Johann Dettweiler
Chief Information Security Officer, stackArmor, a Quantum Sky company
Bottom Line Up Front
FedRAMP is retiring new Rev. 5 applications. Agencies still need Rev. 5-grade evidence. CSPs shouldn’t have to build two compliance programs to get both.
FedRAMP’s Consolidated Rules already map 44 of the current 46 Key Security Indicators back to 209 unique NIST SP 800-53 Rev. 5 controls. That mapping means CSPs don’t have to choose between Rev. 5 control-based assurance and 20x outcome-based assurance. They can run one evidence layer and generate both.
Two KSIs without existing mappings need purpose-built automation instead.
What’s missing isn’t the mapping. It’s someone using it.
FedRAMP has made its direction clear: the program is moving toward 20x, automated assurance, machine-readable evidence, and security outcomes instead of document production as a competitive sport.
As part of that transition, FedRAMP says it will stop accepting applications for new Rev. 5 Certifications on June 11, 2027. Existing Rev. 5 certifications will continue for a while, but the destination is obvious: 20x is supposed to become the primary model.
There is only one tiny complication.
Agencies still must authorize systems.
And those agencies remain responsible for their own FISMA and Risk Management Framework decisions, including categorizing systems, selecting and tailoring NIST SP 800-53 controls, documenting implementation, assessing risk, and issuing an Authorization to Operate (ATO).
FedRAMP certification supplies reusable provider evidence; it does not magically replace an agency Authorizing Official’s responsibility.
Welcome to the Transition. Please Enjoy Speaking Both Languages.
The recent Department of Veterans Affairs memo makes this tension unusually visible.
VA says acquisition documents should not require an existing FedRAMP certification merely to compete for an award. Fine.
But the memo also says security and authorization requirements will still be met through NIST SP 800-53 Rev. 5, along with VA-specific requirements, and it identifies post-award documentation that can include a Security Assessment Report, architecture and data-flow diagrams, inventories, vulnerability scans, and, when applicable, the implementation status of FedRAMP 20x KSIs.
My interpretation of that: welcome to the transition. Please enjoy speaking both languages.
To be precise, the VA memo does not say, “CSPs must maintain every legacy FedRAMP Rev. 5 template forever.”
What it demonstrates is more important: agencies may continue to need the substance of Rev. 5 control-based assurance for their own authorization decisions while FedRAMP simultaneously expects providers to move toward KSI-based automated assurance.
For CSPs, maintaining two entirely separate security-assurance systems for the same cloud service would be an enormous waste of time and money.
Professionally speaking, it’s needlessly chasing two entirely disparate outcomes.
The Mapping Already Exists
Here is the part that makes this problem solvable: FedRAMP has already done much of the conceptual work.
The current Consolidated Rules map most 20x Key Security Indicators to related NIST SP 800-53 Rev. 5 controls.
The current KSI set contains 46 indicators, with only KSI-CNA-OFA and KSI-PIY-RES carrying empty control mappings.
Those 164 repeated references are exactly the kind of duplication an evidence-reuse layer should eliminate operationally, not paper over with another spreadsheet.
That means this is not a situation where Rev. 5 and 20x live on different planets.
Forty-four of the 46 current KSI indicators already have an explicit bridge back to the control framework agencies understand.
So why not use it?
Make the Rev. 5 Evidence Layer Do Double Duty
Instead of asking every CSP to invent a completely new collection of bespoke KSI checks, providers could maintain their Rev. 5 control implementation and evidence model as a canonical security evidence layer, then use automation to generate KSI assertions from the controls mapped in the current Consolidated Rules.
The workflow is straightforward.
Collect
Continuously collect authoritative evidence for the applicable Rev. 5 controls: cloud configuration, IAM state, vulnerability data, logging configuration, deployment pipelines, inventory, recovery testing, change records, and other deterministic telemetry.
Evaluate
Automatically evaluate the implementation status of those controls using repeatable queries and tests.
Map
Apply a versioned FedRAMP KSI-to-control mapping layer that identifies which control assertions and supporting evidence are relevant to each KSI.
