The Frontier Has a Brake Pedal. The Floor Doesn't.
In June I asked whether Anthropic's warning was a brake pedal or a press release. The essay arrived — and it's a real mechanism, aimed one layer above where most of us actually ship agents.
In June I asked whether Anthropic's warning was a brake pedal or a press release. The essay arrived — and it's a real mechanism, aimed one layer above where most of us actually ship agents.
A quick-reference glossary of NIST SP 800-53 control families referenced throughout the FedRAMP series — RA, CM, SA, AC, AU, SI — and what each one means for platform engineers.
Drawing the FedRAMP authorization boundary is the most consequential platform decision in the program — what's in, what's leveraged, what's external, and how 20x turns the boundary from a Visio diagram into a data structure.
FIPS-validated crypto is a hard requirement inside a FedRAMP boundary — not a best practice. A practitioner's walkthrough of where FIPS lands across 800-53 control families, and how the Building for Compliance supply-chain work maps onto it.
A platform engineer's plain-English walkthrough of what FedRAMP actually is — impact levels, the document set (SSP, SAR, POA&M), the ATO process, and how Rev5 and 20x change the picture in 2026.
A short note on why I refreshed the 5-part SOC 2 for ISVs series in 2026 — modernized imagery, and a reset of my own field knowledge from +-5-7 years of customer engagements.
A platform engineer's take on starting the FedRAMP journey from outside the US — why a third-party partner matters, and what the '90 days' promise really means in 2026.
The finale of the Zero Trust series: where compliance frameworks meet ZTNA, how the hyperscalers ship it natively, and what twenty years of remote-access evolution means for working practitioners.
SBOM, provenance, SLSA, cosign — and how FIPS 140-2/3 and FedRAMP land on your container images. A practitioner's map before the rebuild begins.
How AWS Landing Zone Accelerator (LZA) turns YAML configs into governed multi-account environments with Transit Gateway isolation, NACLs, and HIPAA-ready networking.
Choosing an auditor, surviving the Type II observation window, common findings, and how SOC 2 becomes the foundation for ISO 27001, HIPAA, and FedRAMP.
How to turn SOC 2 from a yearly fire drill into a byproduct of how you build — AWS SCPs, GCP Org Policies, OPA, drift detection, and automated evidence collection.
How to map SOC 2 controls to your AWS, GCP, and Kubernetes stack — IAM, logging, encryption, change management, and what auditors actually want to see.
What the five SOC 2 Trust Service Criteria actually mean, which are mandatory, and how to scope your audit so it doesn't sprawl. Part 2 of 5.
Why SOC 2 has become non-negotiable for ISVs selling to enterprises — and what it actually costs to skip it. Part 1 of a 5-part series.