TWO GOVERNMENT WORKFLOWS · DIFFERENT AUTHORITIES

Choose the provider-owned cloud path or the contractor-controlled technical-data path.

Both workflows need current evidence and accountable handoffs. Dextra does not exercise FedRAMP certification, agency authorization, 3PAO assessment, Government verification, authentication, approval, or release authority.

THONIS-led synthetic walkthroughs. Federal scenarios are demonstrated around a bounded stakeholder, problem, authority path, and safe data boundary before any controlled environment is considered. No authorization, official assessment, live integration, Government acceptance, or customer deployment is claimed.

Two government workflows. Different entry conditions.

01 · PROVIDER-OWNED CLOUD PATH

Cloud vulnerability decision and reporting

When the customer confirms the applicable path, class, rule profile, owner, and safe case, AssuranceOps is designed to keep the finding, contextual evaluation, provider-approved response, engineering work, outcome checks, reporting handoff, and reopening trigger connected.

Source boundary: FedRAMP NTC-0014 establishes a transition for affected offerings. It does not prove universal applicability, demand for Dextra, certification, authorization, 3PAO work, or a THONIS outcome.

Request an AssuranceOps walkthrough
02 · CONTRACTOR-CONTROLLED TECHNICAL DATA

Defense technical-data handoff

Conversion is not acceptance. TRACE—Traceable Records, Applicability, Change, and Execution—is gated on a funded sponsor, qualified domain expert, lawful rights-cleared corpus, exact profile and toolchain, approved security path, and named recipient-acceptance route. It prepares the contractor-controlled record for the next authorized activity; Dextra does not exercise Government verification, approval, authentication, acceptance, or release authority.

Source boundary: contract and program requirements establish the source formats, markings, target profile, validation, viewer, testing, and recipient-acceptance path. Customer-specific requirements remain part of a bounded engagement.

Inspect the public TRACE teaser

From static packages to current decision evidence.

OMB M-24-15 directs a more automated, reusable, machine-readable FedRAMP program. CR26 and rule-specific notices turn that direction into operating rules for their in-scope paths, while VDR and VER require persistent vulnerability handling, contextual evaluation, and structured reporting.

When those rules apply, the work is not simply producing another narrative. Teams must preserve which evidence was current, how a vulnerability was evaluated, who approved a disposition, what mitigation occurred, and whether later change invalidated the decision. The same evidence spine can later support customer-selected Security Decision Record, certification-data-sharing, and continuous-monitoring requirements without turning those future paths into current capability claims.

Read the plain-English acronym and applicability guide

Keep the authorities separate.

POLICY

OMB M-24-15

Executive-branch direction for modernizing FedRAMP, reuse, machine-readable artifacts, and API-based exchange where feasible.

Official memorandum
PROGRAM RULES

FedRAMP CR26

The current consolidated FedRAMP ruleset. RFC-0024 was a proposal; CR26 and rule-specific notices now control dates and requirements.

Official timeline
TECHNICAL FORMAT

NIST OSCAL

Machine-readable models for controls, implementation, assessment, and POA&M data. Valid structure does not prove evidence authenticity.

Official project

Detection is only the beginning.

VDR means Vulnerability Detection and Response: persistently find, prioritize, mitigate, remediate, and manage vulnerabilities. The general Rev. 5 rule states that it applies to providers with FedRAMP certifications of any type; class-specific timeframes still require the exact current profile.

VER means Vulnerability Evaluation and Reporting: evaluate exploitability, internet reachability, potential agency impact, status, and decision context. It does not stand for verification.

Official Rev. 5 VDR rules · Official Rev. 5 VER rules

JUL 4, 2026

Optional

Early adoption began, subject to rule-specific applicability.

DEC 7, 2026

Obtain and maintain

VDR and VER become required for affected offerings obtaining or maintaining FedRAMP Certification under the notice.

MAR 7, 2027

Grace ends

The notice's corrective-action grace period ends for affected offerings not following these rules.

The current FedRAMP notice aligned to CISA BOD 26-04 establishes these dates for affected offerings, subject to the exact certification path, class, and rule profile; it does not establish any Dextra certification, authorization, 3PAO role, customer result, or deadline outcome. RFC-0024's proposal timeline is superseded.

Specialists operate it. Accountable leaders decide.

01

Operate

Cloud-provider security, SecOps, engineering, GRC, control-owner, and evidence-owner teams maintain the facts and work.

02

Assess

Independent assessors and reviewers test evidence, question conclusions, and document findings.

03

Authorize

System owners, CISOs, FedRAMP reviewers, and agency authorizing officials consume the risk record and retain decision authority.

This does not apply to every federal employee or every commercial computer user. Most people benefit indirectly and may only complete a narrow assigned task, training, access review, evidence request, or remediation.

Keep the full vulnerability operation in one governed case.

AssuranceOps brings finding intake, contextual evaluation, provider response, engineering work, verification, reporting, exceptions, approval, and reopening into one guided federal operating mode. Approved scanners, tickets, GRC, evidence stores, identity, and reporting systems can remain connected where they retain useful or authoritative records.

Any FedRAMP JSON or OSCAL exchange remains customer-specific implementation and validation scope; it is not represented as a generally available export. AI may classify, compare, summarize, and draft. Deterministic telemetry and official validators remain distinct, and accountable humans approve material risk decisions.

01

Scanner + cloud inventory

Detect the signal and establish the affected asset, service, topology, reachability, and technical state.

02

Ticketing + engineering

Plan and execute the mitigation or remediation work, with owners, changes, tests, and rollback information.

03

GRC + OSCAL tooling

Maintain program records, controls, evidence, POA&M relationships, reporting, and machine-readable exchange.

04

Dextra AssuranceOps

Connect the current context, human judgment, approved response, execution proof, verification result, recurring report, and reopening trigger.

Federal buyers will expect production-grade identity and access, audit history, evidence attachments, deadlines and escalation, scanner and ticket connectors, control and POA&M links, validated human and machine outputs, and an approved deployment boundary. The public teaser demonstrates selected decision states, not a deployed federal service or authorization.

Inspect the evidence-to-decision boundary.

The current synthetic evidence shows how a vulnerability decision can preserve source context, reviewer judgment, a bounded response, verification, and reporting state without implying an agency authorization decision.

Request a tailored walkthrough
Current synthetic FedAssuranceOps vulnerability decision evidence
Current synthetic teaser · THONIS-led walkthrough available · no authorization, production integration, or customer deployment implied

First confirm whether one provider case qualifies.

For one customer-confirmed applicable FedRAMP provider case, support selected CR26 VDR/VER requirements by mapping the exact certification path and class, rule profile, systems involved, scanner signal, cloud context, engineering work, reviewer rationale, decision owner, due date, verification evidence, reporting handoff, and measurable pilot acceptance criteria. THONIS provides bounded implementation support; it does not perform an independent assessment or issue, guarantee, or imply certification, authorization, or endorsement. Do not send sensitive evidence until an approved intake path is defined.

Check the case and profile