What happened
AWS IAM Identity Center has earned FedRAMP Class C certification across four US regions — Ohio, Northern Virginia, Northern California, and Oregon — allowing organizations to manage workforce access to AWS accounts and applications under that compliance framework. Separately, Cloudflare documented how a failed DNSSEC key rollover knocked Albania's entire .AL top-level domain offline, forcing the company to deploy a Negative Trust Anchor to restore resolution for affected users. Rather than silently bypassing DNSSEC validation, Cloudflare's 1.1.1.1 resolver now returns Extended DNS Error code 33, which explicitly signals within the DNS response itself that validation was overridden. Both developments reflect a broader industry push toward making security controls more auditable and transparent rather than invisible.
Why it matters for your business
For organizations operating under federal contracts or pursuing government clients, AWS IAM Identity Center's FedRAMP Class C status removes a significant compliance barrier — teams can now consolidate identity and access management for regulated workloads without architecting around the gap. On the DNS side, Cloudflare's EDE 33 implementation is a concrete win for observability: network and security engineers can now detect validation bypass events directly from DNS response data rather than inferring them from logs or third-party monitoring tools. The practical takeaway is that DNS monitoring pipelines and SIEM integrations should be updated to parse and alert on EDE codes, since this class of signal will likely become standard across major resolvers. Organizations relying on DNSSEC for supply-chain or application integrity checks should treat silent bypass events as a distinct risk category requiring dedicated detection.
What to watch next
AWS's FedRAMP expansion is unlikely to stop at Class C — watch for additional services entering scope as the company continues to court federal and regulated-industry buyers. On the DNS transparency front, Cloudflare's adoption of EDE 33 may pressure other major public resolvers such as Google's 8.8.8.8 to implement similar signaling, which would move the standard from optional to de facto expected. The .AL outage also renews debate around TLD operators' DNSSEC operational maturity, and registrars may face growing pressure to publish rollover procedures publicly.
