![]()
Fortreum, a leading federal cybersecurity assessment and advisory firm, completed two early FedRAMP 20x pilot assessments with InfusionPoints, putting the federal government’s automation-first compliance model to work at both Low and Moderate impact levels.
The company completed the Class B (Low) Phase I pilot on July 31, 2025, followed by the Class C (Moderate) Phase II pilot on April 10, 2026. The work covered 11 Key Security Indicators, 61 KSI rules and 209 validations for InfusionPoints’ XBU40 platform on AWS GovCloud.
As round-one early adopters, the companies entered the pilots before an established Moderate assessment path existed. Rather than follow a proven model, the teams helped determine how to generate, test, and present continuous evidence under FedRAMP 20x.
“There was no finished playbook and no previous Moderate assessment to follow,” said Jason Shropshire, COO at InfusionPoints. “We had to show that continuous evidence could work under real assessment conditions, not simply demonstrate the idea. Fortreum helped us test the model in practice and give the market an early look at how FedRAMP 20x can work at the Moderate level.”
Assessment moves inside the evidence pipeline
Traditional assessments rely heavily on documents that describe controls at a particular point in time. FedRAMP 20x requires continuous, machine-readable evidence to show how security controls operate.
That put the XBU40 evidence pipeline itself under examination. As the third-party assessment organization, Fortreum tested whether the pipeline collected evidence from the correct locations, included each required source, and produced output that matched the program’s security indicators. The process identified refinements that InfusionPoints incorporated into the platform.
“Continuous evidence changes the assessor’s job,” said James Leach, CEO and co-founder of Fortreum. “The work goes beyond reviewing documents and determining whether they accurately describe the environment. Assessors must test the system producing the evidence and determine whether its output can be trusted.”
Early pilots provide a working model
Completing both pilot cohorts gave federal agencies and cloud service providers an early example of how an automation-first assessment could operate at the Low- and Moderate-impact levels. The pilots also showed what cloud providers may need to build into their platforms before submitting evidence for independent assessment.
The work resulted in a certified XBU40 platform that InfusionPoints can use to help customers meet FedRAMP 20x requirements. It also demonstrated that the new model can be managed within a defined, real-world timeline.
“Automation-first compliance had to prove itself under assessment,” added Leach. “These pilots showed that continuous evidence can work, but the platform, evidence pipeline, and assessment process must be engineered to work together. Automating a weak process only produces weak evidence faster.”
The certification did not conclude the relationship. Fortreum and InfusionPoints continue to work together on federal cybersecurity modernization through joint AWS Marketplace offerings, industry events, and thought leadership.
Read the full case study here.
About Fortreum
Fortreum helps the Defense Industrial Base achieve and maintain cybersecurity compliance. The company is a C3PAO accredited for CMMC L2/L3 assessments, with hundreds of successful NIST 800-171, CMMC, and FedRAMP engagements delivered. Fortreum serves leading software providers, high-tech leaders, and defense contractors, and is accredited across FedRAMP, GovRAMP, CMMC L2/L3, SOC 2, ISO 27001, HIPAA, and DoD Impact Levels.
About InfusionPoints
InfusionPoints delivers a comprehensive set of advisory and managed security services that cover the full cybersecurity lifecycle, from concept to operations. A proven leader in Cybersecurity for the past 15 years, InfusionPoints combines extensive US Government security requirements knowledge with cloud expertise, advanced technology, and solid methodologies to provide customer success. In addition, InfusionPoints is in the Amazon Partner Network (APN), is an Advanced Consulting Partner, and is in the AWS Global Security Compliance Acceleration (GSCA), Solution Provider, Public Sector Solution Provider and Public Sector Partner Programs and has the AWS Security, Level 1 MSSP and Government Consulting Competencies. InfusionPoints is a Veteran-Owned Small Business (VOSB) and Historically Underutilized Business Zones (HUBZone) Small Business, and has ISO 9001, ISO 27001, and ISO 17020 Certifications as well as an A2LA FedRAMP 3PAO Certification.
View source version on businesswire.com: https://www.businesswire.com/news/home/20261001061434/en/
Media gallery