sponsor content What's this?
What Comes After Certification? The Shift to Compliant Security Operations.
Presented by
FedHIVE
Federal cloud compliance was once largely treated as a series of boxes to check. Organizations documented their controls, assembled hundreds of pages of artifacts, underwent third-party review and submitted the results for government approval. Reaching the required federal standard represented a major milestone.
“Now, what we're starting to move towards is more of an operational function within the security environment,” said Michael Cardaci, CEO of FedHIVE, during a recent episode of GovExec TV’s Five Questions. “Instead of just a checklist, we're looking at what's the evidence associated with your security, and how are you engaging those things, and how are you proving that to the government.”
FedRAMP and other federal security certifications and authorizations still establish an important baseline for technology providers. What changes after that milestone is the operating environment: but the process has become far more dynamic. As agencies operate in increasingly complex digital environments and demand greater data and systems security, security requirements are now continuously evolving, placing greater demands on technology providers to demonstrate continuous compliance, provide 24/7 monitoring, address vulnerabilities in real-time, and serve as trusted partners in navigating changing mission and security demands.
“This is a whole life cycle of your application, you're going to be doing this forever,” Cardaci said. “Once you have that authorization, you need to work with the agencies, every agency that you're going to be selling to, on an ongoing basis, making sure that your vulnerabilities are met every day, every hour.”
The next phase of compliance, laid out in initiatives like FedRAMP 20x, also places greater emphasis on key security indicators (KSIs) and automation that can help agencies consume security information more quickly.
The larger shift is from proving compliance at a point in time to making security and compliance part of ongoing operations. That is the idea behind Compliant Security Operations: monitoring what is happening, addressing issues as they emerge, producing evidence and maintaining the communication required between technology providers and government. .
Certification is only the beginning
FedHIVE helped pioneer a compliance accelerator model designed to streamline the path to federal certification. But Cardaci draws an important distinction between reaching that milestone faster and sustaining what comes after it.
“Acceleration just gets you to the starting line faster,” Cardaci said. “We're there to help guide folks through. If they do it on their own, there's a lot of learning and experience and misfires and blind alleys that they go down. We help try and eliminate all of those things so you can get to that starting line, but this is just the beginning.”
After certification, the work becomes highly operational. Teams have to monitor vulnerabilities, manage plans of action and milestones (POAMs), coordinate with developers and technical staff, and address issues before deadlines turn them into last-minute compliance problems.
FedHIVE works across those functions, serving as an intermediary, or “connective tissue between the ISV or the CSP and the government,” where differences in priorities, perspectives and expertise can complicate the exchange of information.
That connective role matters because the two sides need different things from the same security process. Agencies need evidence they can evaluate, while providers need to understand what their government customers expect them to demonstrate. Those expectations can also vary depending on the provider, the system and the sensitivity of the data involved.
"Security is really a spectrum. ... The more secure something is, the harder it is to use it. The less secure, the easier it is, but the more vulnerable it is," said Cardaci. "It's playing on the spectrum that the agency deems as correct with regard to their data, and us translating that so the ISV or the CSP understands this is what we need to do in order to make sure that you can continue to provide the services to the government."
Applying DevSecOps lessons to continuous compliance
The evolution of compliance has parallels to the rise of DevSecOps, which brought security more directly into software development rather than leaving it for a later stage of the process.
Compliant Security Operations apply a similar principle to compliance: make security part of the ongoing operating process rather than treating it as work that happens only around a certification or review.
“Instead of looking at the entire waterfall like we used to look at development, we've gone into looking at things more modularly,” Cardaci said. “That's allowed us also to look at these compliance pieces as modules, and being able to quickly attack with either AI support or some of the other automations, whatever the vulnerabilities are, and move in and resolve those based on priority.”
The practical change is important. Rather than waiting to address a large set of compliance issues at once, teams can identify what needs attention, prioritize the work and resolve vulnerabilities as part of an ongoing process.
Urgency is only likely to increase as attackers gain access to many of the same technologies, including AI bots capable of continuously targeting government systems, reinforcing the need, Cardaci said, to embed security throughout the organization.
“You're going to have to fight that with automation from a security standpoint,” he said. “You're going to have to fight that with folks that are vigilant on the security side with regard to the compliant operations, security operations of an organization.”
For federal technology providers, the message is not that certification matters less. It is that certification alone cannot do the work that follows. Evidence has to stay current. Vulnerabilities have to be addressed. Providers and agencies have to remain in communication. And those activities have to continue as the security environment changes.
“The agency really wants their data secure,” Cardaci said. “They don't want to just have documentation that we did this at one point, and now we should be okay. It's ever evolving … We're watching over it to make sure that both the ISV is doing what they're supposed to be doing, and the CIO is communicating what they need, and then we're working together.”
Learn more about how FedHIVE helps federal technology providers operationalize compliance beyond authorization.
This content is made possible by our sponsor FedHIVE; it is not written by and does not necessarily reflect the views of Nextgov/FCWs editorial staff.
NEXT STORY: One Citizen Record, Many Federal Missions




