Mandatory Dec 7, 2026 Request a Readiness Review
New FedRAMP Requirement

Your FedRAMP Vulnerability Program Has Until December 7 to Change

FedRAMP's new Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules become mandatory on December 7, 2026—including for existing Rev. 5 providers.

38North helps cloud service providers assess their current vulnerability process, identify data and automation gaps, and build a practical path to VDR and VER readiness.

Request a VDR & VER Readiness Review

Talk with a FedRAMP specialist about your current process and next steps.

Mandatory adoption
December 7, 2026
Free Consultation

Start Your Readiness Review

"*" indicates required fields

FedRAMP Advisory
Interpret the requirements and define the right operating approach.
Cloud Security Engineering
Connect the systems, data, and automation needed to support it.
Implementation Support
Move from readiness planning to an operational VDR and VER process.
The Problem

Monthly Vulnerability Scanning Is No Longer Enough

The traditional FedRAMP process focused heavily on scheduled scanning, severity ratings, remediation timelines, and recurring report submissions.

The new model requires more.

Providers must be able to evaluate vulnerabilities using the context needed to make faster, more defensible risk decisions—including:

  • Internet reachability and exposure
  • Known exploitation
  • Likely exploitability
  • Whether exploitation can be automated
  • Technical and agency impact
  • Available mitigation
  • Remediation status
  • Ongoing reporting

Finding vulnerabilities is only the beginning.

The harder problem is connecting vulnerability data with asset context, threat information, system architecture, and response decisions quickly enough to determine what needs action first.

Assess Your Current Process
Why Now

This Is an Implementation Deadline, Not a Planning Date

FedRAMP has announced mandatory adoption of VDR and VER for all cloud service offerings obtaining or maintaining FedRAMP Certification.

December 7, 2026
VDR and VER become mandatory.

Providers must begin operating under the new vulnerability evaluation, response, and reporting model.

March 7, 2027
The corrective-action grace period ends.

During the grace period, providers that have not completed adoption may maintain certification only under a corrective action plan, with agency customers notified.

After March 7, 2027
Certification risk.

Cloud service offerings that are not following the rules risk losing FedRAMP Certification.

The work required to meet the deadline may involve new data sources, integrations, decision logic, operating procedures, ownership, reporting, and automation. That work needs to begin before December.

Source: FedRAMP Public Notice NTC-0014.

Build Your VDR & VER Plan
The Review

Start With a VDR & VER Readiness Review

38North helps you determine what already works, what needs to change, and what must be built before the new rules become mandatory.

This is a focused review of your current vulnerability operating model against the emerging VDR and VER requirements. We help your team answer four practical questions:

1

Can you collect the right information?

Determine whether your current tools and data can support vulnerability evaluation using asset context, reachability, exploitability, threat intelligence, impact, mitigation, and remediation status.

2

Can you make the required decisions?

Evaluate how your team determines which vulnerabilities require immediate action, which can be mitigated, and what evidence supports those decisions.

3

Can you operate the process consistently?

Review ownership, escalation, mitigation, remediation, validation, and reporting across security, engineering, compliance, and leadership teams.

4

Can you prove that the process is working?

Assess whether your reporting and evidence can clearly demonstrate how vulnerabilities were evaluated, prioritized, addressed, and communicated.

Request a Readiness Review
What We Review

See Where Your Current Program Stands

Your readiness review can examine these areas:

Vulnerability sources

How findings enter the process from scanners, penetration tests, configuration changes, security research, supply-chain issues, bug reports, and other sources.

Asset and system context

Whether findings can be connected to the affected asset, service, environment, system boundary, data, and agency impact.

Internet reachability and exposure

How your team determines whether internet-originated input can reach an affected component—not simply whether that component has a public IP address.

Exploitability and threat intelligence

How KEV status, available exploits, automation, attack paths, and other evidence inform prioritization.

Mitigation and remediation

How your team reduces immediate risk when a vulnerability cannot yet be fully removed, and how full remediation is tracked.

Ownership and escalation

Who evaluates findings, approves decisions, implements action, confirms completion, communicates status, and handles exceptions.

Reporting and evidence

How evaluation results, risk decisions, mitigation, remediation, and unresolved issues are reported to FedRAMP and agency customers.

Automation and integrations

Where manual research, spreadsheets, handoffs, or disconnected tools could prevent the process from operating at the required speed and scale.

Outcomes

Leave With a Clear Path Forward

The goal is not another report that tells you the requirement exists.

The goal is to give your team a practical implementation path.

Depending on scope, your engagement can provide:

  • A current-state review of your vulnerability operating model
  • A comparison against VDR and VER expectations
  • Identification of process, data, integration, and automation gaps
  • Clear ownership and workflow recommendations
  • A prioritized implementation roadmap
  • Guidance on mitigation, remediation, evaluation, and reporting
  • Identification of areas requiring engineering or automation
  • Support moving from planning into implementation

You will know what needs to change, who needs to own it, and what should happen first.

