Continuous controls monitoring without a false green dashboard
ConMon automation moves repeatable collection and comparison into a scheduled, inspectable workflow: pull permitted security signals, normalize findings, check evidence freshness, flag drift, and prepare a versioned report. It should never convert a failed or partial pull into a clean bill of health. Human owners still decide remediation, accept risk, review reports, and attest to facts the software cannot observe.
Product measurement: scm.cc main defines 13 targeted KSI collector checks across GitHub, Supabase, AWS and scanner facts. That is a count of implemented checks, not 13 verified KSIs or proof that every tenant has the necessary connected sources.
FedRAMP now uses Certification and Classes A-D for package baselines. During the transition through December 31, 2026, Class B (Low), Class C (Moderate) and Class D (High) pair the new class with the earlier label; Class A is a pilot. Certification does not replace an agency's own authorization to operate. Historical Rev 5 baseline identifiers in records stay unchanged.
Which ConMon steps can be automated?
A useful pipeline retains provenance from the original connector run through a finding, its mapped control and a dated report. The current monthly package code creates a content-addressed manifest for its sections; a hash helps detect changed bytes but is not an independent signature. scm.cc can run configured read-only sources on a schedule, deduplicate findings, record open and resolved states, and recompute its tenant coverage dashboard. Monthly runs pin an input snapshot and baseline so a later change does not silently rewrite history. Where a loader fails, the run must show partial or failed rather than succeeded.
- Collect only sources actually connected for that org.
- Mark incomplete or degraded pulls, and avoid auto-resolving unseen findings on those pulls.
- Present source references and the age of evidence alongside the result.
What can no automation honestly decide?
A policy's wording and an owner's signature are not scanner outputs. An agency's risk tolerance, a deviation approval and an independent assessor's finding are also decisions by people. A KSI with fewer than the required automated methods remains unverified; a successful data pull does not create a second method. FedRAMP's 20x principles favor automatic validation where possible while retaining accountability for the security decisions themselves.
- Have the responsible person review source scope and report exceptions.
- Do not treat a generated draft, a starter policy outline, or a demo score as approved evidence.
How should a team test an automation vendor?
Run a complete workflow with one real connector and verify a known source finding reaches the product with the same discovery date. Then intentionally remove a permission or hit a page cap in a test account and check that the run is degraded, not empty-and-clean. Export a monthly package and compare its snapshot and source references with what the tenant dashboard showed. Confirm the owner can see what changed between runs.
- Check both success and failure paths on the same source.
- Verify that reports identify unmeasured resources and missing periods.
- Ask which periodic checks are genuinely scheduled versus merely modeled in a helper library.
What is the cost and operational limit in scm.cc?
A free account allows one connected repo and one connector; the pricing page lists monthly Starter ($299), Pro ($599) and Business ($999) with increasing repo and connector caps. The operational limit matters more than a feature list: the live ConMon run is monthly today. The separate Class C three-day machine-verification path is not yet a production guarantee. Customers must still validate each integration with their own permissions and data.
- Use the public demo only for interface evaluation; it contains fixtures.
- Review the live pricing page before selecting a plan; this article is not a checkout.
Questions teams ask
- Can ConMon be fully automated?
- Collection and comparison can be automated in part. Risk decisions, signatures, independent assessment and source-scope review remain human responsibilities.
- What happens if a connector fails?
- The honest result is a degraded or partial run and no inference that missing findings were fixed. A clean result is only meaningful over the scope actually checked.
- Are 13 collectors equal to 13 compliant KSIs?
- No. They are code-defined checks. Each KSI needs its own qualifying evidence methods and source data; unverified states remain unverified.
- Does the public demo show my company?
- No. /demo is clearly labeled fixture data. The signed-in tenant dashboard is the place to inspect your own connected records.
Primary sources
- FedRAMP 20x overview
- FedRAMP 20x collaborative continuous monitoring rules
- FedRAMP 20x vulnerability detection and response rules
- FedRAMP certification and class designation notice
Source and product behavior reviewed September 30, 2026. Check current FedRAMP rules before relying on a schedule or submission requirement. This is product guidance, not an assessment, legal advice, certification or authorization.