Will FedRAMP 20x Repeat SOC 2’s Mistakes? episode artwork

EPISODE · Jul 17, 2025 · 58 MIN

Will FedRAMP 20x Repeat SOC 2’s Mistakes?

from GRC Uncensored

This week on GRC Uncensored, the crew welcomes John Santore, a longtime FedRAMP and SOC 2 practitioner who has seen firsthand how compliance frameworks evolve, and sometimes unravel. Now serving as Director of Cyber Acceleration at Constellation GovCloud, John joins Troy and Elliot to unpack FedRAMP 20x, a new pilot program designed to streamline the U.S. government’s cloud authorization process dramatically.The promise? Fewer controls, faster approvals, and greater automation.The concern? That all sounds a little too familiar.Together, they explore whether FedRAMP 20x is an overdue modernization or the start of a dangerous slide toward the kind of checkbox compliance that has made SOC 2 certifications easier to get but harder to trust. From control mapping and auditor disruption to agency adoption and AI-assisted audits, this episode provides a deep dive into what happens when good frameworks move too quickly and how to maintain trust when they do.[00:01:00] – Guest intro: John’s history with SOC 2, FedRAMP, and working with Troy[00:06:00] – How SOC 2 influenced John’s transition into federal compliance[00:08:00] – What is FedRAMP 20x, and why is it happening now?[00:10:00] – From 12-month review cycles to fast-tracking assessments[00:14:00] – Key Security Indicators (KSIs): replacing hundreds of controls with a handful of validations[00:18:00] – Are KSIs basically just vague control summaries? (Spoiler: yes)[00:22:00] – Why GRC platforms are being prioritized in the pilot[00:25:00] – Potential expansion to FedRAMP Moderate and High[00:28:00] – Will agencies even accept this?[00:31:00] – Advice for cloud service providers evaluating FedRAMP now[00:34:00] – Is FedRAMP on the path to commoditization?[00:39:00] – Evaluating rigor vs. relevance: security posture ≠ certification[00:44:00] – The problem of vague frameworks and audit inconsistency[00:48:00] – Comparing SOC 2, FedRAMP, and the race to the bottom[00:54:00] – Closing thoughts on AI, automation, and the future of white-collar workGuest: John Santore, Director of Cyber Acceleration, Constellation GovCloudHosts: Troy Fine & Elliot VolkmanRuntime: ~58 minutes Hosted on Acast. See acast.com/privacy for more information.

NOW PLAYING

Will FedRAMP 20x Repeat SOC 2’s Mistakes?

0:00 58:27

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Due Date USA TODAY Due Date is an uncensored journey through one woman's pregnancy. There's no such thing as TMI on this podcast. From weird body issues to mom identity, Host Ashley May drops all pretense and keeps it real. New episodes every Friday. Produced by Ashley May and Shannon Rae Green. Woman's Day Uncensored Woman's Day Recorded inside the Woman's Day offices each week, 'Woman's Day Uncensored' goes beyond the pages to uncover even more gossip from the team that put the magazine together. PROPER PROPAGANDA w/Ennis da Mennis John Wellington Ennis Chuck D once said that rap music is like CNN for Black America. Imagine a news radio show, but instead of headlines you are getting news reports through hip hop tracks. Social commentary and patriotic dissent through old school and underground hip hop, airing Friday nights on Radio Free Brooklyn at 11 p.m. EST/8 p.m. PST. Rebroadcast Sunday at 3 a.m. EST or Saturday at midnight PST. Episode posted online the following Monday. Hand picked in Hollywood, mixed with classic comedy clips and political punchlines, rolled into a blunt of Old school, underground, West Coast, boom bap, conscious, and backpack. Uncensored. Dentistry Uncensored with Howard Farran Howard Farran: Dentist | Dental CE Speaker | Founder & CEO of Dentaltown.co POWERED BY DENTALTOWN.COMUncomplicate your dental life with Dr. Howard Farran as he interviews your fellow townies and leaders in dentistry! Dentists and dental professionals share their wisdom to make your dentistry faster, easier, higher in quality and lower in cost. Episodes released every week day with the full transcripts at dentaltown.com/podcasts.

Frequently Asked Questions

How long is this episode of GRC Uncensored?

This episode is 58 minutes long.

When was this GRC Uncensored episode published?

This episode was published on July 17, 2025.

What is this episode about?

This week on GRC Uncensored, the crew welcomes John Santore, a longtime FedRAMP and SOC 2 practitioner who has seen firsthand how compliance frameworks evolve, and sometimes unravel. Now serving as Director of Cyber Acceleration at Constellation...

Can I download this GRC Uncensored episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!