Register    ➤

Agenda

8 AM EDT

55 MINS
8 AM EDT 55 MINS

Registration & Networking Breakfast

8:55 AM EDT

5 MINS
8:55 AM EDT 5 MINS

Opening Remarks

Frank Konkel
Frank Konkel
Editor-in-Chief
GovExec
Frank Konkel
Frank Konkel
Editor-in-Chief
GovExec
Frank Konkel
Frank Konkel
Editor-in-Chief
GovExec

9 AM EDT

5 MINS
9 AM EDT 5 MINS
Mainstage Programming

Program Introduction

Craig Abod
Craig Abod
President & CEO
Carahsoft Technology Corp.
Craig Abod
Craig Abod
President & CEO
Carahsoft Technology Corp.
Craig Abod
Craig Abod
President & CEO
Carahsoft Technology Corp.

9:05 AM EDT

20 MINS
9:05 AM EDT 20 MINS
Mainstage Programming

FedRAMP Reauthorization

Rep. James Walkinshaw
Rep. James Walkinshaw
Virginia's 11th Congressional District
U.S. Representative

As expectations for government services continue to evolve, agencies are embracing artificial intelligence and automation to deliver faster, more personalized, and more accessible experiences. This keynote will explore how public-sector leaders are moving from CX strategy to execution, leveraging AI and emerging technologies to modernize service delivery, improve outcomes, and strengthen public trust.

Rep. James Walkinshaw
Rep. James Walkinshaw
Virginia's 11th Congressional District
U.S. Representative

As expectations for government services continue to evolve, agencies are embracing artificial intelligence and automation to deliver faster, more personalized, and more accessible experiences. This keynote will explore how public-sector leaders are moving from CX strategy to execution, leveraging AI and emerging technologies to modernize service delivery, improve outcomes, and strengthen public trust.

As expectations for government services continue to evolve, agencies are embracing artificial intelligence and automation to deliver faster, more personalized, and more accessible experiences. This keynote will explore how public-sector leaders are moving from CX strategy to execution, leveraging AI and emerging technologies to modernize service delivery, improve outcomes, and strengthen public trust.

Rep. James Walkinshaw
Rep. James Walkinshaw
Virginia's 11th Congressional District
U.S. Representative

As expectations for government services continue to evolve, agencies are embracing artificial intelligence and automation to deliver faster, more personalized, and more accessible experiences. This keynote will explore how public-sector leaders are moving from CX strategy to execution, leveraging AI and emerging technologies to modernize service delivery, improve outcomes, and strengthen public trust.

9:25 AM EDT

35 MINS
9:25 AM EDT 35 MINS
Mainstage Programming

Opening Fireside Chat: Future of Security in Federal

Greg Barbaccia
Greg Barbaccia
Federal Chief Information Officer
Office of Management and Budget
Hon. Dr. Kevin Rhodes, PMP
Hon. Dr. Kevin Rhodes, PMP
Administrator, Office of Federal Procurement Policy, Office of Management and Budget
Executive Office of the President (EOP)
Frank Konkel
Frank Konkel
Editor-in-Chief
GovExec

A candid conversation featuring senior government leaders on the future of secure cloud adoption and federal technology modernization. Looking beyond today's priorities, they'll reflect on the lasting changes they hope to leave behind, the evolution of FedRAMP including the vision behind FedRAMP 20x, the realities of leading technology policy from inside OMB, and what it takes to successfully partner with the federal government. Attendees will gain firsthand insights into where federal technology is headed, how government is rethinking trust, security, and acquisition, and what these changes mean for agencies and industry alike.

Greg Barbaccia
Greg Barbaccia
Federal Chief Information Officer
Office of Management and Budget
Hon. Dr. Kevin Rhodes, PMP
Hon. Dr. Kevin Rhodes, PMP
Administrator, Office of Federal Procurement Policy, Office of Management and Budget
Executive Office of the President (EOP)
Frank Konkel
Frank Konkel
Editor-in-Chief
GovExec

A candid conversation featuring senior government leaders on the future of secure cloud adoption and federal technology modernization. Looking beyond today's priorities, they'll reflect on the lasting changes they hope to leave behind, the evolution of FedRAMP including the vision behind FedRAMP 20x, the realities of leading technology policy from inside OMB, and what it takes to successfully partner with the federal government. Attendees will gain firsthand insights into where federal technology is headed, how government is rethinking trust, security, and acquisition, and what these changes mean for agencies and industry alike.

A candid conversation featuring senior government leaders on the future of secure cloud adoption and federal technology modernization. Looking beyond today's priorities, they'll reflect on the lasting changes they hope to leave behind, the evolution of FedRAMP including the vision behind FedRAMP 20x, the realities of leading technology policy from inside OMB, and what it takes to successfully partner with the federal government. Attendees will gain firsthand insights into where federal technology is headed, how government is rethinking trust, security, and acquisition, and what these changes mean for agencies and industry alike.

Greg Barbaccia
Greg Barbaccia
Federal Chief Information Officer
Office of Management and Budget
Hon. Dr. Kevin Rhodes, PMP
Hon. Dr. Kevin Rhodes, PMP
Administrator, Office of Federal Procurement Policy, Office of Management and Budget
Executive Office of the President (EOP)
Frank Konkel
Frank Konkel
Editor-in-Chief
GovExec

A candid conversation featuring senior government leaders on the future of secure cloud adoption and federal technology modernization. Looking beyond today's priorities, they'll reflect on the lasting changes they hope to leave behind, the evolution of FedRAMP including the vision behind FedRAMP 20x, the realities of leading technology policy from inside OMB, and what it takes to successfully partner with the federal government. Attendees will gain firsthand insights into where federal technology is headed, how government is rethinking trust, security, and acquisition, and what these changes mean for agencies and industry alike.

