Writing

Articles on audit readiness, compliance architecture and cloud cost governance, by Kenio Shirley.

  1. From SOC 2 to FedRAMP: The Class A Sponsorless Path Is Open

    · 8 min read

    For fifteen years the answer to 'how do we get FedRAMP authorized?' started with 'find an agency sponsor.' As of August 3, 2026, it starts with 'do you have a current SOC 2 Type II?' That changes who the federal market is open to.

  2. CMMC Is Paused. Your CUI Obligations Aren't.

    · 8 min read

    The Department of War paused CMMC Phase II for a 60-day review and half the defense industrial base exhaled. Meanwhile the FAR Council proposed a CUI rule that sweeps in nearly every federal contractor, and DFARS 7012 never went anywhere.

  3. Your Next SOX Audit Runs on New PCAOB Rules

    · 8 min read

    The PCAOB rewrote how auditors evaluate internal control over financial reporting, and the effective date lands on fiscal years ending December 15, 2026 or later. If your ITGC program has a soft spot, the deficiency math just changed underneath it.

  4. FedRAMP 20x Changes What an Authorization Package Is

    · 8 min read

    For twenty years a federal authorization package was a pile of documents a human reviewed. The Consolidated Rules for 2026 make it machine-readable data a pipeline validates. That is not a formatting change — it changes what the evidence is.

  5. The Public-Sector Linux Migration Is a Compliance Decision, Not a Cost Cut

    · 8 min read

    Schleswig-Holstein, Denmark, Austria's armed forces and the French Gendarmerie are all moving public-sector desktops to open platforms. The licence savings are real and mostly beside the point. What changes is the quality of the evidence you can put in front of an auditor.

  6. Population Completeness: The ITGC Finding Nobody Plans For

    · 7 min read

    Teams prepare for the sample. They almost never prepare for the question that comes first: how do you know this list of changes is all of them? That question is where SOX ITGC and SOC 2 audits actually go wrong.

  7. Your CAB Isn't the Problem. Its Design Is.

    · 9 min read

    DORA says formal external approval doesn't reduce change failure rates. NIST CM-3 names the change advisory board directly. Both are right, because the frameworks never asked for a meeting — they asked for a record.

Subscribe by RSS.

Monthly compliance insights

One email a month on audit readiness, FedRAMP and SOC 2 programs, and IT general controls that survive an auditor. No pitches, unsubscribe any time.