Keep your FedRAMP authorization or NIST 800-171 posture current with an agent suite.
The TRGR agent suite is the continuous-authorization layer for a FedRAMP or NIST 800-171 system. Point it at a system you already have authorized, or have TRGR build one first. The checking is deterministic: the agents compare the running system to the authorized baseline and roll the control evidence into a verdict. A model is consulted only to classify what a check already found, and with no model, or on a model error, the finding is still reported and routed to a person. A practitioner reviews and signs off on every result.
Book a consultationHow continuous authorization works
The suite runs the compliance pipeline end to end, and a person supervises it. Agents carry a system from controls to implementation to evidence, roll that evidence into a verdict on each Key Security Indicator FedRAMP 20x validates against, assemble the machine-readable package, and keep watching the system after it ships. A practitioner reviews the output at each stage, so the authorization keeps pace with the running system.
- 01
Controls
The agents establish which controls apply at your impact level and how each one is meant to be satisfied.
- 02
Implementation
The agents read how the running system implements each control, working from live state.
- 03
Evidence
The evidence pipelines map live system state to the controls, so the record reflects the system as it runs.
- 04
Indicators
The control evidence rolls up into a verdict on each of the 46 Key Security Indicators FedRAMP 20x validates a service against, so readiness reads the way 20x scores it.
- 05
OSCAL
The OSCAL package is generated from the control implementations and validated against the baseline, ready for an assessor.
- 06
Package overview
The Certification Package Overview is assembled as machine-readable JSON and checked against the FedRAMP schema, so the summary CR26 requires is maintained rather than rewritten each year.
- 07
Monitoring
The agents run on a per-tenant schedule, between one hour and thirty days apart, comparing the authorized boundary to the baseline and keeping the package current. A practitioner signs off on what changes.
- 08
Vulnerabilities
New vulnerabilities are evaluated for the impact they are likely to have on your federal customers and tracked against the reporting timeframes CR26 sets.
The agents
OSCAL Agent
Generates the OSCAL package for your system and validates it against the baseline, so the package is ready before FedRAMP's 2027 package-data deadlines.
What the agent doesThe agent produces the OSCAL package from the running system and checks every control statement against the baseline.
Practitioner reviewA practitioner reviews the generated package and signs off before it reaches an assessor.
Frameworks- OSCAL
- FedRAMP
- NIST 800-53
Package Overview Agent
Assembles the CR26 Certification Package Overview, the machine-readable summary CR26 requires in both human-readable and JSON form, and validates it against the FedRAMP schema. The overview is a separate artifact from the Security Decision Record, the record that replaced the System Security Plan.
What the agent doesThe agent builds the package overview as JSON from the current system and checks it against the FedRAMP schema, so the overview is maintained by automation rather than going stale between assessments.
Practitioner reviewA practitioner reviews the overview before it is shared with an agency or a reviewer.
Frameworks- OSCAL
- FedRAMP
- CR26
Evidence Agent
Runs the evidence pipelines that map live system state to your security controls, so the package reflects the system as it actually runs.
What the agent doesThe agent collects live system state and maps each piece of evidence to the 800-53 controls it satisfies. When a component carries no mapping, a model proposes one and the result is recorded as pending review, never as a mapping. A low-confidence answer, a model error, or no model at all marks the component for human review instead.
Practitioner reviewA practitioner reviews the evidence mapping and signs off before it is delivered.
Frameworks- NIST 800-53
- OSCAL
Boundary Agent
Reconciles your declared authorization boundary against live cloud inventory, so a resource that moves into or out of scope is caught on the next scheduled run instead of at the next assessment.
What the agent doesThe agent compares the boundary declared in the SSP inventory against the resources running in your accounts and flags anything that has entered or left scope.
Practitioner reviewA practitioner reviews each scope change and decides whether the boundary or the system is what needs to move.
Frameworks- FedRAMP
- NIST 800-53
- OSCAL
Drift Agent
Watches the authorized boundary and flags drift from the authorized state, so a change that breaks a control surfaces early instead of at the next assessment. It also classifies each significant change as adaptive, routine recurring, or transformative, the categories CR26 Significant Change Notification uses.
What the agent doesThe comparison against the authorized configuration is a deterministic diff, and the CR26 change category is derived from the deviation with no model involved. A model is consulted for one thing, the severity of the deviation. With no model, or on a model error, the deviation is still reported and routed to a person for review.
Practitioner reviewA practitioner reviews each flag and its change class and decides what to do about it.
Frameworks- FedRAMP
- CR26
- NIST 800-53
Vulnerability Agent
Detects vulnerabilities from live system state, works out which ones are likely to impact your federal customers, and tracks them against the CR26 reporting timeframes that apply to your certification class.
What the agent doesThe agent normalizes the vulnerability findings from live state, evaluates each one for the impact it is likely to have on a federal customer, and ages it against the reporting timeframe CR26 sets under CISA BOD 26-04.
Practitioner reviewA practitioner reviews the impact evaluation and what is reported.
Frameworks- FedRAMP
- CR26
- NIST 800-53
Remediation Agent
When drift breaks a control, it traces the resource back to the infrastructure code that defines it and opens a pull request with the fix, for your team to review and merge.
What the agent doesThe agent maps the drifted resource to its Terraform or CloudFormation source, generates the change that restores the compliant configuration, and opens a pull request against your repository.