10 AM EDT

45 MINS
10 AM EDT 45 MINS
Mainstage Programming

FedRAMP: A Trust Network

Branko Bokan
Branko Bokan
Chief, Architecture & Engineering Center of Excellence
CISA
Ryan Hoesing
Ryan Hoesing
Chief of Staff, FedRAMP
General Services Administration
Amber Pearson
Amber Pearson
Deputy Chief Officer Support Operations & Executive Director for Business Support Operations
Department of Veterans Affairs
Drew Myklegard
Drew Myklegard
Executive Director of Government Programs
Carahsoft

FedRAMP is more than a certification process, it is a trust framework that enables agencies to confidently adopt shared cloud services. This panel brings together agency leaders to discuss how FedRAMP supports mission outcomes, reduces duplicative assessments, and enables faster procurement while maintaining strong security postures.

Branko Bokan
Branko Bokan
Chief, Architecture & Engineering Center of Excellence
CISA
Ryan Hoesing
Ryan Hoesing
Chief of Staff, FedRAMP
General Services Administration
Amber Pearson
Amber Pearson
Deputy Chief Officer Support Operations & Executive Director for Business Support Operations
Department of Veterans Affairs
Drew Myklegard
Drew Myklegard
Executive Director of Government Programs
Carahsoft

FedRAMP is more than a certification process, it is a trust framework that enables agencies to confidently adopt shared cloud services. This panel brings together agency leaders to discuss how FedRAMP supports mission outcomes, reduces duplicative assessments, and enables faster procurement while maintaining strong security postures.

Branko Bokan
Ryan Hoesing
+2
2 more speakers

FedRAMP is more than a certification process, it is a trust framework that enables agencies to confidently adopt shared cloud services. This panel brings together agency leaders to discuss how FedRAMP supports mission outcomes, reduces duplicative assessments, and enables faster procurement while maintaining strong security postures.

Branko Bokan
Branko Bokan
Chief, Architecture & Engineering Center of Excellence
CISA
Ryan Hoesing
Ryan Hoesing
Chief of Staff, FedRAMP
General Services Administration
Amber Pearson
Amber Pearson
Deputy Chief Officer Support Operations & Executive Director for Business Support Operations
Department of Veterans Affairs
Drew Myklegard
Drew Myklegard
Executive Director of Government Programs
Carahsoft

FedRAMP is more than a certification process, it is a trust framework that enables agencies to confidently adopt shared cloud services. This panel brings together agency leaders to discuss how FedRAMP supports mission outcomes, reduces duplicative assessments, and enables faster procurement while maintaining strong security postures.

Branko Bokan
Ryan Hoesing
+2
2 more speakers

10:45 AM EDT

15 MINS
10:45 AM EDT 15 MINS

Networking Break

11 AM EDT

35 MINS
11 AM EDT 35 MINS
Mainstage Programming

One Year Into FedRAMP Modernization: Updates from Industry

Hemant Baidwan
Hemant Baidwan
Former DHS CISO; Executive CISO
Knox
Kristine Lam
Kristine Lam
Executive Director
CSP-AB
Ross Nodurft
Ross Nodurft
Executive Director
Alliance for Digital Innovation
Kenny Scott
Kenny Scott
Founder & CEO
Paramify
Cortney Steiner
Cortney Steiner
Vice President
Carahsoft

Join industry leaders for a candid discussion on how FedRAMP modernization is playing out one year in. As the FedRAMP Consolidated Rules for 2026 and FedRAMP 20x reshape the program, panelists will share how CSPs are adapting in real time; what’s working, what’s challenging, and what it means for the future of cloud security in the federal market.

Hemant Baidwan
Hemant Baidwan
Former DHS CISO; Executive CISO
Knox
Kristine Lam
Kristine Lam
Executive Director
CSP-AB
Ross Nodurft
Ross Nodurft
Executive Director
Alliance for Digital Innovation
Kenny Scott
Kenny Scott
Founder & CEO
Paramify
Cortney Steiner
Cortney Steiner
Vice President
Carahsoft

Join industry leaders for a candid discussion on how FedRAMP modernization is playing out one year in. As the FedRAMP Consolidated Rules for 2026 and FedRAMP 20x reshape the program, panelists will share how CSPs are adapting in real time; what’s working, what’s challenging, and what it means for the future of cloud security in the federal market.

Hemant Baidwan
Kristine Lam
+3
3 more speakers

Join industry leaders for a candid discussion on how FedRAMP modernization is playing out one year in. As the FedRAMP Consolidated Rules for 2026 and FedRAMP 20x reshape the program, panelists will share how CSPs are adapting in real time; what’s working, what’s challenging, and what it means for the future of cloud security in the federal market.

Hemant Baidwan
Hemant Baidwan
Former DHS CISO; Executive CISO
Knox
Kristine Lam
Kristine Lam
Executive Director
CSP-AB
Ross Nodurft
Ross Nodurft
Executive Director
Alliance for Digital Innovation
Kenny Scott
Kenny Scott
Founder & CEO
Paramify
Cortney Steiner
Cortney Steiner
Vice President
Carahsoft

Join industry leaders for a candid discussion on how FedRAMP modernization is playing out one year in. As the FedRAMP Consolidated Rules for 2026 and FedRAMP 20x reshape the program, panelists will share how CSPs are adapting in real time; what’s working, what’s challenging, and what it means for the future of cloud security in the federal market.

