The FedRAMP trust center.

One platform for every FedRAMP compliance need. Cloud service providers collect evidence and track each requirement, assessors review from the same record, and agencies review the package. FedRAMP 20x and Rev 5, one engine, with AI that drafts and answers from your own evidence and runs on Vertex AI under FedRAMP High.

Consolidated Rules v2026.07.14.01 · providers, assessors, agencies · Rev 5 and 20x

AI, inside the boundary

AI on FedRAMP High. Drafts, reads and answers; never decides.

Every model call runs on Gemini in Google Vertex AI under its FedRAMP High authorization, so your evidence and documents never leave an authorized boundary to be read. What comes back is a draft or an answer for a person to act on. Every verdict on your posture comes from the validator engine reading collected evidence, and nothing a model writes reaches your record until someone saves it.

Zenibot

Ask your package

Zenibot answers from your posture, your registers of vulnerabilities, incidents, changes and inventory, and the requirements behind them. Ask about a control and it quotes the sections of your own SSP and policies that cover it, and says so when nothing has been indexed.

Draft with AI

Draft the Security Decision Record

Proposed text for the entries you have not written, one at a time or queued across the whole record, grounded in your system description and context documents. Placeholders arrive in brackets where a fact is missing, drafting only ever fills empty fields, and nothing is saved until you save it.

Ask about this posture

Explain the run

On the Overview, ask why a requirement failed and what would move it. The answer reads the run the validator engine already produced and the connectors feeding it, names the requirement IDs, and says which evidence or connector would change the finding. It is advisory: the verdict stays the engine's.

Diagram reading

Read the boundary diagram

Upload the authorization boundary diagram you already maintain and it comes back as a component graph: services, data flows and connections you can correct by hand. Switch the reading off and the Inventory page and its uploads stay exactly as they are.

PDF scan drafts

Import the scan that is only a PDF

Exports from Wiz, Nessus, Qualys, Amazon Inspector, Security Command Center and any SARIF tool land in the vulnerability ledger directly. A scanner report that exists only as a PDF is read into draft findings, CVEs, severity and KEV status included, for a person to confirm or discard before it counts.

Smart assign

Triage the assessment

For the assessor: paste the scoping memo or kickoff notes and get a proposed scope and reviewer for each item it touches, and a screenshot of a console or a control panel written up as evidence with what it shows and what it does not. Both are proposals, applied only by whoever runs the assessment.

AI is off until an admin in your organization turns it on, each surface has its own switch, and every switch change is recorded in your activity log. Turning it off stops every surface at once, server-side. Prefer your own assistant? Claude and other MCP clients can connect over a read-only key, and no model runs on our side of that connection.

Who it serves

One platform for everyone in the FedRAMP process.

FedRAMP involves three parties working from one body of evidence. Zenibit gives each of them their own view of the same record, so nothing is exported, re-keyed or out of date between them.

providers

Cloud service providers

Connect your cloud accounts and tooling, and every Consolidated Rules requirement is evaluated against live evidence. Gaps show up as needs evidence, monthly reports and deadlines are tracked, and your public trust center publishes from the result.

assessors

3PAO assessors

Review the package where it lives. Findings, evidence and documents are organized by requirement, each with its collection trace, so the assessment starts from the record rather than a spreadsheet of requests.

agencies

Agency reviewers

Review the package. The provider grants console access to the same findings, evidence and documents its own team works from, organized by requirement with the collection trace behind each.

The trust center

Public proof up front. The real review in the console.

Every Zenibit customer gets a public trust center on its own URL: live status, coverage, your secure configuration documents, and clear instructions for requesting the rest. Everything on it comes from the engine, so what a visitor reads is what your evidence actually supports. When an agency needs the full package, you grant its reviewers private access to the console: the same findings, evidence and documents your own team works from.

status

Live authorization status

Certification type, path, and class, stated from your evaluated posture rather than a marketing claim.

coverage

Automated-check coverage

The share of requirements verified by automation, shown as a percentage on the page.

documents

Public documents, and a path to the rest

Secure configuration guides download openly; NDA-gated material is listed with instructions to request access, never hidden.

freshness

A timestamp you can point to

Every page carries when it was last evaluated and the exact Consolidated Rules version it was evaluated against.

vulnerability

Vulnerability posture, current

Monthly activity reports published where agencies expect them, on the cadence VER requires.

zero setup

Nothing to host

Your trust center is provisioned with your account. No servers, no static-site pipeline, no separate vendor.

New to the idea? What a trust center is, and what belongs on one.

The rules, specifically

Standing obligations, tracked as first-class requirements.

The 2026 rules redefined vulnerability: an out-of-date control statement, drift, or an unverified control now carries the same detection and remediation obligations as a CVE. BOD 26-04 replaced scan-and-file with cadences and clocks. Zenibit tracks each against your evidence and shows exactly where you stand.

RuleObligationWhat Zenibit does
VDR-TFR-KEV Remediate Known Exploited VulnerabilitiesBy the due dates in the CISA KEV Catalog. Keeps KEV due dates in view beside the rest of your remediation queue.
VER-TFR-MHR Report activity monthlyIn a consistent, human-readable format, to all necessary parties. Tracks the cadence so a missed month is visible to you and your assessor at the same time.
VER-TFR-MAV The 192-day clockAnything not fully mitigated or remediated within 192 days of evaluation must be categorized as accepted. Shows the clock on every open finding so acceptance is a decision, not a default.
VDR-TFR-MVF Persistent machine verificationMachine-based verification and validation, a Rev 5 obligation in its own right. Continuous evaluation is the default posture, not a scheduled scan.
VDR-TFR-NMV Verify non-machine resourcesAt least once every 3 months. Tracks the quarterly cadence alongside the machine-based one.

Evaluated against the live Consolidated Rules datafile · currently v2026.07.14.01

Read the rules themselves: every FRR requirement, every Key Security Indicator, and the terms they lean on.

The 2026 dates

The 2026 rules apply to Rev 5 as well as 20x.

The Vulnerability Detection & Response and Vulnerability Evaluation & Reporting rules apply to every FedRAMP certification, whether obtaining or maintaining, on Rev 5 or 20x. Zenibit tracks them on both paths, so a Rev 5 provider is covered without waiting for its 20x transition.

2026-07-04

Optional adoption opened

Providers may adopt VDR and VER early and report under the new rules.

2026-12-07

Required to obtain and maintain

VDR and VER become mandatory for every FedRAMP certification under CISA BOD 26-04.

2027-03-07

Grace period ends

The default grace window closes and the rules are enforced as written.

These three come first. Every ruleset has its own dates, and they differ for 20x and Rev 5: the full deadline table.

Rev 5 and 20x

Both paths. One engine.

20x and Rev 5 differ in which requirements apply, not in how evidence is evaluated. Zenibit runs one validator engine against both rule sets, so the work you do for Rev 5 today is the same work 20x will ask for.

FedRAMP Rev 5

COMPLY NOW

  • Immediate 2026 obligations tracked: vulnerability rules, secure configuration guide, communication and marketplace requirements
  • Continuous evaluation instead of point-in-time assessment prep
  • Evidence gaps surfaced as needs evidence, never a false pass

FedRAMP 20x

ARRIVE READY

  • Key Security Indicators evaluated from the same evidence base
  • Machine-readable status agencies can consume directly
  • Certification path and class resolved per the Consolidated Rules applicability model

Meet Rev 5 today. Move to 20x on the same evidence. Switching paths is a rule-set change in Zenibit, not a second compliance program.

Deciding between them: what actually differs. Already know your path? See which rules apply to you.