Skip to content
Browse docs

Vulnerability Detection and Response — FedRAMP Process

Generated from the official FedRAMP/rules GitHub repo. Source path: fedramp-consolidated-rules.json on main at blob 7d628b63fdd9. Consolidated Rules version: 2026.07.02.02 · upstream last_updated: 2026-07-02. Supporting narrative documentation is available from the official FedRAMP/2026-markdown repository.

Vulnerability Detection and Response

Short name: VDR · Process ID: VDR · Web slug: vulnerability-detection-and-response

Applies to: both, 20x, rev5 Status: stable

Official page: https://www.fedramp.gov/2026/reference/vulnerability-detection-and-response/

Effective Status

  • 20x: required · Mandated by CISA BOD 26-04 · obtain 2026-12-07 · grace through 2027-03-07
  • Rev5: required · Mandated by CISA BOD 26-04 · obtain 2026-12-07 · grace through 2027-03-07
  • Shared requirements: 16

Purpose

The Vulnerability Detection and Response rules require providers to continuously identify, analyze, prioritize, mitigate, and remediate vulnerabilities and related exposures through automated systems. These rules give providers flexibility in implementation while ensuring agencies receive the information needed to support ongoing authorization decisions.

Rule Subsets

  • CSO — General Provider Responsibilities: These rules apply to all providers with FedRAMP Certifications of any type. · types: 20x, Rev5 · classes: B, C, D
  • TFR — Timeframes: These rules apply to timeframes for vulnerability detection and response. · types: 20x, Rev5 · classes: B, C, D

Requirements and Recommendations

BOTH

VDR-CSO-ADT SHOULD — Automate Detection

Providers SHOULD use automated services to improve and streamline vulnerability detection and response.

Terms: Provider, Vulnerability, Vulnerability Detection, Vulnerability Response

Affects: Providers

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

VDR-CSO-AKE SHOULD NOT — Avoid KEVs

Providers SHOULD NOT deploy or otherwise activate new machine-based information resources with Known Exploited Vulnerabilities.

Terms: Information Resource, Known Exploited Vulnerability (KEV), Machine-Based (Information Resources), Provider, Vulnerability

Affects: Providers

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

VDR-CSO-DAC SHOULD — Detect After Changes

Providers SHOULD automatically perform vulnerability detection on representative samples of new or significantly changed information resources.

Terms: Information Resource, Provider, Vulnerability, Vulnerability Detection

Affects: Providers

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

VDR-CSO-DET MUST — Vulnerability Detection

Providers MUST systematically, persistently, and promptly discover and identify vulnerabilities within their cloud service offering using appropriate techniques such as assessment, scanning, threat intelligence, vulnerability disclosure mechanisms, bug bounties, penetration testing, incident response, automated control testing, supply chain monitoring, and other relevant capabilities; this process is called vulnerability detection. Vulnerability detection includes persistently verifying and validating that information resources and processes are operating as intended and documented for FedRAMP Practices.

Terms: Cloud Service Offering, FedRAMP Practices, Incident, Information Resource, Persistently, Promptly, Provider, Vulnerability, Vulnerability Detection, Vulnerability Response

Affects: Providers

Note: FedRAMP’s vulnerability detection (and response) rules are intended to set modern expectations for maintaining the security of a cloud service. Historical FedRAMP guidance on vulnerability scanning or continuous monitoring generally focused only on CVE-type vulnerabilities while leaving other types of vulnerabilities and exposures unaddressed. Providers are encouraged to leverage their existing holistic security review, architecture review, and similar processes to meet these requirements. FedRAMP strongly discourages providers from implementing separate vulnerability detection and response processes for FedRAMP reporting that are operated by independent compliance branches unless these processes are consuming data directly from the areas of the cloud service that actively maintain it.

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

VDR-CSO-DFR SHOULD — Design For Resilience

Providers SHOULD make design and architecture decisions for their cloud service offering that mitigate the risk of vulnerabilities by default AND decrease the risk and complexity of vulnerability detection and response.

Terms: Cloud Service Offering, Provider, Vulnerability, Vulnerability Detection, Vulnerability Response

Affects: Providers

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

VDR-CSO-FAV MUST — Failures Are Vulnerabilities

Providers MUST treat problems or failures with their vulnerability detection and response processes as vulnerabilities.

Terms: Provider, Vulnerability, Vulnerability Detection, Vulnerability Response

Affects: Providers

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

VDR-CSO-MSP SHOULD NOT — Maintain Security

Providers SHOULD NOT weaken the security of information resources to facilitate vulnerability scanning, detection, or assessment activities.

Terms: Information Resource, Provider, Vulnerability, Vulnerability Detection

Affects: Providers

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

VDR-CSO-RES MUST — Vulnerability Response

Providers MUST systematically, persistently, and promptly track, evaluate, monitor, mitigate, remediate, assess exploitation of, report, and otherwise manage all detected vulnerabilities within their cloud service offering; this process is called vulnerability response.

