scm.cc

FedRAMP 20x continuous monitoring, without the spreadsheet.

FedRAMP 20x asks for automated validation and reusable evidence. scm.cc already works that way: it connects the scanners you run, validates your posture on a schedule, and pins every monthly run into evidence you can replay, sign off, and hand over.

Create an account See pricing

Automated validation, on a schedule

Findings stream in hourly from your own accounts - AWS Security Hub, Microsoft Defender for Cloud, GCP Security Command Center, GitHub code scanning, Supabase security advisors - read-only, validated live before anything is stored. Disconnected sources stop counting, so the headline number is always the live one.

Drift that surfaces itself

Each monthly run is re-validated against the pinned previous run. A control that loses evidence coverage becomes a finding and a dashboard alert automatically - and resolves itself the day it is covered again. Overdue policy reviews and plan tests surface the same way; expired risk acceptances reopen on the POA&M.

Reusable evidence, not rebuilt binders

Every monthly run pins its inputs with a tamper-evident hash and replays on demand. The same pinned records assemble the quarterly Ongoing Certification Report draft, the POA&M CSV, and a downloadable monthly artifact package.

Sign-off that locks the record

Monthly runs and quarterly reports carry a real sign-off: named signer, timestamp, and a locked record the engine never rewrites. Significant changes are tracked alongside, linked to the run evidence that shows them.

KSI history, accumulating daily

20x Class C asks for persistent per-KSI verification - two or more automated methods per Key Security Indicator - and six months of metrics history. scm.cc records each KSI's verification status daily with method provenance, starting the clock you cannot retrofill.

Findings become a POA&M

Open weaknesses roll into a plan of action with owners and dates, mapped to the FedRAMP controls they evidence, with a CSV export for the monthly deliverable.

The 20x transition, on official dates

From fedramp.gov, not from us:

Questions, answered straight

What is FedRAMP 20x?

The program's current certification path, widely available since June 2026. Its core principles include Automatic Validation - security status and outcomes validated automatically whenever possible - and clearer, more measurable, more reusable evidence. That is the shape scm.cc was built around.

What does scm.cc actually do today?

Hourly connector syncs, monthly sealed ConMon runs with replayable pinned evidence, drift alerts, a durable POA&M with CSV export, quarterly OCR drafts covering the CCM-mandated sections, sign-off locks, significant-change tracking, and daily per-KSI verification history. What it is not: a 3PAO - it does not perform independent assessments or grant an authorization.

What does ConMon without spreadsheets mean?

Monthly evidence and POA&M records live in one system. Each monthly run is pinned to package, baseline and template versions with an immutable receipt, so the quarterly package is assembled from real records instead of rebuilt by hand.

Connectors: AWS Security Hub, Microsoft Defender for Cloud, GCP Security Command Center, GitHub code scanning, Supabase security advisors - read-only, validated live before anything is stored.