Fortreum Completed Federal Cloud Security Pilot Assessments
The assessment firm validated cloud security protocols through continuous automation across two pilot phases.
Updated on Oct. 1, 2026 in Cybersecurity

Live Poll
Do you trust automated security reporting more than traditional manual audits for government cloud systems?
Fortreum and InfusionPoints completed the Class B Low Phase I pilot in July 2025 and the Class C Moderate Phase II pilot in April 2026. The programs demonstrated the effectiveness of the FedRAMP 20x model, which utilizes automation to replace traditional static compliance documentation.
Why it matters
The federal government has transitioned its cloud security assessment model to an automation-first approach to ensure continuous compliance. This shift moves the focus from point-in-time document reviews to systems that persistently verify security evidence.
The assessments utilized 61 specific rules to verify security posture on the AWS GovCloud platform. These 209 individual validations provided the continuous security evidence required to satisfy FedRAMP 20x standards.
The players
Fortreum
This is an assessment firm that specializes in cybersecurity compliance and validation services for federal agencies.
InfusionPoints
This technology services company provided the XBU40 platform used to execute the continuous security testing during the pilots.
The details
Pilot participants utilized the XBU40 platform on AWS GovCloud to demonstrate continuous evidence of system security. Assessors verified the integrity of these systems by testing the platform output directly rather than relying on historical documentation.
Timeline
July 2025: Fortreum and InfusionPoints completed the Class B Low Phase I pilot.
April 2026: The partners finished the Class C Moderate Phase II pilot assessment.
The Tech Race
The pilot assessments follow the requirements set forth by the FedRAMP 20x framework, which mandates automated and continuous monitoring of cloud systems. This represents a foundational shift from legacy compliance processes to real-time, evidence-based security verification for government contractors.
Cloud service providers aiming to work with the government must now prepare to implement automated security verification tools to maintain authorization. This shift likely reduces the manual labor associated with documentation but requires higher technical investment in monitoring infrastructure.
The takeaway
The move toward automated security metrics marks a permanent change in how cloud-based vendors interact with federal regulations. Providers should prioritize adopting continuous validation tools to remain compliant with the increasingly automated audit landscape.
Further reading
For more information on the evolving standards for securing federal data, visit our Cybersecurity section.
Live Poll
Do you trust automated security reporting more than traditional manual audits for government cloud systems?










