LmCast :: Stay tuned in

FedRAMP VDR & VER: Daily Scans Are Only the Beginning

Recorded: Sept. 24, 2026, 2:10 p.m.

Original Summarized

FedRAMP VDR & VER: Daily Scans Are Only the Beginning

News

Featured
Latest

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

New Windows Defender zero-day blocks Microsoft antivirus updates

EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

Check Point warns of Management Server zero-day exploited in attacks

FedRAMP VDR & VER: Daily Scans Are Only the Beginning

Hackers now exploit critical Roundcube flaw in code injection attacks

Windows 11 KB5124010 update released with 46 changes and fixes

Get AI-powered Autodesk AutoCAD for $399, save $1,696

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityFedRAMP VDR & VER: Daily Scans Are Only the Beginning

FedRAMP VDR & VER: Daily Scans Are Only the Beginning

Sponsored by Anecdotes

September 24, 2026
10:02 AM
0

If you hold a FedRAMP certification, the nearest deadline on your calendar is December 7, 2026. FedRAMP's notice responding to CISA's BOD 26-04 puts it plainly: "The Vulnerability Detection and Response rules will be mandatory for all cloud service offerings obtaining or maintaining FedRAMP Certification effective December 7, 2026," with a grace period through March 7, 2027 for offerings operating under a corrective action plan.
It is also the deadline most programs have not fully scoped. The problem is not the date. It is that VDR and VER read like a scanning requirement and operate like something else entirely.
What the two rulesets actually change
Start with what is retired: the flat monthly-scan-and-POA&M model. Detection frequency is now set by certification class — under rule VDR-TFR-PSD, machine-based resources are scanned at least every 14 days at Class A, every 7 at Class B, every 3 at Class C, and at least once per day at Class D.
Machine verification and validation runs at least monthly for Rev5 holders, and as often as every three days at higher 20x classes.
Then the three provisions that reshape engineering work:
Remediation clocks are tiered and tight. Under VDR-TFR-PVR, fix deadlines are set by a vulnerability's PAIN rating and its exploitability, running from 192 days at the low end to 12 hours at the extreme — a Class D offering with a PAIN-5 vulnerability that is both likely exploited and immediately remotely exploitable.
A 12-hour clock is not a ticket-queue SLA. It is a paging and ownership question, and it has to hold on a holiday weekend.
The burden of proof inverted. VER-EVA-AIA — "Assume It's Automatable" — requires providers, in FedRAMP's words, "to assume exploits are automatable by default, unless they have evidence providing otherwise." Every deferral now needs a defensible artifact behind it, produced at volume, on the same clock as everything else.
Process failures count as vulnerabilities. Rule VDR-CSO-FAV states that providers "[MUST] treat problems or failures with their vulnerability detection and response processes as vulnerabilities." If your detection pipeline silently stops, that is not an operational hiccup you fix quietly before anyone notices. The system that produces your evidence is itself in scope.
Read together, those change the deliverable. You are not being asked to scan more often. You are being asked to run a system that produces defensible, current, machine-readable answers about your own exposure — and to be accountable when it stops running.

FedRAMP VDR & VER: The Technical Solution Brief
What the December 7 rulesets require in practice — daily detection, monthly machine validation, tiered remediation clocks, and process failures as findings — plus how continuous coverage validation is computed from live asset data rather than attested.
Get the Brief

