FedRAMP CR26 & 20x: What Federal Teams Need to Know About the Rev5 Transition (Webinar)
Free Seminar
Free Seminar
FedRAMP is moving toward a more continuous, evidence based approach to cloud security, bringing significant changes to the familiar Rev5 authorization model. For federal employees who are new to FedRAMP, or just beginning to encounter CR26 and FedRAMP 20x, the new terminology and processes can be difficult to navigate.
This webinar breaks down the transition in practical terms. Attendees will see how the move from Rev5 authorization to 20x certification affects areas such as certification classes, system scope and boundaries, security documentation, and ongoing security validation.
The session will also introduce several concepts central to the modernized approach, including Security Decision Records (SDRs), structured security data, Key Security Indicators (KSIs), and automated validation. Rather than examining each topic in depth, the webinar will show how these pieces fit together and why they matter to agencies and cloud service providers.
Attendees will leave with a clearer picture of where FedRAMP is heading, how CR26 and 20x differ from the traditional Rev5 approach, and what their organizations should begin considering as they plan for transition.
Secure and govern AI inside a federal environment — from the threat landscape through to a working agency AI security and governance program.
A full day live on the identity layer: identity, proofing, authentication and MFA, authorization, federation, and the access decision itself — with phishing-resistant MFA at the center.
Practical cybersecurity awareness for the whole government workforce - threats, everyday habits, phishing defense, and the policies that shape your responsibilities.
A half-day live session on insider threat: what the indicators really look like, where to report them, and how insider threat reporting differs from a protected whistleblower disclosure.
Federal agencies are putting AI into service faster than the practices meant to govern and secure it. This intermediate course helps federal staff and their partners build an agency AI governance and security program rooted in federal AI policy and the NIST AI Risk Management Framework — covering AI inventories and risk classification, data governance and privacy, the AI development and acquisition lifecycle, machine learning and generative AI threats, and the oversight and monitoring that keep AI trustworthy, ending with a capstone plan you build yourself.
Assess, authorize, and sustain secure federal cloud services — and stay ahead of FedRAMP's move to the 20x model.
Assess FedRAMP-authorized cloud services, drive the agency ATO process, and hold shared security responsibilities together across the service lifecycle.
A jargon-free grounding in how federal cloud services get secured and where one party's responsibility ends and the other's begins.
An ATO is a beginning, not an ending — federal systems must be watched continuously, with weaknesses tracked and risk reported to leadership over time. This intermediate course grounds Information Security Continuous Monitoring (NIST SP 800-137) in FISMA accountability: design an ISCM strategy, work findings through POA&Ms, and build the metrics and reporting that make ongoing authorization possible.
Recognize and shut down social engineering wherever it comes from — inbox, SMS, phone line, scanned code, or the lobby entrance. Designed to meet the federal yearly security awareness training mandate.