FedRAMP VDR & VER Rules: CSP Compliance Guide for Dec 2026
Compliance Hub · FedRAMP NTC-0014

FedRAMP VDR & VER: the complete guide for cloud service providers.

FedRAMP Public Notice NTC-0014 (June 16, 2026) made the Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules mandatory for every certified cloud service offering by December 7, 2026 — accelerated from 2027 because of CISA BOD 26-04. This hub covers what changed, what the rules require, and how to be ready.

LAST REVIEWED: SEPTEMBER 10, 2026 · SOURCED FROM FEDRAMP.GOV
The Notice

What did NTC-0014 change — and why did the timeline accelerate?

Before June 2026, FedRAMP's modernized vulnerability rules were on a 2027 adoption glide path. BOD 26-04 collapsed that: once FCEB agencies were bound to risk-tiered, continuous remediation, the cloud services they run on could not remain on legacy monthly scanning. NTC-0014 confirmed that all FedRAMP-certified cloud service offerings must adopt the VDR and VER rules by December 7, 2026.

The enforcement sequence has two dates. Miss December 7, 2026, and your offering is placed under a corrective action plan — with notice sent to every agency customer you serve. Remain non-compliant after March 7, 2027, and FedRAMP Certification is revoked, ending your ability to operate cloud services for federal agencies.

DECEMBER 7, 2026
{{ d2 }}
Applies to: FedRAMP CSPs
VDR/VER mandatory adoption

Non-compliant offerings enter a corrective action plan. Agency customers are notified — a commercial event, not just a compliance one.

MARCH 7, 2027
{{ d3 }}
Applies to: FedRAMP CSPs
Certification revocation

FedRAMP Certification is revoked for offerings still out of compliance. Corrective action plans must be active before this date — not submitted on it.

Not sure where your VDR/VER gaps are?
The assessment's Domain 1 questions map 1:1 to the four variables underlying VDR/VER — KEV status, asset exposure, exploit automation, technical impact. Twelve questions, five minutes, a scored answer.
Take the assessment →
The Rules

What do VDR and VER actually require?

VDR · DETECTION & RESPONSE
Continuous detection replaces legacy monthly scanning.

VDR requires a maintained asset inventory across the authorized boundary, continuous correlation against the CISA Known Exploited Vulnerabilities (KEV) catalog, risk-tiered remediation timelines aligned with BOD 26-04, and forensic-capable response for the highest-risk findings. If your vulnerability program is built around a monthly scan-and-report cycle, it does not meet VDR — the detection clock now runs continuously, and so does the remediation clock it starts.

VER · EVALUATION & REPORTING
"Assume It's Automatable" — the standard that exceeds BOD 26-04.

VER governs how findings are evaluated and reported to agencies. Its sharpest edge: providers must treat exploitation of a vulnerability as automatable unless they can demonstrate otherwise. Where BOD 26-04 reads exploit automation from CISA Vulnrichment data, VER flips the burden of proof onto the provider — defaulting findings into shorter timelines. Evaluation rationale, tier assignments, and remediation evidence must be documented and reportable throughout.

The CSP Readiness Checklist

Eight things that must be true before December 7.

01
Complete asset inventory of the authorized boundary, updated continuously — including internet-exposure status per asset.
02
Real-time KEV ingestion correlated against that inventory — not a monthly scan cycle.
03
Documented tier-assignment logic implementing the four-variable model, with "Assume It's Automatable" as the exploit-automation default.
04
A 72-hour remediation path for critical-tier findings — tested, not theoretical, including emergency change control.
05
Forensic triage capability that runs before patching on critical-tier findings, with escalation to incident response.
06
Compensating-controls documentation for findings that cannot be remediated in window, with assessment rationale retained.
07
Agency-ready reporting artifacts — evaluation rationale, tier assignments, and remediation evidence exportable on demand.
08
3PAO engagement scheduled — early enough that assessment findings can be remediated before the deadline, not inside the corrective-action window.
3PAO GuidanceThird Party Assessment Organization capacity will tighten as December approaches. Engage now: a late assessment whose findings land inside the corrective-action window is the highest-risk position a CSP can be in.
Not sure where your VDR/VER gaps actually are? The assessment scores you against the same variables in five minutes.
Take the assessment →