Blog

What FedRAMP 20x KSI Actually Measure, and Why It Changes Everything

White ID badge icon centered within concentric circles on a purple gradient background with a small logo in the corner.

For more than a decade, a FedRAMP package answered one question: can you describe your controls well enough on paper? Providers wrote hundreds of pages of narrative, mapped it to a fixed set of NIST 800-53 controls, and handed the stack to an assessor who checked whether the words lined up. The document was the deliverable. The security was assumed. 

FedRAMP 20x asks a different question, and the Key Security Indicator (KSI) is how it asks. A KSI is not a control to describe. It is a measurable security outcome your system proves, continuously, with machine-readable evidence. The shift is small in wording and enormous in practice. 

From narrative to signal 

Under Rev5, multi-factor authentication was a paragraph. You wrote that you enforced MFA, pointed to a policy, and an assessor read it once a year. Under 20x, MFA is a signal: your environment outputs machine-readable evidence that MFA is active for your privileged users, and that evidence is validated on an ongoing basis, not recited in a document. 

That is the heart of the KSI. It condenses what used to be hundreds of narrative controls into a focused set of outcomes, each one something a tool can check against your live environment. The written story of your security is replaced by the running proof of it. 

Why this is a better test, not just a faster one 

It is tempting to read 20x as “the same audit, but quicker.” It is not. A narrative can be well written and wrong. A KSI cannot pass on eloquence. If your evidence pipeline does not produce the signal, there is nothing to grade. This closes the oldest gap in compliance: the distance between what a document claims and what a system actually does. 

It also changes what “done” feels like. Compliance stops being a project with an end date and becomes a property of how you run. The evidence is generated alongside your code, versioned with it, and refreshed as your environment changes. You are not preparing for an assessment window. You are always in one. 

What this means if you’re starting to look at 20x 

The first instinct of many teams is to ask how many KSIs there are and treat the list as a checklist. That is the wrong first move. The right one is to look at your environment and ask a harder question: which of these outcomes can my system already prove on its own, and which ones am I still describing in words? 

Everywhere you’re still describing, we can help you build the signal instead. Fortreum has been in the details of 20x since the earliest pilots, and the fastest way to know where your evidence pipeline actually stands is to have someone who has done this before look at it with you. Start with the outcomes you can already prove, be honest about the ones you’re still narrating, and let’s map the rest of the way together.