Security testing for public sector and government suppliers
Continuous testing mapped to NIST SP 800-53 Rev. 5, with machine-readable OSCAL and SARIF evidence built in rather than bolted on.
RedStrike is a continuous security testing and cloud posture platform for public sector organisations and the suppliers who sell to them. Findings are mapped to NIST SP 800-53 Rev. 5, ISO/IEC 27001:2022, SOC 2, and GDPR, and exported in OSCAL — NIST's own machine-readable control format — as well as OpenVEX and SARIF. RedStrike does not provide FedRAMP authorization or FedRAMP control mapping; that boundary is stated plainly here rather than discovered during procurement.
The problem
Why public sector security evidence is different
The requirement is rarely a report a human reads. It is a control catalogue, a format, and a schedule.
Evidence has to be machine-readable
Control catalogues, assessment results, and plans of action increasingly move as structured documents between systems. A PDF is the least useful format for a process that wants to ingest, diff, and track a control over time.
Public-facing services are permanently exposed
Citizen-facing portals cannot be taken behind a VPN while you fix them, and their attack surface is enumerated continuously by people who are not you.
Legacy and modern run side by side
A long-lived estate mixes decades-old services with new cloud workloads. Coverage that only understands containers, or only understands network hosts, leaves the seams untested.
Control status must be current, not annual
A control assessed once a year is unassessed for eleven months. What a supplier is usually asked for is the current state, with a trail showing how it got there.
How RedStrike helps
Control-mapped testing with formats the process actually wants
Machine-readable output is a first-class export here, not a professional-services deliverable.
OSCAL export
Assessment results export as OSCAL, the NIST Open Security Controls Assessment Language, so findings enter a control-management process as structured data rather than as prose somebody re-keys.
NIST SP 800-53 Rev. 5 mapping
Application, API, and network findings carry 800-53 Rev. 5 control ids, and AWS accounts are audited against the native 800-53 Rev. 5 benchmark alongside CIS Foundations.
Attack surface discovery
Subdomain enumeration, service fingerprinting, and TLS configuration testing keep the inventory of what is actually exposed current, instead of trusting a register that stopped being accurate two reorganisations ago.
SBOM and supply chain
Software bills of materials are generated in CycloneDX and SPDX and correlated against findings, with OpenVEX documents recording which vulnerabilities actually apply to your build.
Role separation and audit trail
SAML single sign-on, SCIM provisioning, custom roles, and immutable audit logging are available so access to security findings is itself controlled and evidenced.
Continuous cloud posture
Cloud accounts are graded on a schedule with drift tracked over time, so control status is a current answer rather than a historical one.
Compliance coverage
Which frameworks this maps to — and exactly how far the mapping goes
NIST SP 800-53 Rev. 5 is mapped on the application side and checked natively on AWS resources. RedStrike does not provide FedRAMP mapping or authorization — see the FAQ.
| Framework | Edition mapped | Cloud coverage |
|---|---|---|
| NIST SP 800-53NIST | r5 | Native cloud-resource checks on AWS. Azure and GCP are graded against CIS benchmarks instead. |
| ISO/IEC 27001ISO/IEC | 2022 | Native cloud-resource checks on AWS. Azure and GCP are graded against CIS benchmarks instead. |
| SOC 2AICPA | 2017 | Native cloud-resource checks on AWS. Azure and GCP are graded against CIS benchmarks instead. |
| GDPREuropean Union | 2016/679 | Native cloud-resource checks on AWS. Azure and GCP are graded against CIS benchmarks instead. |
| OWASP Top 10OWASP Foundation | 2025 | Mapped on findings from application, API, and network testing. No native cloud-resource checks — pair with CIS benchmark grading for cloud evidence. |
| OWASP API Security Top 10OWASP Foundation | 2023 | Mapped on findings from application, API, and network testing. No native cloud-resource checks — pair with CIS benchmark grading for cloud evidence. |
Every cloud account is graded against CIS Foundations benchmarks on AWS, Azure, GCP, and Kubernetes clusters against the CIS Kubernetes benchmark, regardless of which frameworks above apply to you. Evidence can be exported as a report or pushed into Vanta or Drata.
How it works
From connected to evidence in four steps
Define scope
Add the domains, APIs, and cloud accounts in scope, with rules of engagement recorded before any test runs.
Test continuously
Application, API, network, container, and cloud checks run on a schedule instead of once a year, so drift is caught within a scan cycle.
Verify & de-duplicate
Findings from multiple tools are correlated into one issue, evidence is collected, and severity is scored so the list you read is the list that matters.
Export evidence
Results are mapped to framework controls and exported as a report, or pushed into Vanta or Drata.
Outcomes
What changes once this is running
- Deliver assessment results as OSCAL and SARIF instead of a PDF somebody has to transcribe.
- Report current control status continuously rather than reconstructing it annually.
- Keep an accurate inventory of exposed public services as the estate changes.
- Evidence supply-chain posture with CycloneDX or SPDX SBOMs and OpenVEX applicability statements.
- Control and audit who inside your organisation can see security findings.
Related
Go deeper on the parts that matter to you
Continuous Pentesting
Always-on, verified offensive testing across apps, APIs, and network — not a once-a-year snapshot.
Learn more →Cloud Security (CSPM)
CIS-benchmarked posture across AWS, Azure, and GCP, with drift caught inside a scan cycle.
Learn more →Compliance
How findings become control-mapped audit evidence, and which editions are pinned to your engagement.
Learn more →FAQ
Frequently asked questions
Common questions about RedStrike for Public Sector.
Does RedStrike support FedRAMP?
No. RedStrike does not provide FedRAMP control mapping and is not FedRAMP authorized. The frameworks in the registry are NIST SP 800-53 Rev. 5, ISO/IEC 27001, SOC 2, PCI DSS, HIPAA, GDPR, NIS2, the EU Cyber Resilience Act, and the OWASP Top 10 and API Security Top 10. NIST SP 800-53 Rev. 5 is the control catalogue that overlaps most with FedRAMP baselines, but overlap is not mapping and we will not describe it as such.
What is OSCAL and why does it matter here?
OSCAL is NIST's Open Security Controls Assessment Language, a machine-readable format for control catalogues, system security plans, and assessment results. Exporting assessment results as OSCAL means findings can be ingested by a governance or control-management system directly, rather than being manually transcribed from a report.
Which cloud providers get native NIST 800-53 checks?
AWS only. Azure subscriptions and GCP projects are graded against CIS Foundations benchmarks, and Kubernetes clusters against the CIS Kubernetes benchmark. Application-side 800-53 mapping applies to findings from any environment.
Can RedStrike run in an isolated or on-premises environment?
RedStrike is deployed with Docker Compose and is Kubernetes-ready, with PostgreSQL, MongoDB, and Redis as its data layer, so it can run inside infrastructure you control. Specific isolation, hosting, and data-residency requirements are worth discussing directly before an evaluation.
How is access to findings controlled?
Tenancy is enforced at the database layer with PostgreSQL row-level security, so isolation is not dependent on application code getting every query right. SAML single sign-on, SCIM provisioning, custom roles, and audit logging are available on the appropriate plans.
Does it cover legacy on-premises systems as well as cloud?
Yes. The engine spans network and service discovery, TLS configuration testing, web and API testing, container and infrastructure-as-code scanning, and cloud posture, so a mixed estate is covered by one programme rather than by several disconnected ones.
Control-mapped evidence, in the format the process expects
NIST SP 800-53 Rev. 5 mapping with OSCAL, SARIF, and OpenVEX exports.