As FedRAMP evolves through the consolidated rules of C26 (CR26) initiatives, Government agencies must adapt to new certification pathways, increased automation and stricter cybersecurity requirements. By preparing for emerging priorities, including post-quantum cryptography (PQC), stronger cryptographic governance and continuous compliance, agencies can modernize cybersecurity programs and support the Federal cloud ecosystem. Access the podcast to hear experts from Qanapi, SafeLogic, stackArmor and SCOOP Cyber discuss how FedRAMP CR26 is reshaping the FedRAMP certification process through automation and continuous evidence. Learn how your agency can respond and comply with these updates while strengthening security through cryptographic agility and post-quantum readiness. Fill out the form to access the FedRAMP CR26 podcast to modernize Federal cybersecurity and build a more resilient compliance strategy.
Anthony Jimenez
Welcome back to Carahcast, the podcast from Carahsoft, a trusted government IT solutions provider. Subscribe to get the latest technology updates in the public sector. I'm Anthony Jimenez, your host from the Carahsoft production team.
On behalf of Quantope, SafeLogic, StackArmor, and ScoopCyber, we would like to welcome you to today's podcast, focused around FedRAMP CR26. Martin Rieger, Chief Solutions Officer at Quantope, Evgeny Jervis, CEO of SafeLogic, Johan Detweiler, CISO of StackArmor, and Steve Kooperman, CEO of ScoopCyber, will discuss what FedRAMP CR26 means and how to respond.
Steven Cooperman
Hello, everybody. This is Steve Cooperman with ScoopCyber, and welcome to another podcast. We're here at the Carahsoft studios in Reston, Virginia.
A really timely and interesting topic. I've been in enterprise IT my whole career, talking about FedRAMP, companies that needed to get certified, and FedRAMP to even do business with the government. This is getting turned on its head completely with something called CR26.
We're going to spend the time today educating everybody now, talking about the importance, the benefits, some of the challenge. I'm joined today by Johan Detweiler, CISO of StackArmor, Evgeny Jervis, CEO of SafeLogic, and Martin Rieger, Chief Solution Officer at Quantope.
Johann Dettweiler
Yeah, so I'm the CISO at a company called StackArmor. StackArmor, we help companies to deploy very rapidly and then obtain FedRAMP and DISA, FISMA authorization. Our specialty is really helping our customers come in, automate, and get ready to go through these processes.
We have kind of a weird connection here because we, StackArmor, have a product that we call the Armory, which is designed to host workloads that need to meet the FedRAMP regulations. Kind of strangely, we tie into both Quantope and SafeLogic. So Martin, I'll let you kind of explain how all that works.
Martin Rieger
Quantope specializes in zero trust at the data layer through a combination of encryption, identity, and zero trust policies that allow companies to connect via API to a solution that ultimately provides them the ability to swap crypto in and out at will, aka crypto agility. We also provide key management services in addition to a few other key tools. But the relationship here, and where things kind of get fun, is we are the first customer and first solution inside StackArmor's Armory to be offered to the United States government and then other commercial entities seeking to comply.
Steven Cooperman
Perfect. And then Evgeny, SafeLogic plays a very critical role in all of this, so maybe explain a little bit about that.
Evgeny Gervis
Yeah. Thanks, Steven. So glad to be here.
I appreciate the opportunity. So yeah, SafeLogic, we are a cryptographic software company. So we provide FIPS-validated cryptographic software modules that really help organizations that need to meet requirements of FIPS-validated cryptography to really accelerate their journey.
They can leverage our modules. We can get them certification in their name in less than two months. So if you know traditional process going through the NIST queue takes two years, we can do this in two months, get them certification in their name, and then maintain software and certification over time.
Obviously, very important for FedRAMP, you know, REV5 as well as CR26 continues to be important. Of course, we've also been very focused on post-quantum cryptography. We work very closely with NIST. I actually have the honor and the privilege to lead a PQC migration working group at NIST, and we have great collaborators there. All of SafeLogic's cryptographic modules have PQC enabled, going through the full FIPS process, CAVP and CMVP. And of course, we also focus on the broader PQC migration, including things like cryptographic agility as well and strong entropy and things of that nature. So we tend to be cryptography geeks.
