One platform for every FedRAMP compliance need. Cloud service
providers collect evidence and track each requirement, assessors
review from the same record, and agencies review the package.
FedRAMP 20x and Rev 5, one engine, with AI that drafts and answers
from your own evidence and runs on Vertex AI under FedRAMP High.
evaluated 2h agoevaluated just now
Run validation
Running…
Posture
33/42 attested36/42 attested
↗ +8 pts
of evaluated checks passing
3336Satisfied
31Not satisfied
5Needs evidence
10Error
rules 2026.07.14.01 · evaluated 2026-08-11 09:12Z · 2h agorules 2026.07.14.01 · evaluated 2026-08-11 11:32Z · just now
Evidence sources
AWSAmazon Web Servicesprod-govcloud2h agojust now
AZUMicrosoft Azureacme-gov tenant2h agojust now
OKTOktaacmecloud.okta.com2h agojust now
Manage connectors
Needs attention
All indicators
VDR-TFR-KEVRemediate KEVs2 resources match CISA KEV catalog entries · earliest due date in 3 daysNo open KEV matches in the collected evidenceNot satisfiedSatisfied
VDR-TFR-PDDPersistent Drift DetectionDrift evidence is stale · last evaluated 9 days agoDrift evaluated across 214 collected resourcesNot satisfiedSatisfied
VER-TFR-MHRMonthly Activity ReportAugust report due in 4 days · empty evidence never passesNeeds evidence
✓ Published to trust.zenibit.com/acme
AI, inside the boundary
AI on FedRAMP High. Drafts, reads and answers; never decides.
Every model call runs on Gemini in Google Vertex AI under its FedRAMP
High authorization, so your evidence and documents never leave an
authorized boundary to be read. What comes back is a draft or an
answer for a person to act on. Every verdict on your posture comes
from the validator engine reading collected evidence, and nothing a
model writes reaches your record until someone saves it.
Zenibot viewing VulnerabilitiesGemini on Vertex AI
Hi, I'm Zenibot. Ask me anything about this package: its posture, documents, connectors, or members.
Which findings should we fix first?Which requirements cover vulnerability management?
Which policy covers KEV remediation?
Thinking…
Your Vulnerability Management Policy › 4.2 Known exploited vulnerabilities sets a 14-day fix window for anything on the CISA KEV list, which is what VDR-TFR-KEV checks. The last run still shows 2 KEV findings past it.Patch web-3 first; it is internet facing.
Generated by Gemini on Vertex AI (FedRAMP High Authorization)
Vulnerabilities →
Which policy covers KEV remediation?Ask about Vulnerabilities…
Zenibot
Ask your package
Zenibot answers from your posture, your registers of
vulnerabilities, incidents, changes and inventory, and the
requirements behind them. Ask about a control and it quotes
the sections of your own SSP and policies that cover it, and
says so when nothing has been indexed.
Security Decision Record VDR-TFR-KEV · Remediate KEVsDraft with AIDrafting
Explanation
We match every imported finding against the CISA KEV catalog and open a ticket due on the catalog date.[Ticketing system] routes internet facing assets to the on-call engineer first.Nothing written yet
Verification
The VDR-TFR-KEV check reads the ledger on every run and flags any KEV finding past its due date; the last run on [date] found none.Nothing written yet
AI drafted 2 fields. Review and edit before saving; placeholders in [brackets] need your input.
Proposed text for the entries you have not written, one at a
time or queued across the whole record, grounded in your
system description and context documents. Placeholders arrive
in brackets where a fact is missing, drafting only ever fills
empty fields, and nothing is saved until you save it.
Ask about this postureGemini on Vertex AI
VDR-TFR-PDDPersistent Drift DetectionDrift evidence is stale · last evaluated 9 days agoNot satisfied
Why is VDR-TFR-PDD failing?What should we fix first? Why is a requirement failing?
Ask
VDR-TFR-PDD is not satisfied because the drift evidence is stale: the AWS connector last collected 9 days ago and no scan of drift-prone resources has landed since.Reconnect prod-govcloud in Connectors, then run validation. Nothing else in the run depends on it.