Discuss Your Readiness Review
The Process

From Vulnerability Data to Defensible Action

Source inputs Vulnerability scanners Asset inventory Cloud environment Threat intelligence Application architecture
1

Detect

Bring together vulnerability findings from relevant sources.

2

Add Context

Connect findings with assets, architecture, exposure, reachability, threat information, and impact.

3

Evaluate

Determine likely exploitability, urgency, and the appropriate response.

4

Respond

Mitigate immediate risk, remediate the vulnerability, and confirm the result.

5

Report

Maintain evidence of the evaluation, decisions, actions, and current status.

Outputs Prioritization Mitigation Remediation Evidence Reporting

38North helps you design the data, process, automation, and operating model required across all five stages.

Is This For You?

This Review Is Designed for You If:

You currently maintain a FedRAMP Rev. 5 Certification
You are pursuing Rev. 5 or FedRAMP 20x
Your current process still centers on monthly scan files and POA&M updates
Vulnerability evaluation depends heavily on manual research
Asset, exposure, and threat data live in disconnected systems
Ownership is split across security, engineering, compliance, and operations
Mitigation and remediation decisions are not consistently documented
Your team is unsure what must change before December 7
You need more than an interpretation of the rules—you need an implementation plan
Why 38North

Requirements Are Only Useful When They Can Be Put Into Operation

Meeting VDR and VER requires more than updating policy language.

The process must work across your actual environment, tools, architecture, data, and teams. 38North combines FedRAMP advisory and cloud security engineering to help providers move from:

Rule interpretationOperating design
Vulnerability findingsContextual decisions
Manual analysisScalable automation
Disconnected teamsClear ownership
Readiness planningImplementation

We help you design a process that fits how your cloud service actually operates—not a theoretical workflow that exists only on paper.

Advisory + Engineering

Need Help Implementing the Plan?

A readiness review may identify work that extends beyond policy and process. 38North's engineering team can help with:

You do not have to hand the roadmap to another team and start the explanation over again.

38North can help you move from assessment through implementation.

Talk to 38North
  • Vulnerability and asset-data integrations
  • Evidence and reporting pipelines
  • Cloud and security telemetry
  • Automated evaluation logic
  • Workflow implementation
  • Architecture and configuration improvements
  • Validation and testing
  • Operational readiness
FAQ

Questions, Answered

Does VDR and VER apply to existing Rev. 5 providers?+

Yes. FedRAMP has announced that the rules will apply to all cloud service offerings obtaining or maintaining FedRAMP Certification, including existing Rev. 5 providers.

Is this only a FedRAMP 20x requirement?+

No. VDR was originally developed as part of the 20x model, but FedRAMP has accelerated mandatory adoption across FedRAMP-certified cloud services.

Is monthly scanning still permitted?+

Scanning remains part of vulnerability detection, but FedRAMP has said that the legacy monthly scanning process followed by most Rev. 5 providers is insufficient.

Providers must be able to evaluate vulnerability context, make risk-based decisions, respond appropriately, and maintain meaningful reporting.

What is the difference between VDR and VER?+

Vulnerability Evaluation and Reporting covers how vulnerabilities are evaluated and how the resulting information is reported.

Vulnerability Detection and Response covers the broader process of discovering vulnerabilities and supporting their ongoing mitigation and remediation.

The two rulesets work together.

What is the difference between mitigation and remediation?+

Mitigation reduces the immediate risk while the vulnerability still exists. This may involve restricting access, blocking an attack path, isolating a component, or adding another protection.

Remediation removes the underlying vulnerability through actions such as patching, upgrading, changing code, or replacing the affected component.

What happens if we are not ready by December 7?+

FedRAMP has announced a corrective-action grace period through March 7, 2027. Providers relying on that period may maintain certification only under a corrective action plan, and their agency customers will be notified.

After the grace period, certifications that are not following the rules may be revoked.

Are the rules final?+

FedRAMP has said minor changes may occur before the Consolidated Rules for 2026 are finalized. It has also explicitly told providers to familiarize themselves with the rules and begin preparing as quickly as possible.

Does 38North only provide advisory support?+

No. 38North combines FedRAMP advisory with cloud security engineering. We can help assess readiness, design the operating model, and support the integrations, automation, and technical changes required for implementation.

Mandatory December 7, 2026

December 7 Is Closer Than It Looks

Your team needs time to assess the current process, identify missing information, connect systems, clarify ownership, build automation, test the workflow, and operate it before the requirement becomes mandatory. Start by finding out where you stand.

Request a VDR & VER Readiness Review

Talk with 38North about your current FedRAMP program and the work required before December 7.