Terms: Cloud Service Offering, Fully Mitigated Vulnerability, Partially Mitigated Vulnerability, Persistently, Promptly, Provider, Remediated Vulnerability, Vulnerability, Vulnerability Detection, Vulnerability Response

Affects: Providers

Note: If it is not possible to fully mitigate vulnerabilities or remediate vulnerabilities, providers SHOULD instead partially mitigate vulnerabilities promptly, progressively, and persistently. FedRAMP does not use the terms “mitigation” and “remediation” interchangeably. Mitigation is the process of reducing the risk and impact of a vulnerability through partial mitigation and even full mitigation; remediation is the process of entirely eliminating the vulnerability. A fully mitigated vulnerability will still exist (with negligible risk) until it has been remediated. This separation is based on the plain language definitions of these words. Please refer to FedRAMP Definitions for strict interpretation in the FedRAMP context.

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

VDR-CSO-SIR MAY — Sampling

Providers MAY sample effectively identical information resources, especially machine-based information resources, when performing vulnerability detection UNLESS doing so would decrease the efficiency or effectiveness of vulnerability detection.

Terms: Information Resource, Machine-Based (Information Resources), Provider, Vulnerability, Vulnerability Detection

Affects: Providers

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

VDR-TFR-KEV SHOULD — Remediate KEVs

Providers SHOULD remediate Known Exploited Vulnerabilities according to the due dates in the CISA Known Exploited Vulnerabilities Catalog (even if the vulnerability has been fully mitigated) as required by CISA Binding Operational Directive (BOD) 26-04 or any successor guidance from CISA.

Terms: Known Exploited Vulnerability (KEV), Provider, Vulnerability

Affects: Providers

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

VDR-TFR-NMV MUST — Non-Machine Verification and Validation

Providers MUST verify and validate the status of non-machine-based information resources at least once every 3 months.

Terms: Information Resource, Machine-Based (Information Resources), Provider, Validation, Verification

Affects: Providers

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

VDR-TFR-PCD SHOULD — Persistently Complete Detection

Varies by certification class:

  • Class A SHOULD: Providers with Class A Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every 6 months.
  • Class B SHOULD: Providers with Class B Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every 6 months.
  • Class C SHOULD: Providers with Class C Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every month.
  • Class D SHOULD: Providers with Class D Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every month.

Terms: Drift, Information Resource, Likely, Persistently, Provider, Vulnerability, Vulnerability Detection

Affects: Providers

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

VDR-TFR-PDD SHOULD — Persistent Drift Detection

Varies by certification class:

  • Class A SHOULD: Providers with Class A Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 3 months.
  • Class B SHOULD: Providers with Class B Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every month.
  • Class C SHOULD: Providers with Class C Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 14 days.
  • Class D SHOULD: Providers with Class D Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 7 days.

Terms: Drift, Information Resource, Likely, Persistently, Provider, Vulnerability, Vulnerability Detection

Affects: Providers

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

VDR-TFR-PSD SHOULD — Persistent Sample Detection

Varies by certification class:

  • Class A SHOULD: Providers with Class A Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 14 days.
  • Class B SHOULD: Providers with Class B Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 7 days.
  • Class C SHOULD: Providers with Class C Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 3 days.
  • Class D SHOULD: Providers with Class D Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once per day.

Terms: Information Resource, Machine-Based (Information Resources), Persistently, Provider, Vulnerability, Vulnerability Detection

Affects: Providers

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

VDR-TFR-PVR SHOULD — Mitigation and Remediation Expectations

Varies by certification class:

  • Class A SHOULD: Providers with Class A Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower potential agency impact within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability.
  • Class B SHOULD: Providers with Class B Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower potential agency impact within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:
  • Class C SHOULD: Providers with Class C Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower Potential Agency Impact N-rating within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:
  • Class D SHOULD: Providers with Class D Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower Potential Agency Impact N-rating within the maximum timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:

Terms: Agency, Fully Mitigated Vulnerability, Likely, Partially Mitigated Vulnerability, Potential Agency Impact, Provider, Remediated Vulnerability, Vulnerability

Affects: Providers

Recent update: 2026-07-01 — Added relevent terms and related controls. No change to the requirement.

VDR-TFR-RMN SHOULD — Remaining Vulnerabilities

Providers SHOULD mitigate or remediate remaining vulnerabilities during routine operations as determined necessary by the provider.

Terms: Provider, Vulnerability

Affects: Providers

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

20X

VDR-TFR-MVX VARIES BY CLASS — Persistent Machine Verification and Validation for 20x

Varies by certification class:

  • Class A SHOULD: Providers of FedRAMP 20x Class A offerings SHOULD verify and validate the status of machine-based information resources at least once every month.
  • Class B MUST: Providers of FedRAMP 20x Class B offerings MUST verify and validate the status of machine-based information resources at least once every 7 days.
  • Class C MUST: Providers of FedRAMP 20x Class C offerings MUST verify and validate the status of machine-based information resources at least once every 3 days.

Terms: Information Resource, Machine-Based (Information Resources), Provider, Validation, Verification

Affects: Providers

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

REV5

VDR-TFR-MVF VARIES BY CLASS — Persistent Machine Verification and Validation for Rev5

Varies by certification class:

  • Class B SHOULD: Providers of FedRAMP Rev5 Class B offerings SHOULD verify and validate the status of machine-based information resources at least once every month.
  • Class C MUST: Providers of FedRAMP Rev5 Class C offerings MUST verify and validate the status of machine-based information resources at least once every month.
  • Class D MUST: Providers of FedRAMP Rev5 Class D offerings MUST verify and validate the status of machine-based information resources at least once every month.

Terms: Information Resource, Machine-Based (Information Resources), Provider, Validation, Verification

Affects: Providers

Structured timeframe: 1 months

Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.

URL copied to clipboard