209 Controls, 46 KSIs, and One Very Avoidable Compliance Catastrophe

Johann Dettweiler
Chief Information Security Officer, stackArmor, a Quantum Sky company

Bottom Line Up Front

FedRAMP is retiring new Rev. 5 applications. Agencies still need Rev. 5-grade evidence. CSPs shouldn’t have to build two compliance programs to get both.

FedRAMP’s Consolidated Rules already map 44 of the current 46 Key Security Indicators back to 209 unique NIST SP 800-53 Rev. 5 controls. That mapping means CSPs don’t have to choose between Rev. 5 control-based assurance and 20x outcome-based assurance. They can run one evidence layer and generate both.

Two KSIs without existing mappings need purpose-built automation instead.

What’s missing isn’t the mapping. It’s someone using it.

FedRAMP has made its direction clear: the program is moving toward 20x, automated assurance, machine-readable evidence, and security outcomes instead of document production as a competitive sport.

As part of that transition, FedRAMP says it will stop accepting applications for new Rev. 5 Certifications on June 11, 2027. Existing Rev. 5 certifications will continue for a while, but the destination is obvious: 20x is supposed to become the primary model.

There is only one tiny complication.

Agencies still must authorize systems.

And those agencies remain responsible for their own FISMA and Risk Management Framework decisions, including categorizing systems, selecting and tailoring NIST SP 800-53 controls, documenting implementation, assessing risk, and issuing an Authorization to Operate (ATO).

FedRAMP certification supplies reusable provider evidence; it does not magically replace an agency Authorizing Official’s responsibility.

Welcome to the Transition. Please Enjoy Speaking Both Languages.

The recent Department of Veterans Affairs memo makes this tension unusually visible.

VA says acquisition documents should not require an existing FedRAMP certification merely to compete for an award. Fine.

But the memo also says security and authorization requirements will still be met through NIST SP 800-53 Rev. 5, along with VA-specific requirements, and it identifies post-award documentation that can include a Security Assessment Report, architecture and data-flow diagrams, inventories, vulnerability scans, and, when applicable, the implementation status of FedRAMP 20x KSIs.

My interpretation of that: welcome to the transition. Please enjoy speaking both languages.

To be precise, the VA memo does not say, “CSPs must maintain every legacy FedRAMP Rev. 5 template forever.”

What it demonstrates is more important: agencies may continue to need the substance of Rev. 5 control-based assurance for their own authorization decisions while FedRAMP simultaneously expects providers to move toward KSI-based automated assurance.

For CSPs, maintaining two entirely separate security-assurance systems for the same cloud service would be an enormous waste of time and money.

Professionally speaking, it’s needlessly chasing two entirely disparate outcomes.

The Mapping Already Exists

Here is the part that makes this problem solvable: FedRAMP has already done much of the conceptual work.

The current Consolidated Rules map most 20x Key Security Indicators to related NIST SP 800-53 Rev. 5 controls.

The current KSI set contains 46 indicators, with only KSI-CNA-OFA and KSI-PIY-RES carrying empty control mappings.

373 Total KSI-to-Control Mapping References
209 Unique Rev. 5 Controls Represented
164 Repeated References Across KSIs

Those 164 repeated references are exactly the kind of duplication an evidence-reuse layer should eliminate operationally, not paper over with another spreadsheet.

That means this is not a situation where Rev. 5 and 20x live on different planets.

Forty-four of the 46 current KSI indicators already have an explicit bridge back to the control framework agencies understand.

So why not use it?

Make the Rev. 5 Evidence Layer Do Double Duty

Instead of asking every CSP to invent a completely new collection of bespoke KSI checks, providers could maintain their Rev. 5 control implementation and evidence model as a canonical security evidence layer, then use automation to generate KSI assertions from the controls mapped in the current Consolidated Rules.

The workflow is straightforward.

1

Collect

Continuously collect authoritative evidence for the applicable Rev. 5 controls: cloud configuration, IAM state, vulnerability data, logging configuration, deployment pipelines, inventory, recovery testing, change records, and other deterministic telemetry.

2

Evaluate

Automatically evaluate the implementation status of those controls using repeatable queries and tests.

3

Map

Apply a versioned FedRAMP KSI-to-control mapping layer that identifies which control assertions and supporting evidence are relevant to each KSI.

4

Assert

Produce a machine-readable KSI result that says what was evaluated, which controls and evidence supported the conclusion, when the evaluation occurred, which version of the Consolidated Rules was used, and where human judgment or exceptions were required.

One Security Program, Two Assurance Views

This is hardly hostile to FedRAMP’s modernization goals.

Federal policy already pushes agencies and FedRAMP toward machine-readable authorization and continuous-monitoring artifacts, and the new Security Decision Record (SDR) is explicitly designed to capture implementation, verification, validation, and supporting evidence in a more structured way.

