Agenda
Tuesday, September 29
Coffee & Networking
Opening Remarks
Opening Keynote
Fireside Chat
From Checkbox to Continuous: Scaling Security in Large Organizations
Achieving continuous security at scale is a shared challenge for large organizations in both the private and public sectors. This panel will discuss how large, complex organizations move beyond point-in-time compliance checks toward truly continuous security practices. Panelists will share practical lessons on operationalizing continuous monitoring, automating vulnerability management, and managing change at velocity—offering attendees actionable insight into what continuous security looks like in practice, from both the provider and agency perspective.
The Cost of Fragmentation: The Case for Aligning Federal Cloud Security Frameworks
Cloud service providers today face a patchwork of overlapping and conflicting compliance frameworks. This panel brings together federal officials, industry compliance leaders, and assessors to discuss what “harmonization” actually looks like in practice. Panelists will weigh in on where progress is being made and what CSPs need from regulators to make “assess once, authorize many” a reality rather than a slogan.
Lunch & Networking
Modernizing DoW Cloud Compliance: Strategies, Challenges, and Collaboration (Industry Perspective)
Industry panelists will share real-world perspectives on navigating DoW cloud compliance, from meeting evolving security requirements to working through complex authorization and connectivity processes such as BCAP. The discussion will explore common challenges, lessons learned, and opportunities for greater collaboration, consistency, and efficiency in bringing secure cloud capabilities to DoW missions.
Compliance at Speed: A Look at Today's GRC Tooling
Governance, risk, and compliance (GRC) tooling is reshaping how CSPs and federal agencies manage the volume and complexity of today’s compliance requirements. This panel explores how organizations are adopting GRC platforms to automate evidence collection, streamline authorization workflows, and maintain audit-ready documentation across sprawling control sets. Panelists will discuss lessons learned from tool selection and implementation, integration with existing ATO and ConMon processes, and where automation is delivering the biggest return—giving attendees a practical view of how GRC tooling can reduce manual burden without sacrificing rigor.
The Third Party Perspective: 3PAOs and the Future of Federal ATOs
Third-Party Assessment Organizations (3PAOs) play a pivotal role in validating cloud security across the Federal government. This panel brings together leading 3PAOs to discuss how assessment practices are adapting to new requirements and changes in the ATO process. Panelists will share perspectives on maintaining assessment rigor and consistency amid process change, the growing emphasis on continuous assessment over point-in-time reviews, and how 3PAOs are working alongside CSPs and agencies to keep pace with an evolving compliance landscape.
FedRAMP as a standard for other regulated entities
FedRAMP’s standardized approach to cloud security assessment has drawn growing interest from regulated industries beyond the Federal government. This panel explores the potential for FedRAMP to serve as a compliance framework for sectors such as financial services, which faces its own complex and often overlapping security and compliance mandates. Panelists will discuss where FedRAMP’s structure translates well to other regulatory environments and what opportunities exist for harmonizing federal and industry-specific compliance requirements to reduce duplicative assessment burden on CSPs
Reception
Wednesday, September 30
Meet the FedRAMP team | Rev5 and 20x Community Updates
Welcome Remarks
Keynote: FedRAMP Road Ahead
Behind the Certification: How the FedRAMP Ecosystem Works Together To Ensure Security
The FedRAMP ecosystem brings together a diverse range of expertise, technology, assessment, and operational capabilities to support both cloud providers and government agencies. This panel will explore how accelerators, 3PAOs, advisors, and technology providers contribute at different stages and in different ways—helping organizations navigate evolving requirements, strengthen ongoing security operations, make informed risk decisions, and accelerate the secure adoption of cloud technologies across government.
Agency Roundtable: What It Takes to Earn Agency Trust
Federal officials share what they need from cloud service providers to speed authorizations and strengthen ongoing risk management — from clearer documentation to faster remediation and better communication throughout the ATO and ConMon lifecycle. A candid, agency-eye view of what makes for a strong industry partnership.
Lunch
Decoding FedRAMP 20x: How KSIs Correspond to NIST 800-53 Controls
FedRAMP 20x introduced Key Security Indicators (KSIs) as a streamlined alternative to traditional control-by-control assessment. This panel brings together NIST and the FedRAMP PMO to discuss how KSIs correspond to existing NIST SP 800-53 controls, where the mapping is straightforward, and where interpretation or additional guidance is still needed. Panelists will address the reasoning behind the KSI framework, implications for continuous monitoring, and what CSPs and Federal agencies should expect as the FedRAMP moves to 20x.
Beyond Acceleration: Navigating the Future of FedRAMP and Compliant Security Operations
FedRAMP modernization is changing more than how cloud services achieve authorization—it is reshaping how compliant security operations must function in an environment of continuous change. As FedRAMP 20x advances, Class D (High) emerges, and AI accelerates the complexity and pace of security threats and requirements, hosted accelerators can play an increasingly critical role in helping technology companies and government agencies understand, operationalize, and continuously adapt to what comes next.
VDR
As FedRAMP transitions to a risk-based Vulnerability Detection and Response (VDR) model, cloud providers must rethink how they detect, prioritize, remediate, and report vulnerabilities. This discussion will examine the key implementation challenges facing CSPs and explore practical solutions, lessons learned, and innovative approaches for achieving continuous, outcome-focused vulnerability management at scale.
Break
Moving from Rev5 to 20x
FedRAMP’s shift from the Rev5 baseline to the 20x framework represents the most significant change to the authorization process in years.This panel brings together the FedRAMP PMO and CSPs to unpack what this transition actually means in practice — procedurally and for the underlying security posture of cloud products. Panelists will help CSPs and federal agencies alike understand what’s changing, what’s staying the same, and how to prepare for the shift.