Hemant Baidwan
Kristine Lam
+3
3 more speakers

11:35 AM EDT

45 MINS
11:35 AM EDT 45 MINS

Building the Future FedRAMP

Pete Waterman
Pete Waterman
FedRAMP Director
General Services Administration
Drew Myklegard
Drew Myklegard
Executive Director of Government Programs
Carahsoft

As FedRAMP evolves towards automation, machine‑readable security data, and continuous assurance, the FedRAMP community is redefining what risk management and compliance looks like. Pete Waterman will discuss what is next for FedRAMP and what it means to all FedRAMP stakeholders.

Pete Waterman
Pete Waterman
FedRAMP Director
General Services Administration
Drew Myklegard
Drew Myklegard
Executive Director of Government Programs
Carahsoft

As FedRAMP evolves towards automation, machine‑readable security data, and continuous assurance, the FedRAMP community is redefining what risk management and compliance looks like. Pete Waterman will discuss what is next for FedRAMP and what it means to all FedRAMP stakeholders.

As FedRAMP evolves towards automation, machine‑readable security data, and continuous assurance, the FedRAMP community is redefining what risk management and compliance looks like. Pete Waterman will discuss what is next for FedRAMP and what it means to all FedRAMP stakeholders.

Pete Waterman
Pete Waterman
FedRAMP Director
General Services Administration
Drew Myklegard
Drew Myklegard
Executive Director of Government Programs
Carahsoft

As FedRAMP evolves towards automation, machine‑readable security data, and continuous assurance, the FedRAMP community is redefining what risk management and compliance looks like. Pete Waterman will discuss what is next for FedRAMP and what it means to all FedRAMP stakeholders.

12:20 PM EDT

40 MINS
12:20 PM EDT 40 MINS

Lunch & Networking

1:10 PM EDT

1 HR
1:10 PM EDT 1 HR
Breakout Session

GRC for Agencies

Sean Flowers
Sean Flowers
Chief Information Security Officer
Dept. of Commerce
Michaela Iorga, Ph.D.
Michaela Iorga, Ph.D.
Supervisory Computer Engineer, Director OSCAL Program, SURF Program; Hardware Security Group
NIST
Thomas Weikle
Thomas Weikle
Assistant Director, Information Assurance
Dept. of Justice
Travis Howerton
Travis Howerton
Co-Founder and CEO
RegScale
Ron Ross
Ron Ross
CEO
RONROSSECURE
Gabriela Smith-Sherman
Gabriela Smith-Sherman
Senior Director, FedRAMP and Cybersecurity Solutions
StackArmor
Bobby Tuohy
Bobby Tuohy
Chief Product Officer
Cav

As federal agencies navigate increasingly complex security and compliance requirements, traditional Governance, Risk, and Compliance (GRC) approaches are struggling to keep pace. Disconnected tools, manual processes, and static documentation are no longer sufficient in an era defined by continuous monitoring, automation, and machine-readable evidence. This session explores what a modernized GRC environment could—and should—look like for federal agencies and industry stakeholders. Panelists will examine the concept of a “single pane of glass” for security, where real-time visibility, integrated data, and automated workflows converge to provide a unified view of risk and compliance posture across systems and environments. The conversation will also address the growing imperative for machine readability within frameworks like FedRAMP 20x, and how agencies can evolve their internal capabilities to ingest, validate, and act on continuous data streams rather than point-in-time assessments.

Read More
Sean Flowers
Sean Flowers
Chief Information Security Officer
Dept. of Commerce
Michaela Iorga, Ph.D.
Michaela Iorga, Ph.D.
Supervisory Computer Engineer, Director OSCAL Program, SURF Program; Hardware Security Group
NIST
Thomas Weikle
Thomas Weikle
Assistant Director, Information Assurance
Dept. of Justice
Travis Howerton
Travis Howerton
Co-Founder and CEO
RegScale
Ron Ross
Ron Ross
CEO
RONROSSECURE
Gabriela Smith-Sherman
Gabriela Smith-Sherman
Senior Director, FedRAMP and Cybersecurity Solutions
StackArmor
Bobby Tuohy
Bobby Tuohy
Chief Product Officer
Cav

As federal agencies navigate increasingly complex security and compliance requirements, traditional Governance, Risk, and Compliance (GRC) approaches are struggling to keep pace. Disconnected tools, manual processes, and static documentation are no longer sufficient in an era defined by continuous monitoring, automation, and machine-readable evidence. This session explores what a modernized GRC environment could—and should—look like for federal agencies and industry stakeholders. Panelists will examine the concept of a “single pane of glass” for security, where real-time visibility, integrated data, and automated workflows converge to provide a unified view of risk and compliance posture across systems and environments. The conversation will also address the growing imperative for machine readability within frameworks like FedRAMP 20x, and how agencies can evolve their internal capabilities to ingest, validate, and act on continuous data streams rather than point-in-time assessments.

