Casco is the first standalone FedRAMP-listed agentic offensive security platform

Written by Rene Brandel on Mon Aug 31 2026

Casco for Government is now listed on the FedRAMP Marketplace. Based on our review of the Marketplace's public product listings as of August 31, 2026, Casco is the first standalone listing for an agentic offensive security platform.

This is our first step to achieved FedRAMP 20x Class C certification.

When Ian and I started Casco, federal agencies were not on our roadmap. Then government security teams started showing up at our conference booths.

The conversations followed the same pattern.

  1. Their code and software were growing at an unprecedented rate.
  2. Their attack surface was changing faster than annual assessments could track.
  3. Their adversaries were adopting AI, and the people responsible for protecting public systems needed an equal or stronger force.

CrowdStrike's 2026 Global Threat Report found an 89% year-over-year increase in attacks by AI-enabled adversaries. The average time for an eCrime actor to move laterally after initial access fell to 29 minutes, and the fastest observed breakout took 27 seconds.

At the same time, the 2026 Verizon Data Breach Investigations Report found that vulnerability exploitation became the leading breach entry point for the first time in the report's 19-year history. It accounted for 31% of breaches, while AI compressed the path from a known vulnerability to exploitation from months to hours.

Federal defenders are carrying that pressure across an unusually large and consequential technology estate. The Government Accountability Office reports that the federal government spends more than $100 billion on IT each year, primarily maintaining existing systems. GAO says state and non-state actors attack government and private-sector systems thousands of times a day, and 764 of its 4,387 cybersecurity recommendations since 2010 had not been fully implemented as of January 2025.

An annual point-in-time test cannot match an adversary operating at AI speed. Defense has to become continuous.

Casco team with an American flag and astronaut mascot

Our path to Class C certification

We decided for FedRAMP 20x because it replaces static, paperwork-heavy assurance with continuous evidence (just like Casco does for pentesting!). FedRAMP describes Class C as the tier for common enterprise services likely to be used across an entire agency or to support important government services.

That model fits how Casco already believes security should work.

The Class C certification rules require automated methods to persistently verify Key Security Indicators, with at least two automated methods for each indicator. They call for historical validation metrics, frequent machine-readable reporting, and verification of machine-based resources at least every three days.

More importantly, FedRAMP 20x treats vulnerabilities as operational facts rather than scanner output. Its vulnerability evaluation rules require providers to evaluate whether a finding is likely exploitable, whether it is internet-reachable, and what exploitation could mean for agency customers. The rules say providers must assume exploitation can be automated unless they have evidence otherwise. Class C providers should evaluate detected vulnerabilities within five days.

That is a meaningful change. A long list of theoretical CVEs is not the same as proof that an attacker can reach sensitive data or cross a trust boundary. Context, reachability, exploitability, privilege, and chained weaknesses determine what matters.

Casco is built around that reality. Our agents test running applications, APIs, cloud infrastructure, networks, and AI systems. They retain scope and attack context, pursue multi-step attack paths, reproduce impact, and replay proven attacks to verify a fix. The goal is not to generate more alerts. It is to give defenders evidence they can act on.

FedRAMP's own model now assumes attackers can automate exploitation. Government defense deserves the same leverage.

Built here, for a mission larger than us

Every member of Casco's engineering team is a U.S. citizen. The team includes engineers who previously built AWS GovCloud, AI, and security services. We know what it means to build systems whose availability, isolation, auditability, and failure modes matter.

We also know that our security posture has to be demonstrated through architecture, operating discipline, independent assessment, transparent evidence, and results. FedRAMP 20x gives us a rigorous way to do that in public.

We will publish material progress through our Trust Center and keep our Marketplace status honest.

Thank you, Mycroft

We would not be at this milestone without Mycroft.

The Mycroft team is helping us design, implement, operate, monitor, and document our internal controls. Their platform supports the continuous evidence collection and compliance automation that a 20x program demands. They have treated this as an engineering journey, not a paperwork exercise, and they have been an exceptional partner through every step so far.

Huge shout out to Mike, Jon, Jan, and the entire Mycroft team for helping us get here and for staying with us for the much harder work ahead.

Today, Casco is FedRAMP listed and we are heads-down focused on FedRAMP 20x Class C.

If you are a federal agency, assessor, integrator, or public-sector security team evaluating continuous offensive security, contact us at government@casco.com or follow our progress on the FedRAMP Marketplace.