Mandatory Dec 7, 2026 Request a Readiness Review
New FedRAMP Requirement

Your FedRAMP Vulnerability Program Has Until December 7 to Change

FedRAMP's Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules become mandatory on December 7, 2026—including for providers maintaining an existing Rev. 5 authorization.

Your vulnerability scanner identifies vulnerabilities. VDR and VER require the operating model around that output. 38North works directly with your technical and compliance teams to determine what can stay, what needs to change, and what must be built.

Request a VDR & VER Readiness Review

Talk with a FedRAMP specialist about your current vulnerability operations and next steps.

Mandatory adoption
December 7, 2026
Free Consultation

Start Your Readiness Review

"*" indicates required fields

FedRAMP Advisory
Interpret the requirements and define the operating approach that fits your system.
Cloud Security Engineering
Build the integrations, data, and pipelines needed to support it.
NorthWatch
Operationalize the ongoing process and make VDR and VER results visible and reviewable.
The Problem

A Scanner Gives You Vulnerability Data. VDR Requires More.

The traditional FedRAMP process focused heavily on scheduled scanning, severity ratings, remediation timelines, and recurring report submissions. Your vulnerability scanner is doing its job.

VDR and VER require the operating model built around that scanner output.

Providers must be able to analyze vulnerabilities in the security context of the system in order to make faster, more defensible decisions. That context may include:

  • Internet reachability and exposure
  • Known exploitation
  • Asset role and criticality
  • Affected data
  • Existing security protections
  • Relevant countermeasures
  • Persistence across scans
  • Response status and deadlines

Identifying vulnerabilities is only the beginning.

The harder problem is connecting vulnerability data to the affected asset and the security context of the system, determining the Potential Agency Impact N-rating (PAIN) and the applicable response deadline, and reporting status in a way that is current, reviewable, and defensible.

Assess Your Current Process
Why Now

This Is an Implementation Deadline, Not a Planning Date

FedRAMP has announced mandatory adoption of VDR and VER for all cloud service offerings obtaining or maintaining FedRAMP Certification.

December 7, 2026
VDR and VER become mandatory.

Providers must begin operating under the new vulnerability evaluation, response, and reporting model.

March 7, 2027
The corrective-action grace period ends.

During that period, providers that have not completed VDR and VER adoption may maintain FedRAMP Certification only under a corrective action plan, which will include notice to all agencies. After March 7, cloud service offerings that are not following the rules risk losing FedRAMP Certification.

After March 7, 2027
Certification risk.

Cloud service offerings that are not following the rules risk losing FedRAMP Certification.

The work required to meet the deadline may involve new data sources, integrations, evaluation logic, operating procedures, ownership, structured reporting, and automation. That work needs to begin before December.

Source: FedRAMP Public Notice NTC-0014.

Build Your VDR & VER Plan
The Review

Start With a VDR & VER Readiness Review

38North helps you determine what already works, what needs to change, and what must be built before the new rules become mandatory.

This is a focused review of your current vulnerability operating model against the VDR and VER requirements. We help your team answer four practical questions:

1

Can you collect the right information?

Determine whether your current tools and data can connect vulnerability data to the affected asset and the security context of the system—including reachability, known exploitation, affected data, and existing protections.

2

Can you make the required decisions?

Review how your team determines the PAIN rating, the applicable response deadline, and what information supports those decisions.

3

Can you operate the process consistently?

Review ownership, escalation, response, persistence tracking, validation, and reporting across security, engineering, compliance, and leadership teams.

4

Can you prove that the process is working?

Assess whether your structured reporting outputs can show how vulnerabilities were analyzed, rated, addressed, and communicated—current and historical.

Request a Readiness Review
What We Review

See Where Your Current Program Stands

Your readiness review can examine these areas:

Scanner coverage and output

How vulnerability data enters the process from your scanners, penetration tests, configuration changes, security research, supply-chain issues, and other sources.

Asset inventory and system context

Whether vulnerabilities can be connected to the affected asset, service, environment, system boundary, affected data, and asset criticality.

Internet reachability and exposure

How your team determines whether internet-originated input can reach an affected component—not simply whether that component has a public IP address.

Exploitability and threat intelligence

How known exploitation, available exploits, attack paths, and existing protections inform the PAIN rating.

Response status and deadlines

How response deadlines are applied, how status is maintained, and how persistence across scans is tracked.

Ownership and escalation

Who analyzes vulnerabilities, approves decisions, implements action, confirms completion, communicates status, and handles exceptions.

VDR and VER reporting

How analysis results, PAIN ratings, response decisions, and unresolved vulnerabilities are reported to FedRAMP and agency customers.

Automation and integrations

Which authoritative source systems can be connected and reused, and where manual research or handoffs prevent the process from operating at the required speed and scale.

Outcomes

Leave With a Clear Path Forward

The goal is not another report that tells you the requirement exists.

The goal is to give your team a practical implementation path.

Depending on scope, your engagement can provide:

  • A current-state review of your vulnerability operating model
  • A comparison against VDR and VER expectations
  • Identification of process, data, integration, and automation gaps
  • Clear ownership and workflow recommendations
  • A prioritized implementation roadmap
  • Guidance on PAIN evaluation, response deadlines, persistence, and structured reporting
  • Identification of areas requiring engineering support or NorthWatch
  • Support moving from planning into implementation

You will know what needs to change, who needs to own it, and what should happen first.

Discuss Your Readiness Review
The Process

From Vulnerability Data to Defensible Action

Source inputs Vulnerability scanners Asset inventory Cloud environment Threat intelligence Application architecture
1

Detect

Your vulnerability scanner identifies vulnerabilities across the system.