So our customers don't have to.
Steven Cooperman
I was going to say, I'm glad someone is. I've never met anybody in cryptography that's not.
Johann Dettweiler
Well, and I think a really important point there is you allow customers to obtain a validation in their name. Because there are other companies out there where you can go through this process, but then you end up sort of being hidden on the validation marketplace because you're under a third-party name. So really, really cool.
Yeah, I mean, we've had the opportunity to work together in the past, and that was something that really floored me is, you know, you get your own listing. That's very important. That's right.
Steven Cooperman
Johan, what is FedRAMP CR26? Why is it so important?
Johann Dettweiler
CR26 is FedRAMP's attempt to sort of modernize and automate their processes. And strangely enough, it also introduces the idea that FedRAMP is no longer an authorization program. They are a certification program.
And I mean, that nuance is very slight, but essentially what they're saying now is we are not authorizing you to deploy within agencies. What we're doing is we're certifying that you have demonstrated that you have the materials available to an agency that can properly demonstrate your security. And that's what we're certifying.
And they've sort of taken the idea that FedRAMP owns the authorization and instead said, no, we're going to make sure a CSP has everything that an agency needs to make that decision. But we're making the agencies take it upon themselves to make that decision now. And so in this process, they've introduced an entire new set of rules that are built on top of Rev5.
And then they've also introduced an entirely new certification pathway called 20X. The idea behind 20X is essentially a very rapid certification where they get rid of the 853 controls. They introduce what they call key security indicators, KSIs.
The entire point being that if you're going to go through the 20X process, you need to automate that and demonstrate that you implement the KSIs. So they don't want you to work with an auditor, take screenshots, anything like that. What they want and what they expect is that at any moment, you can say, here is my dashboard, my JSON file, whatever you use to say, these are the status right now in this moment of the KSIs, and then have very dynamic ways to deliver evidence, very dynamic ways to work with auditors.
And then the Rev5 process is still there, but it's also making a push towards more automated, more kind of punctual documentation, where instead of long narratives, it's simply declarative statements around this is how you're doing it. You know, you still have to implement the 853 controls, but the expectation is now get rid of the narratives and tell me this is how you're doing it and this is how you validated that you're doing it. So even in Rev5, they're trying to push towards a more automated approach when the assessor comes in to say, you know, here are a generated set of JSON files or here is an automated process with an outcome that demonstrates that I've implemented certain controls.
So, you know, from the top level, it is really pushing FedRAMP towards automation.
Steven Cooperman
From a company that's already FedRAMPed or I'm thinking of being FedRAMPed, should I be scared of this? Is this something that, you know, as a company, what should be my approach? Do I need to take a class on this?
What do I do?
Martin Rieger
Well, if there's one thing I think the FedRAMP program has been good about, it's broadcasting and in some cases forecasting their desires and their goals and their expectations. So CR26 is a great example of that, right? So 30 days ahead of time, hey, here's what we're getting ready to do.
This is what the next two to three years look like. These are the goals and ambitions. So the answer to that is to say, I don't know if I think they should be worried or concerned if they already have an ATO in place, then, you know, for them, it's going to be adding to an existing continuous monitoring state and compliance framework that they have in place.
And, you know, ultimately they have the ability and I would almost say flexibility to compensate as well as more or less decide how they want to implement those controls and those key security indicators, because they're basically, there's things they have to do, but nobody's telling them exactly how to do it, right? You need to paint your house, but they're not saying what kind of brush do you need to roll or you're going to use latex or whatever. So, yeah, it's very much a situation where the CSPs are being told well ahead of time what they have to do.
And there is a vehicle and a path and an approach where they can reach out to the government and say, OK, we disagree or we're not sure what to do here.
Steven Cooperman
So they have help. So I know one of the things Quantipy focuses on and has great solutions is key management.
