For government & public sector suppliers

Security testing for public sector and government suppliers

Continuous testing mapped to NIST SP 800-53 Rev. 5, with machine-readable OSCAL and SARIF evidence built in rather than bolted on.

RedStrike is a continuous security testing and cloud posture platform for public sector organisations and the suppliers who sell to them. Findings are mapped to NIST SP 800-53 Rev. 5, ISO/IEC 27001:2022, SOC 2, and GDPR, and exported in OSCAL — NIST's own machine-readable control format — as well as OpenVEX and SARIF. RedStrike does not provide FedRAMP authorization or FedRAMP control mapping; that boundary is stated plainly here rather than discovered during procurement.

The problem

Why public sector security evidence is different

The requirement is rarely a report a human reads. It is a control catalogue, a format, and a schedule.

Evidence has to be machine-readable

Control catalogues, assessment results, and plans of action increasingly move as structured documents between systems. A PDF is the least useful format for a process that wants to ingest, diff, and track a control over time.

Public-facing services are permanently exposed

Citizen-facing portals cannot be taken behind a VPN while you fix them, and their attack surface is enumerated continuously by people who are not you.

Legacy and modern run side by side

A long-lived estate mixes decades-old services with new cloud workloads. Coverage that only understands containers, or only understands network hosts, leaves the seams untested.

Control status must be current, not annual

A control assessed once a year is unassessed for eleven months. What a supplier is usually asked for is the current state, with a trail showing how it got there.

How RedStrike helps

Control-mapped testing with formats the process actually wants

Machine-readable output is a first-class export here, not a professional-services deliverable.

OSCAL export

Assessment results export as OSCAL, the NIST Open Security Controls Assessment Language, so findings enter a control-management process as structured data rather than as prose somebody re-keys.

NIST SP 800-53 Rev. 5 mapping

Application, API, and network findings carry 800-53 Rev. 5 control ids, and AWS accounts are audited against the native 800-53 Rev. 5 benchmark alongside CIS Foundations.

Attack surface discovery

Subdomain enumeration, service fingerprinting, and TLS configuration testing keep the inventory of what is actually exposed current, instead of trusting a register that stopped being accurate two reorganisations ago.

SBOM and supply chain

Software bills of materials are generated in CycloneDX and SPDX and correlated against findings, with OpenVEX documents recording which vulnerabilities actually apply to your build.

Role separation and audit trail

SAML single sign-on, SCIM provisioning, custom roles, and immutable audit logging are available so access to security findings is itself controlled and evidenced.

Continuous cloud posture

Cloud accounts are graded on a schedule with drift tracked over time, so control status is a current answer rather than a historical one.

Compliance coverage

Which frameworks this maps to — and exactly how far the mapping goes

NIST SP 800-53 Rev. 5 is mapped on the application side and checked natively on AWS resources. RedStrike does not provide FedRAMP mapping or authorization — see the FAQ.

Compliance framework coverage in RedStrike, by framework and cloud provider
FrameworkEdition mappedCloud coverage
NIST SP 800-53NISTr5Native cloud-resource checks on AWS. Azure and GCP are graded against CIS benchmarks instead.
ISO/IEC 27001ISO/IEC2022Native cloud-resource checks on AWS. Azure and GCP are graded against CIS benchmarks instead.
SOC 2AICPA2017Native cloud-resource checks on AWS. Azure and GCP are graded against CIS benchmarks instead.
GDPREuropean Union2016/679Native cloud-resource checks on AWS. Azure and GCP are graded against CIS benchmarks instead.
OWASP Top 10OWASP Foundation2025Mapped on findings from application, API, and network testing. No native cloud-resource checks — pair with CIS benchmark grading for cloud evidence.
OWASP API Security Top 10OWASP Foundation2023Mapped on findings from application, API, and network testing. No native cloud-resource checks — pair with CIS benchmark grading for cloud evidence.

Every cloud account is graded against CIS Foundations benchmarks on AWS, Azure, GCP, and Kubernetes clusters against the CIS Kubernetes benchmark, regardless of which frameworks above apply to you. Evidence can be exported as a report or pushed into Vanta or Drata.

How it works

From connected to evidence in four steps

01

Define scope

Add the domains, APIs, and cloud accounts in scope, with rules of engagement recorded before any test runs.

02

Test continuously

Application, API, network, container, and cloud checks run on a schedule instead of once a year, so drift is caught within a scan cycle.

03

Verify & de-duplicate

Findings from multiple tools are correlated into one issue, evidence is collected, and severity is scored so the list you read is the list that matters.

04

Export evidence

Results are mapped to framework controls and exported as a report, or pushed into Vanta or Drata.

Outcomes

What changes once this is running

  • Deliver assessment results as OSCAL and SARIF instead of a PDF somebody has to transcribe.
  • Report current control status continuously rather than reconstructing it annually.
  • Keep an accurate inventory of exposed public services as the estate changes.
  • Evidence supply-chain posture with CycloneDX or SPDX SBOMs and OpenVEX applicability statements.
  • Control and audit who inside your organisation can see security findings.
800-53 r5
Control mapping
OSCAL
Machine-readable output
SBOM
CycloneDX & SPDX
SAML/SCIM
Access controlled

FAQ

Frequently asked questions

Common questions about RedStrike for Public Sector.

Does RedStrike support FedRAMP?

No. RedStrike does not provide FedRAMP control mapping and is not FedRAMP authorized. The frameworks in the registry are NIST SP 800-53 Rev. 5, ISO/IEC 27001, SOC 2, PCI DSS, HIPAA, GDPR, NIS2, the EU Cyber Resilience Act, and the OWASP Top 10 and API Security Top 10. NIST SP 800-53 Rev. 5 is the control catalogue that overlaps most with FedRAMP baselines, but overlap is not mapping and we will not describe it as such.

What is OSCAL and why does it matter here?

OSCAL is NIST's Open Security Controls Assessment Language, a machine-readable format for control catalogues, system security plans, and assessment results. Exporting assessment results as OSCAL means findings can be ingested by a governance or control-management system directly, rather than being manually transcribed from a report.

Which cloud providers get native NIST 800-53 checks?

AWS only. Azure subscriptions and GCP projects are graded against CIS Foundations benchmarks, and Kubernetes clusters against the CIS Kubernetes benchmark. Application-side 800-53 mapping applies to findings from any environment.

Can RedStrike run in an isolated or on-premises environment?

RedStrike is deployed with Docker Compose and is Kubernetes-ready, with PostgreSQL, MongoDB, and Redis as its data layer, so it can run inside infrastructure you control. Specific isolation, hosting, and data-residency requirements are worth discussing directly before an evaluation.

How is access to findings controlled?

Tenancy is enforced at the database layer with PostgreSQL row-level security, so isolation is not dependent on application code getting every query right. SAML single sign-on, SCIM provisioning, custom roles, and audit logging are available on the appropriate plans.

Does it cover legacy on-premises systems as well as cloud?

Yes. The engine spans network and service discovery, TLS configuration testing, web and API testing, container and infrastructure-as-code scanning, and cloud posture, so a mixed estate is covered by one programme rather than by several disconnected ones.

Control-mapped evidence, in the format the process expects

NIST SP 800-53 Rev. 5 mapping with OSCAL, SARIF, and OpenVEX exports.