Scrutineer.ai

Scrutineer · By framework

FedRAMP compliance software for FedRAMP 20x, KSI evidence and Rev 5 controls

FedRAMP compliance software now has to satisfy two things at once: the Rev 5 baseline most cloud services were built against, and FedRAMP 20x, where evidence is produced continuously rather than written up for an assessor. Scrutineer maps your existing controls to both.

The rules changed in June 2026: the Consolidated Rules for 2026 renamed FedRAMP Authorization to FedRAMP Certification and replaced impact levels with Certification Classes A through D. Scrutineer is readiness tooling, not a 3PAO.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with FedRAMP

KSIs and Rev 5 controls in one map

FedRAMP 20x collapses control narratives into a much shorter set of Key Security Indicators, while Rev 5 still runs on 156 controls at Low and 323 at Moderate. Scrutineer maps your existing controls to whichever you are pursuing, so you can see coverage on both without maintaining two programs by hand.

Evidence produced continuously

The whole point of 20x is everyday proof rather than audit-day proof, and pilot participants were expected to automate the large majority of their evidence. Read-only connections to your cloud, identity and ticketing systems collect artifacts on a schedule and attach them to the indicator or control they actually prove.

Gaps ranked before the assessor sees them

When a control drifts or evidence goes stale, Scrutineer flags it, ranks it by impact and tracks it to closure with a named owner. You walk into the 3PAO assessment knowing what is weak instead of finding out in a findings report.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps existing controls to FedRAMP 20x Key Security Indicators
  • Covers the Rev 5 Low, Moderate and High baselines for services still on that path
  • Collects evidence automatically and read-only, on a schedule
  • Tracks open gaps with owners, target dates and impact ranking
  • Crosswalks FedRAMP work to SOC 2, ISO 27001 and NIST SP 800-171
  • Scores the subservice organizations and vendors inside your authorization boundary
FEDRAMP readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Mapped to controls · evidence-linked 3 GAPS

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

CR26 reference

FedRAMP Certification Classes A through D, and what they replace

The Consolidated Rules for 2026 retired the Low, Moderate and High impact-level labels in favor of Certification Classes. This is how the old names map to the new ones.

Certification class What it replaces Who it fits
Class A A new baseline with no Rev 5 equivalent Early-stage pilot use by agencies at negligible or low risk, with a longer runway to a full certification
Class B The former Li-SaaS and Low baselines Services handling low-impact federal information, including many single-purpose SaaS tools
Class C The former Moderate baseline The bulk of SaaS sold to federal agencies, where most controlled unclassified information sits
Class D The former High baseline Systems where a compromise would be severe: law enforcement, emergency services, health and financial data

Class labels published by FedRAMP in notice NTC-0004 and the Consolidated Rules for 2026. Verified July 2026. Confirm current status at fedramp.gov.

Good questions

Questions about FedRAMP

FedRAMP compliance means a cloud service has been assessed against the Federal Risk and Authorization Management Program and cleared for use by US federal agencies. In practice it means implementing a defined security baseline, documenting it, having an accredited third-party assessment organization test it, and then continuously monitoring and reporting on it. It is the standard route to selling cloud software to the federal government.
Any cloud service provider whose product will hold or process federal information on behalf of an agency. That covers SaaS, PaaS and IaaS sold directly to agencies, and it frequently reaches subcontractors and resellers whose software sits inside an agency workflow. If a federal contract or a prime contractor asks where your service sits in the FedRAMP Marketplace, the requirement applies to you.
They depend on the path. Under Rev 5 you implement a NIST SP 800-53 baseline, roughly 156 controls at Low and 323 at Moderate, write a System Security Plan, pass a 3PAO assessment and run continuous monitoring afterward. Under FedRAMP 20x you satisfy a much smaller set of Key Security Indicators, but you are expected to prove them with automated, machine-readable evidence on an ongoing basis.
FedRAMP 20x is the redesigned authorization approach the program began piloting in 2025 to cut the cost and time of getting certified. It replaces long written control narratives with Key Security Indicators validated by automated evidence, and it added a Program path that does not require a sponsoring agency. It became broadly available under the Consolidated Rules for 2026 in June 2026.
Rev 5 is documentation-led and audit-day oriented: you write narratives for every control in your baseline and prove them during an assessment window. FedRAMP 20x is evidence-led and continuous: a far shorter list of Key Security Indicators, validated by automation you keep running. Rev 5 also usually requires an agency sponsor, while the 20x Program path does not.
Not any more, if you take the Program path under FedRAMP 20x. That change is the single biggest opening for smaller vendors, because the old requirement to find an agency willing to sponsor you before you started was what kept many companies out of the market entirely. The traditional agency path still exists and is still sponsor-based.
It is being retired on a published runway rather than switched off. FedRAMP has said it will stop accepting applications for new Rev 5 certifications in June 2027, and existing Rev 5 certifications are expected to sunset by the end of 2028. Services already certified keep their status in the meantime, so the practical question for most teams is whether to start a new effort on Rev 5 or go straight to 20x.
No, and treat any vendor implying otherwise with suspicion. Software maps your controls, gathers the evidence, tracks your gaps and keeps continuous monitoring honest. The certification itself comes through the official process: an accredited 3PAO assesses you and FedRAMP or a sponsoring agency issues the authorization. Scrutineer prepares you for that rather than substituting for it.
A meaningful share of it, yes. Access control, multifactor authentication, encryption, logging, change management, incident response and vendor oversight all appear in some form across SOC 2, ISO 27001 and the FedRAMP baselines. What does not carry over is the federal-specific work: authorization boundary definition, US-person and location requirements where they apply, and the continuous monitoring cadence FedRAMP expects after you are certified.

Keep reading

Guides that go deeper on federal cloud compliance

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification