Meet the startup helping businesses get FedRAMP certified
Getting the go-ahead from the Federal Risk and Authorization Management Program is notoriously difficult. Knox Systems speedruns the process.
• 5 min read
When it comes to software, the federal government is so 2000 and late.
That’s because any software the government uses needs to be certified by the Federal Risk and Authorization Management Program, which is notoriously difficult to get through. Enter Knox Systems, a software company that helps others get FedRAMPed: Since May 2025, Knox has gotten more than 50 companies FedRAMP certified, thereby granting governmental agencies access to cutting-edge technology. Governmental tech may not be so 3008, to finish the Black Eyed Peas’ lyric, but it’s at least catching up to 2026.
“It’s crazy that [in] the country that invented AI, the government of that country doesn’t have access to some of the latest and greatest,” Knox CEO and founder Irina Denisenko told Morning Brew. For example, “the entire Veterans Affairs system is not the hospital experience you experience at even a tier two, tier three institution, let alone a tier one in a major city. But the technology exists and the VA knows about it. And they want to use it.”
Knox helps those on the outside get in by operating as a “landing zone” that companies can use to become FedRAMP certified. With Knox’s help, they can do so faster and without the hefty financial investment that has traditionally been part of the process. The startup acts as a sort of FedRAMP concierge; it’s authorized by 16 federal agencies—a number Denisenko said is growing—to act as a sponsor for companies going through the process.
Knox isn’t alone in the space; similar services are also offered by Palantir, Cisco, and IBM. It makes sense that it’s a growing trend, as FedRAMP certification is important for companies hoping to work in financial services, healthcare, and other private-sector industries.
Won’t you be my neighbor?
Denisenko got the idea for Knox when she was the COO at Class, a company that builds virtual classroom technology. When she found out that it would take five years to get Class FedRAMP certified, she decided to take a less traditional approach: She aided Class in the purchase of another company that was already FedRAMP certified, allowing Class to achieve the credential under the wing of that company.
Denisenko compares FedRAMP to a super exclusive neighborhood—if any new residents want to move in, they have to invest a lot of money and time to build their house in the area. Knox, she said, is like a high-rise apartment building in the neighborhood where new residents can move in quickly without having to erect a new structure.
“Our customers move into a floor of that ever-growing skyscraper, which means they don’t have to go hire an architect, get the permit to break ground, all that stuff you’ve got to do if you’re going to build your own house. You’re just moving into a condo. Most importantly, they are inheriting our authorizations to operate,” Denisenko said. “That’s what allows us to move so much more quickly, so much more economically.”
Raising the bar
In addition to helping companies attain FedRAMP certification, Knox also provides a 24/7 security operations center to monitor vulnerabilities. Prior to FedRAMP’s latest consolidated rules (FedRAMP 20x), Knox’s threat identification and remediation was more efficient than the program required.
Top insights for IT pros
From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.
“The process rules of FedRAMP had not been updated for a very long time. Specifically, they still said that you only have to scan your entire environment for vulnerabilities once a month, and the fastest you need to remediate a problem that you find is 30 days,” Denisenko said. Now, FedRAMP requires “continuous monitoring and reporting” and quicker remediation timelines, which Knox implemented for its customers from the beginning.
Knox’s self-healing cybersecurity infrastructure was a big draw for the company’s new CISO, Hemant Baidwan. As the former CISO of the Department of Homeland Security, he told Morning Brew that he saw firsthand how challenging it is for the government to access new technology.
“We need a self-healing infrastructure,” Baidwan said. “When there is a cybersecurity weakness or IT weakness that’s identified, and now the attackers can either chain these weaknesses to exploit those and get into your system, we need the ability—using AI, using automation—to be able to close those holes as quickly as they are discovered. And manually, you just can’t.”
Keep it simple
There’s still a question that underlies Knox’s entire existence: If FedRAMP is so complicated, why not reform the program rather than have applicants use outside companies to get through? Ann Dunkin, a professor of public policy and cybersecurity at Georgia Institute of Technology and the former Department of Energy CIO, told Morning Brew that FedRAMP is as convoluted as it is because it has to satisfy every single governmental agency.
“You have to do everything for authorization to the point where DOD will be happy with it, where the [intelligence community] will be happy with it, where the FDIC will be happy with it,” Dunkin said. “Getting rid of the complexity is very hard because all these people come to the table with their equities, and because it has to satisfy everyone in the government, it’s an overly cautious process.”
And the flip side, Dunkin said, would be each agency having its own cybersecurity authorization process, which would be even more complex.
“FedRAMP is still too complicated. It’s still too hard,” Dunkin said. “It shouldn’t take a third party to be able to do FedRAMP. But it does, and since it does, [companies like Knox] are absolutely critical to people getting stuff out there to their customers.”
Top insights for IT pros
From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.