The compliance process
This is how a federal compliance and authorization engagement runs. It moves through five phases, in order, from scoping the boundary to keeping the authorization current. Each phase closes before the next begins, so you always know what has been built, what is left, and who is responsible for it.
Scope and gap assessment
2 to 4 weeksWe map your target framework to your current environment and find the gap between the controls and the running system.
Deliverables- Authorization boundary diagram
- Gap report against the target baseline
- Scoped timeline and work plan
You provideAccess to your current architecture, your target framework, and the workloads in scope.
TRGR providesThe boundary definition, the control-by-control gap analysis, and a realistic plan before anything is built.
GovCloud architecture
3 to 6 weeksWe design the GovCloud environment and the boundary the controls require, for you to approve before implementation starts.
Deliverables- GovCloud landing zone design
- Network, identity, and encryption architecture
- Evidence source plan
You provideYour workload requirements, your AWS accounts or the authority to create them, and design decisions when we reach them.
TRGR providesA defensible architecture, drawn to your real system, that an assessor can follow.
Control implementation and evidence
2 to 4 monthsWe build the infrastructure and the control implementations, and stand up the pipeline that produces evidence.
Deliverables- Infrastructure as code for the environment
- Implemented controls across the baseline
- Evidence pipeline mapping live state to controls
You provideYour engineering context, review of the implementation, and sign-off on changes to production systems.
TRGR providesThe provisioned environment, the control implementations, and the automated evidence collection.
AI in the loopAI agents generate and validate the evidence that maps live system state to the controls, and the practitioner reviews and signs off.
OSCAL package assembly
3 to 6 weeksWe assemble the machine-readable authorization package from the running system and its evidence.
Deliverables- OSCAL SSP
- Certification Package Overview
- Validated assessment package
You provideOrganizational details, policy documents, and the points of contact the package requires.
TRGR providesThe OSCAL SSP and the Certification Package Overview, generated and validated with AI agents in the loop, ahead of the package-data deadlines in FedRAMP's Consolidated Rules for 2026.
AI in the loopAI agents generate and validate the OSCAL package from the running system, and the practitioner reviews and signs off.
Assessment support and continuous authorization
Assessment window, then ongoingWe support you through the assessment and keep the authorization current after it.
Deliverables- Assessor evidence responses
- Continuous monitoring dashboards
- OSCAL packages regenerated on demand
You provideAssessor coordination, your agency sponsor, and time for review sessions.
TRGR providesEvidence responses during the assessment and the continuous-monitoring machinery that keeps the package current.