FedRAMP VDR and VER
On December 7, 2026, the FedRAMP Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules become mandatory for every cloud service offering obtaining or maintaining FedRAMP Certification. Quzara runs that program from inside an authorized boundary: continuous detection, PAIN evaluation, governed exceptions, and machine readable reporting.
The rules, not the rumors
CISA issued Binding Operational Directive 26-04 on June 10, 2026. FedRAMP responded with Public Notice NTC-0014 on June 16, folding the directive into the Consolidated Rules for 2026 through two rulesets and pulling mandatory adoption forward from 2027.
VDR and VER apply to every FedRAMP offering, Rev5 and 20x alike. Optional adoption opened July 4, 2026. Both rulesets bind on December 7, 2026. Certifications not following the rules after the grace period ends on March 7, 2027 face revocation.
Providers must treat problems or failures in their own vulnerability detection and response processes as vulnerabilities. A collector that dies, a scan that returns a partial population, an asset launched outside the window: each becomes a governed finding carrying its own evaluation and response obligations.
Providers must assume exploitation can be automated unless they hold evidence proving otherwise. The burden of proof sits with the provider, which makes the evidence trail behind every evaluation the artifact that matters.
PAIN is not a severity score inherited from a scanner. It is an estimate, made in the context of your offering, of what exploitation would do to the agencies using it, assigned N1 through N5 from minimal customer effect up to a debilitating effect on more than one agency.
Any vulnerability not fully mitigated or remediated within 192 days of evaluation must be categorized as an accepted vulnerability and reported with a named explanation. Under the Consolidated Rules the provider POA&M is gone as a FedRAMP artifact; accepted vulnerabilities carry that weight instead, and agencies maintain their own plans from what you report.
The Vulnerability Detail Report carries eleven required elements per finding, including the full history of PAIN reductions and the estimated time and target of the next one. Accepted Vulnerability Info carries eight. Both have published JSON schemas. Historical activity should be retrievable by automation, refreshed at least every 7 days at Class D.
Remediation timeframes
Remediation time is a function of three things: the Potential Agency Impact N-rating, whether the vulnerability is likely exploitable, and whether it is internet reachable. This is the Class D table as published. Read the cells as maximum time from evaluation, not from detection.
| PAIN rating | Likely exploitable and internet reachable | Likely exploitable, not internet reachable | Not likely exploitable |
|---|---|---|---|
| N5 | 12 hours | 1 day | 8 days |
| N4 | 2 days | 8 days | 32 days |
| N3 | 8 days | 16 days | 64 days |
| N2 | 24 days | 96 days | 192 days |
| Obligation | Interval | Rule | Level |
|---|---|---|---|
| Detection on representative samples of machine based resources | At least daily | VDR-TFR-PSD | SHOULD |
| Detection on resources likely to drift | At least every 7 days | VDR-TFR-PDD | SHOULD |
| Detection on resources not likely to drift | At least monthly | VDR-TFR-PCD | SHOULD |
| Verify and validate machine based resources | At least monthly | VDR-TFR-MVF | MUST |
| Verify and validate non machine based resources | At least every 3 months | VDR-TFR-NMV | MUST |
| Evaluate all detected vulnerabilities | Within 2 days of detection | VER-TFR-EVU | SHOULD |
| Remediate Known Exploited Vulnerabilities | Per CISA KEV catalog due dates | VDR-TFR-KEV | SHOULD |
| Human readable activity report to all necessary parties | At least monthly | VER-TFR-MHR | MUST |
| Historical activity available as JSON for automated retrieval | At least every 7 days | VER-TFR-MRH | SHOULD |
One consequence worth planning for: an internet reachable, likely exploitable vulnerability rated above N3 should be treated as a FedRAMP Reportable Incident until it is partially mitigated to N3 or below (VER-TFR-IRI). Vulnerability management and incident response stop being separate programs on December 7.
How Quzara operates it
The rules ask for continuous detection, defensible evaluation, governed exceptions, incident handoff, and validated reporting. No single tool covers that span.
NISTCompliance.AI
AI native compliance automation that reconciles scanner population against asset inventory, records PAIN, exploitability, and reachability evaluations against their clocks, and generates the Vulnerability Detail Report and Accepted Vulnerability Info outputs against the published schemas.
Quzara Cybertorch, FR2214150164
A FedRAMP Certified Class D (High) SOC as a Service on Azure Government, staffed 24/7 by U.S. citizen analysts. When a finding crosses the reportable incident threshold, the handoff into incident response is a governed step inside the same boundary.
Quzara advisory
Advisors who hold the program accountable between assessments: resolving which class rules apply to your offering, authoring the policy, governing exceptions, and preparing the evidence an independent assessor will ask for.
Readiness self-check
VDR and VER do not ask whether you found vulnerabilities. They ask whether you can show a program that has been running.
FedRAMP VDR and VER, answered
Two rulesets in the FedRAMP Consolidated Rules for 2026. Vulnerability Detection and Response covers detection cadence, verification and validation, and mitigation and remediation timeframes. Vulnerability Evaluation and Reporting covers contextual evaluation, the PAIN ratings, accepted vulnerabilities, and reporting. Public Notice NTC-0014 made both mandatory for all FedRAMP certified offerings by December 7, 2026.
Both. The rules are published per class across both paths, and the December 7 date applies regardless of which path your offering sits on. For existing Rev5 providers the broader Consolidated Rules become mandatory January 1, 2027, but VDR and VER land three weeks earlier and carry the revocation clock.
Potential Agency Impact N-rating. Providers must estimate, in the context of their own offering, what exploitation would do to the agencies using it, then assign N1 through N5. N1 is a minimal customer effect. N3 is a disruptive effect on one agency. N5 is a debilitating effect on more than one. It is deliberately not a CVSS score, and it drives the remediation clock together with exploitability and internet reachability.
No. A scanner produces findings. The rules require population completeness you can prove, evaluation inside a window with the reasoning recorded, governed exceptions with named owners, schema valid machine readable reporting, incident handoff at the reportable threshold, and treatment of your own detection failures as findings. The scanner is one input to that program.
The provider POA&M is retired as a FedRAMP artifact under the Consolidated Rules. Anything not fully mitigated or remediated within 192 days of evaluation becomes an accepted vulnerability, reported with an explanation through Accepted Vulnerability Info. Agencies still maintain their own plans of action and milestones, built from what you report to them.
Yes. Quzara Cybertorch (FR2214150164) operates on Azure Government inside a FedRAMP Certified Class D (High) boundary with U.S. citizen analyst staffing, and NISTCompliance.AI operates inside that same boundary. Integration works against your existing scanners and data sources rather than requiring your vulnerability data to move to a commercial SaaS platform.
The integration work is the short part. The long part is operating history: continuous coverage records, evaluation records inside their windows, obligation tracking, and governed exceptions accumulate only by running. Since December 7 tests whether a program is running rather than whether one exists on paper, the useful question is how many reporting cycles you will have completed by then. We will scope that against your boundary and your current cadence.
December 7 is approaching
December 7, 2026 is the adoption date. March 7, 2027 is when non compliant certifications begin to be revoked. The practical deadline sits earlier than both, because what gets assessed is the record your program produced in the months before.