FedRAMP's Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules become mandatory on December 7, 2026—including for providers maintaining an existing Rev. 5 authorization.
Your vulnerability scanner identifies vulnerabilities. VDR and VER require the operating model around that output. 38North works directly with your technical and compliance teams to determine what can stay, what needs to change, and what must be built.
Talk with a FedRAMP specialist about your current vulnerability operations and next steps.
"*" indicates required fields
The traditional FedRAMP process focused heavily on scheduled scanning, severity ratings, remediation timelines, and recurring report submissions. Your vulnerability scanner is doing its job.
VDR and VER require the operating model built around that scanner output.
Providers must be able to analyze vulnerabilities in the security context of the system in order to make faster, more defensible decisions. That context may include:
Identifying vulnerabilities is only the beginning.
The harder problem is connecting vulnerability data to the affected asset and the security context of the system, determining the Potential Agency Impact N-rating (PAIN) and the applicable response deadline, and reporting status in a way that is current, reviewable, and defensible.
FedRAMP has announced mandatory adoption of VDR and VER for all cloud service offerings obtaining or maintaining FedRAMP Certification.
Providers must begin operating under the new vulnerability evaluation, response, and reporting model.
During that period, providers that have not completed VDR and VER adoption may maintain FedRAMP Certification only under a corrective action plan, which will include notice to all agencies. After March 7, cloud service offerings that are not following the rules risk losing FedRAMP Certification.
Cloud service offerings that are not following the rules risk losing FedRAMP Certification.
The work required to meet the deadline may involve new data sources, integrations, evaluation logic, operating procedures, ownership, structured reporting, and automation. That work needs to begin before December.
Source: FedRAMP Public Notice NTC-0014.
38North helps you determine what already works, what needs to change, and what must be built before the new rules become mandatory.
This is a focused review of your current vulnerability operating model against the VDR and VER requirements. We help your team answer four practical questions:
Determine whether your current tools and data can connect vulnerability data to the affected asset and the security context of the system—including reachability, known exploitation, affected data, and existing protections.
Review how your team determines the PAIN rating, the applicable response deadline, and what information supports those decisions.
Review ownership, escalation, response, persistence tracking, validation, and reporting across security, engineering, compliance, and leadership teams.
Assess whether your structured reporting outputs can show how vulnerabilities were analyzed, rated, addressed, and communicated—current and historical.
Your readiness review can examine these areas:
How vulnerability data enters the process from your scanners, penetration tests, configuration changes, security research, supply-chain issues, and other sources.
Whether vulnerabilities can be connected to the affected asset, service, environment, system boundary, affected data, and asset criticality.
How your team determines whether internet-originated input can reach an affected component—not simply whether that component has a public IP address.
How known exploitation, available exploits, attack paths, and existing protections inform the PAIN rating.
How response deadlines are applied, how status is maintained, and how persistence across scans is tracked.
Who analyzes vulnerabilities, approves decisions, implements action, confirms completion, communicates status, and handles exceptions.
How analysis results, PAIN ratings, response decisions, and unresolved vulnerabilities are reported to FedRAMP and agency customers.
Which authoritative source systems can be connected and reused, and where manual research or handoffs prevent the process from operating at the required speed and scale.
The goal is not another report that tells you the requirement exists.
The goal is to give your team a practical implementation path.
Depending on scope, your engagement can provide:
You will know what needs to change, who needs to own it, and what should happen first.
Your vulnerability scanner identifies vulnerabilities across the system.
Connect vulnerability data to the affected asset and the security context of the system.
Determine the Potential Agency Impact N-rating (PAIN) and the applicable response deadline.
Track response status, persistence across scans, and the organization's response.
Produce the structured information required for VDR and VER.
38North helps you design the data, process, automation, and operating model required across all five stages. NorthWatch can operationalize the evaluation, tracking, and reporting layer on an ongoing basis.
Meeting VDR and VER requires more than updating policy language.
The process must work across your actual environment, tools, architecture, data, and teams. Advisory defines the path, engineering builds the capabilities and pipelines, and NorthWatch operationalizes the ongoing process. One team carries the thread. We help providers move from:
We help you design a process that fits how your cloud service actually operates—not a theoretical workflow that exists only on paper.
A readiness review may identify work that extends beyond policy and process. We stay with your team through implementation and into ongoing operations, reducing handoffs and lost context.
You do not have to hand the roadmap to another team and start the explanation over again.
38North can help you move from interpretation through implementation and ongoing operations.
Talk to 38North →Yes. FedRAMP has announced that the rules will apply to all cloud service offerings obtaining or maintaining FedRAMP Certification, including existing Rev. 5 providers.
No. VDR was originally developed as part of the 20x model, but FedRAMP has accelerated mandatory adoption across FedRAMP-certified cloud services.
Scanning remains part of vulnerability detection, but FedRAMP has said that the legacy monthly scanning process followed by most Rev. 5 providers is insufficient.
Providers must be able to analyze vulnerabilities in the security context of the system, apply PAIN ratings and response deadlines, and maintain meaningful reporting.
Vulnerability Evaluation and Reporting covers how vulnerabilities are evaluated—including the PAIN rating and the applicable response deadline—and how the resulting information is reported.
Vulnerability Detection and Response covers the broader process of identifying vulnerabilities and operating the response around them.
The two rulesets work together.
Mitigation reduces the immediate risk while the vulnerability still exists. This may involve restricting access, blocking an attack path, isolating a component, or adding another protection.
Remediation removes the underlying vulnerability through actions such as patching, upgrading, changing code, or replacing the affected component.
FedRAMP has announced a corrective-action grace period through March 7, 2027. Providers relying on that period may maintain certification only under a corrective action plan, and their agency customers will be notified.
After the grace period, certifications that are not following the rules may be revoked.
Yes. FedRAMP launched the Consolidated Rules for 2026 on June 24, 2026. VDR and VER are mandatory for cloud service offerings obtaining or maintaining FedRAMP Certification beginning December 7, 2026. It has also explicitly told providers to familiarize themselves with the rules and begin preparing as quickly as possible.
Usually not. Keep the scanner. The review identifies which existing investments and authoritative source systems can be reused, where data is missing, and where integration or engineering is genuinely required.
We determine what can stay, what needs to change, and what must be built.
No. 38North combines FedRAMP advisory with cloud security engineering, and NorthWatch can operationalize the ongoing process—ingesting scanner output, analyzing vulnerabilities in the security context of your system, calculating PAIN ratings and response deadlines, maintaining status and historical context, and producing VDR and VER reporting outputs.
Your team needs time to review the current process, identify missing information, connect authoritative source systems, clarify ownership, build automation, test the workflow, and operate it before the requirement becomes mandatory. Start by finding out where you stand.
Request a VDR & VER Readiness Review →Talk with 38North about your current FedRAMP program and the work required before December 7.