FedRAMP VDR & VER: the complete guide for cloud service providers.
FedRAMP Public Notice NTC-0014 (June 16, 2026) made the Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules mandatory for every certified cloud service offering by December 7, 2026 — accelerated from 2027 because of CISA BOD 26-04. This hub covers what changed, what the rules require, and how to be ready.
What did NTC-0014 change — and why did the timeline accelerate?
Before June 2026, FedRAMP's modernized vulnerability rules were on a 2027 adoption glide path. BOD 26-04 collapsed that: once FCEB agencies were bound to risk-tiered, continuous remediation, the cloud services they run on could not remain on legacy monthly scanning. NTC-0014 confirmed that all FedRAMP-certified cloud service offerings must adopt the VDR and VER rules by December 7, 2026.
The enforcement sequence has two dates. Miss December 7, 2026, and your offering is placed under a corrective action plan — with notice sent to every agency customer you serve. Remain non-compliant after March 7, 2027, and FedRAMP Certification is revoked, ending your ability to operate cloud services for federal agencies.
Non-compliant offerings enter a corrective action plan. Agency customers are notified — a commercial event, not just a compliance one.
FedRAMP Certification is revoked for offerings still out of compliance. Corrective action plans must be active before this date — not submitted on it.
What do VDR and VER actually require?
VDR requires a maintained asset inventory across the authorized boundary, continuous correlation against the CISA Known Exploited Vulnerabilities (KEV) catalog, risk-tiered remediation timelines aligned with BOD 26-04, and forensic-capable response for the highest-risk findings. If your vulnerability program is built around a monthly scan-and-report cycle, it does not meet VDR — the detection clock now runs continuously, and so does the remediation clock it starts.
VER governs how findings are evaluated and reported to agencies. Its sharpest edge: providers must treat exploitation of a vulnerability as automatable unless they can demonstrate otherwise. Where BOD 26-04 reads exploit automation from CISA Vulnrichment data, VER flips the burden of proof onto the provider — defaulting findings into shorter timelines. Evaluation rationale, tier assignments, and remediation evidence must be documented and reportable throughout.