Vulnerability Detection and Response — FedRAMP Process
Generated from the official FedRAMP/rules GitHub repo. Source path:
fedramp-consolidated-rules.jsononmainat blob7d628b63fdd9. Consolidated Rules version:2026.07.02.02· upstreamlast_updated:2026-07-02. Supporting narrative documentation is available from the officialFedRAMP/2026-markdownrepository.
Vulnerability Detection and Response
Short name: VDR · Process ID: VDR · Web slug: vulnerability-detection-and-response
Applies to: both, 20x, rev5
Status: stable
Official page: https://www.fedramp.gov/2026/reference/vulnerability-detection-and-response/
Effective Status
- 20x: required · Mandated by CISA BOD 26-04 · obtain 2026-12-07 · grace through 2027-03-07
- Rev5: required · Mandated by CISA BOD 26-04 · obtain 2026-12-07 · grace through 2027-03-07
- Shared requirements: 16
Purpose
The Vulnerability Detection and Response rules require providers to continuously identify, analyze, prioritize, mitigate, and remediate vulnerabilities and related exposures through automated systems. These rules give providers flexibility in implementation while ensuring agencies receive the information needed to support ongoing authorization decisions.
Rule Subsets
CSO— General Provider Responsibilities: These rules apply to all providers with FedRAMP Certifications of any type. · types: 20x, Rev5 · classes: B, C, DTFR— Timeframes: These rules apply to timeframes for vulnerability detection and response. · types: 20x, Rev5 · classes: B, C, D
Requirements and Recommendations
BOTH
VDR-CSO-ADT SHOULD — Automate Detection
Providers SHOULD use automated services to improve and streamline vulnerability detection and response.
Terms: Provider, Vulnerability, Vulnerability Detection, Vulnerability Response
Affects: Providers
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
VDR-CSO-AKE SHOULD NOT — Avoid KEVs
Providers SHOULD NOT deploy or otherwise activate new machine-based information resources with Known Exploited Vulnerabilities.
Terms: Information Resource, Known Exploited Vulnerability (KEV), Machine-Based (Information Resources), Provider, Vulnerability
Affects: Providers
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
VDR-CSO-DAC SHOULD — Detect After Changes
Providers SHOULD automatically perform vulnerability detection on representative samples of new or significantly changed information resources.
Terms: Information Resource, Provider, Vulnerability, Vulnerability Detection
Affects: Providers
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
VDR-CSO-DET MUST — Vulnerability Detection
Providers MUST systematically, persistently, and promptly discover and identify vulnerabilities within their cloud service offering using appropriate techniques such as assessment, scanning, threat intelligence, vulnerability disclosure mechanisms, bug bounties, penetration testing, incident response, automated control testing, supply chain monitoring, and other relevant capabilities; this process is called vulnerability detection. Vulnerability detection includes persistently verifying and validating that information resources and processes are operating as intended and documented for FedRAMP Practices.
Terms: Cloud Service Offering, FedRAMP Practices, Incident, Information Resource, Persistently, Promptly, Provider, Vulnerability, Vulnerability Detection, Vulnerability Response
Affects: Providers
Note: FedRAMP’s vulnerability detection (and response) rules are intended to set modern expectations for maintaining the security of a cloud service. Historical FedRAMP guidance on vulnerability scanning or continuous monitoring generally focused only on CVE-type vulnerabilities while leaving other types of vulnerabilities and exposures unaddressed. Providers are encouraged to leverage their existing holistic security review, architecture review, and similar processes to meet these requirements. FedRAMP strongly discourages providers from implementing separate vulnerability detection and response processes for FedRAMP reporting that are operated by independent compliance branches unless these processes are consuming data directly from the areas of the cloud service that actively maintain it.
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
VDR-CSO-DFR SHOULD — Design For Resilience
Providers SHOULD make design and architecture decisions for their cloud service offering that mitigate the risk of vulnerabilities by default AND decrease the risk and complexity of vulnerability detection and response.
Terms: Cloud Service Offering, Provider, Vulnerability, Vulnerability Detection, Vulnerability Response
Affects: Providers
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
VDR-CSO-FAV MUST — Failures Are Vulnerabilities
Providers MUST treat problems or failures with their vulnerability detection and response processes as vulnerabilities.
Terms: Provider, Vulnerability, Vulnerability Detection, Vulnerability Response
Affects: Providers
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
VDR-CSO-MSP SHOULD NOT — Maintain Security
Providers SHOULD NOT weaken the security of information resources to facilitate vulnerability scanning, detection, or assessment activities.
Terms: Information Resource, Provider, Vulnerability, Vulnerability Detection
Affects: Providers
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
VDR-CSO-RES MUST — Vulnerability Response
Providers MUST systematically, persistently, and promptly track, evaluate, monitor, mitigate, remediate, assess exploitation of, report, and otherwise manage all detected vulnerabilities within their cloud service offering; this process is called vulnerability response.
Terms: Cloud Service Offering, Fully Mitigated Vulnerability, Partially Mitigated Vulnerability, Persistently, Promptly, Provider, Remediated Vulnerability, Vulnerability, Vulnerability Detection, Vulnerability Response
Affects: Providers
Note: If it is not possible to fully mitigate vulnerabilities or remediate vulnerabilities, providers SHOULD instead partially mitigate vulnerabilities promptly, progressively, and persistently. FedRAMP does not use the terms “mitigation” and “remediation” interchangeably. Mitigation is the process of reducing the risk and impact of a vulnerability through partial mitigation and even full mitigation; remediation is the process of entirely eliminating the vulnerability. A fully mitigated vulnerability will still exist (with negligible risk) until it has been remediated. This separation is based on the plain language definitions of these words. Please refer to FedRAMP Definitions for strict interpretation in the FedRAMP context.