Martin Rieger
Yeah. So when it comes to data security and FedRAMP itself has explicit requirements around key management, we at Quantipy have a solution that basically allows customers to continuously monitor as well as provide tamper resistant evidence around that key governance and that their requirements across regions, availability zones, in addition to who owns them and how they're distributed. So we have a distributed key management solution that specifically supports this, that is very robust.
It is built upon attribute role based access controls in addition to identity tied back to that. So all of those elements together are also what supports our data security components. But from a key management perspective, having that type of redundancy and having that consistent and or persistent availability is critical.
From a almost a post quantum perspective, which is which is really what I would say is probably one of the hottest topics right now, there's an expectation that down the road quantum computers are going to be able to bust through everything. Technically, they can break through right now.
Evgeny Gervis
Yeah. You know, we've been obviously following SCR 26 with great interest. And, you know, you mentioned the key security indicators from everything we see, there's been no dilution of requirements as far as cryptography is concerned, you know, and that's for good reason.
I mean, cryptography there is really foundational to digital privacy trust. Right. And you want to make sure that cryptography is well implemented.
Right. You don't want somebody just when I go to the basement, code something up and say, here it is. You know, you wanted to actually go through the process.
Right. So so we, you know, we see our 26. There are some nuances depending on the level and the sensitivity of the data.
But for the worst, you know, for the sensitive data, you absolutely still have the requirement to have PIPs with a cryptography. Now, PIPs on 40-3 and that really is has not gone away. Right.
It's it's still there. And as a matter of fact, not to talk about post-quantum much, but there's been a very important executive order just came out this week, actually just past Monday on June 22nd. So the president signed two of them.
One was on kind of advancement of quantum computing. The other one is safety. Right.
So it's really around post-quantum cryptography and set some real timeline for for for migrating to post-quantum cryptography. But in addition to migrating post-quantum cryptography, the executive order actually reaffirmed that the implementations, the PQC implementations have to be PIPs validated. I didn't think I was going to say the words, you know, PIPs and actually mentioned the NIST CMVP program and the executive order that was like, yeah, that was pretty cool.
And it talked about like it needs to be validated. It also talked about the validation process. There's a lot of, you know, there's attempts to sort of streamline and accelerate and Safelight actually participates in those efforts.
But the point is that whether it's classical cryptography or post-quantum cryptography, when it comes to FedRAMP CR26, the requirements are still very much there. And you have to have well implemented. And what the government means by that is certified, certified cryptography.
Steven Cooperman
So, Martin, you know, what's the ultimate goal? Why did they do this? I think there's a number of reasons.
Martin Rieger
One is, is we across the last couple of administrations, we've had a lot of memos, a lot of guidance, a lot of change. You know, who would have thought that the entire government would have access to AI without any guardrails up front and immediately pull that back? Well, this is really level setting the playing field, right, in terms of explaining explicitly what must be done, how it has to be done.
And you're either going to comply or you're not going to comply. And to me, that's their objective here. Now, whether you're talking 853 or you're talking CR26, it doesn't change the fact that encryption is a critical, critical component and set of controls within both frameworks.
In addition to the fact that it's been there for the end, whether you look at FISMA, FedRAMP, RMF or even CMMC, it's built into all of them. I mean, how HIPAA is using FIPS, right? So the outcome of this is basically to set the explicit requirements and make sure everybody understands here's what you have to do to be compliant.
So finally, it's not nebulous, it's explicit. You don't have to guess, you don't have to wonder, you don't have to go, OK, which memo was it that said I had to do what?
Steven Cooperman
So another hot topic I hear all the time with a number of vendors we support is FIPS 143.
Evgeny Gervis
Yeah.
Steven Cooperman
But how is this placed in all this?
Evgeny Gervis
It's the latest and greatest version of the NIST standards for cryptography. So the reality is, you know, the bad guys are not standing still. Right.
And there's new cryptolytic attacks all the time. And that's even outside of the quantum computer. So the standards have to keep up.
So for 20 years, we had FIPS 140-2 and even within that, there's been changes. But as of it's actually rapidly approaching September of this year, if you still have FIPS 140-2 module, it will go historical, meaning that it's no longer recommended for new procurements. So the push to move to FIPS 140-3 is real.
