Skip to content
Quzara LLCDec 31, 19706 min read

FedRAMP VDR and VER Requirements 2026: What CSPs Must Do Before December 7

FedRAMP VDR and VER at a glance: The FedRAMP Consolidated Rules 2026 introduce two mandatory rulesets under Public Notice NTC-0014: Vulnerability Detection and Response (VDR) and Vulnerability Evaluation and Reporting (VER). Both apply to every FedRAMP offering, Rev5 and 20x alike, and must be in operation by December 7, 2026. Noncompliant certifications face revocation after the grace period ends March 7, 2027.

Key requirements: Daily detection cadences · PAIN/LEV/IRV evaluations inside defined windows · 12-hour remediation clock for the worst class of finding · Machine-readable VDT and AVI reporting · Detection failures treated as governed findings

See how Quzara operates VDR & VER from inside a Class D (High) boundary →

What are FedRAMP VDR and VER?

VDR (Vulnerability Detection and Response) and VER (Vulnerability Evaluation and Reporting) are two distinct but related rulesets within the FedRAMP Consolidated Rules for 2026. Together they define how cloud service providers must find, evaluate, remediate, govern, and report vulnerabilities across their entire FedRAMP authorization boundary.

They replace the older continuous monitoring approach of periodic scanning and POA&M tracking. Under the Consolidated Rules, the provider POA&M is retired as a FedRAMP artifact. In its place, VDR and VER create a continuous operating program with defined detection cadences, evaluation SLAs, machine-readable reporting schemas, and explicit treatment of process failures as findings.

VDR covers: How you detect vulnerabilities, how frequently, across which resource types, what counts as a detection failure, and how fast you must respond.

VER covers: How you evaluate each detection, what contextual ratings apply, how you govern exceptions and accepted vulnerabilities, and what machine-readable outputs you must produce.

Why are VDR and VER mandatory in 2026?

CISA issued Binding Operational Directive 26-04 on June 10, 2026. FedRAMP responded with Public Notice NTC-0014 on June 16, folding the directive into the Consolidated Rules and pulling mandatory VDR/VER adoption forward to December 7, 2026.

Under NTC-0014, the rules apply to obtaining and maintaining FedRAMP certification. A CSP that held authorization before December 7 is not exempt. The grace period ends March 7, 2027, after which non-compliant certifications begin the revocation process.

A program started in late November will not have enough operating history to demonstrate compliance. December 7 is the date the program must be demonstrably running, not the date to start building it.

VDR requirements: detection, coverage, and response

Detection cadences at Class D

Resource typeDetection intervalRuleLevel
Machine-based resources (representative samples)At least dailyVDR-TFR-PSDSHOULD
Resources likely to driftAt least every 7 daysVDR-TFR-PDDSHOULD
Resources not likely to driftAt least monthlyVDR-TFR-PCDSHOULD
Verify and validate machine-based resourcesAt least monthlyVDR-TFR-MVFMUST
Verify and validate non-machine resourcesAt least every 3 monthsVDR-TFR-NMVMUST

Coverage completeness

Detection must cover every resource inside your authorization boundary. Under VDR-CSO-FAV, an asset present in inventory but absent from scan results is a governed finding. A clean scanner report from an incomplete scan is not evidence of a healthy program.

Detection failures as vulnerabilities

VDR-CSO-FAV explicitly requires providers to treat failures in their own vulnerability detection and response processes as vulnerabilities. Scanner downtime, partial scan results, or missed newly launched assets each become findings with named owners, clocks, and resolution paths.

Known Exploited Vulnerabilities

VDR-TFR-KEV requires that vulnerabilities in the CISA KEV catalog be remediated per CISA's published due dates, in addition to the PAIN-based clocks.

VER requirements: evaluation, reporting, and PAIN ratings

The PAIN rating

Every vulnerability must receive a Potential Agency Impact N-rating (PAIN): a provider-constructed estimate of what exploitation would do to the agencies using the offering, from N1 (minimal customer effect) to N5 (debilitating effect on more than one agency). Under VER-EVA-AIA, exploitation must be assumed automatable unless the provider holds evidence proving otherwise.