Generated by Gemini on Vertex AI (FedRAMP High Authorization). Statuses come from the validator engine; this explanation is advisory.
Ask about this posture
Explain the run
On the Overview, ask why a requirement failed and what would
move it. The answer reads the run the validator engine already
produced and the connectors feeding it, names the requirement
IDs, and says which evidence or connector would change the
finding. It is advisory: the verdict stays the engine's.
Inventory Gov PlatformUpload diagram
boundary-v7.png
Uploading… 1.2 MBReading…Read just now
6 components · 5 connections · 2 external. Read from 1.2 MB of image/png by Gemini, just now.
Diagram reading
Read the boundary diagram
Upload the authorization boundary diagram you already maintain
and it comes back as a component graph: services, data flows
and connections you can correct by hand. Switch the reading
off and the Inventory page and its uploads stay exactly as
they are.
Import scan results VulnerabilitiesDetect from the file · Nessus
PDFnessus-monthly-2026-08.pdfReading the file… 38 pages3 findings read from the PDF. None of them has entered the ledger.
Draft findings awaiting reviewextracted from a PDF report · just now
xz-utils backdoor in sshdbuild-runner-2CVE-2024-3094CriticalKEVConfirm✕In the ledger
Nothing here is in the ledger yet. Confirm each finding you accept, or discard what the model got wrong.2 awaiting review · 1 in the ledger
PDF scan drafts
Import the scan that is only a PDF
Exports from Wiz, Nessus, Qualys, Amazon Inspector, Security
Command Center and any SARIF tool land in the vulnerability
ledger directly. A scanner report that exists only as a PDF is
read into draft findings, CVEs, severity and KEV status
included, for a person to confirm or discard before it counts.
Smart assign Assessment scopingGemini on Vertex AI
Kickoff notes: Priya owns account automation (Okta lifecycle rules done in July). Marcus has the KEV backlog. The IR runbook was rewritten and needs a fresh look.Paste the material to triage
Suggest scope and assigneesReading…
KSI-IAM-AAMto [email protected]The notes put the Okta lifecycle rules with Priya.
KSI-INR-RIR(unassigned)The runbook rewrite is named, but no reviewer is.
Apply 3 suggestionsApplying selects each item and sets its assignee.
3 suggestions applied to the scope.
Smart assign
Triage the assessment
For the assessor: paste the scoping memo or kickoff notes and
get a proposed scope and reviewer for each item it touches, and
a screenshot of a console or a control panel written up as
evidence with what it shows and what it does not. Both are
proposals, applied only by whoever runs the assessment.
AI is off until an admin in your organization turns it on, each
surface has its own switch, and every switch change is recorded in
your activity log. Turning it off stops every surface at once,
server-side. Prefer your own assistant? Claude and other MCP clients
can connect over a read-only key, and no model runs on our side of
that connection.
Who it serves
One platform for everyone in the FedRAMP process.
FedRAMP involves three parties working from one body of evidence.
Zenibit gives each of them their own view of the same record, so
nothing is exported, re-keyed or out of date between them.
Evidence sources Gov PlatformContinuous
AWSAWS GovCloudCollecting…just now
GHGitHubCollecting…just now
OKOktaCollecting…just now
VDR-TFR-KEVRemediate KEVsNeeds evidenceSatisfied
Last run: 2 hours ago.Published to trust.zenibit.com/acme · just now
providers
Cloud service providers
Connect your cloud accounts and tooling, and every Consolidated
Rules requirement is evaluated against live evidence. Gaps show
up as needs evidence, monthly reports and deadlines are
tracked, and your public trust center publishes from the result.
Assessor review KSI-IAM-AAMItem 41 of 58
Automated account management
DOCAccess policy §4.2indexed from access-policy.pdf
TRCCollection traceOkta connector · 2 hours ago
IMGLifecycle rules screenshotfiled against this item
VerdictConclude…Reviewed · satisfied
41 of 58 items reviewed.42 of 58 items reviewed.
assessors
3PAO assessors
Review the package where it lives. Findings, evidence and
documents are organized by requirement, each with its collection
trace, so the assessment starts from the record rather than a
spreadsheet of requests.
They review the package where it lives: the same findings, evidence and documents your team works from, organized by requirement.
