Fortreum Completed Federal Cloud Security Pilot Assessments

The assessment firm validated cloud security protocols through continuous automation across two pilot phases.

Updated on Oct. 1, 2026 in Cybersecurity

Fortreum Completed Federal Cloud Security Pilot Assessments

Live Poll

Do you trust automated security reporting more than traditional manual audits for government cloud systems?

Fortreum and InfusionPoints completed the Class B Low Phase I pilot in July 2025 and the Class C Moderate Phase II pilot in April 2026. The programs demonstrated the effectiveness of the FedRAMP 20x model, which utilizes automation to replace traditional static compliance documentation.

Why it matters

The federal government has transitioned its cloud security assessment model to an automation-first approach to ensure continuous compliance. This shift moves the focus from point-in-time document reviews to systems that persistently verify security evidence.

The assessments utilized 61 specific rules to verify security posture on the AWS GovCloud platform. These 209 individual validations provided the continuous security evidence required to satisfy FedRAMP 20x standards.

The players

Fortreum

This is an assessment firm that specializes in cybersecurity compliance and validation services for federal agencies.

InfusionPoints

This technology services company provided the XBU40 platform used to execute the continuous security testing during the pilots.

The details

Pilot participants utilized the XBU40 platform on AWS GovCloud to demonstrate continuous evidence of system security. Assessors verified the integrity of these systems by testing the platform output directly rather than relying on historical documentation.

Timeline

  1. July 2025: Fortreum and InfusionPoints completed the Class B Low Phase I pilot.

  2. April 2026: The partners finished the Class C Moderate Phase II pilot assessment.

The Tech Race

The pilot assessments follow the requirements set forth by the FedRAMP 20x framework, which mandates automated and continuous monitoring of cloud systems. This represents a foundational shift from legacy compliance processes to real-time, evidence-based security verification for government contractors.

Cloud service providers aiming to work with the government must now prepare to implement automated security verification tools to maintain authorization. This shift likely reduces the manual labor associated with documentation but requires higher technical investment in monitoring infrastructure.

The takeaway

The move toward automated security metrics marks a permanent change in how cloud-based vendors interact with federal regulations. Providers should prioritize adopting continuous validation tools to remain compliant with the increasingly automated audit landscape.

Further reading

For more information on the evolving standards for securing federal data, visit our Cybersecurity section.

Live Poll

Do you trust automated security reporting more than traditional manual audits for government cloud systems?