IT Brief US - Technology news for CIOs & IT decision-makers
United States
RegScale & Microsoft target faster FedRAMP on Azure

RegScale & Microsoft target faster FedRAMP on Azure

Thu, 20th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

RegScale has agreed a collaboration with Microsoft to support customers seeking FedRAMP readiness and authorisation to operate on Microsoft Azure. The work centres on a compliance-as-code approach for cloud service providers selling to US federal agencies.

The arrangement is intended to reduce the time and effort typically associated with FedRAMP, the federal programme that assesses cloud services used by the US government. According to RegScale, the process often takes at least 18 months for cloud service providers seeking entry to that market.

Under the collaboration, customers will use Microsoft Azure's FedRAMP-authorised cloud environment alongside RegScale's compliance automation and continuous controls monitoring software. RegScale says its system automates evidence collection and continuously validates controls against FedRAMP Key Security Indicators.

The announcement also links the work to FedRAMP 20x, an initiative that aims to shift security assurance away from point-in-time documentation towards automated, continuous validation. The approach reflects a broader move in public-sector cyber oversight towards machine-readable evidence and ongoing monitoring rather than periodic audit preparation.

RegScale says its model reports controls in real time instead of gathering material solely for an audit event. Its RegML AI agents are part of that process, although the collaboration is focused on the route to FedRAMP readiness and authorisation on Azure.

Federal market

FedRAMP remains a significant hurdle for software and cloud suppliers seeking to sell into the US federal market. Providers often face long implementation cycles, extensive documentation requirements, and repeated validation work before securing approval.

For Microsoft, the collaboration adds another compliance-focused Azure offering for suppliers serving defence and civilian government customers. For RegScale, it places its monitoring and automation software alongside one of the main cloud environments used for regulated public-sector workloads.

RegScale says it achieved FedRAMP High using its own platform in six months, presenting that as evidence that automation can shorten a process that often takes much longer. That experience, it says, informed the customer model now being offered with Microsoft.

Eric Erston, Chief Revenue Officer at RegScale, outlined the commercial and regulatory significance of the move.

"FedRAMP is the front door to the U.S. federal market, and for too many cloud service providers it has been a significant barrier to entry," said Eric Erston, Chief Revenue Officer at RegScale.

"FedRAMP 20x is changing that, giving agencies faster access to modern technology at the right security assurance levels, and this collaboration meets customers wherever they are on that journey. Whether they manage compliance themselves, use a managed service, or adopt a managed landing zone, RegScale enables faster certification and keeps them continuously compliant long after they get there," said Erston.

Continuous monitoring

The emphasis on continuous compliance reflects a broader debate in government technology procurement over whether security accreditation can keep pace with software delivery cycles. Traditional assessment models have often been criticised for relying on static evidence collected at fixed intervals, leaving a gap between audit status and live operational conditions.

By contrast, continuous controls monitoring tools are designed to track whether controls remain in place and whether evidence can be collected automatically from systems as they operate. In regulated sectors, that can reduce manual preparation work and give auditors or agency buyers a more current view of a supplier's security posture.

Microsoft says the collaboration is aimed at companies across the defence industrial base and the wider federal supplier market that need a more predictable route through the process.

"Companies across the defense industrial base and broader federal market need a faster, more predictable path to FedRAMP so they can focus on their mission, not their paperwork," said Jamie Harper, Vice President, Defence Industrial Base, Microsoft.

"Through this collaboration with RegScale, we're helping enable a faster route to certification on Azure, backed by automation that keeps them continuously compliant, not just compliant at audit time," said Harper.

Beyond provider certification, RegScale says it is developing tools intended to help federal agencies consume continuous monitoring data directly from cloud service providers. That suggests the collaboration may extend beyond helping vendors gain approval into how agencies review supplier security information once services are in use.

The shift matters because agencies are under pressure to adopt newer software more quickly while maintaining oversight of cyber risk. Any effort to shorten FedRAMP timelines without weakening assurance is likely to draw attention from software vendors that have found federal entry costs too high, as well as from agencies trying to widen their supplier base.

RegScale says heavily regulated organisations, including federal users and large companies, already use its platform to manage compliance work and audit preparation.