Fortreum Completed FedRAMP 20x Compliance Pilots

The pilot program transitioned federal cloud security assessments toward automated, continuous monitoring.

Updated on Oct. 1, 2026 in Cybersecurity

Isometric editorial illustration of a modular data server rack with rectilinear metal housing, representing automated federal security monitoring systems.
Fortreum and InfusionPoints completed the FedRAMP 20x pilot program in April 2026, marking a federal shift toward continuous, automated cloud security verification. AI Illustration. Upload story photo >

Live Poll

Do you trust automated security reporting more than traditional manual audits for government cloud systems?

Fortreum and InfusionPoints completed FedRAMP 20x Low and Moderate impact pilot assessments by April 2026. This shift replaces traditional static compliance documentation with automated measurement and continuous security verification.

Why it matters

The federal government has shifted its cloud security assessment model to an automation-first approach to improve security oversight. This move moves the industry away from point-in-time document reviews toward persistent evidence generation.

The pilot assessed 11 Key Security Indicators using 61 applied rules and 209 total validations. This framework relies on persistent evidence generation rather than relying on point-in-time documentation.

The players

Fortreum

A cybersecurity firm specializing in FedRAMP compliance and cloud assessment services.

InfusionPoints

A cloud security and managed services firm focused on federal compliance automation.

AWS GovCloud

An isolated Amazon Web Services region built to host sensitive government data and comply with rigorous federal security requirements.

The details

Participants utilized the XBU40 platform hosted on AWS GovCloud—a specialized Amazon Web Services region designed for sensitive federal workloads—to automate evidence collection. Assessors evaluated the system generating security data directly rather than reviewing manual records. Under the FedRAMP 20x framework, Class C providers must utilize automated methods to persistently verify Key Security Indicators, with independent assessments required annually.

Timeline

  1. July 2025: Completed the Class B Low Phase I pilot.

  2. April 2026: Completed the Class C Moderate Phase II pilot.

The Tech Race

This pilot program marks a fundamental evolution of the FedRAMP framework by replacing manual, static documentation with continuous security measurement. It positions automation as the new standard for verifying security compliance in federal cloud environments.

Cloud service providers serving federal agencies should prepare for a transition from static document audits to automated, continuous evidence reporting. The requirement for independent annual assessments for Class B and C providers indicates a more frequent and rigorous compliance cadence.

The takeaway

The move to FedRAMP 20x signals that manual compliance documentation is being phased out in favor of systems that demonstrate persistent, automated security evidence. Stakeholders should monitor for the formalization of these pilot requirements into final, enterprise-wide agency standards.

Further reading

For broader trends in federal security compliance, review our coverage of Cybersecurity.

Live Poll

Do you trust automated security reporting more than traditional manual audits for government cloud systems?