**this session is not being recorded and is subject to Chatham House Rules, meaning there is no attribution to individuals or organizations. This ensures a candid and open discussion environment.**

Sean Flowers
Michaela Iorga, Ph.D.
+5
5 more speakers

As federal agencies navigate increasingly complex security and compliance requirements, traditional Governance, Risk, and Compliance (GRC) approaches are struggling to keep pace. Disconnected tools, manual processes, and static documentation are no longer sufficient in an era defined by continuous monitoring, automation, and machine-readable evidence. This session explores what a modernized GRC environment could—and should—look like for federal agencies and industry stakeholders. Panelists will examine the concept of a “single pane of glass” for security, where real-time visibility, integrated data, and automated workflows converge to provide a unified view of risk and compliance posture across systems and environments. The conversation will also address the growing imperative for machine readability within frameworks like FedRAMP 20x, and how agencies can evolve their internal capabilities to ingest, validate, and act on continuous data streams rather than point-in-time assessments.

Read More
Sean Flowers
Sean Flowers
Chief Information Security Officer
Dept. of Commerce
Michaela Iorga, Ph.D.
Michaela Iorga, Ph.D.
Supervisory Computer Engineer, Director OSCAL Program, SURF Program; Hardware Security Group
NIST
Thomas Weikle
Thomas Weikle
Assistant Director, Information Assurance
Dept. of Justice
Travis Howerton
Travis Howerton
Co-Founder and CEO
RegScale
Ron Ross
Ron Ross
CEO
RONROSSECURE
Gabriela Smith-Sherman
Gabriela Smith-Sherman
Senior Director, FedRAMP and Cybersecurity Solutions
StackArmor
Bobby Tuohy
Bobby Tuohy
Chief Product Officer
Cav

As federal agencies navigate increasingly complex security and compliance requirements, traditional Governance, Risk, and Compliance (GRC) approaches are struggling to keep pace. Disconnected tools, manual processes, and static documentation are no longer sufficient in an era defined by continuous monitoring, automation, and machine-readable evidence. This session explores what a modernized GRC environment could—and should—look like for federal agencies and industry stakeholders. Panelists will examine the concept of a “single pane of glass” for security, where real-time visibility, integrated data, and automated workflows converge to provide a unified view of risk and compliance posture across systems and environments. The conversation will also address the growing imperative for machine readability within frameworks like FedRAMP 20x, and how agencies can evolve their internal capabilities to ingest, validate, and act on continuous data streams rather than point-in-time assessments.

**this session is not being recorded and is subject to Chatham House Rules, meaning there is no attribution to individuals or organizations. This ensures a candid and open discussion environment.**

Sean Flowers
Michaela Iorga, Ph.D.
+5
5 more speakers

1:10 PM EDT

1 HR
1:10 PM EDT 1 HR
Breakout Session

Leveraging FedRAMP at New Agencies

Ryan Hoesing
Ryan Hoesing
Chief of Staff, FedRAMP
General Services Administration
Josh Seefried
Josh Seefried
Assistant CIO
HUD
Bob Carter
Bob Carter
VP of Public Sector and Public Markets
IBM Apptio
Irina Denisenko
Irina Denisenko
CEO
Knox
Stephen Pipino
Stephen Pipino
Distinguished Cybersecurity Architect
Salesforce
Drew Myklegard
Drew Myklegard
Executive Director of Government Programs
Carahsoft

Achieving a FedRAMP Authorization to Operate (ATO) is a major milestone—but it’s only the beginning of a successful public sector journey. This session explores how cloud service providers and ISVs can effectively leverage their FedRAMP authorization to drive adoption across multiple agencies, turning initial authorization into sustained growth. Panelists will share practical insights into “land and expand” strategies used by leading vendors, including how to position reuse packages, navigate agency-specific procurement processes, and build credibility with mission owners and acquisition teams. The discussion will also highlight what federal buyers expect to see in a strong reuse package—from clear security documentation to evidence of operational maturity and customer success.

Read More
Ryan Hoesing
Ryan Hoesing
Chief of Staff, FedRAMP
General Services Administration
Josh Seefried
Josh Seefried
Assistant CIO
HUD
Bob Carter
Bob Carter
VP of Public Sector and Public Markets
IBM Apptio
Irina Denisenko
Irina Denisenko
CEO
Knox
Stephen Pipino
Stephen Pipino
Distinguished Cybersecurity Architect
Salesforce
Drew Myklegard
Drew Myklegard
Executive Director of Government Programs
Carahsoft

Achieving a FedRAMP Authorization to Operate (ATO) is a major milestone—but it’s only the beginning of a successful public sector journey. This session explores how cloud service providers and ISVs can effectively leverage their FedRAMP authorization to drive adoption across multiple agencies, turning initial authorization into sustained growth. Panelists will share practical insights into “land and expand” strategies used by leading vendors, including how to position reuse packages, navigate agency-specific procurement processes, and build credibility with mission owners and acquisition teams. The discussion will also highlight what federal buyers expect to see in a strong reuse package—from clear security documentation to evidence of operational maturity and customer success.

**this session is not being recorded and is subject to Chatham House Rules, meaning there is no attribution to individuals or organizations. This ensures a candid and open discussion environment.**

Ryan Hoesing
Josh Seefried
+4
4 more speakers

Achieving a FedRAMP Authorization to Operate (ATO) is a major milestone—but it’s only the beginning of a successful public sector journey. This session explores how cloud service providers and ISVs can effectively leverage their FedRAMP authorization to drive adoption across multiple agencies, turning initial authorization into sustained growth. Panelists will share practical insights into “land and expand” strategies used by leading vendors, including how to position reuse packages, navigate agency-specific procurement processes, and build credibility with mission owners and acquisition teams. The discussion will also highlight what federal buyers expect to see in a strong reuse package—from clear security documentation to evidence of operational maturity and customer success.

