Coalfire
More Events
Events We Are Sponsoring

The federal compliance landscape is shifting fast — but beneath the acronyms, something important is happening. NIST Rev 5, the 20x initiative and DoW's Software Fast Track (SWFT), are all converging on the following principles: automated risk management, machine-readable security documentation and continuous evidence over point-in-time audits.
For organizations supporting both civilian and defense customers, this convergence is an opportunity. The challenge has always been maintaining separate baselines for separate frameworks — a costly, error-prone approach that doesn't scale. But if your Rev 5 baseline is built right, it can serve as the foundation for DoW overlays without starting over.
In this session, we will:
- Unpack how 20x, Rev 5 cATO and DoW SWFT align.
- Show you how to architect a single, extensible baseline that satisfies all three.
- Cover how OSCAL makes machine-readable SSPs the connective tissue across frameworks.
- What "build once, extend everywhere" looks like in practice.
- How teams use these shared principles to accelerate authorization timelines without sacrificing rigor.
Whether you're an ISSO, system owner or GRC practitioner navigating a multi-framework environment, this session will give you a concrete strategy for building compliance infrastructure that's ready for where federal risk management is headed — not just where it's been.