Static evidence is stale.

FedRAMP® 20x requires continuous validation.

NorthWatch connects to operational systems, automates applicable KSI checks, evaluates vulnerability findings in context, and makes current and historical results visible—so teams can see what is passing, what changed, and what needs attention.

NorthWatch

KSI Validation Status

  • Pass: 51% (30)
  • Partial: 24% (14)
  • Fail: 25% (15)

Last Update: February 20, 2026 at 4:20 PM

Total KSIs

59

Key Security Indicators

Validations

368

Total Validations

Success Rate

51%

Passed Validations

SCN

33

Pending Notifications

Compliance has changed.

FedRAMP used to rely on point-in-time assessments: manual artifacts, audit preparation, and evidence assembled around review cycles.
20x shifts the model to continuous validation, where proof comes from live system signals.

Before Point-in-time
  • Point-in-time evidence
  • Manual artifacts
  • Audit preparation
Now Continuous validation
  • Continuous validation
  • Machine-verifiable signals
  • Current readiness visibility
  • Historical metrics
  • Annual independent assessment supported by current evidence

NorthWatch is where FedRAMP 20x assurance becomes visible.

Assurance lives continuously, visibly, and with controlled transparency across three core modules.

VDR (Vulnerability Detection & Response)

NorthWatch ingests vulnerability-scanner findings, applies configured environmental context, calculates PAIN ratings and response deadlines, and tracks whether findings persist across scans.

Vulnerability risk becomes contextual, prioritized, and easier to report.

KSI (Key Security Indicators) Posture

A current view of monitored KSI status, including pass/fail results, failed checks, success percentage, and historical trends.

Posture is visible as it evolves, not reconstructed later.

SCN (Significant Change Notification)

NorthWatch supports configured significant change notification delivery.

Providers remain responsible for the broader change evaluation, approval, recordkeeping, history, and audit process.

How NorthWatch Works

NorthWatch | Compliance Operations Platform for FedRAMP 20x | VDR | VER | KSI | 38North Security | GRC

Continuous validation, in practice.

Current validation visibility

Security posture is continuously visible as systems evolve — not reconstructed later.

  • KSI posture reflects live system behavior
  • Failed checks and changes are easier to see
  • Historical trends show how status changes over time

Assurance is continuously available,
not assembled on demand

Less manual effort, more reliable validation

Move from documentation workflows
to system-generated validation.

  • Reduce reliance on static evidence
  • Generate validation results from operational signals
  • Reduce repetitive artifact collection

Validation becomes part of the system’s
normal operation

Faster decisions, stronger confidence

Make security posture easier to evaluate,
trust, and act on.

  • Stakeholders can review current posture at any time
  • Security reviews move faster with structured assurance
  • Controlled transparency supports internal and external trust

When assurance is current, decisions don’t stall

Better economics, less repeated effort

FedRAMP 20x changes where cost accumulates: less recurring audit activity, less duplicated infrastructure, and less manual evidence work.

  • Reduce parallel environments and duplicated operational effort
  • Shift assessment activity away from large, recurring audit events
  • Replace manual evidence collection with automated pipelines
  • Keep engineering focused on product, security, and system improvement

When proof comes from the system, teams spend less time reconstructing evidence later.

Controlled Transparency

FedRAMP 20x makes more security posture visible.

NorthWatch helps control what gets shared, with whom, and in what format — so teams can provide useful assurance without exposing more than they intend.

Transparency becomes intentional, structured, and defensible.

Built for independent validation
— not self-certification

NorthWatch does not replace assessment. It makes it more reliable.

FedRAMP 20x increases the importance of continuous, machine-verifiable assurance.
NorthWatch supports this model by generating structured, operational proof directly from live systems — not reconstructed artifacts.

