<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Fedramp on CuraSec</title><link>https://curasec.metacog.co.kr/tags/fedramp/</link><description>Recent content in Fedramp on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 24 Jul 2026 12:43:46 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/fedramp/index.xml" rel="self" type="application/rss+xml"/><item><title>FedRAMP 20x Replaces Rev5 With Continuous Evidence Requirements</title><link>https://curasec.metacog.co.kr/insights/2026-07-24-fedramp-rev5-is-ending-what-the-20x-transition-really-requir/</link><pubDate>Fri, 24 Jul 2026 12:43:46 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-24-fedramp-rev5-is-ending-what-the-20x-transition-really-requir/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If your team supports a FedRAMP-authorized product, start mapping how you&amp;rsquo;ll generate continuous, machine-readable control evidence — point-in-time assessment artifacts will no longer suffice once the transition deadline arrives.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If your organization holds or pursues FedRAMP authorization, place the Rev5-to-20x transition on the roadmap this quarter: budget for tooling that produces continuous evidence and assess your current ATO timeline against the sunset date. Note this piece appears to be vendor-authored content from Anecdotes, so verify transition specifics against GSA primary sources.&lt;/li>
&lt;/ul></description></item></channel></rss>