The 38North Security Podcast

38North Security

Join us as we discuss news and current events, trends, and controversies in the world of cybersecurity. We have strong feelings and they're not limited to FedRAMP, CMMC, FISMA, IRAP, security engineering, or documentation. Anything goes -- some of the things we say are probably even helpful! Interested in having words? Email us at info@38northsecurity.com.

  1. Episode 1

    FedRAMP 20x Is Here: The Six Changes That Matter Most

    With FedRAMP's Consolidated Rules for 2026 being final, FedRAMP 20x is officially here.  That changes how cloud service providers enter FedRAMP, define scope, prove security, maintain certification, and work with federal agencies. In this episode, Ingrid Velasquez-Woodley speaks with Sam Leestma, Vice President of Solutions Engineering, and Spence Witten, Principal Consultant at 38North Security, about the six parts of CR26 most likely to affect cloud providers and agencies. Topics include: * How the new certification classes differ from the Rev. 5 impact levels* Whether Minimum Assessment Scope will actually reduce cost and complexity* Why Key Security Indicators may provide better assurance than point-in-time evidence* Whether the Security Decision Record could become the next oversized compliance document* What VDR and VER require before the December 7, 2026 deadline* Why existing Rev. 5 providers may struggle with vulnerability automation* How ongoing certification differs from continuous validation* Whether annual assessments should become less burdensome* Why CR26 limits agencies from creating their own parallel FedRAMP requirements* What the major CR26 transition dates mean for providers* What CSPs considering 20x—and those already holding Rev. 5 certifications—should do now The discussion also covers where FedRAMP got the model right, where the final rules still create uncertainty, and how implementation by agencies, assessors, and providers will determine whether CR26 actually reduces duplication and improves security visibility. Important dates discussed: June 24, 2026 — CR26 becomes finalJuly 4, 2026 — Optional early adoption beginsJuly 28, 2026 — FedRAMP Ready becomes a legacy designationAugust 3, 2026 — Class A applications openAugust 10, 2026 — Limited Rev. 5 Class B and C transition pathways openAugust 31, 2026 — 20x Class B and C applications openDecember 7, 2026 — VDR and VER become mandatoryJanuary 1, 2027 — Broader mandatory CR26 adoption beginsJune 11, 2027 — FedRAMP stops accepting new Rev. 5 certification applications Explore more FedRAMP 20x insights from 38North Security: https://38northsecurity.com/fedramp-20x/   Explore 38North Security’s FedRAMP services:https://38northsecurity.com/security-compliance/north-america/fedramp/ #FedRAMP #FedRAMP20x #cloudsecurity #cybersecurity #govtech  #38NorthSecurity #federal #cloudsecuritypodcast

About

Join us as we discuss news and current events, trends, and controversies in the world of cybersecurity. We have strong feelings and they're not limited to FedRAMP, CMMC, FISMA, IRAP, security engineering, or documentation. Anything goes -- some of the things we say are probably even helpful! Interested in having words? Email us at info@38northsecurity.com.