Read More
Ryan Hoesing
Ryan Hoesing
Chief of Staff, FedRAMP
General Services Administration
Josh Seefried
Josh Seefried
Assistant CIO
HUD
Bob Carter
Bob Carter
VP of Public Sector and Public Markets
IBM Apptio
Irina Denisenko
Irina Denisenko
CEO
Knox
Stephen Pipino
Stephen Pipino
Distinguished Cybersecurity Architect
Salesforce
Drew Myklegard
Drew Myklegard
Executive Director of Government Programs
Carahsoft

Achieving a FedRAMP Authorization to Operate (ATO) is a major milestone—but it’s only the beginning of a successful public sector journey. This session explores how cloud service providers and ISVs can effectively leverage their FedRAMP authorization to drive adoption across multiple agencies, turning initial authorization into sustained growth. Panelists will share practical insights into “land and expand” strategies used by leading vendors, including how to position reuse packages, navigate agency-specific procurement processes, and build credibility with mission owners and acquisition teams. The discussion will also highlight what federal buyers expect to see in a strong reuse package—from clear security documentation to evidence of operational maturity and customer success.

**this session is not being recorded and is subject to Chatham House Rules, meaning there is no attribution to individuals or organizations. This ensures a candid and open discussion environment.**

Ryan Hoesing
Josh Seefried
+4
4 more speakers

1:10 PM EDT

1 HR
1:10 PM EDT 1 HR
Breakout Session

FedRAMP 20x in Practice — From Roadmap to Reality

Amber Pearson
Amber Pearson
Deputy Chief Officer Support Operations & Executive Director for Business Support Operations
Department of Veterans Affairs
Nicole Thompson
Nicole Thompson
Security Director of FedRAMP
General Services Administration
Irfan Nawaz
Irfan Nawaz
Board Chair
CSP-AB
John Gallagher
John Gallagher
GRC Technical Lead
OpenAI
Bhanu Jagasia
Bhanu Jagasia
Founding Samurai, Chief Executive Samurai (CEO)
blackstack.io
Kenny Scott
Kenny Scott
Founder & CEO
Paramify

As FedRAMP 20x continues to reshape the authorization landscape, organizations are seeking clarity on what the future state truly looks like—and how to get there. This session moves beyond high-level vision to examine the FedRAMP roadmap in practice, providing a grounded view of where the program stands today, what changes are actively underway, and how both agencies and cloud service providers can align to emerging expectations. Panelists will unpack the current state of FedRAMP 20x initiatives, including the shift toward automation, continuous validation, and Key Security Indicators (KSIs) as a mechanism for demonstrating security posture. The discussion will address one of the most pressing questions facing the ecosystem: how KSIs can be trusted as a reliable, secure, and scalable alternative to traditional control-based assessments.

Read More
Amber Pearson
Amber Pearson
Deputy Chief Officer Support Operations & Executive Director for Business Support Operations
Department of Veterans Affairs
Nicole Thompson
Nicole Thompson
Security Director of FedRAMP
General Services Administration
Irfan Nawaz
Irfan Nawaz
Board Chair
CSP-AB
John Gallagher
John Gallagher
GRC Technical Lead
OpenAI
Bhanu Jagasia
Bhanu Jagasia
Founding Samurai, Chief Executive Samurai (CEO)
blackstack.io
Kenny Scott
Kenny Scott
Founder & CEO
Paramify

As FedRAMP 20x continues to reshape the authorization landscape, organizations are seeking clarity on what the future state truly looks like—and how to get there. This session moves beyond high-level vision to examine the FedRAMP roadmap in practice, providing a grounded view of where the program stands today, what changes are actively underway, and how both agencies and cloud service providers can align to emerging expectations. Panelists will unpack the current state of FedRAMP 20x initiatives, including the shift toward automation, continuous validation, and Key Security Indicators (KSIs) as a mechanism for demonstrating security posture. The discussion will address one of the most pressing questions facing the ecosystem: how KSIs can be trusted as a reliable, secure, and scalable alternative to traditional control-based assessments.

**this session is not being recorded and is subject to Chatham House Rules, meaning there is no attribution to individuals or organizations. This ensures a candid and open discussion environment.**

Amber Pearson
Nicole Thompson
+4
4 more speakers

As FedRAMP 20x continues to reshape the authorization landscape, organizations are seeking clarity on what the future state truly looks like—and how to get there. This session moves beyond high-level vision to examine the FedRAMP roadmap in practice, providing a grounded view of where the program stands today, what changes are actively underway, and how both agencies and cloud service providers can align to emerging expectations. Panelists will unpack the current state of FedRAMP 20x initiatives, including the shift toward automation, continuous validation, and Key Security Indicators (KSIs) as a mechanism for demonstrating security posture. The discussion will address one of the most pressing questions facing the ecosystem: how KSIs can be trusted as a reliable, secure, and scalable alternative to traditional control-based assessments.