And we've been doing a lot of work with our customers, as you might imagine, moving them to FIPS 140-3.
Martin Rieger
Well, and that's because of all the folks that managed to get that 11th hour back in 2022, right before the switch to 140-3, in case you're curious, like, wait a minute, why did that happen? Right. Sneaky, sneaky.
But yeah, I mean, the FIPS aspect isn't lost. But we talk about FedRAMP and we talk about encryption, but there's no explicit quantum aspects built into FedRAMP yet. They're still relying on NIST to handle that and the NSA and DOD and the federal government as a whole.
You got FIPS 203, 204, 205 that are mandating each have their own specific elements around those quantum requirements that FedRAMP will point to. But for the purposes of this discussion, the requirement of encryption for any any federal system, cloud or not, has been there from the beginning.
Johann Dettweiler
You know, cryptography is probably one of the better highlights of the new direction that FedRAMP is trying to go in, because cryptography lends itself well to automation. If you've properly built your system, you should be able to query it, pull deterministic telemetry that demonstrates the modules that you have in place. And instead of sitting with an auditor and going through every operating system and having someone go into the CLI and open up the page that shows FIPS mode on and that auditor takes a screenshot, that's incredibly laborious.
Nine times out of 10, they'll take a screenshot of one representative thing in the environment and call that good enough. You know, it really was never a great audit of cryptography. Now, moving towards this automated fashion, I think we're going to get much more brutal truth.
I think people are going to realize that maybe where they thought cryptography was enabled, maybe it's not fully enabled. But I think we're going to get a much broader scope and spectrum and a much more honest telling of, you know, this is truly where we've encrypted the data. And I mean, the nice thing is FedRAMP has also opened up the ideas that, you know, not everything has to be treated as the same within the environment.
You know, this new set of rules is saying, hey, if it's not sensitive data, well, then don't worry about these. Just protect the sensitive data. So I think cryptography is a really good example of where this direction of the new FedRAMP can be really helpful.
Evgeny Gervis
Dovetailing on your point just now, you know, there's been fundamental lack of what we call proper cryptographic posture management in general. Right. And, you know, the need to migrate to post-quantum cryptography is right now really shining the light of that as the catalyst.
Hey, where is your cryptography in the first place? Do we have visibility into your cryptography? How are you using it today?
Right. So that cryptographic posture management, which, by the way, there's a lot of existing because of that, a lot of existing cryptographic debt, you know, forget like quantum computers. If you were to look at a lot of environments right now, you'll still find a lot of SHA-1, MD5, things that are like classically vulnerable, not just vulnerable to quantum, like have been vulnerable for decades.
They're still there. So right now, actually, this PQC readiness is actually forcing us to establish better cryptographic posture management, get better visibility of cryptography, which actually will also help with something like CR26, right, because you need to have the visibility to know where you have cryptography and if it's protecting sensitive data, it needs to be PIPs validated. It needs to be PQC and PQC algorithms, like you mentioned, are now part of the PIPs on 40-3 standards.
The other thing here is you kind of like mentioned the term crypto agility, right? This is a very important concept these days because the world in which you could have cryptographic algorithms and for them to be basically the same for 20 years is over. That will not repeat itself.
Right. So right now, we need to be prepared to properly govern and seamlessly migrate our cryptographic infrastructure in cases where either, you know, your compliance requirements or your internal threat model or external threats, you know, or advancements of, you know, quantum computing, whatnot, are having you migrate. So maybe right now I need to move from RSA and elliptic curves, public key cryptography, and I'm going to move to ML camp, PIPs 203.
But let's say in a few years, I actually want to move to a new key exchange mechanism from NIST HQC once it gets standardized. It should not be like, oh, my God, how do I do that? You should literally should be able to go to one place and change.
ML camp to HQC and that should be able to now get propagated across your cryptographic infrastructure. And you should be able to have that visibility, continuous visibility to make sure that's, in fact, happening and your cryptographic policy gets honored. So.
Steven Cooperman
So writing this is key. Agility.
