Answers to the questions practitioners most commonly ask about ConMon.
Does submitting monthly ConMon deliverables mean my system's authorization stays valid automatically?
No. Continuous monitoring deliverables support an authorization, but they do not make it self-renewing or permanent. An Authority to Operate (ATO) is time-bound and remains contingent on the authorizing official's ongoing acceptance of risk. Monthly ConMon deliverables are one input the authorizing official (or, in the FedRAMP context, the reviewing body) uses to decide whether that risk posture remains acceptable. Consistent submission demonstrates the required monitoring activity, but the authorizing official retains discretion to require additional action, escalate findings, or revisit the authorization decision. Confirm your specific ConMon obligations against your authorization terms and current official guidance.
If I'm meeting all my monthly ConMon reporting requirements, does that mean my system is secure?
Not necessarily. Meeting monthly ConMon deliverable requirements demonstrates compliance with a monitoring and reporting process; it does not by itself establish that a system is secure. Compliance and security are related but distinct: a package can be submitted on time and in the correct format while still reflecting unresolved vulnerabilities, open items on a plan of action and milestones (POA&M), or residual risk that the authorizing official has chosen to accept. ConMon deliverables are a mechanism for making that risk visible and tracking it over time, not a certification of security. Evaluate the substance of the findings, not just the completeness of the submission.
What items are typically included in a monthly ConMon deliverable package?
Contents vary by program, authorization path, and applicable revision, so you should confirm the exact expected artifacts against your authorization terms and current official guidance. In many implementations, a monthly package generally includes vulnerability scan results (often across operating system, web application, and database layers), an updated plan of action and milestones (POA&M) reflecting open and closed items, and supporting documentation of the monitoring period. Some programs also expect inventory reconciliation and evidence of remediation activity. Because required artifacts and formats differ across federal civilian, defense, and FedRAMP contexts, verify the specific deliverable list that applies to your system rather than assuming a universal template.
How should open findings be tracked between monthly submissions?
Open findings are typically tracked through the plan of action and milestones (POA&M), which is generally carried forward and updated each reporting cycle to reflect status changes, remediation progress, and newly identified items. In most implementations, each finding is associated with information such as identification, planned remediation, and expected completion, so that the authorizing official can observe trends over successive months. Timelines and prioritization expectations differ by program and by the severity or risk associated with each item, and these can be subject to agency tailoring. Confirm the required POA&M format, update cadence, and any remediation timeframe expectations against your current authoritative guidance.
What are common reasons a monthly ConMon deliverable is rejected or flagged?
Deliverables are commonly flagged for issues such as incomplete or inconsistent artifacts, discrepancies between the POA&M and the scan results, unexplained changes in the reported inventory, missing supporting documentation, or findings that lack adequate remediation status. Because reviewers evaluate the substance of the monitoring data and not just its presence, a package that is complete in form but shows unaddressed or inconsistently reported findings may still draw attention. Specific acceptance criteria are program-dependent and may reflect agency-specific interpretation, so verify what your reviewing body requires and how it evaluates submissions against current official sources.
Who is responsible for preparing and reviewing monthly ConMon deliverables?
Responsibilities are generally distributed across roles rather than held by a single party, and the precise assignments depend on your organization and authorization structure. In many implementations, security and system staff (for example, roles aligned with an information system security manager or security officer function) prepare and validate the artifacts, while the authorizing official, or the applicable reviewing body in a FedRAMP context, reviews the submission and makes risk decisions based on it. Contractors operating a system on behalf of a government customer may carry preparation duties defined by their agreement. Confirm the exact roles, review authority, and submission responsibilities against your authorization terms and current official guidance, as these can be subject to agency-specific interpretation.