Read More
Amber Pearson
Amber Pearson
Deputy Chief Officer Support Operations & Executive Director for Business Support Operations
Department of Veterans Affairs
Nicole Thompson
Nicole Thompson
Security Director of FedRAMP
General Services Administration
Irfan Nawaz
Irfan Nawaz
Board Chair
CSP-AB
John Gallagher
John Gallagher
GRC Technical Lead
OpenAI
Bhanu Jagasia
Bhanu Jagasia
Founding Samurai, Chief Executive Samurai (CEO)
blackstack.io
Kenny Scott
Kenny Scott
Founder & CEO
Paramify

As FedRAMP 20x continues to reshape the authorization landscape, organizations are seeking clarity on what the future state truly looks like—and how to get there. This session moves beyond high-level vision to examine the FedRAMP roadmap in practice, providing a grounded view of where the program stands today, what changes are actively underway, and how both agencies and cloud service providers can align to emerging expectations. Panelists will unpack the current state of FedRAMP 20x initiatives, including the shift toward automation, continuous validation, and Key Security Indicators (KSIs) as a mechanism for demonstrating security posture. The discussion will address one of the most pressing questions facing the ecosystem: how KSIs can be trusted as a reliable, secure, and scalable alternative to traditional control-based assessments.

**this session is not being recorded and is subject to Chatham House Rules, meaning there is no attribution to individuals or organizations. This ensures a candid and open discussion environment.**

Amber Pearson
Nicole Thompson
+4
4 more speakers

2:10 PM EDT

5 MINS
2:10 PM EDT 5 MINS

Networking Break

2:15 PM EDT

1 HR
2:15 PM EDT 1 HR
Breakout Session

The GovRAMP Difference: Building Security Through Shared Risk Management

Noah Brown
Noah Brown
Executive Advisor
GovRAMP PMO
David Resler
David Resler
COO/CTO
GovRAMP
Charles Rote
Charles Rote
State CISO
Maine
Shawnzia Thomas
Shawnzia Thomas
State CIO
Georgia
Drenan Dudley
Drenan Dudley
Head of State, Local, Tribal, and Territorial Government Partnerships and Senior Advisor for Global Cyber Policy
Zscaler
Leah McGrath
Leah McGrath
Executive Director
GovRAMP

As cyber threats multiply, AI accelerates innovation, and technology ecosystems become increasingly interconnected, risk is no longer something any organization - private or public - can manage alone. Yet many security programs still treat risk management as an individual organization's responsibility. GovRAMP was built on a different premise: security is a shared responsibility, and risk management must be shared as well. More than a certification program, GovRAMP brings together governments, providers, assessors, and security leaders around a common framework for trust, accountability, and continuous improvement. This session explores the GovRAMP difference—how a shared risk management model helps organizations navigate a rapidly changing threat landscape, promotes consistent and practical interpretations of security requirements, and creates a stronger foundation for innovation, including the adoption of AI and emerging technologies.

Read More
Noah Brown
Noah Brown
Executive Advisor
GovRAMP PMO
David Resler
David Resler
COO/CTO
GovRAMP
Charles Rote
Charles Rote
State CISO
Maine
Shawnzia Thomas
Shawnzia Thomas
State CIO
Georgia
Drenan Dudley
Drenan Dudley
Head of State, Local, Tribal, and Territorial Government Partnerships and Senior Advisor for Global Cyber Policy
Zscaler
Leah McGrath
Leah McGrath
Executive Director
GovRAMP

As cyber threats multiply, AI accelerates innovation, and technology ecosystems become increasingly interconnected, risk is no longer something any organization - private or public - can manage alone. Yet many security programs still treat risk management as an individual organization's responsibility. GovRAMP was built on a different premise: security is a shared responsibility, and risk management must be shared as well. More than a certification program, GovRAMP brings together governments, providers, assessors, and security leaders around a common framework for trust, accountability, and continuous improvement. This session explores the GovRAMP difference—how a shared risk management model helps organizations navigate a rapidly changing threat landscape, promotes consistent and practical interpretations of security requirements, and creates a stronger foundation for innovation, including the adoption of AI and emerging technologies.

**this session is not being recorded and is subject to Chatham House Rules, meaning there is no attribution to individuals or organizations. This ensures a candid and open discussion environment.**

Noah Brown
David Resler
+4
4 more speakers

As cyber threats multiply, AI accelerates innovation, and technology ecosystems become increasingly interconnected, risk is no longer something any organization - private or public - can manage alone. Yet many security programs still treat risk management as an individual organization's responsibility. GovRAMP was built on a different premise: security is a shared responsibility, and risk management must be shared as well. More than a certification program, GovRAMP brings together governments, providers, assessors, and security leaders around a common framework for trust, accountability, and continuous improvement. This session explores the GovRAMP difference—how a shared risk management model helps organizations navigate a rapidly changing threat landscape, promotes consistent and practical interpretations of security requirements, and creates a stronger foundation for innovation, including the adoption of AI and emerging technologies.

Read More
Noah Brown
Noah Brown
Executive Advisor
GovRAMP PMO
David Resler
David Resler
COO/CTO
GovRAMP
Charles Rote
Charles Rote
State CISO
Maine
Shawnzia Thomas
Shawnzia Thomas
State CIO
Georgia
Drenan Dudley
Drenan Dudley
Head of State, Local, Tribal, and Territorial Government Partnerships and Senior Advisor for Global Cyber Policy
Zscaler
Leah McGrath
Leah McGrath
Executive Director
GovRAMP

As cyber threats multiply, AI accelerates innovation, and technology ecosystems become increasingly interconnected, risk is no longer something any organization - private or public - can manage alone. Yet many security programs still treat risk management as an individual organization's responsibility. GovRAMP was built on a different premise: security is a shared responsibility, and risk management must be shared as well. More than a certification program, GovRAMP brings together governments, providers, assessors, and security leaders around a common framework for trust, accountability, and continuous improvement. This session explores the GovRAMP difference—how a shared risk management model helps organizations navigate a rapidly changing threat landscape, promotes consistent and practical interpretations of security requirements, and creates a stronger foundation for innovation, including the adoption of AI and emerging technologies.

