FedRAMP sets Dec 7, 2026 deadline for new vulnerability detection and response rules
FedRAMP has confirmed that its Vulnerability Detection and Response (VDR) and Vulnerability Exploitability Rating (VER) rules, issued in response to CISA's BOD 26-04, become mandatory for all cloud service offerings by December 7, 2026, with a grace period through March 7, 2027 for those under a corrective action plan. The rules replace the old monthly scan-and-POA&M model with scan frequencies and remediation deadlines tied to certification class and vulnerability severity, in some cases as short as 12 hours.
GoKawiil's interpretation of the reporting above, not reported fact.
The tight remediation clocks and the new default assumption that exploits are automatable could force cloud providers to overhaul incident response staffing and evidence-gathering processes well before the deadline, since a 12-hour fix window functions more like an on-call paging requirement than a routine patch cycle. Treating process failures themselves as vulnerabilities suggests FedRAMP is pushing providers toward continuous, auditable operational discipline rather than periodic compliance checks. Programs that have not fully scoped these requirements may face compressed timelines to redesign monitoring and remediation workflows.
- FedRAMP's VDR and VER rules become mandatory December 7, 2026, with a grace period to March 7, 2027 for corrective action plans.
- Scan and remediation frequencies now scale with certification class (A–D) and vulnerability severity, with some fixes required within 12 hours.
- New rules shift the burden of proof onto providers to justify why a vulnerability isn't automatable, and treat process failures as vulnerabilities in themselves.
Source: bleepingcomputer.com, 2026-09-24
Published there as: “FedRAMP VDR & VER: Daily Scans Are Only the Beginning”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.