Cybertorch, a division of Quzara LLC
Mandatory December 7, 2026 FedRAMP Public Notice NTC-0014. Grace period ends March 7, 2027.

FedRAMP VDR and VER

VDR and VER are an operating program, not a scanner.

On December 7, 2026, the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules become mandatory for every cloud service offering obtaining or maintaining FedRAMP Certification. Quzara runs that program from inside an authorized boundary: continuous detection, PAIN evaluation, governed exceptions, and machine readable reporting.

Quzara Cybertorch is FedRAMP Certified Class D (High), Marketplace ID FR2214150164, operating on Azure Government and authorized for DoD IL-4, staffed by U.S. citizen analysts. NISTCompliance.AI operates inside that same authorization boundary.

The rules, not the rumors

What actually changes on December 7

CISA issued Binding Operational Directive 26-04 on June 10, 2026. FedRAMP responded with Public Notice NTC-0014 on June 16, folding the directive into the Consolidated Rules for 2026 through two rulesets and pulling mandatory adoption forward from 2027.

Remediation timeframes

The Class D clocks

Remediation time is a function of three things: the Potential Agency Impact N-rating, whether the vulnerability is likely exploitable, and whether it is internet reachable. This is the Class D table as published. Read the cells as maximum time from evaluation, not from detection.

Mitigation and remediation expectations for Class D certifications, per VDR-TFR-PVR. FedRAMP states these as SHOULD, so a deviation is defensible only with recorded rationale and evidence.
PAIN rating Likely exploitable and internet reachable Likely exploitable, not internet reachable Not likely exploitable
N512 hours1 day8 days
N42 days8 days32 days
N38 days16 days64 days
N224 days96 days192 days
Detection, evaluation, and reporting cadences at Class D.
ObligationIntervalRuleLevel
Detection on representative samples of machine based resourcesAt least dailyVDR-TFR-PSDSHOULD
Detection on resources likely to driftAt least every 7 daysVDR-TFR-PDDSHOULD
Detection on resources not likely to driftAt least monthlyVDR-TFR-PCDSHOULD
Verify and validate machine based resourcesAt least monthlyVDR-TFR-MVFMUST
Verify and validate non machine based resourcesAt least every 3 monthsVDR-TFR-NMVMUST
Evaluate all detected vulnerabilitiesWithin 2 days of detectionVER-TFR-EVUSHOULD
Remediate Known Exploited VulnerabilitiesPer CISA KEV catalog due datesVDR-TFR-KEVSHOULD
Human readable activity report to all necessary partiesAt least monthlyVER-TFR-MHRMUST
Historical activity available as JSON for automated retrievalAt least every 7 daysVER-TFR-MRHSHOULD

One consequence worth planning for: an internet reachable, likely exploitable vulnerability rated above N3 should be treated as a FedRAMP Reportable Incident until it is partially mitigated to N3 or below (VER-TFR-IRI). Vulnerability management and incident response stop being separate programs on December 7.

How Quzara operates it

Three layers, one program

The rules ask for continuous detection, defensible evaluation, governed exceptions, incident handoff, and validated reporting. No single tool covers that span.

Automated evaluation and reporting

NISTCompliance.AI

AI native compliance automation that reconciles scanner population against asset inventory, records PAIN, exploitability, and reachability evaluations against their clocks, and generates the Vulnerability Detail Report and Accepted Vulnerability Info outputs against the published schemas.

  • Daily intake from your existing scanners, including Tenable and Microsoft Defender
  • Coverage reconciliation so an incomplete scan surfaces as a finding
  • Class aware evaluation across 20x Class A, B, C and Rev5 Class B, C, D
  • Schema validation before release, not after an agency rejects the file

Detection, response, and incident handoff

Quzara Cybertorch, FR2214150164

A FedRAMP Certified Class D (High) SOC as a Service on Azure Government, staffed 24/7 by U.S. citizen analysts. When a finding crosses the reportable incident threshold, the handoff into incident response is a governed step inside the same boundary.

