Skip to Content

Security & Compliance

Lynx Compliance - FedRAMP 20x

FedRAMP 20x Key Security Indicators as an overlay on NIST SP 800-53 - each indicator cross-referenced to the underlying controls, so an existing 800-53 profile carries straight over.

lynx_compliance_fedramp · v19.0.1.0.0 · Add-on Beta

What this solves

Lynx Compliance - FedRAMP 20x

FedRAMP authorisation has always been NIST SP 800-53 plus a baseline plus a process. FedRAMP 20x changes the process: instead of narrating every control in a document nobody rereads, a cloud service provider validates a set of Key Security Indicators continuously, in a form a machine can check.

This pack ships those indicators as assessable controls. It is an overlay, not a second copy of 800-53. Every indicator carries the 800-53 control codes it evidences, and those codes match the ones in lynx_compliance_nist_80053 exactly, so the crosswalk pairs them in both directions. A provider who has already assessed AC-2 does not assess it again to answer the identity indicators.

The pack also carries the authorisation artefacts that sit around the indicators - categorisation, baseline tailoring, the System Security Plan, the POA&M and continuous monitoring - because those are what an assessor asks for and they are not indicators themselves.

Accuracy note: FedRAMP is actively iterating 20x. The indicator set here reflects the Phase One release covering Low impact. Validate it against FedRAMP's current publication before relying on it for a live authorisation.

Key Features

  • 42 controls across five functions - ten Key Security Indicator families plus the authorisation artefacts.

  • Cross-referenced to NIST SP 800-53 by control code - AC-2, SI-4, CP-9 and the rest, matching the codes shipped by the 800-53 pack, so assessments propagate automatically.

  • Overlay, not a duplicate - the 296 controls of 800-53 are not re-seeded, so a provider holding both packs assesses each control once.

  • Evidence guidance naming connectors - identity, SIEM, scanner, backup and cloud connectors are named per indicator rather than "collect appropriate evidence".

  • Authorisation artefacts included - FIPS 199 categorisation, baseline tailoring, SSP currency, POA&M ageing and continuous-monitoring cadence.

  • Residual-risk examples written as partial states - no provider is uniformly green mid-authorisation, and the examples reflect that.

Integrates With

  • lynx_compliance_nist_80053 - the underlying baseline this overlays; install both for the crosswalk to do its work.

  • lynx_compliance - CSF 2.0 profiles cross-reference through the shared 800-53 mappings.

  • lynx_compliance_evidence_collectors - continuous monitoring is the point of 20x, and scheduled collection is how it is evidenced.

Try Lynx Compliance - FedRAMP 20x on your team.

Free trial, no credit card. Talk to sales when you're ready.