FedRAMP AKS Migration and New Process

Prev Next

We are modernizing the platform underneath OneSpan Sign FedRAMP environments from virtual machines to a containerized architecture on the Azure Kubernetes Service (“AKS”). The service stays in the same FedRAMP Azure environment, at the same FedRAMP Moderate authorization level, and the new environment will be FedRAMP-authorized before any customer is moved onto it.

The containerized platform gives us better resiliency, faster recovery, a stronger security posture, and a shorter path to delivering new features.

After September 16, 2026 for your Sandbox environment and after October 7, 2026 for your Production environment, new or changed outbound destinations will follow a new process. If you wish to make any updates to your current configurations after these dates your domains will need to be submitted to our Support Team in advance so they can be whitelisted and thus authorized for use. Once validated, you may proceed with setting your desired configurations in the UI, or via APIs. Note that we will only need your callback URLs. For a more detailed explanation of this process see Outbound destinations - required actions.

What is not changing

  • Your URLs, domain names, and API endpoints all remain the same.

  • Outbound IP addresses remain unchanged. If you currently whitelist OneSpan Sign outbound IP addresses in your environment, no changes are required. (This is separate from outbound destinations, covered below.)

  • Your login credentials and your single sign-on configuration.

  • The OneSpan Sign feature set — this is a like-for-like upgrade. For information on features that are not supported in FedRAMP environments, see Unsupported FedRAMP features.

Single sign-on — please test in Sandbox

The new environment includes a new single sign-on implementation. Your SSO configuration carries over unchanged, and we do not expect any difference in what your users see — no new screens, no additional prompts for signers.

Because SSO sits on the critical path for every user, we ask you to test it thoroughly in the upgraded Sandbox environment rather than rely on the Production cutover as the first real-world test. Please cover your normal sign-in paths, any identity provider–initiated flows you use, and the accounts and roles your users actually sign in with. Report anything that behaves differently to our Support Team as soon as you see it, so we can address it well ahead of the Production date.

Outbound destinations — required actions

As part of our ongoing security improvements, outbound traffic from the FedRAMP environment - such as callbacks - will be controlled by a whitelist of allowed destinations, enforced on the new platform. The whitelist is DNS-based (for example, partner.example.com) rather than IP-based.

What we're doing for you: every outbound destination (for example, callbacks) configured in your account on or before September 16, 2026 for the Sandbox environment and October 7, 2026 for the Production environment will be copied to the new environment exactly as configured. You don't need to re-enter anything.

What we need from you:

  • Avoid adding or modifying outbound destinations after September 16, 2026 (Sandbox) and October 7, 2026 (Production). Contact our Support Team if changes are required.

  • If you'd like to verify your list, contact our Support Team. We will provide the outbound destinations we hold for your account, so you can confirm nothing is missing.

  • After the migration has completed, please test in Sandbox to confirm that your outbound calls behave as expected. If anything is unexpectedly blocked, contact our Support Team right away so we can correct it well before the Production date, preferably by November 7.

After September 16, 2026 for Sandbox and after October 7, 2026 for Production, new or changed outbound destinations will follow this process - your domains will need to be submitted to OneSpan in advance so they can be authorized before use. Note that we will only need your callback URLs.

What we ask of you — summary

  1. No action is required to maintain connectivity — no reintegration, no new IP addresses to whitelist.

  2. Note the four maintenance windows below — two preparatory, two cutover — and plan around them.

  3. Avoid adding or modifying outbound destinations after September 16, 2026 (Sandbox) and October 7, 2026 (Production). Contact our Support Team if changes are required.

  4. Test your single sign-on, your integrations, and your outbound connections in the upgraded Sandbox between October 10 and November 7, 2026, and report anything unexpected.

Maintenance windows

This migration will require extended planned maintenance windows for both the Sandbox and Production FedRAMP environments.

Each environment is migrated in two stages. First, a preparatory maintenance window, in which we validate the complete migration procedure on the environment itself — this is how we confirm timings, verify every step end to end, and resolve anything that needs attention before it can affect the live move. The environment continues to run on its current platform afterwards. Second, the cutover window, in which the environment moves to the new platform.

Your environments will be unavailable for the duration of both windows.

Environment

Stage

Date

Window (ET)

Estimated duration

Sandbox

Preparatory maintenance

Saturday, September 26, 2026

9:30 AM – 5:30 PM

approx. 8 hours

Sandbox

Cutover

Saturday, October 10, 2026

9:30 AM – 5:30 PM

approx. 8 hours

Production

Preparatory maintenance

Saturday, October 24, 2026

from 8:00 PM

TBD

Production

Cutover

Saturday, November 14, 2026

from 8:00 PM

TBD

Please note: The estimated duration is currently being finalized and will be updated once the maintenance in Sandbox has been completed and the results have been assessed. The cutover durations are estimated: we will refine them using what we learn from each preparatory window and confirm the final window for each environment ahead of the date, published as a Notice of Scheduled Maintenance. Because this is a significant infrastructure change, we've built thorough verification into the window to de-risk it.

Release schedule

The migration changes the near-term release sequence for the FedRAMP environment.

  • FedRAMP will move from 26.R5 directly to 27.R1. 26.R6 is not delivered to FedRAMP as a separate release.

  • You do not lose functionality. 27.R1 is cumulative — it contains the functionality released in 26.R6. FedRAMP customers receive that functionality later, and under a different version number, rather than as a separate release to review and test.

  • Why: the FedRAMP Sandbox and Production environments are frozen through the end of September 2026 for certification, and the cutover from the current VM environment to the new AKS environment takes place on November 14, 2026. Fitting an additional release between those two events would add risk to the migration without adding capability.

  • What this means in practice: the FedRAMP environment runs 26.R5 from the end of October 2026 until 27.R1 arrives at the very end of January / beginning of February 2027 — approximately three months. From 27.R1 onward we expect the FedRAMP release schedule to be broadly in line with our commercial SaaS environment.

  • Security updates continue throughout. Minor changes and fixes for critical and high-severity vulnerabilities can be deployed during the certification freeze, and out-of-cycle updates can be arranged in the period between 26.R5 and 27.R1 if they are needed.

If you have any questions or concerns, please contact our Support Team. We will provide confirmation of the final maintenance window ahead of each migration date.