FedRAMP VDR and VER at a glance: The FedRAMP Consolidated Rules 2026 introduce two mandatory rulesets under Public Notice NTC-0014: Vulnerability Detection and Response (VDR) and Vulnerability Evaluation and Reporting (VER). Both apply to every FedRAMP offering, Rev5 and 20x alike, and must be in operation by December 7, 2026. Noncompliant certifications face revocation after the grace period ends March 7, 2027.
Key requirements: Daily detection cadences · PAIN/LEV/IRV evaluations inside defined windows · 12-hour remediation clock for the worst class of finding · Machine-readable VDT and AVI reporting · Detection failures treated as governed findings
See how Quzara operates VDR & VER from inside a Class D (High) boundary →
VDR (Vulnerability Detection and Response) and VER (Vulnerability Evaluation and Reporting) are two distinct but related rulesets within the FedRAMP Consolidated Rules for 2026. Together they define how cloud service providers must find, evaluate, remediate, govern, and report vulnerabilities across their entire FedRAMP authorization boundary.
They replace the older continuous monitoring approach of periodic scanning and POA&M tracking. Under the Consolidated Rules, the provider POA&M is retired as a FedRAMP artifact. In its place, VDR and VER create a continuous operating program with defined detection cadences, evaluation SLAs, machine-readable reporting schemas, and explicit treatment of process failures as findings.
VDR covers: How you detect vulnerabilities, how frequently, across which resource types, what counts as a detection failure, and how fast you must respond.
VER covers: How you evaluate each detection, what contextual ratings apply, how you govern exceptions and accepted vulnerabilities, and what machine-readable outputs you must produce.
CISA issued Binding Operational Directive 26-04 on June 10, 2026. FedRAMP responded with Public Notice NTC-0014 on June 16, folding the directive into the Consolidated Rules and pulling mandatory VDR/VER adoption forward to December 7, 2026.
Under NTC-0014, the rules apply to obtaining and maintaining FedRAMP certification. A CSP that held authorization before December 7 is not exempt. The grace period ends March 7, 2027, after which non-compliant certifications begin the revocation process.
A program started in late November will not have enough operating history to demonstrate compliance. December 7 is the date the program must be demonstrably running, not the date to start building it.
| Resource type | Detection interval | Rule | Level |
|---|---|---|---|
| Machine-based resources (representative samples) | At least daily | VDR-TFR-PSD | SHOULD |
| Resources likely to drift | At least every 7 days | VDR-TFR-PDD | SHOULD |
| Resources not likely to drift | At least monthly | VDR-TFR-PCD | SHOULD |
| Verify and validate machine-based resources | At least monthly | VDR-TFR-MVF | MUST |
| Verify and validate non-machine resources | At least every 3 months | VDR-TFR-NMV | MUST |
Detection must cover every resource inside your authorization boundary. Under VDR-CSO-FAV, an asset present in inventory but absent from scan results is a governed finding. A clean scanner report from an incomplete scan is not evidence of a healthy program.
VDR-CSO-FAV explicitly requires providers to treat failures in their own vulnerability detection and response processes as vulnerabilities. Scanner downtime, partial scan results, or missed newly launched assets each become findings with named owners, clocks, and resolution paths.
VDR-TFR-KEV requires that vulnerabilities in the CISA KEV catalog be remediated per CISA's published due dates, in addition to the PAIN-based clocks.
Every vulnerability must receive a Potential Agency Impact N-rating (PAIN): a provider-constructed estimate of what exploitation would do to the agencies using the offering, from N1 (minimal customer effect) to N5 (debilitating effect on more than one agency). Under VER-EVA-AIA, exploitation must be assumed automatable unless the provider holds evidence proving otherwise.
VER-TFR-EVU requires all detected vulnerabilities to be evaluated within 2 days of detection at Class D. The evaluation must be recorded with PAIN reason codes, LEV and IRV determinations, and analyst attribution.
Maximum times from evaluation to full mitigation or remediation under VDR-TFR-PVR. The clock starts at evaluation, not detection.
| PAIN rating | Likely exploitable & internet reachable | Likely exploitable, not internet reachable | Not likely exploitable |
|---|---|---|---|
| N5 | 12 hours | 1 day | 8 days |
| N4 | 2 days | 8 days | 32 days |
| N3 | 8 days | 16 days | 64 days |
| N2 | 24 days | 96 days | 192 days |
Any vulnerability not fully mitigated or remediated within 192 days of evaluation must be categorized as an accepted vulnerability under VDR-TFR-MAV, requiring AVI disclosure with a named explanation and owner. This replaces the provider POA&M. The clock starts at evaluation. NISTcompliance.ai tracks every finding against the 192-day boundary in real time.
Quzara operates this program from inside a FedRAMP Class D (High) authorization boundary (FR2214150164), using NISTcompliance.ai for automated PAIN/LEV/IRV evaluation and Cybertorch for 24/7 MDR and incident handoff. Learn more about how Quzara operates VDR and VER →
Yes. NTC-0014 applies to all FedRAMP offerings regardless of authorization path. The December 7 date and March 7, 2027 grace period apply to Rev5 and 20x alike.
No. A scanner provides findings. VDR and VER require a continuous operating program: coverage completeness per asset class, evaluations inside defined windows with documentation, governed exceptions, JSON-schema-valid reporting, incident handoff, and detection failures treated as findings.
The provider POA&M is retired. Findings not resolved within 192 days of evaluation become accepted vulnerabilities reported through AVI with a named explanation and owner.
PAIN estimates what exploitation would do to agencies (N1 minimal to N5 debilitating). LEV assesses whether exploitation is probable. IRV determines whether the resource is internet-reachable. All three determine the remediation clock.
Most programs need 6 to 10 weeks of running time to accumulate a defensible operating record. The practical start date is now.
Ready to build your VDR and VER program? Contact Quzara to speak with a FedRAMP advisor, or review the full VDR and VER resource.