Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
FedRAMP's December 7 Deadline Ends the POA&M EraFedRAMP Program
4 min readFor Cloud Service Providers (DoD/FedRAMP)

FedRAMP's December 7 Deadline Ends the POA&M Era

The FedRAMP Consolidated Rules 2026 retired the provider Plan of Action and Milestones (POA&M) as a compliance artifact. In its place are Vulnerability Detection and Response (VDR) and Vulnerability Evaluation and Reporting (VER). These rulesets transform vulnerability management from periodic documentation to a continuous program with detection cadences, evaluation service-level agreements, and machine-readable reporting schemas.

Public Notice NTC-0014 issued on June 16, 2026, mandates both VDR and VER for every FedRAMP offering by December 7, 2026. Certifications that don't comply face revocation after the grace period ends on March 7, 2027.

What Changed

Previously, you scanned periodically, logged findings in a POA&M, tracked remediation milestones, and submitted updates during continuous monitoring reviews. The POA&M served as both a tracking document and a negotiation tool, allowing findings to age while you documented progress.

VDR and VER eliminate that flexibility. Detection now runs on fixed cadences tied to resource type. Every finding receives a Potential Agency Impact N-rating (PAIN) from N1 to N5, a Likely Exploitable Vulnerability (LEV) determination, and an Internet Reachable Vulnerability (IRV) classification. These inputs set a remediation clock. At Class D (High), an N5 finding that's likely exploitable and internet-reachable must be remediated within 12 hours of evaluation.

Findings not resolved within 192 days of evaluation become accepted vulnerabilities under VDR-TFR-MAV, requiring Accepted Vulnerability Info (AVI) disclosure with a named owner and documented rationale. The POA&M is gone, replaced by a time-bound process with explicit failure modes.

Key Findings

Detection failures are now governed findings. VDR-CSO-FAV requires you to treat failures in your own vulnerability detection and response processes as vulnerabilities. Scanner downtime, partial scan results, or newly launched assets absent from the next scan each become findings with named owners and resolution paths. A clean scanner report from an incomplete scan is not evidence of compliance.

Evaluation is time-bound and documented. VER-TFR-EVU requires all detected vulnerabilities to be evaluated within 2 days of detection at Class D. The evaluation must record PAIN reason codes, LEV and IRV determinations, and analyst attribution. An unevaluated finding breaches the SLA and becomes an assessor target.

Coverage must be complete and verifiable. Detection must cover every resource inside your authorization boundary. Under VDR-CSO-FAV, an asset present in inventory but absent from scan results is a governed finding. Your asset inventory and your scanner population must reconcile, and discrepancies must be governed as findings.

Machine-readable reporting replaces narrative updates. VER-TFR-MRH requires two outputs: a Vulnerability Detail Report (VDT) with eleven required elements per finding, and an Accepted Vulnerability Info (AVI) report with eight required elements per accepted vulnerability. Both must validate against published JSON schemas and refresh at least every 7 days. Assessors will automate retrieval and validation.

The 192-day boundary replaces indefinite POA&M aging. Any vulnerability not fully mitigated or remediated within 192 days of evaluation must be categorized as an accepted vulnerability with AVI-compliant documentation. The clock starts at evaluation, not detection. You can't extend it by documenting progress.

What This Means for Your Team

You're building an operating program, not a documentation workflow. Assessors will look for evidence that the program runs continuously, not just that you can produce reports on demand.

Your scanner must run on cadences tied to resource type: daily for machine-based resources, every 7 days for resources likely to drift, monthly for stable resources. You must verify and validate machine-based resources monthly and non-machine resources every 3 months under VDR-TFR-MVF and VDR-TFR-NMV.

Your evaluation process must complete within 2 days and produce documented PAIN/LEV/IRV determinations with analyst attribution. If you're evaluating manually, ensure you have enough analyst capacity to meet the SLA during high-volume detection periods. If you're automating, your tooling must produce documentation that survives assessor review.

Your remediation tracking must account for every finding from evaluation through resolution or acceptance. At Class D, an N5 finding likely exploitable and internet-reachable gives you 12 hours from evaluation. An N2 finding not likely exploitable gives you 192 days. The clock doesn't pause while you document progress or request extensions.

Your reporting outputs must validate against JSON schemas and refresh at least every 7 days. Assessors will automate retrieval. If your VDT or AVI output fails schema validation, or if the population denominator can't be verified against your asset inventory, you've created a reporting failure.

Action Items by Priority

Immediate (if you haven't started): Reconcile your asset inventory to your scanner population. Every asset in scope must appear in scan results. Discrepancies become governed findings under VDR-CSO-FAV. This reconciliation is the foundation of coverage completeness.

Week 1-2: Implement detection cadences per resource type and verify that scanner failures create governed findings automatically. Your program must treat its own process failures as vulnerabilities. Configure monitoring to detect scanner downtime, partial results, or missed newly launched assets.

Week 3-4: Build or configure your evaluation workflow to meet the 2-day SLA with documented PAIN/LEV/IRV determinations and analyst attribution. If you're automating, validate that your tooling produces assessor-defensible documentation. If you're evaluating manually, confirm you have capacity to handle volume.

Week 5-6: Implement remediation clock tracking per finding from evaluation. Map PAIN/LEV/IRV combinations to remediation windows and configure alerting before clocks expire. Test your workflow for findings approaching the 192-day boundary to ensure AVI documentation triggers automatically.

Week 7-8: Validate your VDT and AVI outputs against the published JSON schemas. Automate the refresh cadence and confirm that the population denominator in your reporting matches your asset inventory. Run a full validation cycle and resolve schema failures before December 7.

Ongoing: Deliver monthly human activity reports with sign-off. Maintain AVI-compliant documentation for all accepted vulnerabilities with named owners and documented rationales. Track detection failures as governed findings and resolve them within the same clocks as other vulnerabilities.

FedRAMP Compliance

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like