Evaluation SLAs

VER-TFR-EVU requires all detected vulnerabilities to be evaluated within 2 days of detection at Class D. The evaluation must be recorded with PAIN reason codes, LEV and IRV determinations, and analyst attribution.

Machine-readable reporting outputs

  • Vulnerability Detail Report (VDT): Per-finding with eleven required elements including the full PAIN reduction history.
  • Accepted Vulnerability Info (AVI): Per-accepted-vulnerability with eight required elements including named owner and explanation.
  • Historical activity (VER-TFR-MRH): Machine-readable, refreshed at least every 7 days, retrievable by automation against the published JSON schema.

Class D remediation clocks

Maximum times from evaluation to full mitigation or remediation under VDR-TFR-PVR. The clock starts at evaluation, not detection.

PAIN ratingLikely exploitable & internet reachableLikely exploitable, not internet reachableNot likely exploitable
N512 hours1 day8 days
N42 days8 days32 days
N38 days16 days64 days
N224 days96 days192 days

Five failure modes assessors look for

  1. Coverage gaps: Assets in the boundary absent from scan results.
  2. Collector failures: Scanner downtime, partial results, or missed new assets, each a governed finding under VDR-CSO-FAV.
  3. Evaluation SLA breach: Findings not evaluated within 2 days, or evaluated without documentation and analyst attribution.
  4. Ungoverned exceptions: Accepted vulnerabilities without a named owner, documented rationale, and AVI-compliant evidence.
  5. Reporting failures: VDT or AVI outputs that fail JSON schema validation or whose population denominator cannot be verified.

The 192-day rule and accepted vulnerabilities

Any vulnerability not fully mitigated or remediated within 192 days of evaluation must be categorized as an accepted vulnerability under VDR-TFR-MAV, requiring AVI disclosure with a named explanation and owner. This replaces the provider POA&M. The clock starts at evaluation. NISTcompliance.ai tracks every finding against the 192-day boundary in real time.

How to prepare before December 7

  • Asset inventory reconciled to scanner population, discrepancies governed as findings
  • Detection failures creating governed findings automatically
  • PAIN/LEV/IRV evaluations recorded within 2 days with reason codes and analyst attribution
  • Remediation clocks tracked per finding from evaluation
  • JSON-schema-valid VDT and AVI outputs validated before release
  • Monthly human activity report delivered and signed off
  • Accepted vulnerabilities formally governed with AVI-compliant documentation

Quzara operates this program from inside a FedRAMP Class D (High) authorization boundary (FR2214150164), using NISTcompliance.ai for automated PAIN/LEV/IRV evaluation and Cybertorch for 24/7 MDR and incident handoff. Learn more about how Quzara operates VDR and VER →

Frequently asked questions

Do VDR and VER apply to existing Rev5 authorizations?

Yes. NTC-0014 applies to all FedRAMP offerings regardless of authorization path. The December 7 date and March 7, 2027 grace period apply to Rev5 and 20x alike.

Is a vulnerability scanner sufficient for VDR/VER compliance?

No. A scanner provides findings. VDR and VER require a continuous operating program: coverage completeness per asset class, evaluations inside defined windows with documentation, governed exceptions, JSON-schema-valid reporting, incident handoff, and detection failures treated as findings.

What happened to the provider POA&M?

The provider POA&M is retired. Findings not resolved within 192 days of evaluation become accepted vulnerabilities reported through AVI with a named explanation and owner.

What is the difference between PAIN, LEV, and IRV?

PAIN estimates what exploitation would do to agencies (N1 minimal to N5 debilitating). LEV assesses whether exploitation is probable. IRV determines whether the resource is internet-reachable. All three determine the remediation clock.

When does a program need to start to be ready by December 7?

Most programs need 6 to 10 weeks of running time to accumulate a defensible operating record. The practical start date is now.

Ready to build your VDR and VER program? Contact Quzara to speak with a FedRAMP advisor, or review the full VDR and VER resource.

Discover More Topics