**this session is not being recorded and is subject to Chatham House Rules, meaning there is no attribution to individuals or organizations. This ensures a candid and open discussion environment.**

Noah Brown
David Resler
+4
4 more speakers

2:15 PM EDT

1 HR
2:15 PM EDT 1 HR
Breakout Session

The Path to 4,500: Scaling Secure Cloud Adoption Across Government

Ryan Hoesing
Ryan Hoesing
Chief of Staff, FedRAMP
General Services Administration
Josh Seefried
Josh Seefried
Assistant CIO
HUD
Michael Cardaci
Michael Cardaci
CEO
FedHIVE/HRTec
Matt Huntgate
Matt Huntgate
Managing Principal
Schellman
Morgan Kaplan
Morgan Kaplan
Head of Public Sector
Vanta
Ross Nodurft
Ross Nodurft
Executive Director
Alliance for Digital Innovation

As demand for secure, cloud-based solutions continues to grow across the federal landscape, a central question emerges: how do we scale the FedRAMP marketplace to meet it? With ambitious goals to dramatically expand the number of authorized products, success will depend on deeper collaboration between government and industry to streamline pathways to authorization and accelerate adoption.

This session explores what it will take to move from today’s state to a future where thousands of secure solutions are readily available to agencies. Panelists will examine how FedRAMP 20x initiatives—including automation, reuse, and machine-readable validation—can reduce friction in the authorization process while maintaining trust in security outcomes. The discussion will also focus on the shared responsibilities required to scale: how agencies can modernize procurement and embrace reuse, and how industry can deliver standardized, high-quality security evidence that supports faster evaluation and broader adoption.

Read More
Ryan Hoesing
Ryan Hoesing
Chief of Staff, FedRAMP
General Services Administration
Josh Seefried
Josh Seefried
Assistant CIO
HUD
Michael Cardaci
Michael Cardaci
CEO
FedHIVE/HRTec
Matt Huntgate
Matt Huntgate
Managing Principal
Schellman
Morgan Kaplan
Morgan Kaplan
Head of Public Sector
Vanta
Ross Nodurft
Ross Nodurft
Executive Director
Alliance for Digital Innovation

As demand for secure, cloud-based solutions continues to grow across the federal landscape, a central question emerges: how do we scale the FedRAMP marketplace to meet it? With ambitious goals to dramatically expand the number of authorized products, success will depend on deeper collaboration between government and industry to streamline pathways to authorization and accelerate adoption.

This session explores what it will take to move from today’s state to a future where thousands of secure solutions are readily available to agencies. Panelists will examine how FedRAMP 20x initiatives—including automation, reuse, and machine-readable validation—can reduce friction in the authorization process while maintaining trust in security outcomes. The discussion will also focus on the shared responsibilities required to scale: how agencies can modernize procurement and embrace reuse, and how industry can deliver standardized, high-quality security evidence that supports faster evaluation and broader adoption.

**this session is not being recorded and is subject to Chatham House Rules, meaning there is no attribution to individuals or organizations. This ensures a candid and open discussion environment.**

Ryan Hoesing
Josh Seefried
+4
4 more speakers

As demand for secure, cloud-based solutions continues to grow across the federal landscape, a central question emerges: how do we scale the FedRAMP marketplace to meet it? With ambitious goals to dramatically expand the number of authorized products, success will depend on deeper collaboration between government and industry to streamline pathways to authorization and accelerate adoption.

This session explores what it will take to move from today’s state to a future where thousands of secure solutions are readily available to agencies. Panelists will examine how FedRAMP 20x initiatives—including automation, reuse, and machine-readable validation—can reduce friction in the authorization process while maintaining trust in security outcomes. The discussion will also focus on the shared responsibilities required to scale: how agencies can modernize procurement and embrace reuse, and how industry can deliver standardized, high-quality security evidence that supports faster evaluation and broader adoption.

Read More
Ryan Hoesing
Ryan Hoesing
Chief of Staff, FedRAMP
General Services Administration
Josh Seefried
Josh Seefried
Assistant CIO
HUD
Michael Cardaci
Michael Cardaci
CEO
FedHIVE/HRTec
Matt Huntgate
Matt Huntgate
Managing Principal
Schellman
Morgan Kaplan
Morgan Kaplan
Head of Public Sector
Vanta
Ross Nodurft
Ross Nodurft
Executive Director
Alliance for Digital Innovation

As demand for secure, cloud-based solutions continues to grow across the federal landscape, a central question emerges: how do we scale the FedRAMP marketplace to meet it? With ambitious goals to dramatically expand the number of authorized products, success will depend on deeper collaboration between government and industry to streamline pathways to authorization and accelerate adoption.

This session explores what it will take to move from today’s state to a future where thousands of secure solutions are readily available to agencies. Panelists will examine how FedRAMP 20x initiatives—including automation, reuse, and machine-readable validation—can reduce friction in the authorization process while maintaining trust in security outcomes. The discussion will also focus on the shared responsibilities required to scale: how agencies can modernize procurement and embrace reuse, and how industry can deliver standardized, high-quality security evidence that supports faster evaluation and broader adoption.

