Excentium, Inc. is a FedRAMP recognized Independent Assessment Service (IAS) – continuously accredited since 2015 and we took part in the assessment of a system for the FedRAMP 20x Low pilot. As a Service-Disabled Veteran-Owned Small Business with 20 years of federal delivery experience, Excentium is your full-lifecycle compliance partner providing independent security assessment services for Cloud Service Providers pursuing FedRAMP authorization under both the 20x and Rev5 paths. Our approach is collaborative and partnership-driven: findings are shared in real time. We deliver premium-quality compliance outcomes at mid-market prices, so that every company that should be serving the federal government can afford to. Throughout our work, we engage your experts, share findings as the work proceeds, and offer the assessment advice the rules permit, always within the bounds that keep the assessment objective and independent. You always know where you stand. No surprises. Ever.

Contact Information

Colin Corlett, President and CEO, CISSP

Email: IAS@Excentium.com

Excentium, Inc., 1768 Business Center Dr, Suite 220, Reston, VA 20190

Services Offered

FedRAMP 20x Independent Assessment

A FedRAMP 20x Independent Assessment is the independent verification and validation behind a FedRAMP 20x Certification – FedRAMP’s modern approach. Assurance is built primarily on measured outcomes expressed as Key Security Indicators (KSIs) across Certification Classes A, B, and C on the Program path. Excentium took part as an assessor in the FedRAMP 20x Low Pilot – we have worked inside this model since it took shape. We verify that the measures implemented across your cloud service offering match your documented FedRAMP Practices, and we validate that each indicator achieves its intended security outcome, supplying machine-readable evidence aligned to Independent Verification and Validation. You receive a per-Practice Assessment Summary for your Security Decision Record and an Overall Summary of Assessment for your Certification Package Overview. The process stays collaborative and transparent from kickoff through decision.

FedRAMP Rev5 Independent Assessment

A FedRAMP Rev5 Independent Assessment is the independent verification and validation a Cloud Service Provider needs to earn and maintain a FedRAMP Rev5 Certification. Rev5 follows FedRAMP’s established approach, where assurance is built primarily on documented plans mapped to the NIST SP 800-53 Rev5 control set across Certification Classes B, C, and D. Excentium verifies that the measures implemented across your cloud service offering match what you document in your Security Decision Record, and validates that those measures achieve their intended outcomes for the applicable FedRAMP Practices. We assess all applicable Rev5 Controls on the three-year cycle FedRAMP requires, repeat the assessment annually, and reassess any control that carried a negative finding in the next cycle. You receive a per-Practice Assessment Summary for your Security Decision Record and an Overall Summary of Assessment for your Certification Package Overview.

 Annual Independent Assessment

After a Cloud Service Provider earns its initial FedRAMP Certification, Excentium performs the recurring FedRAMP Independent Assessment that sustains Ongoing Certification. Each cycle, we independently verify that the measures implemented across your cloud service offering match your Security Decision Record, and we validate that they continue to achieve their intended outcomes for the applicable FedRAMP Practices. That scope includes your vulnerability detection and response and your vulnerability evaluation and reporting capabilities, which we assess for implementation and effectiveness as FedRAMP Practices in their own right. You receive a per-Practice Assessment Summary for your Security Decision Record and an Overall Summary of Assessment for your Certification Package Overview.

Independent Transformative Change Review

Between assessment cycles, Excentium provides the independent review the FedRAMP rules recommend when you plan a transformative change to your cloud service offering. Before you begin, we evaluate the scope and security impact of the planned change, concentrated on the security decisions that call for human validation. After the change is complete, we verify and validate it so you can confirm to all necessary parties that the work was independently checked. Our review keeps your Ongoing Certification sound as your offering evolves, verifying that changed measures still match your Security Decision Record and continue to achieve their intended outcomes for the applicable FedRAMP Practices. We share findings and permitted assessment advice as the work proceeds.

Machine-Readable IAS Data

This information is also available in structured JSON format for automated and programmatic access.