Join us as we discuss news and current events, trends, and controversies in the world of cybersecurity. We have strong feelings and they're not limited to FedRAMP, CMMC, FISMA, IRAP, security engineering, or documentation. Anything goes -- some of the things we say are probably even helpful! Interested in having words? Email us at info@38northsecurity.com.

The 38North Security Podcast
Claim This Podcastby 38North Security
Podcast Authority
Beta
Podcast Overview
Join us as we discuss news and current events, trends, and controversies in the world of cybersecurity. We have strong feelings and they're not limited to FedRAMP, CMMC, FISMA, IRAP, security engineering, or documentation. Anything goes -- some of the things we say are probably even helpful! Interested in having words? Email us at info@38northsecurity.com.
Language
🇺🇲
Publishing Since
1/30/2024
Unlock The Full Podcast Authority Score Report
See how your podcast performs across key metrics
Podcast Authority
Beta
Recommendations available
Unlock the full report to see detailed tips
Recommendations available
Unlock the full report to see detailed tips
Unlock comprehensive insights including:
- • YouTube presence analysis
- • Social media reach metrics
- • RSS compliance scoring
- • Podcast 2.0 features
- • Technical standards
Detailed Analytics
- Complete breakdown of all 19 authority metrics
- Personalized recommendations for each metric
- Industry benchmarks and comparisons
- Technical RSS feed analysis and compliance scoring
Growth Strategies
- Step-by-step action plans for improvement
- Quick wins to boost your score immediately
- Pro tips from successful podcasters
See how your show performs across every key metric
High authority scores make your podcast more attractive to industry leaders and influencers who want to appear on credible shows.
Sponsors look for podcasts with proven authority and engagement. Your score demonstrates your podcast's value to potential partners.
Understanding your strengths and weaknesses helps you make data-driven decisions to expand your listener base effectively.
1 verified contact email on file for The 38North Security Podcast
Pitch yourself as a guest, propose sponsorships, or reach out directly to the host.
Recent Episodes

July 2, 2026
FedRAMP 20x Is Here: The Six Changes That Matter Most
<p>With FedRAMP's Consolidated Rules for 2026 being final, FedRAMP 20x is officially here. </p><p>That changes how cloud service providers enter FedRAMP, define scope, prove security, maintain certification, and work with federal agencies.</p><p>In this episode, Ingrid Velasquez-Woodley speaks with Sam Leestma, Vice President of Solutions Engineering, and Spence Witten, Principal Consultant at 38North Security, about the six parts of CR26 most likely to affect cloud providers and agencies.</p><p>Topics include:</p><p>* How the new certification classes differ from the Rev. 5 impact levels<br>* Whether Minimum Assessment Scope will actually reduce cost and complexity<br>* Why Key Security Indicators may provide better assurance than point-in-time evidence<br>* Whether the Security Decision Record could become the next oversized compliance document<br>* What VDR and VER require before the December 7, 2026 deadline<br>* Why existing Rev. 5 providers may struggle with vulnerability automation<br>* How ongoing certification differs from continuous validation<br>* Whether annual assessments should become less burdensome<br>* Why CR26 limits agencies from creating their own parallel FedRAMP requirements<br>* What the major CR26 transition dates mean for providers<br>* What CSPs considering 20x—and those already holding Rev. 5 certifications—should do now</p><p>The discussion also covers where FedRAMP got the model right, where the final rules still create uncertainty, and how implementation by agencies, assessors, and providers will determine whether CR26 actually reduces duplication and improves security visibility.</p><p>Important dates discussed:</p><p>June 24, 2026 — CR26 becomes final<br>July 4, 2026 — Optional early adoption begins<br>July 28, 2026 — FedRAMP Ready becomes a legacy designation<br>August 3, 2026 — Class A applications open<br>August 10, 2026 — Limited Rev. 5 Class B and C transition pathways open<br>August 31, 2026 — 20x Class B and C applications open<br>December 7, 2026 — VDR and VER become mandatory<br>January 1, 2027 — Broader mandatory CR26 adoption begins<br>June 11, 2027 — FedRAMP stops accepting new Rev. 5 certification applications</p><p>Explore more FedRAMP 20x insights from 38North Security: <br>https://38northsecurity.com/fedramp-20x/ </p><p>Explore 38North Security’s FedRAMP services:<br>https://38northsecurity.com/security-compliance/north-america/fedramp/</p><p>#FedRAMP #FedRAMP20x #cloudsecurity #cybersecurity #govtech #38NorthSecurity #federal #cloudsecuritypodcast</p>

July 28, 2025
Why Engineers Hate Compliance—And Why They’re Not Wrong
<p>Welcome to Part 1 of our Compliance Engineering Mini-Series, a focused look at what it means to build secure, auditable systems by design.</p><p><br>In this kickoff episode, 38North Director of Engineering Larry Spector joins Chris Davis to talk about a familiar tension: engineers want to move fast, and compliance gets in the way. But what if the engineers are right? Or at least, right to feel the way they do?</p><p>Together, they explore:</p><ul><li>Why compliance often fails when it’s treated as a bolt-on</li><li>How audit fatigue and rework are symptoms of deeper engineering gaps</li><li>The difference between “checking boxes” and proving operational excellence</li><li>What it actually means to build systems that generate their own evidence</li></ul><p>Larry and Chris reframe the problem and set the stage for a new way of thinking about compliance, engineering, and trust.</p>

May 28, 2025
GovRAMP: Navigating the Path to Authorization
Matt Strasburg, Cloud Security Advisory manager, outlines the GovRAMP authorization process, including key steps and timelines for cloud providers, in this interview episode.
7 total episodes available
Recent guests on The 38North Security Podcast
Guests from recent episodes — sign up to see every guest that has ever appeared on this show.
Matt Strasburg
Guest
Deep-dive analytics for The 38North Security Podcast
Frequently asked questions
Have a different question and can't find the answer you're looking for? Reach out to our support team by sending us an email and we'll get back to you as soon as we can.
- What is The 38North Security Podcast?
- How often does this podcast release new episodes?
This podcast updates weekly.
- Where can I listen to this podcast?
This podcast is available on 6 platforms including Apple Podcasts, Spotify, and more. You can also use the RSS feed directly.
- Does this podcast accept guests?
Yes, this podcast regularly features guests.
Legal Disclaimer
Pod Engine is not affiliated with, endorsed by, or officially connected with any of the podcasts displayed on this platform. We operate independently as a podcast discovery and analytics service.
All podcast artwork, thumbnails, and content displayed on this page are the property of their respective owners and are protected by applicable copyright laws. This includes, but is not limited to, podcast cover art, episode artwork, show descriptions, episode titles, transcripts, audio snippets, and any other content originating from the podcast creators or their licensors.
We display this content under fair use principles and/or implied license for the purpose of podcast discovery, information, and commentary. We make no claim of ownership over any podcast content, artwork, or related materials shown on this platform. All trademarks, service marks, and trade names are the property of their respective owners.
While we strive to ensure all content usage is properly authorized, if you are a rights holder and believe your content is being used inappropriately or without proper authorization, please contact us immediately at hey@podengine.ai for prompt review and appropriate action, which may include content removal or proper attribution.
By accessing and using this platform, you acknowledge and agree to respect all applicable copyright laws and intellectual property rights of content owners. Any unauthorized reproduction, distribution, or commercial use of the content displayed on this platform is strictly prohibited.