<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>FedRAMP 20x on</title><link>https://waypointca.com/blog/tags/fedramp-20x/</link><description>Recent content in FedRAMP 20x on</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 11 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://waypointca.com/blog/tags/fedramp-20x/index.xml" rel="self" type="application/rss+xml"/><item><title>FedRAMP 20x Turns Compliance Into Code</title><link>https://waypointca.com/blog/posts/fedramp-20x-compliance-becomes-code/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><guid>https://waypointca.com/blog/posts/fedramp-20x-compliance-becomes-code/</guid><description>20x is not a version bump. It replaces narrative control descriptions with automated Key Security Indicators, replaces the annual audit with continuous validation, and replaces documents with machine-readable data. Here is what that actually demands of a cloud service provider.</description></item><item><title>Your FedRAMP Package Has to Be Machine-Readable by September 30</title><link>https://waypointca.com/blog/posts/fedramp-machine-readable-september-30-deadline/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><guid>https://waypointca.com/blog/posts/fedramp-machine-readable-september-30-deadline/</guid><description>RFC-0024&amp;rsquo;s machine-readable package requirements were confirmed in NTC-0009 and finalized in the Consolidated Rules for 2026, with initial compliance due September 30, 2026. They apply to existing Rev 5 certifications, not just new applicants, and most providers have not started.</description></item></channel></rss>