Pull to refresh
Logo
Aikido Security wins FedRAMP Moderate Authorization in months through Knox partnership

Aikido Security wins FedRAMP Moderate Authorization in months through Knox partnership

New Capabilities

The software security firm's federal edition is now procurable by U.S. agencies ahead of a December CISA deadline

2 days ago: Aikido achieves FedRAMP Moderate Authorization

Overview

Updated 1 hour ago

U.S. federal agencies can now buy Aikido Security's software security platform. The company received FedRAMP Moderate Authorization on October 5, 2026, through Knox Systems, a managed federal cloud provider.

The authorization took months, not the three-plus years and millions of dollars that traditionally mark the FedRAMP process. It lands as CISA's Binding Operational Directive 26-04 forces agencies to remediate some vulnerabilities within three days, with full compliance due December 7, 2026.

Why it matters

Agencies facing three-day vulnerability remediation deadlines can now procure Aikido's automated fix platform without a multi-year authorization wait.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

90 days
Knox's FedRAMP authorization timeline
Knox says SaaS vendors can achieve FedRAMP authorization in 90 days through its shared boundary.
3+ years
Traditional FedRAMP authorization timeline
Traditional FedRAMP authorization often takes three or more years and millions in compliance costs.
Dec 7, 2026
BOD 26-04 agency compliance deadline
CISA's directive requires agencies to remediate some vulnerabilities within three days.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

July 2025 December 2026

4 events Latest: 2 days ago
Tap a bar to jump to that date
  1. BOD 26-04 agency compliance deadline

    Upcoming Deadline

    Agencies must be fully compliant with CISA's vulnerability remediation directive.

  2. Aikido achieves FedRAMP Moderate Authorization

    Latest Authorization

    Aikido Security receives FedRAMP Moderate Authorization through Knox Systems' federal managed cloud boundary.

  3. CISA issues Binding Operational Directive 26-04

    Regulation

    The directive ties vulnerability remediation speed to real-world exploitability, requiring some fixes within three days.

  4. Knox launches FedRAMP Boundary Platform on AWS Marketplace

    Product Launch

    Knox offers SaaS vendors FedRAMP authorization in 90 days at 90% lower cost.

Scenarios

1

Aikido lands first federal contracts before BOD 26-04 deadline

Possible Resolves by Dec 7, 2026

Discussed by: Govly, which tracks federal procurement signals

The December 7, 2026 compliance deadline gives agencies under BOD 26-04 a reason to move quickly. Aikido's automation directly addresses the three-day remediation requirement, and its availability through SEWP and CDM contract vehicles could shorten procurement timelines. Govly notes the authorization makes the platform eligible for procurement, not an agency contract award.

2

Aikido's federal expansion builds slowly through evaluations

Likely Resolves by Q2 2027

Discussed by: TipRanks, which noted financial impact depends on converting authorization into engagements

Eligibility is not a contract. Agencies may evaluate the platform through pilots and assessments before committing. Aikido's federal revenue growth would depend on converting these evaluations into paid engagements, a process that could take quarters.

3

Knox's shared-boundary model becomes the standard FedRAMP path

Possible Resolves by Oct 5, 2027

Discussed by: Knox Systems, which markets the model as a 90-day, 90%-lower-cost alternative

Aikido joins Adobe, BigID, and Kovr.ai as Knox customers. If more SaaS companies follow this path, the traditional multi-year FedRAMP cycle could give way to shared-boundary authorizations. The FedRAMP Marketplace would show a growing number of companies authorized through Knox's boundary.

Historical Context

2 moments from history that rhyme with this story — and how they unfolded.

December 2011

FedRAMP program launch (2011)

The Federal Risk and Authorization Management Program was created to standardize security assessments for cloud services used by federal agencies. The goal was to let agencies reuse one authorization instead of each conducting its own review.

Then

The program consolidated security assessments, but the authorization process itself became slow and expensive.

Now

Authorizations routinely took three or more years and millions of dollars, creating a bottleneck for cloud adoption.

Why this matters now

Knox's shared-boundary model compresses this cycle to months, directly addressing the bottleneck FedRAMP was meant to solve.

2011

AWS GovCloud launch (2011)

Amazon Web Services launched GovCloud, a dedicated cloud region for U.S. government customers with stricter compliance controls. It gave agencies a path to cloud computing without sharing infrastructure with commercial customers.

Then

GovCloud became a foundation for government cloud adoption.

Now

It established the pattern of purpose-built government cloud environments that Knox's boundary builds on.

Why this matters now

Aikido for Government runs inside Knox's FedRAMP boundary, hosted in AWS GovCloud (US-Gov-East), showing how these layers stack.

Sources

(6)