December 7 is the first installment, not a one-off
The Consolidated Rules for 2026 reorganized FedRAMP into rulesets and started the clock on a much larger change.
Rev5 is not being maintained alongside 20x: FedRAMP describes it as "a legacy FedRAMP Certification process that is being replaced entirely by FedRAMP 20x," and says providers "are expected to follow new rules and adopt new FedRAMP Practices from FedRAMP 20x into their FedRAMP Rev5 Certified cloud service offerings."
The rules become mandatory for all stakeholders on January 1, 2027, and FedRAMP stops accepting new Rev5 applications on June 11, 2027.
So VDR and VER are not a detour you take before the real transition. They are the transition, arriving in installments — and that reframe is the most useful thing available to a program right now, because it changes sequencing.
Work scoped as "get through December" gets rebuilt in 2027. Work scoped as the first slice of continuous validation transfers.
What got removed tells you where this is going
Look at the structural changes rather than the deadline table. The System Security Plan and its appendices give way to a Certification Package Overview and a Security Decision Record. Plans of Action & Milestones, FedRAMP writes, "have been eliminated entirely and replaced with a list of Accepted Weaknesses."
Continuous Monitoring becomes Ongoing Certification — renamed, FedRAMP explains, because "continuous monitoring" had "become synonymous with 'vulnerability scans'" and the new requirements are "far broader than before."
Every one of those was a place where the artifact stood in for the reality. FedRAMP was unusually direct about closing them, telling providers they will need to build or buy modern GRC capabilities and "populate them using automation based on real-world data where possible, rather than maintaining artisanal hand-crafted documents."
Here is what deadline coverage keeps missing: almost none of this is a demand for new security. Access control, identity, encryption, logging, incident procedures, training — largely intact, largely reusable.
What changed is that describing them no longer counts as evidence of them.
Three judgments that separate the programs that make it
The work is still compliance; the deliverable is now engineering. What you hand over is a set of running validations that pull from the systems holding the truth — cloud configuration, identity provider, SIEM, CI/CD, ticketing — and emit machine-readable results on a schedule.
Providers must persistently validate their Key Security Indicators, of which CR26 currently lists 49 across ten categories. That is an entry requirement, which makes every transition plan an automation engineering plan underneath whatever it says on the cover.
Someone has to own "continuous." Monthly monitoring had a due date, an owner, and a natural rhythm of catching up. A validation cadence has none of those. It runs, or it silently stops, and the difference is invisible until an assessor or a customer finds it.
Before building pipelines, answer the operational questions: who is paged when a validation fails, what the response time is, who notices when an evidence source quietly changes its API.
Design for the cadence, not the submission. FedRAMP defines persistently as "occurring in a firm, steady way that is repeated over a long period of time in spite of obstacles or difficulties" — a description of an operating state, not a date.
Teams that build toward a submission build a system tuned for a single moment and then rebuild it afterward.
The part that outlives FedRAMP
Once evidence is structured data rather than narrative, it stops belonging to a framework. The identity evidence satisfying a FedRAMP indicator is the same evidence a SOC 2 auditor wants and the same evidence a large customer's diligence team asks for.
Compliance stops being parallel projects that each rebuild the same picture in a different vocabulary and becomes one substrate that many consumers read from.
The economics invert along with it. Point-in-time compliance costs rise with every framework and every region you add, because each addition is more description to produce and maintain. Continuous validation costs materially more to stand up and barely more to run.
December 7 is a hard date, and it deserves the attention it is getting. But financial-services supervisors, the EU's resilience and product-security regimes, and enterprise procurement teams are converging on the same demand from different directions: show me current state, not last year's description.
FedRAMP arrived first because it had the clearest mandate and the least patience. A team that builds this once has not solved a federal problem — it has built the capability every one of those demands will keep asking for.
anecdotes holds a FedRAMP 20x Class C certification, earned as a Phase Two pilot participant, using the anecdotes platform to run it. The same platform runs commercial compliance for more than 140 enterprise customers.
Standard basis: FedRAMP Consolidated Rules for 2026 and FedRAMP Notice NTC-0014. Rules and Key Security Indicators change through FedRAMP's public rules process; confirm the live standard at fedramp.gov before baselining your plan.
Learn how Anecdotes helps you operationalize VDR & VER and download the technical solutions brief here.
Sponsored and written by Anecdotes.

Anecdotes
Cybersecurity
FedRAMP
FedRAMP Rev5

Previous Article

Comments have been disabled for this article.

Popular Stories

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

Microsoft reminds admins to migrate Entra ID users to passkeys

New Windows Defender zero-day blocks Microsoft antivirus updates

Sponsor Posts

Automate Onboarding and Access Reviews with No-Code IGA: See how it works

Overdue a password health-check? Audit your Active Directory for free

AI is a data-breach time bomb: Read the new report

Build cyber resilience with Wazuh: The open-source SIEM & XDR for proactive protection

Daily detection, monthly validation, 12-hour clocks. Are you VDR & VER ready?

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

The forthcoming requirements under FedRAMP Vulnerability Detection and Response (VDR) and Vulnerability Exposure and Remediation (VER) rules mandate a fundamental shift in how cloud service providers manage security, moving away from static scanning models toward continuous, machine-readable validation. The most immediate deadline for these changes is December 7, 2026, with subsequent requirements becoming mandatory for all cloud service offerings maintaining FedRAMP Certification.

The core change involves redefining detection frequency and remediation timelines. The traditional flat monthly scanning model is replaced by a system where detection cadence is determined by the certification class, specifying intervals such as every 14 days for Class A, every 7 days for Class B, every 3 days for Class C, and at least once per day for Class D resources. Furthermore, remediation clocks are tiered and significantly tighter, tying fix deadlines to a vulnerability's PAIN rating and exploitability, allowing remediation timelines to range dramatically from 192 days down to 12 hours for severe vulnerabilities. This implies that the remediation process must account for operational realities, such as scheduling fixes around holidays, rather than being treated as simple ticket queue Service Level Agreements.

The framework also inverts the burden of proof through the principle that providers must assume exploits are automatable by default unless they can provide evidence to the contrary. This necessitates that any deferral of remediation must be supported by a defensible artifact produced at the same cadence as other validation activities. A critical change is that process failures within the vulnerability detection and response pipelines are now explicitly counted as vulnerabilities, meaning the systems used to produce evidence must also be continually validated.

This evolution redefines the deliverable from a compliance submission to an engineering outcome. Instead of simply scanning, providers must establish systems that pull data from live asset sources, including cloud configurations, identity providers, SIEMs, and ticketing systems, and emit machine-readable results on a continuous basis. This continuous validation, renamed Ongoing Certification, moves beyond narrative documentation; it requires real-time evidence derived from live data rather than relying solely on attested documentation.

The transition further necessitates that teams focus on building and maintaining operational cadences rather than focusing solely on a static submission date. This requires answering operational questions about validation, such as who is paged upon validation failure and the established response time. Consequently, the focus shifts from building systems tuned for a single moment to designing systems tuned for persistent, steady operation, acknowledging that continuous monitoring must occur in a long-term, repeatable manner despite obstacles.

Ultimately, as evidence becomes structured data rather than narrative, it transcends framework boundaries, aligning with requirements from various consumers, including SOC 2 auditors and enterprise diligence teams. This transition signals an inversion in economics, where the cost of point-in-time compliance increases with added complexity, and continuous validation costs are significantly higher to establish and maintain reliably. This forces an emphasis on automation engineering to create scalable, resilient security systems that produce actionable, current state information.