Martin Rieger
Agility. And there's obvious places where crypto applies and expectations, for example, transport. Right.
So a lot of companies will decide, am I encrypting the tunnel or am I encrypting the data and just sending it? So it's it's there have been requirements in place that stated when and where certain things should be encrypted. But the government has always left it up to the service providers or worked with them to say what to encrypt.
Right. And then how long are they keeping it for? What's the sensitivity level?
So all those things around the data itself have always been up to the government from an auditor's perspective, the mechanisms for that encryption and those algorithms and modules. Are they historically retired? Are they still active?
Do you have a number behind them? So the auditors, when they come in and are looking to understand. Not just where did you encrypt, but what did you encrypt and why?
Right. Our statement was always very simple. If you're going to encrypt, it must be FIPS and that's something that you had to educate customers on right away, because most most companies don't even know about this or aren't even thinking about it.
Steven Cooperman
So just spending time with you guys, you know, you are the experts. What's the single biggest operational challenge for an organization?
Johann Dettweiler
Well, I'll take it probably from it, because I mean, cryptography is always a challenge, but something that both BOD 2604, which came out on the 10th of June and then the new CR26 rules introduce is a new way of looking at vulnerabilities, moving from a sort of score based approach to a risk based approach where essentially you have to consider, you know, the structure of the component upon which the vulnerability is found. Is it Internet reachable?
You have to consider whether or not this is a known exploitable vulnerability. You know, look at things like the Kev, look at EPSS scores. Can the vulnerability be automated?
And then, you know, what is the scope of if the vulnerability is exploited? Does it allow full system takeover partial? Based on those metrics, you know, what used to be for FedRAMP, 30 days to remediate high vulnerabilities, 90 to remediate moderate.
Now we're talking about, you know, in the situation where something is exploitable, you know, on an Internet based component, you have three days to immediately do something about it. And it's also an incident. And so, you know, if you think about what that means, I mean, there are teams out there right now, CSPs that are FedRAMP authorized that struggle with the 30, 90, 180 day timelines.
This completely shifts that on its head. You need to be far more dynamic in your approach to vulnerability management, not just being able to determine things like attack paths and then how you're going to associate and even categorize the scores, because FedRAMP is not prescriptive, neither is the bot. It simply says you come up with a way to do this.
Make sure it's solid, because if it's not, you're likely going to get pwned by Mythos or something like that. You know, so this is really up to you to do this. This behooves you to put in good security.
Martin Rieger
I think the statement you just made is a conversation we almost have daily around when companies are looking at, for example, Q day, that day when everybody has access to a quantum computer and can break through everything. The reality is, AI is already doing everything we feared Q day would bring. We can break through everything right now.
Right. Which is why it's always just beginning. Yeah.
I mean, AI is chaining together. They're putting kill chains together with low risk vulnerabilities that as humans, we probably wouldn't have even considered or thought of.
Johann Dettweiler
FedRAMP actually goes out and just says, consider everything automatable at this point. Unless you can prove otherwise, just consider it to be automatable. And I actually agree.
I think, you know, I mean, we saw that with Fable 5 being in the wild for four days or something like that.
Martin Rieger
There was a 14-year-old that broke through multiple DODs. It wasn't even a script kitty. Literally just said, break in.
Evgeny Gervis
Right.
Martin Rieger
So back to that point, that's why the encryption at the data layer, not to mention encryption period, is so important. Is it OK that AI right now, it's breaking in, but if it's not encrypted, it's not protected. Well, yeah, that's on those organizations.
The least they can do is if you're building a federal system and it has any kind of sensitivity around it. But the concern, I guess, going back to it is we're still a few years away from that post-quantum mentality, but it doesn't negate the fact that AI is here right now and already doing everything we're worried about today.
Johann Dettweiler
So when we're talking about quantum cryptography breaking encryption, it's a little bit different than something like Mythos hacking into your system, right? Because Mythos, it can bypass a lot of your security, get to the encrypted data, but it still doesn't have the capability to actually break encryption. But that changes with post-quantum computers, right?
