Fortreum has completed FedRAMP 20x pilot assessments with cybersecurity provider InfusionPoints at both the Low and Moderate impact levels, giving the companies an early role in testing the federal government’s shift toward automation-first cloud security assessments.
The companies completed the Class B (Low) Phase I pilot in July 2025 and the Class C (Moderate) Phase II pilot in April 2026, according to Fortreum. The work covered 11 Key Security Indicators (KSIs), 61 KSI rules, and 209 validations for InfusionPoints’ XBU40 platform on AWS GovCloud.
The Moderate assessment was particularly significant because Fortreum and InfusionPoints entered the pilot before an established assessment process for that level was in place.
“There was no finished playbook and no previous Moderate assessment to follow,” said Jason Shropshire, COO at InfusionPoints. “We had to show that continuous evidence could work under real assessment conditions, not simply demonstrate the idea.”
FedRAMP 20x shifts compliance toward continuous evidence
FedRAMP 20x is the federal government’s new cloud security assessment and certification model, designed to replace much of the traditional reliance on static compliance documentation with continuous security measurement, automation, and machine-readable evidence.
FedRAMP says the model emphasizes continuously enforced, monitored, and reported security rather than security controls prepared primarily for point-in-time audits. Classes A, B, and C have now moved beyond the pilot stage, with finalized certification rules available.
The distinction becomes more pronounced at higher certification levels. Under the finalized rules, Class C providers must use automated methods to persistently verify and validate KSIs, including at least two automated methods for each indicator, while providing historical metrics from persistent validation.
FedRAMP 20x changes the assessor’s role
For Fortreum, that changes what independent assessors are examining.
“Continuous evidence changes the assessor’s job,” said James Leach, CEO and co-founder of Fortreum. “Assessors must test the system producing the evidence and determine whether its output can be trusted.”
FedRAMP’s current rules reinforce that role: Class B and Class C providers must include all applicable KSIs in an independent FedRAMP assessment at least annually.
Compliance automation expands services opportunity
The work also fits into a broader opportunity for cybersecurity consultants and service providers as federal compliance programs become more technically complex.
Channel Insider previously spoke with Fortreum Chief Strategy Officer Andrew Black about a similar dynamic surrounding CMMC. Black said organizations often underestimate differences between commercial certifications and federal requirements, creating opportunities for service providers to help customers interpret requirements, define security boundaries, and build compliant environments.
FedRAMP 20x adds an automation dimension to that opportunity. Instead of helping customers prepare documentation for an audit alone, providers supporting federal cloud environments may increasingly need expertise around continuous evidence collection, compliance engineering, security telemetry, and the systems used to prove that controls remain effective.
For Fortreum and InfusionPoints, the pilots offer an early demonstration of what that model can look like in practice.
“Automation-first compliance had to prove itself under assessment,” Leach said. “These pilots showed that continuous evidence can work, but the platform, evidence pipeline, and assessment process must be engineered to work together. Automating a weak process only produces weak evidence faster.”




