Under FedRAMP's Consolidated Rules, every certified offering must produce machine-readable VDR/VER vulnerability reporting by December 7, 2026, with most other CR26 requirements following January 1, 2027. Enablement® generates those artifacts from live scan data, inside your own boundary, under your own authorization.
The platform and its scanning stack install inside your existing boundary, as part of your system.
Evidence collection is activated for all 46 Key Security Indicators and your boundary is described in the 20x document set.
CR26 artifacts assemble continuously from your own scan data: schema-validated, current, and re-runnable.
Your 3PAO works from live evidence endpoints. We provide assessor liaison through the assessment and refer assessors at no cost.
Submission does not wait on a six-month monitoring history: under the published rules, mechanisms in place plus a written commitment satisfy that requirement at initial certification.
$7,500 one-time
$48,000 one-time
$2,500 /month per offering
| Also | Cost |
|---|---|
| Rev5 → 20x Migration, Class B (Low) | $19,500 one-time |
| Class B → Class C upgrade, any time later | $28,500 one-time, the exact difference between the two migration fees. Starting at Low carries no penalty. |
| Class D (High) migration | Quoted individually |
| 3PAO referral | No charge. Referred assessors have committed pricing against the reduced 20x verification workload. |
How these costs compare with consultants and GRC platforms →
Our offering is listed on the FedRAMP Marketplace under the 20x track, and our 3PAO assessment runs on the same artifacts this pipeline generates for you.
The modern FedRAMP certification type. Instead of a documented control baseline assessed by prose review, offerings are assessed against measurable Key Security Indicators (KSIs), with machine-readable packages and continuous validation between reviews.
Under the Consolidated Rules for 2026, machine-readable VDR/VER vulnerability reporting is required by December 7, 2026, and most other CR26 requirements take effect January 1, 2027.
A Key Security Indicator: a measurable statement about your security posture that can be validated with evidence, ideally automated. Your 3PAO verifies the evidence methods instead of manually assessing each area from documents.
No, the opposite. Enablement deploys inside your existing boundary as part of your system, and the authorization remains yours. This is the structural difference from boundary-hosting platforms, where your product moves into someone else's authorized environment.
No. Scanning, evidence generation and report assembly all run inside your boundary. There is no external SaaS receiving your telemetry.
Listing FR2628647239 on the FedRAMP Marketplace: 20x track, Class C (Moderate), Initial Implementation phase, with 3PAO assessment underway. The Marketplace listing is the authoritative source for current status.
See your real KSI readiness picture before December, with no data leaving your boundary.
Deterministic helper: every answer here is authored and approved, never AI-generated. That is rather the point.