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
VDR-CSO-SIR MAY — Sampling
Providers MAY sample effectively identical information resources, especially machine-based information resources, when performing vulnerability detection UNLESS doing so would decrease the efficiency or effectiveness of vulnerability detection.
Terms: Information Resource, Machine-Based (Information Resources), Provider, Vulnerability, Vulnerability Detection
Affects: Providers
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
VDR-TFR-KEV SHOULD — Remediate KEVs
Providers SHOULD remediate Known Exploited Vulnerabilities according to the due dates in the CISA Known Exploited Vulnerabilities Catalog (even if the vulnerability has been fully mitigated) as required by CISA Binding Operational Directive (BOD) 26-04 or any successor guidance from CISA.
Terms: Known Exploited Vulnerability (KEV), Provider, Vulnerability
Affects: Providers
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
VDR-TFR-NMV MUST — Non-Machine Verification and Validation
Providers MUST verify and validate the status of non-machine-based information resources at least once every 3 months.
Terms: Information Resource, Machine-Based (Information Resources), Provider, Validation, Verification
Affects: Providers
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
VDR-TFR-PCD SHOULD — Persistently Complete Detection
Varies by certification class:
- Class A SHOULD: Providers with Class A Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every 6 months.
- Class B SHOULD: Providers with Class B Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every 6 months.
- Class C SHOULD: Providers with Class C Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every month.
- Class D SHOULD: Providers with Class D Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every month.
Terms: Drift, Information Resource, Likely, Persistently, Provider, Vulnerability, Vulnerability Detection
Affects: Providers
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
VDR-TFR-PDD SHOULD — Persistent Drift Detection
Varies by certification class:
- Class A SHOULD: Providers with Class A Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 3 months.
- Class B SHOULD: Providers with Class B Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every month.
- Class C SHOULD: Providers with Class C Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 14 days.
- Class D SHOULD: Providers with Class D Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 7 days.
Terms: Drift, Information Resource, Likely, Persistently, Provider, Vulnerability, Vulnerability Detection
Affects: Providers
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
VDR-TFR-PSD SHOULD — Persistent Sample Detection
Varies by certification class:
- Class A SHOULD: Providers with Class A Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 14 days.
- Class B SHOULD: Providers with Class B Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 7 days.
- Class C SHOULD: Providers with Class C Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 3 days.
- Class D SHOULD: Providers with Class D Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once per day.
Terms: Information Resource, Machine-Based (Information Resources), Persistently, Provider, Vulnerability, Vulnerability Detection
Affects: Providers
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
VDR-TFR-PVR SHOULD — Mitigation and Remediation Expectations
Varies by certification class:
- Class A SHOULD: Providers with Class A Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower potential agency impact within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability.
- Class B SHOULD: Providers with Class B Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower potential agency impact within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:
- Class C SHOULD: Providers with Class C Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower Potential Agency Impact N-rating within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:
- Class D SHOULD: Providers with Class D Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower Potential Agency Impact N-rating within the maximum timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating as defined in VER-EVA-EPA (Estimate Potential Agency Impact), internet reachability, and likely exploitability:
Terms: Agency, Fully Mitigated Vulnerability, Likely, Partially Mitigated Vulnerability, Potential Agency Impact, Provider, Remediated Vulnerability, Vulnerability
Affects: Providers
Recent update: 2026-07-01 — Added relevent terms and related controls. No change to the requirement.
VDR-TFR-RMN SHOULD — Remaining Vulnerabilities
Providers SHOULD mitigate or remediate remaining vulnerabilities during routine operations as determined necessary by the provider.
Terms: Provider, Vulnerability
Affects: Providers
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
20X
VDR-TFR-MVX VARIES BY CLASS — Persistent Machine Verification and Validation for 20x
Varies by certification class:
- Class A SHOULD: Providers of FedRAMP 20x Class A offerings SHOULD verify and validate the status of machine-based information resources at least once every month.
- Class B MUST: Providers of FedRAMP 20x Class B offerings MUST verify and validate the status of machine-based information resources at least once every 7 days.
- Class C MUST: Providers of FedRAMP 20x Class C offerings MUST verify and validate the status of machine-based information resources at least once every 3 days.
Terms: Information Resource, Machine-Based (Information Resources), Provider, Validation, Verification
Affects: Providers
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.
REV5
VDR-TFR-MVF VARIES BY CLASS — Persistent Machine Verification and Validation for Rev5
Varies by certification class:
- Class B SHOULD: Providers of FedRAMP Rev5 Class B offerings SHOULD verify and validate the status of machine-based information resources at least once every month.
- Class C MUST: Providers of FedRAMP Rev5 Class C offerings MUST verify and validate the status of machine-based information resources at least once every month.
- Class D MUST: Providers of FedRAMP Rev5 Class D offerings MUST verify and validate the status of machine-based information resources at least once every month.
Terms: Information Resource, Machine-Based (Information Resources), Provider, Validation, Verification
Affects: Providers
Structured timeframe: 1 months
Recent update: 2026-06-24 — Official launch of the FedRAMP Consolidated Rules for 2026.