Skip to content
All posts

The Pathway from SOC 2 to FedRAMP 20x: SOC 2 Bridge and Submission Readiness


What is FedRAMP 20x?

FedRAMP 20x is the next step in modernization of the federal government's cloud security program. It is a big step in automation and replaces documentation heavy compliance models with a cloud native approach that allows for continuous validation. FedRAMP 20x is based on KSI (Key Security Indicators) and is designed with speed to market in mind. FedRAMP currently includes Classes available this year, Class A, Class B and Class C Certifications, with Class D planned for a future phase.

The Class A Opportunity

FedRAMP 20x has opened the doors to any CSP to participate in FedRAMP 20x, and even created a pathway to leverage your current SOC 2 Type II report, as long as it has been completed in the last 12 months. A FedRAMP package is still required.

What is in a FedRAMP package?

A FedRAMP Package includes CPO, SDR, OCR, Rules response matrix, KSI narratives and evidence index. You can find the information to fill out these items from your SOC 2 report. As long as you have your package complete, you can submit for FedRAMP 20x Class A.

How do you complete your FedRAMP package?

First, you validate that FedRAMP makes sense for your organization. Do you have federal prospects? Do you have clients that support federal clients? Do you support automation and are you cloud native? Have you completed a SOC 2 Type II in the last 12 months? If the answer to these is yes, then it's time to map evidence from your SOC report to the FedRAMP 20x Class A KSI deltas.

Organizations that already use compliance automation tools or have established GRC engineering practices may have an easier path to FedRAMP 20x. With controls and evidence already maintained in structured workflows, teams can spend less time gathering documentation and more time identifying and addressing gaps between SOC 2 and FedRAMP 20x requirements.

It is important to understand that the FedRAMP package is different from the SOC 2 Type 2 report, and that if you submit a pile of SOC 2 PDFs, the FedRAMP PMO won't know what to do. To build the package, which includes your CPO, SDR, OCR, JSON and Trust center content, you can refer to your SOC 2 report Auditor opinion, management assertion, system description, test of controls, exceptions and CUECs and subservice orgs. There is likely a delta between the SOC 2 reports and the Final submission packet for FedRAMP because there are some rules that do not translate cleanly. For this, you would write KSI narratives, which include summaries so the reviewers can understand without digging into the SOC 2 report too deep. Combine that with your Rules response matrix, and evidence index, and you have a submission ready packet.

How do I know that my package will be accepted?

Prescient Security is a FedRAMP 3PAO with deep experience and expertise in the FedRAMP world. We offer Independent Validation and Verification (IV&V) to ensure your package is complete and ready for FedRAMP. This includes:

  • Defect log before submission

  • Evidence sufficiency and freshness review

  • JSON/Schema validation

  • Clear assumptions and limitations 

 

How long does this process take?

All in all, FedRAMP 20x Class A can be completed in about 4-6 weeks, as long as there is a fresh SOC 2 report, and the boundary is already documented. To complete this process in an efficient manner, you would only need to provide:

  • Complete SOC 2 type II report

  • Bridge/gap letter and next audit schedule

  • Architecture and data flow diagrams

  • Vulnerability and incident evidence

  • IAM, Training, network, and encryption evidence

  • Trust Center or public information content

 

How do I learn more?

Connect with our federal team today!

 

Learn more about the pathway from SOC 2 to FedRAMP