**this session is not being recorded and is subject to Chatham House Rules, meaning there is no attribution to individuals or organizations. This ensures a candid and open discussion environment.**

Ryan Hoesing
Josh Seefried
+4
4 more speakers

2:15 PM EDT

1.05 HRS
2:15 PM EDT 1.05 HRS
Breakout Session

Continuous Monitoring To Address Cyber Threats

Jay Gazlay
Jay Gazlay
Deputy Associate Director
CISA
Nicole Thompson
Nicole Thompson
Security Director of FedRAMP
General Services Administration
Rashaan Green
Rashaan Green
VP, Security
Second Front Systems
Mitch Herckis
Mitch Herckis
Head of Global Government Affairs
Wiz
Neil Sethi
Neil Sethi
Account Executive
Splunk
Kristine Lam
Kristine Lam
Executive Director
CSP-AB

As the Federal government faces persistent and increasingly sophisticated malicious cyber campaigns agencies must improve how they protect their networks and continuously ensure the security of IT assets. CISA’s recent Binding Operational Directive (BOD) changes how agencies prioritize vulnerability patching and a result FedRAMP is requiring CSPs to implement new Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules by December 7, 2026. This session explores how agencies and CSPs are approaching this new era of vulnerability management, how responsibilities are shared between CSPs and government stakeholders, and how both sides can work together to maintain a strong security posture without duplicating effort or creating bottlenecks. The discussion will also highlight lessons learned from agencies successfully implementing continuous monitoring at scale—demonstrating how automation, telemetry, and standardized data can reduce manual burden while improving visibility and trust.

Read More
Jay Gazlay
Jay Gazlay
Deputy Associate Director
CISA
Nicole Thompson
Nicole Thompson
Security Director of FedRAMP
General Services Administration
Rashaan Green
Rashaan Green
VP, Security
Second Front Systems
Mitch Herckis
Mitch Herckis
Head of Global Government Affairs
Wiz
Neil Sethi
Neil Sethi
Account Executive
Splunk
Kristine Lam
Kristine Lam
Executive Director
CSP-AB

As the Federal government faces persistent and increasingly sophisticated malicious cyber campaigns agencies must improve how they protect their networks and continuously ensure the security of IT assets. CISA’s recent Binding Operational Directive (BOD) changes how agencies prioritize vulnerability patching and a result FedRAMP is requiring CSPs to implement new Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules by December 7, 2026. This session explores how agencies and CSPs are approaching this new era of vulnerability management, how responsibilities are shared between CSPs and government stakeholders, and how both sides can work together to maintain a strong security posture without duplicating effort or creating bottlenecks. The discussion will also highlight lessons learned from agencies successfully implementing continuous monitoring at scale—demonstrating how automation, telemetry, and standardized data can reduce manual burden while improving visibility and trust.

**this session is not being recorded and is subject to Chatham House Rules, meaning there is no attribution to individuals or organizations. This ensures a candid and open discussion environment.**

Jay Gazlay
Nicole Thompson
+4
4 more speakers

As the Federal government faces persistent and increasingly sophisticated malicious cyber campaigns agencies must improve how they protect their networks and continuously ensure the security of IT assets. CISA’s recent Binding Operational Directive (BOD) changes how agencies prioritize vulnerability patching and a result FedRAMP is requiring CSPs to implement new Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules by December 7, 2026. This session explores how agencies and CSPs are approaching this new era of vulnerability management, how responsibilities are shared between CSPs and government stakeholders, and how both sides can work together to maintain a strong security posture without duplicating effort or creating bottlenecks. The discussion will also highlight lessons learned from agencies successfully implementing continuous monitoring at scale—demonstrating how automation, telemetry, and standardized data can reduce manual burden while improving visibility and trust.

Read More
Jay Gazlay
Jay Gazlay
Deputy Associate Director
CISA
Nicole Thompson
Nicole Thompson
Security Director of FedRAMP
General Services Administration
Rashaan Green
Rashaan Green
VP, Security
Second Front Systems
Mitch Herckis
Mitch Herckis
Head of Global Government Affairs
Wiz
Neil Sethi
Neil Sethi
Account Executive
Splunk
Kristine Lam
Kristine Lam
Executive Director
CSP-AB

As the Federal government faces persistent and increasingly sophisticated malicious cyber campaigns agencies must improve how they protect their networks and continuously ensure the security of IT assets. CISA’s recent Binding Operational Directive (BOD) changes how agencies prioritize vulnerability patching and a result FedRAMP is requiring CSPs to implement new Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules by December 7, 2026. This session explores how agencies and CSPs are approaching this new era of vulnerability management, how responsibilities are shared between CSPs and government stakeholders, and how both sides can work together to maintain a strong security posture without duplicating effort or creating bottlenecks. The discussion will also highlight lessons learned from agencies successfully implementing continuous monitoring at scale—demonstrating how automation, telemetry, and standardized data can reduce manual burden while improving visibility and trust.

**this session is not being recorded and is subject to Chatham House Rules, meaning there is no attribution to individuals or organizations. This ensures a candid and open discussion environment.**

Jay Gazlay
Nicole Thompson
+4
4 more speakers

3:15 PM EDT

5 MINS
3:15 PM EDT 5 MINS

Program Concludes