Vulnerability Detection and Response¶
The Vulnerability Detection and Response rules require providers to continuously identify, analyze, prioritize, mitigate, and remediate vulnerabilities and related exposures through automated systems. These rules give providers flexibility in implementation while ensuring agencies receive the information needed to support ongoing authorization decisions.
Subsets
Effective Date(s) & Overall Applicability for Rev5
- Required (Consolidated Rules for 2026)
- Optional Adoption: 2026-07-04
- Obtain: 2027-01-01
- Maintain: 2027-06-01
- Grace Ends: 2028-01-01
- Sign-up Form: ADDME
General Provider Responsibilities¶
These rules apply to all providers with FedRAMP Certifications of any type.
Vulnerability Detection¶
VDR-CSO-DET
Changelog:
- 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.
Providers MUST systematically, persistently, and promptly discover and identify vulnerabilities within their cloud service offering using appropriate techniques such as assessment, scanning, threat intelligence, vulnerability disclosure mechanisms, bug bounties, penetration testing, incident response, automated control testing, supply chain monitoring, and other relevant capabilities; this process is called vulnerability detection. Vulnerability detection includes persistently verifying and validating that information resources and processes are operating as intended and documented for FedRAMP Practices.
Vulnerability Detection and Response includes all efforts to identify weaknesses in a system and is NOT limited to traditional vulnerability scanning or testing. An out-of-date control statement in the Security Decision Record is a vulnerability that must be detected and remediated just like any other vulnerability.
Notes:
- FedRAMP's vulnerability detection (and response) rules are intended to set modern expectations for maintaining the security of a cloud service. Historical FedRAMP guidance on vulnerability scanning or continuous monitoring generally focused only on CVE-type vulnerabilities while leaving other types of vulnerabilities and exposures unaddressed.
- Providers are encouraged to leverage their existing holistic security review, architecture review, and similar processes to meet these requirements. FedRAMP strongly discourages providers from implementing separate vulnerability detection and response processes for FedRAMP reporting that are operated by independent compliance branches unless these processes are consuming data directly from the areas of the cloud service that actively maintain it.
Terms: Cloud Service Offering, FedRAMP Practices, Incident, Information Resource, Persistently, Promptly, Vulnerability, Vulnerability Detection, Vulnerability Response
Vulnerability Response¶
VDR-CSO-RES
Changelog:
- 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.
Providers MUST systematically, persistently, and promptly track, evaluate, monitor, mitigate, remediate, assess exploitation of, report, and otherwise manage all detected vulnerabilities within their cloud service offering; this process is called vulnerability response.
Notes:
- If it is not possible to fully mitigate vulnerabilities or remediate vulnerabilities, providers SHOULD instead partially mitigate vulnerabilities promptly, progressively, and persistently.
- FedRAMP does not use the terms "mitigation" and "remediation" interchangeably. Mitigation is the process of reducing the risk and impact of a vulnerability through partial mitigation and even full mitigation; remediation is the process of entirely eliminating the vulnerability. A fully mitigated vulnerability will still exist (with negligible risk) until it has been remediated. This separation is based on the plain language definitions of these words.
- Please refer to FedRAMP Definitions for strict interpretation in the FedRAMP context.
Terms: Cloud Service Offering, Fully Mitigated Vulnerability, Partially Mitigated Vulnerability, Persistently, Promptly, Remediated Vulnerability, Vulnerability, Vulnerability Detection, Vulnerability Response
Failures Are Vulnerabilities¶
VDR-CSO-FAV
Changelog:
- 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.
Providers MUST treat problems or failures with their vulnerability detection and response processes as vulnerabilities.
Terms: Vulnerability, Vulnerability Detection, Vulnerability Response
Design For Resilience¶
VDR-CSO-DFR
Changelog:
- 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.
Providers SHOULD make design and architecture decisions for their cloud service offering that mitigate the risk of vulnerabilities by default AND decrease the risk and complexity of vulnerability detection and response.
Terms: Cloud Service Offering, Vulnerability, Vulnerability Detection, Vulnerability Response
Automate Detection¶
VDR-CSO-ADT
Changelog:
- 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.
Providers SHOULD use automated services to improve and streamline vulnerability detection and response.
Terms: Vulnerability, Vulnerability Detection, Vulnerability Response
Detect After Changes¶
VDR-CSO-DAC
Changelog:
- 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.
Providers SHOULD automatically perform vulnerability detection on representative samples of new or significantly changed information resources.
