Join us as we discuss news and current events, trends, and controversies in the world of cybersecurity. We have strong feelings and they're not limited to FedRAMP, CMMC, FISMA, IRAP, security engineering, or documentation. Anything goes -- some of the things we say are probably even helpful! Interested in having words? Email us at info@38northsecurity.com.
Listen to episodes
6 recent
January 30, 2024Episode 124 min
Refresher: What's in The FedRAMP Modernization Memo?
We're about to see significant changes in the way FedRAMP is managed: automation, more pathways to authorization, and no more JAB. It's all in the name of modernization, baby! Well, that and the undeniable fact that the process to get more offerings in the FedRAMP marketplace needs to be much, much faster. But what does it all mean? How will it affect CSPs' efforts to get ATO? Matt Strasburg answers.
June 10, 2024Episode 232 min
FedRAMP: Goodbye FedRAMP JAB! Hello TAG, Board, and FSCAC!
FedRAMP just came out with *three* new bodies governing the program going forward: the TAG, the Board, and the FSCAC. There's a lot of uncertainty right now, not to mention confusion and misinformation. Why are these changes happening? What does it mean for CSPs, 3PAOs, and agencies? Is the JAB gone?!! Matt Strasburg and Jeremiah Thompson shed light on these massive changes and discuss their wide-reaching impact.
May 14, 2025Episode 16 min
GovRAMP: What Is It, Anyway?
Welcome to Part 1 of our GovRAMP Mini-Series —a quick, focused look at what GovRAMP is, why it matters, and how cloud service providers can use it to unlock the public sector. In this episode, we tackle the basics: What exactly is GovRAMP? Why the rebrand from StateRAMP? And is this more than just a name change? Elizabeth Lopez helps us break it down. Liz, one of our cloud security technical writers here at 38North Security, has been deep in the weeds of policy, frameworks, and language—so she’s the perfect person to walk us through what GovRAMP is really all about.
May 16, 2025Episode 27 min
GovRAMP: Why It’s a Smart Growth Move for Cloud Providers
This is Part 2 of the GovRAMP Mini-Series . In this episode, we’re digging into the big question: Why would a cloud provider pursue GovRAMP in the first place? We’re joined by Jeremiah Thompson , 38North Security's VP of IT and Cloud Solutions. We also have Matt Strasburg , Manager of our Cloud Security Advisory practice. Jeremiah’s been in the compliance world for years and brings a pragmatic, strategic lens to why GovRAMP is gaining traction—not just for security reasons, but for smart market growth. Matt, on the other hand, has been pivotal in standing up similar federal programs in past years.
May 28, 2025Episode 310 min
GovRAMP: Navigating the Path to Authorization
Welcome to Part 3, the final episode of our GovRAMP Mini-Series . Over the last two episodes, we’ve covered what GovRAMP is and why companies are pursuing it. Today, we’re closing things out by getting tactical—what does the GovRAMP process actually look like from start to finish? To walk us through it, we’re joined by Matt Strasburg, manager of our Cloud Security Advisory practice. Matt has guided dozens of companies through complex public sector frameworks, and he’s here to break down the steps, timelines, and fast-track options that cloud providers should know about.
July 2, 2026Episode 10 min
FedRAMP 20x Is Here: The Six Changes That Matter Most
With FedRAMP's Consolidated Rules for 2026 being final, FedRAMP 20x is officially here. That changes how cloud service providers enter FedRAMP, define scope, prove security, maintain certification, and work with federal agencies. In this episode, Ingrid Velasquez-Woodley speaks with Sam Leestma, Vice President of Solutions Engineering, and Spence Witten, Principal Consultant at 38North Security, about the six parts of CR26 most likely to affect cloud providers and agencies. Topics include: * How the new certification classes differ from the Rev. 5 impact levels * Whether Minimum Assessment Scope will actually reduce cost and complexity * Why Key Security Indicators may provide better assurance than point-in-time evidence * Whether the Security Decision Record could become the next oversized compliance document * What VDR and VER require before the December 7, 2026 deadline * Why existing Rev. 5 providers may struggle with vulnerability automation * How ongoing certification differs from continuous validation * Whether annual assessments should become less burdensome * Why CR26 limits agencies from creating their own parallel FedRAMP requirements * What the major CR26 transition dates mean for providers * What CSPs considering 20x—and those already holding Rev. 5 certifications—should do now The discussion also covers where FedRAMP got the model right, where the final rules still create uncertainty, and how implementation by agencies, assessors, and providers will determine whether CR26 actually reduces duplication and improves security visibility. Important dates discussed: June 24, 2026 — CR26 becomes final July 4, 2026 — Optional early adoption begins July 28, 2026 — FedRAMP Ready becomes a legacy designation August 3, 2026 — Class A applications open August 10, 2026 — Limited Rev. 5 Class B and C transition pathways open August 31, 2026 — 20x Class B and C applications open December 7, 2026 — VDR and VER become mandatory January 1, 2027 — Broader mandatory CR26 adoption begins June 11, 2027 — FedRAMP stops accepting new Rev. 5 certification applications Explore more FedRAMP 20x insights from 38North Security: https://38northsecurity.com/fedramp-20x/ Explore 38North Security’s FedRAMP services: https://38northsecurity.com/security-compliance/north-america/fedramp/ #FedRAMP #FedRAMP20x #cloudsecurity #cybersecurity #govtech #38NorthSecurity #federal #cloudsecuritypodcast
Is this your show?
Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.