  • 24/7 managed detection and response, U.S. citizen only staffing
  • KEV monitoring tied to CISA catalog due dates
  • Escalation path for internet reachable findings above N3
  • Native Microsoft Sentinel and Defender XDR integration

Program governance and assessor support

Quzara advisory

Advisors who hold the program accountable between assessments: resolving which class rules apply to your offering, authoring the policy, governing exceptions, and preparing the evidence an independent assessor will ask for.

  • Class resolution across Rev5 and 20x paths
  • Exception governance with named owner, rationale, and evidence
  • Independent verification and validation readiness
  • Monthly activity report review and sign off

Readiness self-check

Six questions an assessor can ask on any given day

VDR and VER do not ask whether you found vulnerabilities. They ask whether you can show a program that has been running.

  1. Does your detection cover every resource inside the boundary?Including resources launched after your last detection window opened.
  2. Can you prove the population was complete, per resource class, on a given date?Not show a report. Prove the denominator was right.
  3. Is every finding evaluated inside its window, with the evaluation recorded?At Class D that window is 2 days from detection.
  4. When a collector fails, what happens?Under VDR-CSO-FAV the failure is itself a finding with its own clock. Does yours open automatically, or does an assessor open it for you?
  5. Can you show each finding's full PAIN history, not just its current rating?The Vulnerability Detail Report asks for every completed reduction and the target of the next one.
  6. Who approved each accepted vulnerability, on what rationale, recorded where?An email thread is not an evidence record.

FedRAMP VDR and VER, answered

Common questions

What are VDR and VER?

Two rulesets in the FedRAMP Consolidated Rules for 2026. Vulnerability Detection and Response covers detection cadence, verification and validation, and mitigation and remediation timeframes. Vulnerability Evaluation and Reporting covers contextual evaluation, the PAIN ratings, accepted vulnerabilities, and reporting. Public Notice NTC-0014 made both mandatory for all FedRAMP certified offerings by December 7, 2026.

Do these apply to Rev5 authorizations, or only to 20x?

Both. The rules are published per class across both paths, and the December 7 date applies regardless of which path your offering sits on. For existing Rev5 providers the broader Consolidated Rules become mandatory January 1, 2027, but VDR and VER land three weeks earlier and carry the revocation clock.

What is PAIN, exactly?

Potential Agency Impact N-rating. Providers must estimate, in the context of their own offering, what exploitation would do to the agencies using it, then assign N1 through N5. N1 is a minimal customer effect. N3 is a disruptive effect on one agency. N5 is a debilitating effect on more than one. It is deliberately not a CVSS score, and it drives the remediation clock together with exploitability and internet reachability.

Is a vulnerability scanner enough?

No. A scanner produces findings. The rules require population completeness you can prove, evaluation inside a window with the reasoning recorded, governed exceptions with named owners, schema valid machine readable reporting, incident handoff at the reportable threshold, and treatment of your own detection failures as findings. The scanner is one input to that program.

What happened to POA&Ms?

The provider POA&M is retired as a FedRAMP artifact under the Consolidated Rules. Anything not fully mitigated or remediated within 192 days of evaluation becomes an accepted vulnerability, reported with an explanation through Accepted Vulnerability Info. Agencies still maintain their own plans of action and milestones, built from what you report to them.

Can our vulnerability data stay inside our authorization boundary?

Yes. Quzara Cybertorch (FR2214150164) operates on Azure Government inside a FedRAMP Certified Class D (High) boundary with U.S. citizen analyst staffing, and NISTCompliance.AI operates inside that same boundary. Integration works against your existing scanners and data sources rather than requiring your vulnerability data to move to a commercial SaaS platform.

How long does it take to stand a program up?

The integration work is the short part. The long part is operating history: continuous coverage records, evaluation records inside their windows, obligation tracking, and governed exceptions accumulate only by running. Since December 7 tests whether a program is running rather than whether one exists on paper, the useful question is how many reporting cycles you will have completed by then. We will scope that against your boundary and your current cadence.

December 7 is approaching

Start accumulating operating history now.

December 7, 2026 is the adoption date. March 7, 2027 is when non compliant certifications begin to be revoked. The practical deadline sits earlier than both, because what gets assessed is the record your program produced in the months before.