Scrutineer · By framework
FedRAMP compliance software for FedRAMP 20x, KSI evidence and Rev 5 controls
FedRAMP compliance software now has to satisfy two things at once: the Rev 5 baseline most cloud services were built against, and FedRAMP 20x, where evidence is produced continuously rather than written up for an assessor. Scrutineer maps your existing controls to both.
The rules changed in June 2026: the Consolidated Rules for 2026 renamed FedRAMP Authorization to FedRAMP Certification and replaced impact levels with Certification Classes A through D. Scrutineer is readiness tooling, not a 3PAO.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with FedRAMP
KSIs and Rev 5 controls in one map
FedRAMP 20x collapses control narratives into a much shorter set of Key Security Indicators, while Rev 5 still runs on 156 controls at Low and 323 at Moderate. Scrutineer maps your existing controls to whichever you are pursuing, so you can see coverage on both without maintaining two programs by hand.
Evidence produced continuously
The whole point of 20x is everyday proof rather than audit-day proof, and pilot participants were expected to automate the large majority of their evidence. Read-only connections to your cloud, identity and ticketing systems collect artifacts on a schedule and attach them to the indicator or control they actually prove.
Gaps ranked before the assessor sees them
When a control drifts or evidence goes stale, Scrutineer flags it, ranks it by impact and tracks it to closure with a named owner. You walk into the 3PAO assessment knowing what is weak instead of finding out in a findings report.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps existing controls to FedRAMP 20x Key Security Indicators
- Covers the Rev 5 Low, Moderate and High baselines for services still on that path
- Collects evidence automatically and read-only, on a schedule
- Tracks open gaps with owners, target dates and impact ranking
- Crosswalks FedRAMP work to SOC 2, ISO 27001 and NIST SP 800-171
- Scores the subservice organizations and vendors inside your authorization boundary
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
CR26 reference
FedRAMP Certification Classes A through D, and what they replace
The Consolidated Rules for 2026 retired the Low, Moderate and High impact-level labels in favor of Certification Classes. This is how the old names map to the new ones.
| Certification class | What it replaces | Who it fits |
|---|---|---|
| Class A | A new baseline with no Rev 5 equivalent | Early-stage pilot use by agencies at negligible or low risk, with a longer runway to a full certification |
| Class B | The former Li-SaaS and Low baselines | Services handling low-impact federal information, including many single-purpose SaaS tools |
| Class C | The former Moderate baseline | The bulk of SaaS sold to federal agencies, where most controlled unclassified information sits |
| Class D | The former High baseline | Systems where a compromise would be severe: law enforcement, emergency services, health and financial data |
Class labels published by FedRAMP in notice NTC-0004 and the Consolidated Rules for 2026. Verified July 2026. Confirm current status at fedramp.gov.
Good questions
Questions about FedRAMP
Keep reading
Guides that go deeper on federal cloud compliance
FedRAMP 20x vs Rev 5, compared
The requirements, the CR26 timeline and how to decide which path a new authorization effort should take.
Read the guideCMMC Phase 2 suspended: what still applies
What the July 13, 2026 pause changed for defense contractors, and what stayed in force.
Read the guideAll 93 ISO 27001 Annex A controls
Every control by number and name, and the evidence auditors ask for against each one.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification