FedRAMP 20x introduced a bold rethinking of the Authorization to Operate (ATO) process, moving toward a faster, more outcome-driven model.
The traditional ATO process — manual, duplicative and slow — has long been a bottleneck in adopting secure cloud services. With new guidance focused on automation, machine-readable artifacts and outcome-based metrics like Key Security Indicators (KSIs), the program is redefining what it means to assess and authorize cloud systems in the federal space.
Now, several months into implementation, agencies are seeing early signs of impact and starting to ask what it means for their own ATO strategy.
In this timely webinar, experts from the Cloud Security Alliance and RegScale will explore:
In this timely webinar, experts from the Cloud Security Alliance and RegScale explored:
- What’s changing in FedRAMP 20x's approach to ATOs and why it matters.
- How KSIs shift agency oversight from static documentation to real-time performance.
- The role of OSCAL, Compliance as Code and automation in continuous authorizations.
- How risk envelopes and other structural reforms could reduce redundancy and rework.
- What agencies should be doing now to prepare for a more agile, data-driven ATO process.