What this enables

  • Less evidence churn
  • Clearer validation of control effectiveness
  • Fewer late-stage surprises

Validation becomes

  • Grounded in live system behavior
  • Continuously available instead of assembled on demand
  • Less dependent on manual reconstruction of evidence

The Product Brief

A practical overview of how NorthWatch turns live security signals into visible, continuous FedRAMP 20x assurance.

Where are you
in the FedRAMP process?

Most teams fall into one of these four categories:

New to FedRAMP

You’re evaluating whether FedRAMP 20x is the right starting point for your system, maturity, and federal market strategy.

Stalled Without a Sponsor

You’ve invested in FedRAMP, but sponsorship has slowed the path forward. 20x may offer a new route to authorization.

Already FedRAMP Certified, Preparing for VDR+VER

You have an existing Rev. 5 Certification and need to understand what VDR and VER require before the December 7 deadline.

Evaluating the Move to 20x

You want to understand how your current FedRAMP investment maps to continuous validation, live signals, and 20x readiness.

Common Questions

What teams ask before they start

Answers to the questions that come up most often in NorthWatch walkthroughs.

Bring your hardest questions →
Does NorthWatch replace our vulnerability scanner?

No. Your existing scanners continue to identify vulnerabilities. NorthWatch ingests that vulnerability data and evaluates each finding using the configured security context of the affected environment, then calculates the applicable PAIN rating and response deadline.

Is NorthWatch SaaS or self-hosted?

NorthWatch is self-hosted and deployed within your environment. It is not a SaaS platform.

Does NorthWatch replace our change-management system?

No. The SCN capability supports the FedRAMP notification and reporting workflow, and integrates with your existing change-management system rather than replacing it. Providers remain responsible for the broader change evaluation, approval, and recordkeeping process.

How does NorthWatch know whether a KSI is passing?

NorthWatch connects to the authoritative operational source for each applicable KSI and runs configured validation logic against that data. The validation record can show the source queried, the resources evaluated, the expected condition, the observed result, and the resulting status.

Can a KSI be partially passing, or is it only pass/fail?

NorthWatch supports Pass, Partial, and Fail KSI status. A Partial status reflects a KSI for which some associated validations are passing and others are not.

Can we change what NorthWatch checks, and how often it checks?

Yes. Validations are built around your environment rather than applied as fixed universal tests, and you are involved in defining how your implementation should be represented and validated. The validation schedule is configurable depending on the implementation.

What if a system we need to validate does not have an API?

38North designs the validation pipeline around your environment. That may use APIs, logs, configuration data, custom parsers, or a defined manual process where a requirement cannot reasonably be automated. NorthWatch is not limited to a fixed catalog of integrations.

How does NorthWatch handle ephemeral assets?

NorthWatch groups assets into asset classes, so contextual attributes do not have to be recreated for every short-lived asset. New assets are associated with an existing class based on configured characteristics, and assets that disappear from later inventories are reconciled as the environment changes.

Can different agencies or customers be limited to only what they should see?

Yes. NorthWatch supports role-based access and separation between client and system views, so authorized stakeholders can be given access to the information they are entitled to and nothing beyond it. Access remains controlled by the provider and the configured role model.

Will NorthWatch automatically detect a change and create an SCN?

No. NorthWatch does not watch the environment and independently decide that a change constitutes a significant change. The intended automation starts from your existing change-management process; information from that workflow can then populate the appropriate SCN record.

Does NorthWatch replace independent assessment?

No. Annual independent assessment remains under FedRAMP 20x. NorthWatch supports that assessment with structured, operational validation generated directly from live systems, rather than evidence reconstructed after the fact.

What does onboarding actually involve?

Implementation starts by understanding your Cloud Product Environment and identifying where each relevant requirement is actually being met. 38North maps the technologies and authoritative sources, determines the required validation logic and data flows, and then builds or configures the pipelines the implementation needs.

Make FedRAMP
assurance continuous.

If 20x requires everyday assurance, your compliance surface cannot be a periodic scramble.
NorthWatch turns operational security signals into visible, live assurance.