- Knox has unveiled a platform to bring continuous vulnerability detection to FedRAMP 20x
- Knox operates across AWS, Azure and GCP in more than 100 production environments
- The 2026 FedCiv Summit will explore AI, cloud, cybersecurity and more
Knox Systems has introduced Knox for FedRAMP 20x designed to operationalize continuous vulnerability detection, reporting and evidence generation at scale under the Federal Risk and Authorization Management Program 20x initiative and the FedRAMP 2026 Consolidated Rules.

As agencies move toward continuous compliance models like FedRAMP 20x, questions remain around how organizations will keep pace with cloud security, data governance and modernization demands. The Potomac Officers Club’s 2026 FedCiv Summit on Oct. 29 will bring together government and industry leaders to discuss AI adoption, cloud infrastructure, cybersecurity and compliance-driven initiatives. Sign up now to join the conversation!
What Is FedRAMP 20x?
Knox said Wednesday FedRAMP 20x is a modernized federal framework for authorizing cloud services that replaces static, point-in-time compliance reviews with continuous, evidence-based validation. The framework allows cloud providers to demonstrate security effectiveness through ongoing monitoring rather than periodic audits and paperwork.
What Is Knox for FedRAMP 20x?
According to the company, Knox for FedRAMP 20x is a platform that continuously ingests security telemetry across cloud environments, monitors remediation and risk acceptance, and assesses vulnerabilities against FedRAMP requirements. The platform produces human-readable and machine-readable evidence needed to support ongoing authorization. Knox performs these functions across Amazon Web Services, Microsoft Azure and Google Cloud Platform in more than 100 customer production environments.
Knox supports reporting and operating capabilities required under the FedRAMP 20x framework, including continuous vulnerability detection and response; risk-based vulnerability evaluation and prioritization; and vulnerability-level reporting aligned to FedRAMP requirements.
The platform also provides documentation and governance for accepted vulnerabilities and persistent validation of security controls. Additional capabilities include continuous security decision records, Key Security Indicator tracking, ongoing certification reporting, significant change management and continuous evidence readiness.
What Did Knox Officials Say About FedRAMP 20x?
“FedRAMP 20x fundamentally changes how agencies evaluate security by moving away from static documentation toward live operational evidence. Knox gives agencies and commercial software providers the ability to adopt that operating model today, making security decisions faster, more transparent, and continuously validated,” said Irina Denisenko, founder and CEO of Knox Systems.
Hemant Baidwan, executive chief information security officer at Knox, said FedRAMP 20x represents a fundamentally different way of operating rather than simply a new reporting requirement, and that addressing vulnerabilities within hours rather than months requires continuous security posture, risk prioritization, documented decisions and evidence agencies can immediately use.
“Knox was designed around those capabilities from day one, enabling compliance to become part of daily operations instead of an exercise performed every few months,” added Baidwam, former chief information security officer at the Department of Homeland Security.
What Other Federal Moves Has Knox Made?
The FedRAMP 20x launch adds to a series of moves Knox Systems has made to expand its footprint in the federal cloud market. Knox partnered with Microsoft to give commercial software companies a faster, more secure path to deploying their products on Microsoft Azure Government Cloud for federal customers. The company also teamed up with Google Public Sector to help software-as-a-service and AI vendors bring commercial software into federal environments.
Knox has also grown its physical presence in the federal market, establishing a new office in Crystal City, Virginia, to bring FedRAMP-focused support closer to its government customers. In April, the company secured FedRAMP High authorization for its AI-managed cloud platform.


