NorthWatch is here: FedRAMP 20x continuous validation, operationalized.
Explore
→
X
Cloud Security Advisory
Cloud Security Advisory
Compliance Engineering
Security Architecture
Security Engineering
LaunchPad
Documentation Development
Security Gap Analysis
Compliance Roadmap
NorthWatch
Security Compliance
Security Compliance
North America
-
FedRAMP
DoD IL2/IL4/IL5
CMMC
GovRAMP
NIST 800-171
FISMA
NIST Cybersecurity Framework
FFIEC
-
GLBA
HIPAA
MARS-E
PCI DSS
Shared Assessments
Canadian Security Profiles
SOC 2
Global
-
Australian ISM/IRAP
Japan ISMAP
German BSI C5
French SecNumCloud
International ISO 27017
Singapore OSPAR
UK Cyber Essentials
-
Cloud Security Alliance (CSA)
ENS
GDPR
ISOs
About 38North
Company
Leadership
Careers
Learn
Learn
FedRAMP 20x
Blog
Case Studies
Live Now: NorthWatch
Contact the Team
Cloud Security Advisory
Cloud Security Advisory
Security Architecture
Security Engineering
Documentation Development
Security Gap Analysis
Compliance Roadmap
Security Compliance
Security Compliance
North America
FedRAMP
DoD IL2/IL4/IL5
GovRAMP
CMMC
NIST 800-171
FISMA
NIST Cybersecurity Framework
FFIEC
GLBA
HIPAA
MARS-E
PCI DSS
Shared Assessments
Canadian Security Profiles
SOC 2
Global
Australian ISM/IRAP
Japan ISMAP
German BSI C5
French SecNumCloud
International ISO 27017
Singapore OSPAR
UK Cyber Essentials
Cloud Security Alliance (CSA)
ENS
GDPR
ISOs
LaunchPad
Partners
About 38North
Company
Leadership
Careers
Contact The Team
FedRAMP
20x in Practice
,
Articles
October 9, 2026
Process Spotlight: When Routine Recurring Changes Do Not Need a Formal Notification
Read More
20x in Practice
,
Articles
October 7, 2026
Process Spotlight: Getting Your FedRAMP Rules Independently Assessed Each Year
Read More
20x in Practice
,
Articles
September 30, 2026
Process Spotlight: Judging Whether a Vulnerability Is Actually Exploitable
Read More
Articles
September 18, 2026
Reading the Blitz: A Football Take on FedRAMP VER
Read More
20x in Practice
,
Uncategorized
September 16, 2026
Process Spotlight: Deciding Which Vulnerabilities Are Reachable From the Internet
Read More
Articles
August 3, 2026
One Month Into FedRAMP CR26: What Cloud Providers Need to Know
Read More
Articles
May 12, 2026
From Controls to Security Outcomes: How to Think About KSIs in FedRAMP 20x
Read More
Articles
February 15, 2026
Understanding SC-7: Boundary Protection and Logical Isolation in FedRAMP
Read More
Articles
January 30, 2026
FedRAMP Rev. 5 and Encrypted Traffic: What AC-4(4), SI-4(10), and AU-11 Really Require
Read More
Articles
,
Company News
January 9, 2026
WithSecure Partners with 38North Security to Begin FedRAMP Preparation for Cloud Protection for Salesforce
Read More