
Secureframe Achieves FedRAMP 20x Moderate Authorization
Emily Bonnie
Senior Content Marketing Manager
Today we're excited to share that Secureframe meets the FedRAMP® security requirements for 20x Moderate authorization as one of 13 organizations selected to participate in FedRAMP's Phase Two Moderate pilot.
Like our FedRAMP 20x Low authorization, this is more than a compliance milestone. It's proof that the automation-driven approach we've built our platform around can hold up at a much higher bar — one that covers the moderate-impact, moderate-risk federal data that makes up the majority of federal cloud workloads, including systems handling Controlled Unclassified Information (CUI).
"Moderate authorization isn't just the next step after Low, it's proof that automation-first authorization holds up as the stakes get higher,” said Shrav Mehta, Founder and CEO at Secureframe. “We built our platform to meet the same high bar, and this is the clearest evidence yet that the model works at scale."
What we learned by participating in the FedRAMP 20x Moderate pilot
FedRAMP 20x Low proved that automation-based validation was possible. Phase Two asked whether that same approach would hold up for moderate-impact systems, where the requirements are deeper, the interdependencies are more complex, and the data is more sensitive.
The Moderate baseline introduces a new KSI theme, Authorization by FedRAMP, that roughly quadruples the validation scope compared to Low. As one of only 13 CSPs that were selected for the Phase Two pilot, meeting these standards meant providing persistent validation that pulls evidence directly from production environments, evaluated continuously rather than at a single point in time. It also meant working closely with FedRAMP throughout the process, through structured workshops and ongoing collaboration with our assessor, Coalfire.
Recommended reading
The FedRAMP 20x Phase Two Moderate Pilot Explained & Why Secureframe Is Participating
Simplify federal compliance

Emily Bonnie
Senior Content Marketing Manager
Emily Bonnie is a seasoned digital marketing strategist with over ten years of experience creating content that attracts, engages, and converts for leading SaaS companies. At Secureframe, she helps demystify complex governance, risk, and compliance (GRC) topics, turning technical frameworks and regulations into accessible, actionable guidance. Her work aims to empower organizations of all sizes to strengthen their security posture, streamline compliance, and build lasting trust with customers.