Practitioner reviewA practitioner reviews the pull request and your team merges it. Nothing is applied to your environment automatically.
Frameworks- FedRAMP
- NIST 800-53
- OSCAL
Control-Mapping Agent
Annotates 800-53 evidence with the NIST 800-171 requirement and the CMMC Level 2 practice the same evidence answers, working from the embedded NIST 800-171 Rev 2 catalog: all 110 requirements across 14 families, each carrying its Appendix D 800-53 mapping.
What the agent doesThe pass is deterministic and read-only, and no model is consulted. Evidence that is met or inherited yields one informational finding per 800-171 requirement its control maps to, and one for the CMMC Level 2 practice derived from that requirement. Evidence whose control the catalog does not map is flagged as not reused. On an 800-171 run, a coverage engine rolls the same evidence up over all 110 requirements and reports each as met, not met, or a gap, for 800-171 and for CMMC Level 2. Crediting flows only through the catalog: evidence for a control enhancement also credits its base control, but base evidence never credits an enhancement, so bare IA-2 evidence never answers a multifactor requirement.
Practitioner reviewA practitioner reviews the annotations and the coverage rollup and decides what to do with them.
Frameworks- NIST 800-53
- NIST 800-171
- CMMC
KSI Agent
Evaluates your system against the 46 Key Security Indicators FedRAMP 20x validates a service against, rolling the control evidence into a verdict on each indicator. This is the readiness view a 20x reviewer works from.
What the agent doesThe agent rolls the control evidence up through the CR26 indicator-to-control mappings and scores each indicator as met, partial, not met, a gap, or an indicator that needs a manual attestation.
Practitioner reviewA practitioner reviews the verdicts and signs off before they stand as readiness.
Frameworks- KSI
- FedRAMP 20x
- NIST 800-53
Readiness Agent
Scores the system against the control baseline for its impact level and against the Key Security Indicators, and ranks the gaps by remediation priority, so you know what is missing before an assessor does.
What the agent doesThe scoring is deterministic and consults no model. The agent counts the controls the evidence satisfies against the impact-level baseline, rolls up the KSI verdicts, and ranks the gaps that stand between you and an assessment.
Practitioner reviewA practitioner reviews the score and the gap list and signs off on the plan to close them.
Frameworks- FedRAMP
- NIST 800-53
- KSI
POA&M Agent
Opens a POA&M item for every control the evidence leaves not met or partially met, on the frameworks that require one, NIST 800-171 and CMMC, and ages each item against a fixed window: 30 days for a not-met control, 90 for a partial one.
What the agent doesThe pass is deterministic and consults no model. The agent opens one item per gap, ages it from the date the gap was first seen, or from the baseline authorization date when no history exists, and reports each item as open or overdue.
Practitioner reviewA practitioner reviews the POA&M state and signs off on what is reported.
Frameworks- NIST 800-171
- CMMC
- OSCAL
Where the agents run and where your data stays
The agents run against your own cloud, not a copy of it. You keep control of the boundary, and the compliance evidence never leaves it.
A scoped, read-only role
You run a template that creates an IAM role in your account. The role is read-only and scoped to what the agents need, and it trusts the TRGR principal through an external ID. TRGR never takes root credentials and never holds a standing key to your account.
In-boundary for GovCloud and high impact
For GovCloud and high-impact systems, the agents run inside the authorization boundary, so evidence and live system state never leave it. For commercial and lower-impact systems, the agents read from your account under the scoped role.
Your data stays in your boundary
The data stays inside your environment. The agents read your Config, Security Hub, and live system state, generate the OSCAL package, and flag drift. The artifacts are delivered to you, and a practitioner signs off before anything is reported.
One engine, two ways to buy
The agent suite is one engine. You can buy it built into a TRGR authorization from the start, or bring it to a system that is already authorized. Both are supervised by a practitioner, and both route to the same consultation.
Build to ATO
The agent suite bundled into a TRGR FedRAMP or NIST 800-171 engagement. We build the architecture, the evidence pipelines, and the OSCAL package, and the agents carry it forward as continuous authorization once the system is live.
Book a consultationContinuous authorization
The agents on their own, for a team already running an authorized system or with its own compliance staff. It still starts with a lighter onboarding to stand up the read-only role, baseline the boundary, and validate the first OSCAL package. The practitioner review stays bundled and is not optional. No agent output ships without a practitioner signing off, because TRGR does not sell raw, unreviewed compliance automation. If you prefer, your ISSO can own final sign-off under a bring-your-own-reviewer arrangement, with TRGR providing the agents and the validation. There is no self-serve tier and no login.
Book a consultation
How it is priced
The suite is priced per system per authorization boundary per month, as a continuous-authorization retainer scaled by impact level across Low, Moderate, and High. A one-time onboarding stands up the read-only role and the collectors, baselines the system, and produces the first OSCAL package, and the monthly retainer runs from there. Price is tiered by scope, from an OSCAL-only engagement to the full suite, and by the number of frameworks and accounts in play. Bought with a build, it bundles as an add-on during the engagement and converts to the retainer after authorization. Bought standalone, the onboarding is lighter than a full build. Exact pricing is scoped on your consultation.
Put continuous authorization on your system.
The paid compliance consultation scopes the agent suite to your impact level and the frameworks your system must meet.
Book a consultation