Yeah.
Evgeny Gervis
And, you know, both of those things do come down to ability to really manage and govern your cryptography. You know, I kind of sometimes think about this and it's a really good point you just made, Martin, in terms of like AI, right? I mean, yes, even before Q-Day, AI is already finding all those zero-day vulnerabilities, right?
And some of those are cryptographic infrastructure. It's like the evil cousin. It's like, yeah, it's like, and do you know where that cryptographic infrastructure lives, right?
So, you know, and can you easily change it today? Again, forget quantum, just with AI, right? And so the way I kind of think about this is, you know, if we want to go fast with AI, we need to also be able to govern our cryptography properly.
It's kind of like this example that people give, you know, the brakes are there to allow you to go fast in the car, right? If there were no brakes, you couldn't go fast. If you want to go fast with AI, we've got to go and build that ability to manage and govern our cryptography.
So whether it's Q-Day or it's a zero-day that gets discovered by Amethyst, you know exactly where that is. You can easily migrate. So, you know, it's not, you know, you don't have to like cut out the drywall every time you want to change the pipes.
You build an access panel, you can get it. This is the crypto agility, right? So but yes, both of those things with quantum people talk about harvest now, decrypt later, things like that.
Pipes are already leaking. Got to do something today, but they're leaking for other reasons. Like, you know, AI is also creating a huge leak, right?
And can you discover those pipes and change the model?
Martin Rieger
Your analogy has like Ricky Bobby sitting on my shoulder saying, go faster. So to that point, let's go back to the data layer for just a second. And this is the situation you just described.
Harvest now, decrypt later. Crypto agility, yes, but there is still the today's situation as well as Q-Day. And that is literally the reason we created data layer tools, because they're not just using encryption.
We're also using identity and then we're using zero trust attribute animal based policies so that, OK, let's just say it does bust through the encryption. It's not going to matter because of the fact that those policies that are put in place along with the identity requirements will have to be accessible and obtained by an AI or quantum or a threat actor. So together, those components offset that.
But when that encryption is broken and we expect it to be broken, a lot of them have art that's already happened, like 44 qubits to get through AES right now. So it can be done. It's expensive, unrealistic.
But when that day comes, that's where the post quantum crypto agility aspect comes in to say, OK, that got broken, let's swap it out, but let's have the ability to do it in a simplistic, easy manner so that you don't have to rebuild the architecture, the framework or the code base.
Steven Cooperman
The urgency, regardless of this, is exponential related to post quantum and AI.
Johann Dettweiler
AI has introduced an attack path and an attack ecosystem that is so much faster than it's ever been before. I mean, you know, patch cycles used to be quarterly sometimes, maybe monthly if you were lucky and had a great company. Like that's not acceptable anymore.
Like companies are going to have to step up and start thinking about weekly, most likely daily patches, because, you know, that's the thing is these enhanced vulnerability timelines are only going to work if the vendors out there step up their patching cycles as well. And I mean, obviously, they're going to utilize AI to kind of help that happen. Right.
But this new BOD and CR26 is kind of that forcing function, I think, to move the ecosystem towards, look, these things are out in the wild. If you're not actively doing something more than responding to a high vulnerability in 30 days, you got real problems. So I think, again, it's a good step in the right direction.
Steven Cooperman
Martin, if you were talking to a federal CSO and they're considering a new CSP on their CR26, what would you tell them to focus on?
Martin Rieger
Depending on the solution, but let's just assume there's no AI involved. As a component of an agency authorizing a system, I would tell you without a doubt, I don't think any system, whether it's FISMA, FedRAMP or other, is going to get away with not addressing post-quantum readiness. Right.
And along those lines, the rest of the security controls or KSIs, if you go the 20x route, are going to be there. That's not going away. I think the biggest things that they're looking at in addition to encryption are, you know, software build materials along with AI build materials and things of that nature, as well as, you know, what's in their boundaries.
So from a security perspective, I don't know that I think any of that's really going to change unless we're looking at folks who don't quite meet the requirements or do have a FIPS 140-2 that's about to expire without a plan or a roadmap. But data and the security of the data is always the first thing they focus on and protecting that agency's information. So I think encryption is going to be paramount to that.