The record is shared, never exported.
agencies
Agency reviewers
Review the package. The provider grants console access to the
same findings, evidence and documents its own team works from,
organized by requirement with the collection trace behind each.
The trust center
Public proof up front. The real review in the console.
Every Zenibit customer gets a public trust center on its own URL: live
status, coverage, your secure configuration documents, and clear
instructions for requesting the rest. Everything on it comes from the
engine, so what a visitor reads is what your evidence actually
supports. When an agency needs the full package, you grant its
reviewers private access to the console: the same findings, evidence
and documents your own team works from.
status
Live authorization status
Certification type, path, and class, stated from your evaluated posture rather than a marketing claim.
coverage
Automated-check coverage
The share of requirements verified by automation, shown as a percentage on the page.
documents
Public documents, and a path to the rest
Secure configuration guides download openly; NDA-gated material is listed with instructions to request access, never hidden.
freshness
A timestamp you can point to
Every page carries when it was last evaluated and the exact Consolidated Rules version it was evaluated against.
vulnerability
Vulnerability posture, current
Monthly activity reports published where agencies expect them, on the cadence VER requires.
zero setup
Nothing to host
Your trust center is provisioned with your account. No servers, no static-site pipeline, no separate vendor.
Standing obligations, tracked as first-class requirements.
The 2026 rules redefined vulnerability: an out-of-date control
statement, drift, or an unverified control now carries the same
detection and remediation obligations as a CVE. BOD 26-04 replaced
scan-and-file with cadences and clocks. Zenibit tracks each against
your evidence and shows exactly where you stand.
Rule
Obligation
What Zenibit does
VDR-TFR-KEV
Remediate Known Exploited VulnerabilitiesBy the due dates in the CISA KEV Catalog.
Keeps KEV due dates in view beside the rest of your remediation queue.
VER-TFR-MHR
Report activity monthlyIn a consistent, human-readable format, to all necessary parties.
Tracks the cadence so a missed month is visible to you and your assessor at the same time.
VER-TFR-MAV
The 192-day clockAnything not fully mitigated or remediated within 192 days of evaluation must be categorized as accepted.
Shows the clock on every open finding so acceptance is a decision, not a default.
VDR-TFR-MVF
Persistent machine verificationMachine-based verification and validation, a Rev 5 obligation in its own right.
Continuous evaluation is the default posture, not a scheduled scan.
VDR-TFR-NMV
Verify non-machine resourcesAt least once every 3 months.
Tracks the quarterly cadence alongside the machine-based one.
Evaluated against the live Consolidated Rules datafile · currently v2026.07.14.01
The Vulnerability Detection & Response and Vulnerability Evaluation
& Reporting rules apply to every FedRAMP certification, whether
obtaining or maintaining, on Rev 5 or 20x. Zenibit tracks them on both
paths, so a Rev 5 provider is covered without waiting for its 20x
transition.
2026-07-04
Optional adoption opened
Providers may adopt VDR and VER early and report under the new rules.
2026-12-07
Required to obtain and maintain
VDR and VER become mandatory for every FedRAMP certification under CISA BOD 26-04.
2027-03-07
Grace period ends
The default grace window closes and the rules are enforced as written.
These three come first. Every ruleset has its own dates, and they
differ for 20x and Rev 5:
the full deadline table.
Rev 5 and 20x
Both paths. One engine.
20x and Rev 5 differ in which requirements apply, not in how evidence
is evaluated. Zenibit runs one validator engine against both rule sets,
so the work you do for Rev 5 today is the same work 20x will ask for.
FedRAMP Rev 5
COMPLY NOW
Immediate 2026 obligations tracked: vulnerability rules, secure configuration guide, communication and marketplace requirements
Continuous evaluation instead of point-in-time assessment prep
Evidence gaps surfaced as needs evidence, never a false pass
FedRAMP 20x
ARRIVE READY
Key Security Indicators evaluated from the same evidence base
Machine-readable status agencies can consume directly
Certification path and class resolved per the Consolidated Rules applicability model
Meet Rev 5 today. Move to 20x on the same evidence.
Switching paths is a rule-set change in Zenibit, not a second compliance program.