Assert
Produce a machine-readable KSI result that says what was evaluated, which controls and evidence supported the conclusion, when the evaluation occurred, which version of the Consolidated Rules was used, and where human judgment or exceptions were required.
One Security Program, Two Assurance Views
This is hardly hostile to FedRAMP’s modernization goals.
Federal policy already pushes agencies and FedRAMP toward machine-readable authorization and continuous-monitoring artifacts, and the new Security Decision Record (SDR) is explicitly designed to capture implementation, verification, validation, and supporting evidence in a more structured way.
The agency gets familiar control-oriented evidence for its RMF process. FedRAMP gets automated, continuously refreshed KSI assurance. The CSP operates one security program instead of maintaining two parallel universes.
This Should Not Be a Dumb “All Controls Green = KSI Green” Equation
There is an important caveat. FedRAMP describes these as related SP 800-53 controls. A mapping is not automatically a mathematical equivalence.
A KSI may express an outcome that spans several controls, emphasizes persistent measurement, or requires a level of automation not satisfied merely because someone wrote “Implemented” in an SSP three years ago.
The Consolidated Rules themselves expect KSI evidence to address the measures used, their persistent cycle where applicable, verification, automation sufficiency, and validation.
The proposal should not be: “AC-2 passed; therefore the KSI passed. Everybody go home.”
The better model is evidence reuse with transparent roll-up logic. A KSI assertion should show the relevant mapped controls, the live validation results for those controls, the evidence supporting them, and any KSI-specific logic necessary to demonstrate the stated outcome.
FedRAMP could make this significantly easier by publishing a canonical KSI assertion schema and standardized interpretation rules, with evidence references and rules-version metadata:
Demonstrated • Partially Demonstrated • Not Demonstrated • Not Applicable
That would preserve the outcome-oriented intent of 20x without forcing every CSP, assessor, and agency to independently invent what a “good” KSI test looks like.
And Then There Were Two
What about the two KSIs without control mappings? Those should get purpose-built automation.
KSI-CNA-OFA, Optimizing for Availability, could be demonstrated through automated review of high-availability architecture, redundancy, health checks, failover capability, recovery telemetry, RTO/RPO performance, and recovery test results.
KSI-PIY-RES, Reviewing Executive Support, is less infrastructure-friendly, but it can still be systematized.
Evidence might include scheduled executive security reviews, security-goal approval, risk acceptance workflows, budget or investment decisions, and documented governance actions.
Not every security outcome needs to be a cloud API call to be measurable.
Two dedicated KSI mechanisms are manageable.
Forty-six bespoke KSI interpretations layered on top of hundreds of controls CSPs already maintain are not modernization.
It’s the blueprint for a time machine back to the pre-FedRAMP 2011 world that we all despised.
Give Everyone One Source of Security Truth
The most practical path through the Rev. 5-to-20x transition is not to force CSPs to choose between control-based assurance and outcome-based assurance. It is to make one feed the other.
FedRAMP already wants machine-readable artifacts and automated evidence.
Agencies still need enough NIST control-level information to make defensible authorization decisions.
The Consolidated Rules already provide the mapping that connects most KSIs to those controls. Use it.
Let CSPs continuously validate their Rev. 5 controls, preserve the evidence agencies need, and automatically roll that evidence into transparent KSI assertions.
Require dedicated automation where the mapping does not exist.
Version the mappings. Preserve provenance. Let assessors validate the automation instead of repeatedly reconstructing the same security truth in different formats.
FedRAMP gets automation. Agencies get defensible authorization evidence. CSPs stop getting hammered with the unreasonable expectation of maintaining two representations of the same security program.
From Two Systems to One Source of Truth
This is more than a compromise between Rev. 5 and 20x.
It is what a sensible transition should have looked like in the first place.
One Security Program. One Source of Truth.
See how stackArmor can help your organization prepare for the transition from FedRAMP Rev. 5 to 20x without building parallel compliance programs.
Schedule ATO Acceleration Briefing