Evgeny Gervis
One thing I would say is that turn a challenge into an opportunity. Right. I always think of compliance, you know, I've been in the security space for a long time.
Right. My perspective is that compliance should be a byproduct of good risk management. Right.
So in other words, can you take, and I think CR26 is more conducive to that than REV5, can you take that and actually make that a core part of your risk management program such as whatever evidence you need to produce telemetry is actually all naturally flowing from your risk management process. So in other words, rather than studying for the test, right, make this part of your risk management program to actually manage your overall risks. And as a CISO, you've got to do that.
Your job kind of depends on that. This gives you an opportunity to do that.
Johann Dettweiler
So a playbook to get that done. Yeah. Yeah.
And I mean, this is where I kind of toot stack armor's horn. Right. Is, you know, if you have companies like you guys, you specialize in cryptography.
That's what you want to give the government. That's the service. Maybe you don't want to spend a whole lot of time having to develop an entire engineering program around CR26.
You know, that's where stack armor comes in. Let us worry about that part of it. Allow you guys to deploy your workload in a known good environment where we've done all the research.
We've put all the automation in place to meet these new CR26 rules to also go after FedRAMP 20X. So let us worry about that so that you guys can concentrate on it. Because for a small CSP, I mean, CR26 is going to be difficult.
I mean, so much so that, I mean, FedRAMP recommends you will try and read it. You work with it using an LLM agent. That's how complex the consolidated rule JSON is.
You know, so that's a lot to take in. So if you're a small company, you know, maybe working with an advisor, come into a company like StackArmor so that we can worry about all of that for you and let you focus on your service, what you want to give the government. Right.
Steven Cooperman
And then we have this better together story.
Evgeny Gervis
Well, you know, so for instance, you know, part of this FedRAMP obviously journey and I'm not, you guys are much more experts in FedRAMP. But our piece is cryptography. But obviously, I know we've worked with StackArmor before as part of, you know, being part of that stack to kind of, you know, taking something that could be very tall, you know, a pole in the tent to get to FedRAMP and just kind of making this a non-issue.
And same message as what you said, you know, you don't want to be dabbling in this world. Cryptography is difficult. It changes all the time.
Even within FIPS 140-2, I mean, there's been a lot of changes. It's going to be the same thing with Dash 3. You know, there's constant transitions.
You want to let people who do this for a living do this for you and just enable you. And then the other controls.
Johann Dettweiler
To this day, if somebody comes to us and they say, we have our own cryptographing module, I pretty much just pick up the phone and send them to you guys. Because, I mean, it is that specialty. It's that specialization, like trying to figure out the validation process for FIPS when you're also trying to improve the product that you're trying to sell to the government.
Like, that's a very difficult thing to do. And again, like, you know, the answer is not going to be to via code your way out of it. Like, it's just not going to happen.
Evgeny Gervis
Yeah, yeah, yeah. To toot, I guess, our horn for a second, this year, I think 25% of all the cryptographic modules that come out from the SAP program has been basically by safe logic. So, you know, so we have developed a certain ability to do this.
Martin Rieger
We would recommend that. So to that point, despite our name, we don't create encryption, right? And so while we're in the armory as kind of the inaugural system, we also are a partner and we leverage safe logics, libraries and algorithms and modules in that capacity and enable them.
Right. So that that that's kind of that full circle, almost ecosystem there. You worry about the compliance.
We'll deal with the framework and API, you guys provide the encryption and everybody will be happy.
Steven Cooperman
Yeah, one of the great one of the great things about working with Kairosoft, we could put a bundle together. So as we wrap up, any just, you know, thing you want to say to people out there, if they're just getting going, you know, where do they start? What do they do?
Johann Dettweiler
Yeah. So, you know, it doesn't hurt to familiarize yourself with these things. I mean, FedRAMP recommends digesting their rules, using an LLM and working with an agent.
