RMF, and CMMC initiatives, helping organizations strengthen their security posture while navigating complex regulatory and authorization requirements.
Dillard's experience spans security architecture, federal cloud compliance strategy, assessment readiness, continuous monitoring, and risk management across highly regulated environments. His work focuses on bridging technical operations with practical compliance execution, helping organizations build scalable and defensible security programs aligned to evolving federal standards.
Owen Rousu
Manager, FedRAMP Practice Lead | Riveron
Owen is the Manager, FedRAMP Practice at Riveron, leading end-to-end FedRAMP and CMMC compliance engagements, guiding clients from readiness through authorization by designing and validating secure cloud architectures. Responsible for developing SSPs and supporting documentation while partnering closely with engineering and security teams. Former Ranger Medic.
15
5:00 PM - 6:00 PM