One Security Program, Two Assurance Views
Rev. 5 Control Implementation Cloud configuration, IAM, vulnerability data, logging, inventories, recovery testing, and other control evidence.
Automated Control Assertions Repeatable tests continuously evaluate control implementation and supporting evidence.
KSI Mapping + Roll-Up Logic Versioned mappings connect validated Rev. 5 controls to the relevant FedRAMP 20x KSIs.
20x KSI Assurance Machine-readable KSI results include status, supporting evidence, provenance, and validation.
Agency RMF / ATO View Familiar NIST SP 800-53 control evidence for defensible authorization decisions.
FedRAMP 20x View Automated, continuously refreshed KSI assurance built from the same evidence layer.
One evidence layer supports both agency authorization needs and FedRAMP 20x assurance.

The agency gets familiar control-oriented evidence for its RMF process. FedRAMP gets automated, continuously refreshed KSI assurance. The CSP operates one security program instead of maintaining two parallel universes.

That sounds suspiciously like a compromise that everyone can get on board with.

This Should Not Be a Dumb “All Controls Green = KSI Green” Equation

There is an important caveat. FedRAMP describes these as related SP 800-53 controls. A mapping is not automatically a mathematical equivalence.

A KSI may express an outcome that spans several controls, emphasizes persistent measurement, or requires a level of automation not satisfied merely because someone wrote “Implemented” in an SSP three years ago.

The Consolidated Rules themselves expect KSI evidence to address the measures used, their persistent cycle where applicable, verification, automation sufficiency, and validation.

The proposal should not be: “AC-2 passed; therefore the KSI passed. Everybody go home.”

The better model is evidence reuse with transparent roll-up logic. A KSI assertion should show the relevant mapped controls, the live validation results for those controls, the evidence supporting them, and any KSI-specific logic necessary to demonstrate the stated outcome.

FedRAMP could make this significantly easier by publishing a canonical KSI assertion schema and standardized interpretation rules, with evidence references and rules-version metadata:

Demonstrated  •  Partially Demonstrated  •  Not Demonstrated  •  Not Applicable

That would preserve the outcome-oriented intent of 20x without forcing every CSP, assessor, and agency to independently invent what a “good” KSI test looks like.

Because nothing says “standardization” quite like 400 providers and assessors independently interpreting the same sentence.

And Then There Were Two

What about the two KSIs without control mappings? Those should get purpose-built automation.

44 KSIs with Rev. 5 Mappings
2 KSIs Requiring Dedicated Logic

KSI-CNA-OFA, Optimizing for Availability, could be demonstrated through automated review of high-availability architecture, redundancy, health checks, failover capability, recovery telemetry, RTO/RPO performance, and recovery test results.

KSI-PIY-RES, Reviewing Executive Support, is less infrastructure-friendly, but it can still be systematized.

Evidence might include scheduled executive security reviews, security-goal approval, risk acceptance workflows, budget or investment decisions, and documented governance actions.

Not every security outcome needs to be a cloud API call to be measurable.

Two dedicated KSI mechanisms are manageable.

Forty-six bespoke KSI interpretations layered on top of hundreds of controls CSPs already maintain are not modernization.

It’s the blueprint for a time machine back to the pre-FedRAMP 2011 world that we all despised.

Give Everyone One Source of Security Truth

The most practical path through the Rev. 5-to-20x transition is not to force CSPs to choose between control-based assurance and outcome-based assurance. It is to make one feed the other.

FedRAMP already wants machine-readable artifacts and automated evidence.

Agencies still need enough NIST control-level information to make defensible authorization decisions.

The Consolidated Rules already provide the mapping that connects most KSIs to those controls. Use it.

Let CSPs continuously validate their Rev. 5 controls, preserve the evidence agencies need, and automatically roll that evidence into transparent KSI assertions.

Require dedicated automation where the mapping does not exist.

Version the mappings. Preserve provenance. Let assessors validate the automation instead of repeatedly reconstructing the same security truth in different formats.

FedRAMP gets automation. Agencies get defensible authorization evidence. CSPs stop getting hammered with the unreasonable expectation of maintaining two representations of the same security program.

From Two Systems to One Source of Truth

This is more than a compromise between Rev. 5 and 20x.

It is what a sensible transition should have looked like in the first place.

One Security Program. One Source of Truth.

See how stackArmor can help your organization prepare for the transition from FedRAMP Rev. 5 to 20x without building parallel compliance programs.

Schedule ATO Acceleration Briefing

SHARE

MOST RECENT

FedRAMP 20x: Automation, Reciprocity & What Comes Next

FedRAMP 20x is moving federal cloud security in the right direction. But if agencies still require duplicative documentation and assessments, have we really solved the problem? Johann Dettweiler examines the next challenge: reciprocity.

CONTACT US

This field is for validation purposes and should be left unchanged.