And that's a great place to start. You know, go in, start asking questions, start figuring out, you know, how complex is this? You know, there's a lot of tooling out there, both open source and, you know, paid programs that do things like gap analysis and things like that.
But I mean, I will say if if there are new terms that you're hearing, if you've never heard FIPS 140-2, if you've never heard, you know, validated versus certified versus, you know, what is that or you didn't know cryptography was going to be on the table, you really might want to consider reaching out to companies and reaching out to third parties and building that into your security budget, because, again, trying to start down the path of some of these things when your main focus still needs to be selling to the government, creating a product that the government wants, because, you know, everything is going to become more agile. That's the entire point of CR26 is to allow them to authorize systems much, much faster. We've heard, you know, crypto agility is now very important.
So everything is becoming more agile and your competitors are going to be more agile. So you need to focus on your service. You need to make it as good as possible.
So, you know, consider reaching out to third parties that have experienced these things. Perfect. Martin, I know you have a comment on this.
Martin Rieger
I do. It's a differentiator for first and foremost. I mean, it's required to FedRAMP itself or any kind of compliance element.
But from that perspective, valid versus compliant or validated, but also inheritance versus leveraging. And I say those things to kind of emphasize the fact that a lot of companies can be duped into thinking they're good to go, that they're compliant because they leveraged a product that said we are FIPS compliant, right, without actually being validated by someone like SafeLogic or even the inheritance model, right? SolarWinds comes to mind, right, as an organization who's like, yeah, we don't provide algorithms and modules.
We inherit it from the host OS. Only if you enable that or turn it on, right? And a lot of folks got burned by it.
And so over the years, we've educated and told folks, you need to make sure all of this is accounted for so that we don't have that, just as a loose example, that SolarWinds situation where there was no FIPS encryption, right? That being said, I think CR26, just to kind of bring it back a little bit, is going to help in a lot of ways in terms of supporting the audit and giving that real world view into an environment using those key security indicators. I don't think it's going to change anything around preparation and what it takes to get ready for something like that or even implement it.
So that's another reason we kind of developed the tools the way we did is to help simplify that process and get folks up and running in a matter of minutes.
Evgeny Gervis
Well, you know, I think in a way, CR26 is making FedRAMP, in my opinion, more accessible as long as you do it with the right partner. Don't try to do this alone. I think the right way to think about this is, again, risk management.
How do you integrate this with your overall security program and kind of make some of those artifacts almost like fall out naturally from that? There is some possibility to use cryptography that's maybe not well-made for certain use cases. And validate for others.
But honestly, if I'm going through this process, do I really want to have to explain to somebody why I thought this data was sensitive or not sensitive, whether it took this path or that path? If I'm working with the right partner, I can just have all my cryptography be validated, certified, and that argument is closed. And you get, you know, hopefully some comparative advantages also with that by having your certification public.
And really kind of take a look again, as we talked about crypto agility, cryptographic posture management, you're going to need this to get the visibility for FedRAMP. You're going to need this for your PQC migration. You're going to need to know that, you know, the next time, you know, there's improvements to the Mythos model.
And there are some. So you're just going to have to be better and fluid at managing, which really underpins your digital privacy and trust is cryptography.
Steven Cooperman
Yeah. All right. So I think we'll wrap it up.
But, you know, spending time prepping for this and spending time with you guys. I learned a lot about CR26 and the importance. I got a good feel for the threat landscape that's ever increasing, you know, the synergies that takes a better together story to solve it.
So I'd like to thank StackArmor, SafeLogic, Quantopea, pronounced correctly. And the whole audience. There'll be a lot of material out of this, a way to contact everybody.
And I appreciate everybody participating. So thanks. Great.
Anthony Jimenez
Thanks for listening. Thank you to our guests, Martin, Evgeny, Johan, and Steve. Don't forget to like, comment and subscribe to Carahcast and be sure to listen to our other discussions.
If you'd like more information on how Quantopea, SafeLogic, StackArmor, and ScoopCybert can assist your organization, please visit www.kerasoft.com or email us at quantopeamarketing at kerasoft.com. Thanks again for listening and have a great day.