Skip to main content
Category: Continuous Monitoring

Monthly ConMon Deliverables

Also known as: ConMon, Monthly Continuous Monitoring Deliverables, Continuous Monitoring Deliverables
Simply put

Monthly ConMon deliverables are the set of security documents and data files that a cloud service provider must submit each month to keep its FedRAMP authorization in good standing. They give reviewers an ongoing view of the system's security posture, including known vulnerabilities and plans to fix them. Submitting these deliverables is part of the continuous monitoring process that follows an authorization rather than a one-time event.

Formal definition

Within the FedRAMP continuous monitoring (ConMon) program, monthly ConMon deliverables are the recurring artifacts a Cloud Service Provider uploads to the designated document repository for its Cloud Service Offering (CSO). Per FedRAMP PMO guidance, these generally include a summary report, vulnerability scan files, an updated Plan of Action and Milestones (POA&M) and system inventory, deviation requests (DRs), and significant change requests (SCRs). The FedRAMP PMO recommends uploading these deliverables together, and their submission supports the ongoing risk determination that underlies an authorization; note that specific required items, formats, and cadence are governed by the applicable FedRAMP baseline revision (for example, Rev 5) and should be verified against current FedRAMP templates and guidance. This entry describes the deliverable set at a conceptual level and does not cover agency-specific tailoring, contractual terms, or the detailed acceptance criteria a reviewing authority may apply.

Why it matters

A FedRAMP authorization is not a permanent credential. It reflects a risk determination made at a specific point in time, and that determination only remains valid if the authorizing body continues to receive current evidence about the system's security posture. Monthly ConMon deliverables are the primary mechanism through which a Cloud Service Provider (CSP) demonstrates that its Cloud Service Offering (CSO) is still being actively managed. Without this recurring flow of vulnerability scan data, an updated Plan of Action and Milestones (POA&M), and related artifacts, an authorizing official loses visibility into whether known weaknesses are being remediated and whether new risks have emerged since the authorization was granted.

Who it's relevant to

Cloud Service Providers pursuing or maintaining FedRAMP authorization
CSPs bear direct responsibility for assembling and submitting monthly ConMon deliverables to the CSO document repository. Their ability to keep an authorization in good standing depends on producing complete, accurate, and timely artifacts that align with the current FedRAMP baseline revision and templates.
Information System Security Managers and security teams
The personnel who run vulnerability scans, maintain the POA&M and system inventory, and prepare deviation and significant change requests are responsible for the underlying data quality. They must ensure that what is submitted accurately reflects the system's posture and remediation progress, since submission alone does not equate to security.
Authorizing Officials and reviewing authorities
Agency authorizing officials and other reviewers rely on the monthly deliverables to sustain the ongoing risk determination behind an authorization. This audience uses the recurring evidence to confirm that known vulnerabilities are being addressed and that changes to the system are being tracked, treating the authorization as time-bound and dependent on continuous monitoring rather than permanent.
Compliance officers and third-party assessors
Those advising on or evaluating a CSP's program need to understand what the deliverable set generally comprises and how it maps to current FedRAMP guidance. They should confirm specific required items, formats, and cadence against official sources, since agency-specific tailoring and detailed acceptance criteria fall outside a conceptual description.

Inside ConMon

Continuous Monitoring (ConMon) Overview
Monthly ConMon deliverables are the recurring artifacts a Cloud Service Provider (CSP) or system owner submits to demonstrate ongoing security posture after an authorization is granted. In the FedRAMP context these are generally submitted to the authorizing body and, for reuse, to the FedRAMP PMO. Continuous monitoring reflects the principle that an Authority to Operate (ATO) is time-bound and conditional, not permanent, and that authorization status depends on sustained monitoring rather than a one-time assessment.
Vulnerability Scan Results
Recurring scans typically cover operating systems, databases, web applications, and (in most implementations) container images, submitted on the cadence specified by the authorizing official. Readers should confirm required scan types, authenticated (credentialed) scanning expectations, and coverage thresholds against the current authoritative program guidance, as these can vary by program and revision.
Plan of Action and Milestones (POA&M)
An updated POA&M tracking open findings, their risk severity, planned remediation, and milestone dates. It is generally expected to reconcile with the current scan results and to reflect remediation timelines that align with the program's severity-based deadlines. Specific timeframe values should be verified against the applicable program guidance and revision in effect.
Deviation Requests and Documented Risk Decisions
Requests such as operational requirements, false positives, and risk adjustments used to reclassify or defer findings. These generally require supporting evidence and approval from the authorizing official; approval is not automatic and the underlying finding remains subject to review during continuous monitoring.
Inventory and Change Tracking
An updated system inventory and, where applicable, significant change notifications or records reflecting configuration and asset changes since the prior reporting period. Significant changes may trigger additional review or a separate significant change request process, which is distinct from routine monthly reporting.
Reporting Cadence and Authorization Linkage
The monthly cadence supports the authorizing official's ongoing risk determination and the maintained validity of the ATO. Sustained noncompliance or failure to submit deliverables can affect authorization status. The exact required components, formats, and cadence are set by the applicable authorizing program and revision and should be verified against current official sources.

Common questions

Answers to the questions practitioners most commonly ask about ConMon.

