Agenda

Tuesday, September 29

9:00AM - 9:55AM

Coffee & Networking

10:00AM - 10:05AM

Opening Remarks

10:05AM - 10:20AM

Opening Keynote

10:25AM - 10:55AM

Fireside Chat

11:00AM - 11:40AM

From Checkbox to Continuous: Scaling Security in Large Organizations

Achieving continuous security at scale is a shared challenge for large organizations in both the private and public sectors. This panel will discuss how large, complex organizations move beyond point-in-time compliance checks toward truly continuous security practices. Panelists will share practical lessons on operationalizing continuous monitoring, automating vulnerability management, and managing change at velocity—offering attendees actionable insight into what continuous security looks like in practice, from both the provider and agency perspective.

11:45AM - 12:15PM

The Cost of Fragmentation: The Case for Aligning Federal Cloud Security Frameworks

Cloud service providers today face a patchwork of overlapping and conflicting compliance frameworks. This panel brings together federal officials, industry compliance leaders, and assessors to discuss what “harmonization” actually looks like in practice. Panelists will weigh in on where progress is being made and what CSPs need from regulators to make “assess once, authorize many” a reality rather than a slogan.

12:15PM - 1:15PM

Lunch & Networking

1:15PM - 1:45PM

Modernizing DoW Cloud Compliance: Strategies, Challenges, and Collaboration (Industry Perspective)

Industry panelists will share real-world perspectives on navigating DoW cloud compliance, from meeting evolving security requirements to working through complex authorization and connectivity processes such as BCAP. The discussion will explore common challenges, lessons learned, and opportunities for greater collaboration, consistency, and efficiency in bringing secure cloud capabilities to DoW missions.

1:50PM - 2:25PM

Compliance at Speed: A Look at Today's GRC Tooling

Governance, risk, and compliance (GRC) tooling is reshaping how CSPs and federal agencies manage the volume and complexity of today’s compliance requirements. This panel explores how organizations are adopting GRC platforms to automate evidence collection, streamline authorization workflows, and maintain audit-ready documentation across sprawling control sets. Panelists will discuss lessons learned from tool selection and implementation, integration with existing ATO and ConMon processes, and where automation is delivering the biggest return—giving attendees a practical view of how GRC tooling can reduce manual burden without sacrificing rigor.

2:30PM - 3:10PM

The Third Party Perspective: 3PAOs and the Future of Federal ATOs

Third-Party Assessment Organizations (3PAOs) play a pivotal role in validating cloud security across the Federal government. This panel brings together leading 3PAOs to discuss how assessment practices are adapting to new requirements and changes in the ATO process. Panelists will share perspectives on maintaining assessment rigor and consistency amid process change, the growing emphasis on continuous assessment over point-in-time reviews, and how 3PAOs are working alongside CSPs and agencies to keep pace with an evolving compliance landscape.

3:15PM - 3:45PM

FedRAMP as a standard for other regulated entities

FedRAMP’s standardized approach to cloud security assessment has drawn growing interest from regulated industries beyond the Federal government. This panel explores the potential for FedRAMP to serve as a compliance framework for sectors such as financial services, which faces its own complex and often overlapping security and compliance mandates. Panelists will discuss where FedRAMP’s structure translates well to other regulatory environments and what opportunities exist for harmonizing federal and industry-specific compliance requirements to reduce duplicative assessment burden on CSPs

4:00PM

Reception

Wednesday, September 30

9:00AM - 9:50AM

Meet the FedRAMP team | Rev5 and 20x Community Updates

10:00AM - 10:15AM

Welcome Remarks

10:15AM - 10:45AM

Keynote: FedRAMP Road Ahead

10:45AM - 11:30AM

Behind the Certification: How the FedRAMP Ecosystem Works Together To Ensure Security

The FedRAMP ecosystem brings together a diverse range of expertise, technology, assessment, and operational capabilities to support both cloud providers and government agencies. This panel will explore how accelerators, 3PAOs, advisors, and technology providers contribute at different stages and in different ways—helping organizations navigate evolving requirements, strengthen ongoing security operations, make informed risk decisions, and accelerate the secure adoption of cloud technologies across government.

11:35AM - 12:05PM

Agency Roundtable: What It Takes to Earn Agency Trust

Federal officials share what they need from cloud service providers to speed authorizations and strengthen ongoing risk management — from clearer documentation to faster remediation and better communication throughout the ATO and ConMon lifecycle. A candid, agency-eye view of what makes for a strong industry partnership.

12:05PM - 12:55PM

Lunch

1PM - 1:35PM

Decoding FedRAMP 20x: How KSIs Correspond to NIST 800-53 Controls

FedRAMP 20x introduced Key Security Indicators (KSIs) as a streamlined alternative to traditional control-by-control assessment. This panel brings together NIST and the FedRAMP PMO to discuss how KSIs correspond to existing NIST SP 800-53 controls, where the mapping is straightforward, and where interpretation or additional guidance is still needed. Panelists will address the reasoning behind the KSI framework, implications for continuous monitoring, and what CSPs and Federal agencies should expect as the FedRAMP moves to 20x.

1:40PM - 2:10PM

Beyond Acceleration: Navigating the Future of FedRAMP and Compliant Security Operations

FedRAMP modernization is changing more than how cloud services achieve authorization—it is reshaping how compliant security operations must function in an environment of continuous change. As FedRAMP 20x advances, Class D (High) emerges, and AI accelerates the complexity and pace of security threats and requirements, hosted accelerators can play an increasingly critical role in helping technology companies and government agencies understand, operationalize, and continuously adapt to what comes next.

2:15PM - 2:45PM

VDR

As FedRAMP transitions to a risk-based Vulnerability Detection and Response (VDR) model, cloud providers must rethink how they detect, prioritize, remediate, and report vulnerabilities. This discussion will examine the key implementation challenges facing CSPs and explore practical solutions, lessons learned, and innovative approaches for achieving continuous, outcome-focused vulnerability management at scale.

2:45PM - 3:00PM

Break

3:00PM - 3:30PM

Moving from Rev5 to 20x

FedRAMP’s shift from the Rev5 baseline to the 20x framework represents the most significant change to the authorization process in years.This panel brings together the FedRAMP PMO and CSPs to unpack what this transition actually means in practice — procedurally and for the underlying security posture of cloud products. Panelists will help CSPs and federal agencies alike understand what’s changing, what’s staying the same, and how to prepare for the shift.

3:30PM - 3:35PM

Closing remarks