FedRAMP makes VDR and VER rules mandatory by December 7, 2026

August 4, 2026

About: FedRAMP

#program-changes

On June 16, 2026, FedRAMP published Public Notice NTC-0014 explaining how it will align continuous monitoring with Cybersecurity and Infrastructure Security Agency (CISA) Binding Operational Directive (BOD) 26-04. The notice pulls forward mandatory adoption of FedRAMP’s Vulnerability Detection and Response (VDR) and Vulnerability Evaluation and Reporting (VER) rules to December 7, 2026, for every cloud service obtaining or maintaining FedRAMP Certification.

This is separate from the FedRAMP 20x Class A pipeline opening covered earlier on this site. It changes how all FedRAMP-certified offerings must detect, prioritize, and report vulnerabilities, including providers still on Rev5 paths.

What changed

BOD 26-04 tells federal civilian agencies to prioritize vulnerability work by public exposure, Known Exploited Vulnerability (KEV) status, whether an exploit is automatable, and technical impact. FedRAMP says cloud providers that follow VDR and VER meet or exceed that approach.

Under NTC-0014:

  • Legacy monthly vulnerability scanning for Rev5 offerings is not enough for BOD 26-04 assurance
  • VDR and VER become mandatory on December 7, 2026
  • Providers that miss the date may stay certified under a corrective action plan only through March 7, 2027
  • After March 7, 2027, FedRAMP says certification will be revoked for offerings that still do not follow these rules

FedRAMP also notes that the Consolidated Rules for 2026 incorporate this accelerated timeline. The earlier plan had targeted a later mandatory date; BOD 26-04 compressed it.

The current FedRAMP authorization status of a cloud service does not freeze the old scanning model in place. Continuous monitoring expectations are changing for the whole marketplace.

What to do now

  1. If you sell or buy FedRAMP-authorized cloud, confirm whether your offering (or vendor) already operates under VDR/VER or still relies on legacy monthly scanning.
  2. Map remediation workflows to KEV timelines, internet-reachability checks, and exploitability evaluation, not CVSS-only queues.
  3. Treat December 7, 2026 as a hard planning date and March 7, 2027 as the end of any corrective-action grace period.
  4. Read NTC-0014 alongside the Consolidated Rules for 2026.
  5. See the FedRAMP page for how Ongoing Certification works, and follow FedRAMP on this site for further rule updates.

#program-changes

← Back to news