Terms: Information Resource, Vulnerability, Vulnerability Detection
Maintain Security¶
VDR-CSO-MSP
Changelog:
- 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.
Providers SHOULD NOT weaken the security of information resources to facilitate vulnerability scanning, detection, or assessment activities.
Terms: Information Resource, Vulnerability, Vulnerability Detection
Avoid KEVs¶
VDR-CSO-AKE
Changelog:
- 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.
Providers SHOULD NOT deploy or otherwise activate new machine-based information resources with Known Exploited Vulnerabilities.
Terms: Information Resource, Known Exploited Vulnerability (KEV), Machine-Based (Information Resources), Vulnerability
Sampling¶
VDR-CSO-SIR
Changelog:
- 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.
Providers MAY sample effectively identical information resources, especially machine-based information resources, when performing vulnerability detection UNLESS doing so would decrease the efficiency or effectiveness of vulnerability detection.
Terms: Information Resource, Machine-Based (Information Resources), Vulnerability, Vulnerability Detection
Timeframes¶
These rules apply to timeframes for vulnerability detection and response.
Non-Machine Verification and Validation¶
VDR-TFR-NMV
Changelog:
- 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.
Providers MUST verify and validate the status of non-machine-based information resources at least once every 3 months.
Terms: Information Resource, Machine-Based (Information Resources), Validation, Verification
Persistent Drift Detection¶
VDR-TFR-PDD
Changelog:
- 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.
Providers with Class C Certifications SHOULD persistently perform vulnerability detection on all information resources that are likely to drift, at least once every 14 days.
Timeframe: 14 days
Terms: Drift, Information Resource, Likely, Persistently, Vulnerability, Vulnerability Detection
Persistently Complete Detection¶
VDR-TFR-PCD
Changelog:
- 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.
Providers with Class C Certifications SHOULD persistently perform vulnerability detection on all information resources that are NOT likely to drift, at least once every month.
Timeframe: 1 month
Terms: Drift, Information Resource, Likely, Persistently, Vulnerability, Vulnerability Detection
Mitigation and Remediation Expectations¶
VDR-TFR-PVR
Changelog:
- 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.
Providers with Class C Certifications SHOULD partially mitigate vulnerabilities, fully mitigate vulnerabilities, or remediate vulnerabilities to a lower Potential Agency Impact N-rating within the timeframes from evaluation shown below, factoring for the current Potential Agency Impact N-rating, internet reachability, and likely exploitability:
Potential Agency Impact N-rating (PAIN) Timeframes:
| PAIN Rating | LEV + IRV | LEV + NIRV | NLEV |
|---|---|---|---|
| PAIN-5 | 2 days | 4 days | 16 days |
| PAIN-4 | 4 days | 8 days | 64 days |
| PAIN-3 | 16 days | 32 days | 128 days |
| PAIN-2 | 48 days | 128 days | 192 days |
Terms: Fully Mitigated Vulnerability, Likely, Partially Mitigated Vulnerability, Potential Agency Impact, Remediated Vulnerability, Vulnerability
Remaining Vulnerabilities¶
VDR-TFR-RMN
Changelog:
- 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.
Providers SHOULD mitigate or remediate remaining vulnerabilities during routine operations as determined necessary by the provider.
Terms: Vulnerability
Remediate KEVs¶
VDR-TFR-KEV
Changelog:
- 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.
Providers SHOULD remediate Known Exploited Vulnerabilities according to the due dates in the CISA Known Exploited Vulnerabilities Catalog (even if the vulnerability has been fully mitigated) as required by CISA Binding Operational Directive (BOD) 26-04 or any successor guidance from CISA.
Reference: CISA BOD 26-04
Persistent Sample Detection¶
VDR-TFR-PSD
Changelog:
- 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.
Providers with Class C Certifications SHOULD persistently perform vulnerability detection on representative samples of similar machine-based information resources, at least once every 3 days.
Timeframe: 3 days
Terms: Information Resource, Machine-Based (Information Resources), Persistently, Vulnerability, Vulnerability Detection
Persistent Machine Verification and Validation for Rev5¶
VDR-TFR-MVF
Changelog:
- 2026-06-30: Initial reset for the Consolidated Rules for 2026 Public Preview.
Providers of FedRAMP Rev5 Class C offerings MUST verify and validate the status of machine-based information resources at least once every month.
Timeframe: 1 month
Terms: Information Resource, Machine-Based (Information Resources), Validation, Verification