The compliance process

This is how a federal compliance and authorization engagement runs. It moves through five phases, in order, from scoping the boundary to keeping the authorization current. Each phase closes before the next begins, so you always know what has been built, what is left, and who is responsible for it.

  1. Scope and gap assessment

    2 to 4 weeks

    We map your target framework to your current environment and find the gap between the controls and the running system.

    Deliverables
    • Authorization boundary diagram
    • Gap report against the target baseline
    • Scoped timeline and work plan
    You provide

    Access to your current architecture, your target framework, and the workloads in scope.

    TRGR provides

    The boundary definition, the control-by-control gap analysis, and a realistic plan before anything is built.

  2. GovCloud architecture

    3 to 6 weeks

    We design the GovCloud environment and the boundary the controls require, for you to approve before implementation starts.

    Deliverables
    • GovCloud landing zone design
    • Network, identity, and encryption architecture
    • Evidence source plan
    You provide

    Your workload requirements, your AWS accounts or the authority to create them, and design decisions when we reach them.

    TRGR provides

    A defensible architecture, drawn to your real system, that an assessor can follow.

  3. Control implementation and evidence

    2 to 4 months

    We build the infrastructure and the control implementations, and stand up the pipeline that produces evidence.

    Deliverables
    • Infrastructure as code for the environment
    • Implemented controls across the baseline
    • Evidence pipeline mapping live state to controls
    You provide

    Your engineering context, review of the implementation, and sign-off on changes to production systems.

    TRGR provides

    The provisioned environment, the control implementations, and the automated evidence collection.

    AI in the loop

    AI agents generate and validate the evidence that maps live system state to the controls, and the practitioner reviews and signs off.

  4. OSCAL package assembly

    3 to 6 weeks

    We assemble the machine-readable authorization package from the running system and its evidence.

    Deliverables
    • OSCAL SSP
    • Certification Package Overview
    • Validated assessment package
    You provide

    Organizational details, policy documents, and the points of contact the package requires.

    TRGR provides

    The OSCAL SSP and the Certification Package Overview, generated and validated with AI agents in the loop, ahead of the package-data deadlines in FedRAMP's Consolidated Rules for 2026.

    AI in the loop

    AI agents generate and validate the OSCAL package from the running system, and the practitioner reviews and signs off.

  5. Assessment support and continuous authorization

    Assessment window, then ongoing

    We support you through the assessment and keep the authorization current after it.

    Deliverables
    • Assessor evidence responses
    • Continuous monitoring dashboards
    • OSCAL packages regenerated on demand
    You provide

    Assessor coordination, your agency sponsor, and time for review sessions.

    TRGR provides

    Evidence responses during the assessment and the continuous-monitoring machinery that keeps the package current.

Book a consultationSee the compliance overview
The compliance process · TRGR