We run this pipeline on our own package: FR2628647239, 3PAO assessment underway

December 7, 2026: is your VDR pipeline built yet?

Under FedRAMP's Consolidated Rules, every certified offering must produce machine-readable VDR/VER vulnerability reporting by December 7, 2026, with most other CR26 requirements following January 1, 2027. Enablement® generates those artifacts from live scan data, inside your own boundary, so you keep your authorization instead of renting a platform's.

The problem

Two options today. Both expensive.

1. Consultants

They rebuild your evidence by hand, every cycle. The deliverable is a snapshot that starts going stale the day it's zipped, and you pay for the rebuild again next cycle.

2. "Instant FedRAMP" platforms

They move your product into their boundary, so the authorization is theirs, not yours. Shared fate, lock-in, and a migration problem waiting at the end.

3. Enablement®

Own your authorization, automate the evidence. The engine runs inside your boundary and generates the CR26 artifacts continuously from your own scan data.

What you get

The evidence engine, inside your boundary

Proof, not promises

We are our own first customer

Our own offering runs on this exact pipeline and is live on the FedRAMP Marketplace under the 20x track, with 3PAO assessment underway on the same artifacts we generate for you.

FAQ

FedRAMP 20x, briefly

What is FedRAMP 20x?

The modern FedRAMP certification type. Instead of a documented control baseline assessed by prose review, offerings are assessed against measurable Key Security Indicators (KSIs), with machine-readable packages and continuous validation between reviews.

What are the CR26 deadlines?

Under the Consolidated Rules for 2026, machine-readable VDR/VER vulnerability reporting is required by December 7, 2026, and most other CR26 requirements take effect January 1, 2027.

What is a KSI?

A Key Security Indicator: a measurable statement about your security posture that can be validated with evidence, ideally automated. Your 3PAO verifies the evidence methods instead of manually assessing each area from documents.

Do I lose my authorization by using Enablement?

No, the opposite. Enablement deploys inside your existing boundary as part of your system, and the authorization remains yours. This is the structural difference from boundary-hosting platforms, where your product moves into someone else's authorized environment.

Does my data or evidence leave my boundary?

No. Scanning, evidence generation, and report assembly all run inside your boundary. There is no external SaaS receiving your telemetry.

What is Enablement's own FedRAMP status?

Listing FR2628647239 on the FedRAMP Marketplace: 20x track, Initial Implementation phase, not yet certified, with 3PAO assessment underway. We publish our full machine-readable package publicly, and the Marketplace listing is always the authoritative source for our current status.

Twenty minutes to a VDR from your own environment

See your real KSI readiness picture before December: no commitment, no data leaving your boundary.