Skip to content
Open to board advisory and board seats: 2H 2026, then CY 2027-2028.
See details →
Captricity · 2016 to 2017

Delivering a FedRAMP Moderate ATO on Time

Took over a FedRAMP Moderate authorization four months behind schedule and delivered the ATO on time and on budget. Also cut AWS cost by about 40%.

Schedule at takeover
4 months behind
ATO
On time, on budget
AWS cost
About 40% lower

The problem

As Head of Information Security at Captricity, reporting to the CEO, I took over a FedRAMP Moderate authorization project that was four months behind schedule. A 2017 FedRAMP post on baselines and impact levels describes Moderate as most appropriate for cloud services where the loss of confidentiality, integrity, and availability would have serious adverse effects on an agency's operations, assets, or individuals. The finish line is an authorization to operate, the ATO.

The same role carried SOC 2, HIPAA, and EU privacy readiness, plus a geo-distributed AWS estate spread across hundreds of instances.

The approach

On a late authorization, the first thing I'd check is whether the documented system matches the running one. A control narrative written against a system that doesn't exist yet is work you do twice.

I put SOC 2, HIPAA, and EU privacy readiness under one risk framework, so a control gets designed and evidenced once, then mapped to every obligation it meets. I built SecDevOps into CI/CD, so security runs in the same pipeline that ships the product; I've written about why security and DevOps belong under one roof. And I automated the AWS estate with Ansible, Chef, and Puppet. A configuration defined in code is one you can show an assessor, rebuild, and keep from drifting.

The outcome

We delivered the ATO on time and on budget. Separately, I cut AWS cost about 40% through redesign and vendor rationalization.

What I'd tell anyone inheriting a late authorization: settle the scope and make the paperwork match the system before you ask anyone to write faster.

FedRAMPComplianceAWS