FedRAMP sets Dec 7, 2026 deadline for new vulnerability detection and response rules
FedRAMP has confirmed that its Vulnerability Detection and Response (VDR) and Vulnerability Exploitability Rating (VER) rules, issued in response to CISA's BOD 26-04, become mandatory for all cloud service offerings by December 7, 2026, with a grace period through March 7, 2027 for those under a corrective action plan. The rules replace the old monthly scan-and-POA&M model with scan frequencies and remediation deadlines tied to certification class and vulnerability severity, in some cases as short as 12 hours.