FedRAMP has announced that its new Vulnerability Detection and Response (VDR) and Verification (VER) rules will be mandatory for all cloud service offerings with FedRAMP Certification by December 7, 2026. A grace period extends to March 7, 2027, for offerings under a corrective action plan. These rules represent a significant shift from previous requirements.
The previous model of flat monthly scans and Plans of Action and Milestones (POA&M) is being retired. Under the new VDR-TFR-PSD rule, detection frequency is now tied to the certification class. Machine-based resources must be scanned at least every 14 days for Class A, every 7 days for Class B, every 3 days for Class C, and at least once per day for Class D. Machine verification and validation will run monthly for Rev5 holders and as frequently as every three days for higher 20x classes.
The VDR-TFR-PVR rule introduces tiered remediation deadlines. These deadlines are determined by a vulnerability's PAIN rating and its exploitability, ranging from 192 days for low-impact issues down to 12 hours for extreme cases, such as a Class D offering with a PAIN-5 vulnerability that is both likely and immediately remotely exploitable. This 12-hour clock necessitates immediate response capabilities, even during off-hours.
Under VER-EVA-AIA, providers must assume exploits are automatable by default unless they can provide evidence to the contrary. This means every deferral of remediation requires a defensible artifact. This provision increases the documentation and validation burden on providers.
The VDR-CSO-FAV rule mandates that problems or failures within vulnerability detection and response processes must be treated as vulnerabilities. This means that any silent failure in a detection pipeline is not merely an operational issue but a security vulnerability itself, placing the system producing evidence directly within the scope of compliance.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
FedRAMP's new Vulnerability Detection and Response (VDR) and Verification (VER) rules become mandatory on December 7, 2026, replacing the monthly scan model with more frequent, tiered scanning requirements. These changes introduce tighter remediation deadlines, shift the burden of proof for exploitability, and classify process failures as vulnerabilities, significantly altering engineering work for certified cloud service offerings.