Does submitting monthly ConMon deliverables mean my system's authorization stays valid automatically?
No. Continuous monitoring deliverables support an authorization, but they do not make it self-renewing or permanent. An Authority to Operate (ATO) is time-bound and remains contingent on the authorizing official's ongoing acceptance of risk. Monthly ConMon deliverables are one input the authorizing official (or, in the FedRAMP context, the reviewing body) uses to decide whether that risk posture remains acceptable. Consistent submission demonstrates the required monitoring activity, but the authorizing official retains discretion to require additional action, escalate findings, or revisit the authorization decision. Confirm your specific ConMon obligations against your authorization terms and current official guidance.
If I'm meeting all my monthly ConMon reporting requirements, does that mean my system is secure?
Not necessarily. Meeting monthly ConMon deliverable requirements demonstrates compliance with a monitoring and reporting process; it does not by itself establish that a system is secure. Compliance and security are related but distinct: a package can be submitted on time and in the correct format while still reflecting unresolved vulnerabilities, open items on a plan of action and milestones (POA&M), or residual risk that the authorizing official has chosen to accept. ConMon deliverables are a mechanism for making that risk visible and tracking it over time, not a certification of security. Evaluate the substance of the findings, not just the completeness of the submission.
What items are typically included in a monthly ConMon deliverable package?
Contents vary by program, authorization path, and applicable revision, so you should confirm the exact expected artifacts against your authorization terms and current official guidance. In many implementations, a monthly package generally includes vulnerability scan results (often across operating system, web application, and database layers), an updated plan of action and milestones (POA&M) reflecting open and closed items, and supporting documentation of the monitoring period. Some programs also expect inventory reconciliation and evidence of remediation activity. Because required artifacts and formats differ across federal civilian, defense, and FedRAMP contexts, verify the specific deliverable list that applies to your system rather than assuming a universal template.
How should open findings be tracked between monthly submissions?
Open findings are typically tracked through the plan of action and milestones (POA&M), which is generally carried forward and updated each reporting cycle to reflect status changes, remediation progress, and newly identified items. In most implementations, each finding is associated with information such as identification, planned remediation, and expected completion, so that the authorizing official can observe trends over successive months. Timelines and prioritization expectations differ by program and by the severity or risk associated with each item, and these can be subject to agency tailoring. Confirm the required POA&M format, update cadence, and any remediation timeframe expectations against your current authoritative guidance.
What are common reasons a monthly ConMon deliverable is rejected or flagged?
Deliverables are commonly flagged for issues such as incomplete or inconsistent artifacts, discrepancies between the POA&M and the scan results, unexplained changes in the reported inventory, missing supporting documentation, or findings that lack adequate remediation status. Because reviewers evaluate the substance of the monitoring data and not just its presence, a package that is complete in form but shows unaddressed or inconsistently reported findings may still draw attention. Specific acceptance criteria are program-dependent and may reflect agency-specific interpretation, so verify what your reviewing body requires and how it evaluates submissions against current official sources.
Who is responsible for preparing and reviewing monthly ConMon deliverables?
Responsibilities are generally distributed across roles rather than held by a single party, and the precise assignments depend on your organization and authorization structure. In many implementations, security and system staff (for example, roles aligned with an information system security manager or security officer function) prepare and validate the artifacts, while the authorizing official, or the applicable reviewing body in a FedRAMP context, reviews the submission and makes risk decisions based on it. Contractors operating a system on behalf of a government customer may carry preparation duties defined by their agreement. Confirm the exact roles, review authority, and submission responsibilities against your authorization terms and current official guidance, as these can be subject to agency-specific interpretation.

Common misconceptions

Once a system receives an ATO, continuous monitoring deliverables are optional or a formality.
An ATO is time-bound and conditional. Ongoing authorization generally depends on submitting and maintaining monthly ConMon deliverables; a lapse or sustained noncompliance can jeopardize authorization status. Continuous monitoring is the mechanism that keeps an authorization valid between assessments.
Submitting monthly deliverables that show findings means the system is out of compliance and loses its authorization.
Open findings are expected and are managed through the POA&M and, where applicable, approved deviation requests rather than automatically invalidating an authorization. The authorizing official makes a risk-based determination; timely, transparent tracking of findings is part of compliant continuous monitoring, and compliance should not be equated with a finding-free state.
A completed assessment or authorization package satisfies the monthly reporting obligation.
Assessment and authorization are distinct from continuous monitoring. The initial assessment supports the authorization decision, but monthly ConMon deliverables are a separate, ongoing obligation. Reuse of a FedRAMP authorization by another agency also does not automatically satisfy separate program requirements, including any DoD-specific expectations, which must be confirmed independently.

Best practices

Establish a fixed monthly submission calendar aligned to the cadence set by your authorizing official, and build in internal lead time so scans, POA&M updates, and deviation requests are reviewed before the deadline.
Reconcile each monthly POA&M directly against the current scan results so that open findings, severities, and remediation milestones remain consistent and traceable across deliverables.
Use authenticated (credentialed) scanning where required and confirm scan coverage across operating systems, databases, web applications, and container images against the current program guidance rather than assuming prior scope still applies.
Support every deviation request (operational requirement, false positive, or risk adjustment) with clear evidence and route it for authorizing official approval, treating unapproved deviations as still-open findings.
Keep the system inventory and change records current each cycle, and distinguish routine monthly reporting from significant changes that may require a separate review or significant change process.
Verify the required deliverable components, formats, severity-based remediation timeframes, and cadence against the current authoritative program text in effect, since these can change across revisions and agency tailoring.