trade-press
FedRAMP 20x ends compliance theater with 2, 4 day vuln deadlines
If your security team reviews findings weeks after engineering ships code, your FedRAMP authorization is at risk, the pipeline is the control now.
FedRAMP Director Pete Waterman told vendors at Carahsoft's FedRAMP Summit that those who can't fix critical, internet-facing vulnerabilities within days don't belong in the federal marketplace. FedRAMP 20x codifies that expectation: risk reduction must begin within two to four days, and system security state must be verified at least every three days. The implication is structural, vendors whose compliance staff sit apart from engineering cannot sustain that pace. Continuous authorization requires continuous delivery, and the deployment pipeline itself becomes the control.