FedRAMP's 2026 rules replaced the baselines with 46 Key Security Indicators and 246 requirements on fixed dates. Diamondback shows which you can evidence from live configuration today, and which deadlines are closing.
curl -sL https://diamondback.run/install.sh | bash -s -- --region us-east-1
Diamondback turns live AWS configuration into FedRAMP evidence — and says plainly which indicators it cannot speak to.
19 of FedRAMP's 46 Key Security Indicators, evidenced from real configuration and joined to each indicator through the NIST controls it names — not a mapping drawn by hand.
246 requirements, filtered to your certification type, path and class. VDR and VER bind on 7 December 2026 under CISA BOD 26-04, and the register leads with what is closing.
CIS AWS Foundations, AWS FSBP and NIST 800-53 from our own checks — no Security Hub subscription, no per-finding bill.
One read-only pass over your account — every enabled region, and every account in your AWS Organization if you point it there — turned into evidence against FedRAMP's indicators. Everything it can't prove, it says so, plainly.
One CloudFormation stack in your own AWS account — App Runner, RDS, Cognito. Your configuration never leaves it.
SecurityAudit + ViewOnlyAccess and nothing else. Every call is a describe, list or get — checkable in source, and refused by IAM if it weren't.
When a check needs a service you haven't enabled, Diamondback says which, why, what it unlocks, and the exact aws command — including what it will cost you.
Point it at your AWS Organization and it assumes a read-only role in each member account and sweeps them together. Every finding still names the account it came from — and any account it could not reach is named too, as unassessed.
The console reads its own role back from IAM and shows you the policies attached — not a claim in a brochure, a live check.
One command in AWS CloudShell, in the account you want assessed — no local tooling:
curl -sL https://diamondback.run/install.sh | bash -s -- --region us-east-1
Permission to create a CloudFormation stack containing IAM roles, RDS, Cognito, VPC and App Runner. The installer creates them and attaches Diamondback's role read-only SecurityAudit + ViewOnlyAccess.
A Cognito user pool is created for you. Operators are invited by email — no self-registration, MFA available, and a 15-character password floor to match the ISM's own.
Enable Security Hub and Diamondback reads its failing CIS/FSBP controls as AWS-authored evidence. It is charged per check, so it stays your call — every control below is assessed without it.
Two AWS managed read-only policies. No write path, no standing secret, and no access to the contents of your buckets or databases — it assesses configuration, not data. Teardown is one command.
The reason to trust a compliance tool is what it declines to claim.
A KSI statement is broader than any check that informs it. Diamondback reports evidence, currently clean at the very most. Whether the indicator is met is a 3PAO's determination, and the status vocabulary has no word for it.
No evidence is not assessed. A missing prerequisite is no visibility. A permission error is no visibility — never mistaken for "no resources exist".
They are programme and process obligations — independent assessment, marketplace listing, change notification. Grading them from an AWS account would be nonsense, so Diamondback carries the register and the dates, and assesses none of it.
Before a scan has run, indicators show unscanned rather than clean, because clean would be an artefact of having no findings to show.
The two look identical: both produce no findings. So every report states which accounts it covered and names the ones it did not, and if your organisation could not even be listed it says the number of accounts it missed is unknown.
One scan, every framework a finding touches — pinned to real published versions. FedRAMP leads; the Australian ISM is still carried in full for customers who need both.
Built by Abhijit Ghosh — nearly a decade in national-government cyber security, including several years at the Australian Cyber Security Centre (ACSC) and the Australian Signals Directorate (ASD), assessing cloud systems against exactly this kind of control framework.
Diamondback is the tool that assessment work kept calling for: a control framework turned into something you can run, read, and hand to an assessor — with the honest gaps shown, not a spreadsheet re-filled by hand each quarter. It reads only, holds nothing but two AWS read-only policies, and keeps your data in your own account.
Diamondback is built to be approvable in an afternoon. The install templates are public, and the full source is available to security teams on request — read the code, verify there's no write path, watch it hold nothing but SecurityAudit and ViewOnlyAccess. Reach us at security@diamondback.run.