2

Add Context

Connect vulnerability data to the affected asset and the security context of the system.

3

Evaluate

Determine the Potential Agency Impact N-rating (PAIN) and the applicable response deadline.

N1N2N3N4
4

Respond

Track response status, persistence across scans, and the organization's response.

5

Report

Produce the structured information required for VDR and VER.

Outputs PAIN ratings Response deadlines Persistence & status VDR reporting VER reporting

38North helps you design the data, process, automation, and operating model required across all five stages. NorthWatch can operationalize the evaluation, tracking, and reporting layer on an ongoing basis.

Is This For You?

This Review Is Designed for You If:

You currently maintain a FedRAMP Rev. 5 Certification
You are pursuing Rev. 5 or FedRAMP 20x
Your current process still centers on monthly scan files and POA&M updates
Vulnerability analysis depends heavily on manual research
Asset, exposure, and threat data live in disconnected systems
Ownership is split across security, engineering, compliance, and operations
Response decisions and deadlines are not consistently documented
Your team is unsure what must change before December 7
You need more than an interpretation of the rules—you need an implementation plan
Why 38North

Requirements Are Only Useful When They Can Be Put Into Operation

Meeting VDR and VER requires more than updating policy language.

The process must work across your actual environment, tools, architecture, data, and teams. Advisory defines the path, engineering builds the capabilities and pipelines, and NorthWatch operationalizes the ongoing process. One team carries the thread. We help providers move from:

Rule interpretationOperating design
Scanner outputSecurity context
Manual analysisScalable automation
Disconnected teamsClear ownership
Readiness planningImplementation

We help you design a process that fits how your cloud service actually operates—not a theoretical workflow that exists only on paper.

Advisory + Engineering + NorthWatch

Need Help Implementing the Plan?

A readiness review may identify work that extends beyond policy and process. We stay with your team through implementation and into ongoing operations, reducing handoffs and lost context.

You do not have to hand the roadmap to another team and start the explanation over again.

38North can help you move from interpretation through implementation and ongoing operations.

Talk to 38North
Advisory
  • Mapping your current process to VDR and VER
  • What applies, what can be reused, what must change
  • Prioritizing the highest-impact gaps before December 7
Engineering
  • Scanner integrations and source-system connections
  • Asset tagging, asset context, and data normalization
  • APIs, pipelines, and reporting flows
  • Security capability uplift where a real gap exists
NorthWatch
  • Analyzes vulnerabilities in the security context of your system
  • Calculates PAIN ratings and response deadlines
  • Maintains status, persistence, and historical context
  • Produces VDR and VER reporting outputs
FAQ

Questions, Answered

Does VDR and VER apply to existing Rev. 5 providers?+

Yes. FedRAMP has announced that the rules will apply to all cloud service offerings obtaining or maintaining FedRAMP Certification, including existing Rev. 5 providers.

Is this only a FedRAMP 20x requirement?+

No. VDR was originally developed as part of the 20x model, but FedRAMP has accelerated mandatory adoption across FedRAMP-certified cloud services.

Is monthly scanning still permitted?+

Scanning remains part of vulnerability detection, but FedRAMP has said that the legacy monthly scanning process followed by most Rev. 5 providers is insufficient.

Providers must be able to analyze vulnerabilities in the security context of the system, apply PAIN ratings and response deadlines, and maintain meaningful reporting.

What is the difference between VDR and VER?+

Vulnerability Evaluation and Reporting covers how vulnerabilities are evaluated—including the PAIN rating and the applicable response deadline—and how the resulting information is reported.

Vulnerability Detection and Response covers the broader process of identifying vulnerabilities and operating the response around them.

The two rulesets work together.

What is the difference between mitigation and remediation?+

Mitigation reduces the immediate risk while the vulnerability still exists. This may involve restricting access, blocking an attack path, isolating a component, or adding another protection.

Remediation removes the underlying vulnerability through actions such as patching, upgrading, changing code, or replacing the affected component.

What happens if we are not ready by December 7?+

FedRAMP has announced a corrective-action grace period through March 7, 2027. Providers relying on that period may maintain certification only under a corrective action plan, and their agency customers will be notified.

After the grace period, certifications that are not following the rules may be revoked.

Are the rules final?+

Yes. FedRAMP launched the Consolidated Rules for 2026 on June 24, 2026. VDR and VER are mandatory for cloud service offerings obtaining or maintaining FedRAMP Certification beginning December 7, 2026. It has also explicitly told providers to familiarize themselves with the rules and begin preparing as quickly as possible.

Do we need to replace our scanner or GRC platform?+

Usually not. Keep the scanner. The review identifies which existing investments and authoritative source systems can be reused, where data is missing, and where integration or engineering is genuinely required.

We determine what can stay, what needs to change, and what must be built.

Does 38North only provide advisory support?+

No. 38North combines FedRAMP advisory with cloud security engineering, and NorthWatch can operationalize the ongoing process—ingesting scanner output, analyzing vulnerabilities in the security context of your system, calculating PAIN ratings and response deadlines, maintaining status and historical context, and producing VDR and VER reporting outputs.

Mandatory December 7, 2026

December 7 Is Closer Than It Looks

Your team needs time to review the current process, identify missing information, connect authoritative source systems, clarify ownership, build automation, test the workflow, and operate it before the requirement becomes mandatory. Start by finding out where you stand.

Request a VDR & VER Readiness Review

Talk with 38North about your current FedRAMP program and the work required before December 7.