When a seller says they’re listed on a government marketplace, what do you think it means? Does it mean their product is officially authorized, or can sellers be listed there for other reasons?

I’m looking to see how people interpret this now with the changes that will be in place in 2026.

I've noticed that ‘listed on the FedRAMP Marketplace’ seems to be used almost like a credential itself. Though a listing on the marketplace can actually mean so many things. Like initial implementation, ready, in Process, certified etc. And for 20x specifically, initial implementation ,arketplace listing is before the vendor provides certification.

So if a vendor says ‘We’re listed on the FedRamp marketplace’ without explaining it any further, do you think of that as something more indicative other than just having a listing? In my case I d need to know what kind of service and what status it is in before taking that as a guarantee. Maybe people that deal with this on a daily basis would understand how this could be misleading to a customer or someone involved in procurement - they could take “FedRAMP Marketplace” for “FedRAMP Certified”.

reddit.com
u/omytolawschool — 13 days ago
▲ 3 r/grc

How do I categorize outside material thats shown on the website of the regulatory body?

I’m facing this evidence categorization issue, and it looks simple until you deal with it yourself .For example, an association submitted a report, platform, or an example to a regulator as a part of a public inquiry and asking for written material. Later the regulator uploaded it to its website. However the same webpage says clearly that the documents are accepted without any changes and do not necessarily reflect the regulator’s opinion. How could you categorize this in your internal records?

There is definitely more context here than in a simple case where someone uploaded the same document on their blog, as you can find out all the details. But it d be incorrect to say the regulator validated or accepted the content just cause they have the document on their webpage.

What I mean here would be: guidelines by a regulatory body, views expressed by regulator staff, regulatory inquiry or document, outside material issued by the regulator, independent outside material, different variances have different value of the evidence. Do people really differentiate such things in registers of evidence in GRC or compliance?

And if the department states, ‘this strategy is from [some_regulator],’ is it correct or it should be stated like ‘submitted to and published by [some_regulator]?

reddit.com
u/omytolawschool — 13 days ago

Is the ‘free diagnosis and paid solution’ model really effective?

I've been spotting certain types of freemium schemes more often. The free version doesn't really solve anything. It merely reveals what's wrong.  Free security scan → pay to fix the security issues. Free cloud audit → pay to make everything right. Free SEO analysis → pay for the proper solution. Free compliance assessment→ pay to have everything under control.

From the perspective of this being a great offer, the free tier proves that there's a problem worth solving. Though I'm starting to wonder if it brings up some trust issues. After all, if the same company tells me there are some 47 problems to be solved and then offers their solution for solving all the problems, I might be skeptical about the actual number. Especially now that with the free version the company seems to be discovering even more problems while they keep imposing higher prices. 

Has anyone ever made or employed this kind of SaaS? 

Is it true that making the diagnostic layer free makes selling the paid product easier, or do the clients think too much about how the free results are designed in order to provoke urgency?

reddit.com
u/omytolawschool — 13 days ago

When does a security PoC turn into what can be called a ‘real-world deployment’?

Let’s say there’s a security product which is tested within an environment closely resembling the production one. The application, network topology, integration, certificates/configurations and traffic are all the same .In this situation testing seems to be successful, and it shows that the controls can be installed in the application without disrupting it. But everything happens in a lab. There are no real customers or dealings. Would you treat this as a real-world deployment?

To me, this proves more than just a PoC. The issues of compatibility, interoperability, and the level of efficiency can also be investigated. However, it doesn’t allow us to understand what will happen in the case of actual traffic, edge case, failures, or something like that.

How should we define the term we are using for such trials?

reddit.com
u/omytolawschool — 13 days ago