Fortinetics
← Insights · FedRAMP · · 8 min read

FedRAMP rebuilds vulnerability management for CSPs: VDR, VER, and the end of monthly scanning

FedRAMP's NTC-0014 (June 16, 2026) folds CISA BOD 26-04 into the Consolidated Rules for 2026 through two new rulesets — Vulnerability Detection and Response (VDR) and Vulnerability Evaluation and Reporting (VER). They move certified cloud providers off the legacy monthly-scan cadence toward an exposure- and threat-based model that prioritizes internet-reachable, exploitable, and Known-Exploited vulnerabilities. Mandatory December 7, 2026, with a grace period to March 7, 2027 — after which non-compliant certifications are revoked. The BOD binds agencies, not CSPs; this is the rule that makes it bind you.

Published as NTC-0014 (June 16, 2026). FedRAMP folded CISA’s BOD 26-04 into the Consolidated Rules for 2026 through two new rulesets — Vulnerability Detection and Response (VDR) and Vulnerability Evaluation and Reporting (VER). They move certified cloud providers off the legacy monthly-scan cadence toward an exposure- and threat-based model: internet-reachable, exploitable, and Known-Exploited vulnerabilities move to the front of the line. The rules are mandatory December 7, 2026, with a grace period to March 7, 2027 — after which a non-compliant certification is revoked. The directive itself binds federal agencies, not you; this is the rule that makes it bind you.

When CISA issued Binding Operational Directive 26-04, we wrote that it does not reach private companies — a BOD binds Federal Civilian Executive Branch agencies, and a defense contractor’s obligations come from its contract, not the directive. That is still true. NTC-0014 is the other side of the coin: FedRAMP looked at the same risk-based model and chose to adopt it as a condition of certification. For a cloud service provider, BOD 26-04 was a model worth understanding; under NTC-0014 it becomes a requirement you are measured against — with a revocation date attached.

What FedRAMP adopted, and why it matters more for CSPs than the BOD did

BOD 26-04 replaced the old flat “patch every Known Exploited Vulnerability on one clock” rule with a model that scores each vulnerability on four signals: public exposure, KEV status, automatability, and technical impact. The more of those a vulnerability meets, the shorter the remediation window. FedRAMP’s NTC-0014 takes that model and expresses it as two mandatory rulesets that every certified cloud service must follow.

The distinction that matters: a BOD is a federal-agency obligation, so a CSP could read BOD 26-04 as useful context and nothing more. NTC-0014 closes that gap. The model is now wired into the FedRAMP certification itself, which means it reaches the provider directly and carries a consequence the BOD never could against a private company — loss of the certification. This is the same pattern we flagged for defense contractors, where the KEV catalog reaches a program through DFARS and CMMC rather than the directive. For CSPs, the channel is FedRAMP.

The two rulesets

Vulnerability Detection and Response (VDR)

VDR governs the act of fixing things. It requires ongoing mitigation and remediation of vulnerabilities, and its load-bearing rule is VDR-TFR-KEV (Remediate KEVs): a provider must remediate Known Exploited Vulnerabilities on the BOD 26-04 timelines unless there is a valid technical reason not to. The KEV catalog — CISA’s authoritative, evidence-based list of vulnerabilities being exploited in the wild — becomes the spine of the remediation obligation, and the timelines flow from the directive’s risk scoring rather than a uniform deadline.

Vulnerability Evaluation and Reporting (VER)

VER governs how a provider sizes a vulnerability before it acts — and this is where FedRAMP goes a step beyond the directive. Three rules define the evaluation:

  • VER-EVA-EIR — evaluate whether the vulnerability is internet-reachable. FedRAMP notes this exceeds the BOD’s own requirement; exposure is the first sort key.
  • VER-EVA-ELX — assess exploitability, KEV status, and automation potential. This is the risk-scoring step that decides which timeline a vulnerability falls into.
  • VER-EVA-AIAassume an exploit is automatable by default unless the provider has evidence otherwise. The burden is on the provider to prove a vulnerability is not easily weaponized, not the other way around.

Read together, VDR and VER turn vulnerability management into a prioritization engine: VER decides how dangerous a finding is, VDR sets the clock that follows. The default posture is conservative — assume reachable, assume automatable — and the provider earns a longer timeline by evidencing lower risk.

The end of the flat monthly cadence

The operational change for most CSPs is the move away from a uniform monthly scan-and-report rhythm. The legacy continuous-monitoring model treated vulnerabilities largely on a calendar: scan monthly, report monthly, remediate on standard timelines. NTC-0014 reprioritizes by exposure and threat. An internet-reachable, KEV-listed, automatable vulnerability is handled fast, on directive timelines; a low-risk internal finding is not forced onto the same clock.

That is a more defensible allocation of remediation capacity — the same argument CISA made when it retired the flat KEV deadline — but it is also more demanding to operate. A flat cadence is easy to prove: you scanned, you reported, on schedule. A risk-scored model has to demonstrate the scoring: that you evaluated reachability and exploitability, that you assigned the right timeline, and that the KEV-listed, internet-facing items actually moved first. The evidence an assessor wants shifts from “here is the monthly scan” to “here is how we decided what to fix and when, and the record that we did.”

This lands on top of the broader continuous-monitoring discipline that already separates a durable authorization from a fragile one — the same operating-discipline gap we see in the IL5 controls that burn CSPs, where the program that treats monitoring as a checkbox is the one that loses its authorization.

The dates — and the revocation clock

NTC-0014 carries the firmest enforcement language in the Consolidated Rules for 2026:

  • June 10, 2026 — CISA issues BOD 26-04.
  • June 16, 2026 — FedRAMP publishes NTC-0014 as its response.
  • End of June 2026 — the Consolidated Rules for 2026 formally release.
  • December 7, 2026 — VDR and VER are mandatory for all FedRAMP certifications.
  • December 7, 2026 – March 7, 2027 — grace period for corrective action.
  • After March 7, 2027FedRAMP certification is revoked for any cloud service offering not following the rules.

A revocation date is not a finding you remediate at leisure. The window from mandatory-date to revocation is three months, and it starts in December. A provider that treats VDR/VER as a 2027 problem will find the grace period is the deadline, not the start.

What a cloud provider should do now

  1. Map your vulnerability pipeline to VER’s three evaluations. Can you show, per vulnerability, whether it is internet-reachable, whether it is exploitable / KEV-listed / automatable, and the timeline that follows? If your tooling reports findings but not this scoring, that is the build.
  2. Wire the KEV catalog into remediation, not just detection. VDR-TFR-KEV makes KEV-listed remediation a certification obligation on directive timelines. The catalog needs to drive an expedited track, with evidence that it does.
  3. Default to reachable and automatable. VER-EVA-AIA puts the burden on you to prove low risk. Build the evidence path for down-scoring a vulnerability, because absent evidence, the conservative timeline applies.
  4. Treat December 7 as the deadline and March 7 as the cliff. Scope the work to be operating — not just designed — by December 7, 2026, and use the grace period for correction, not for starting.
  5. Keep the FedRAMP and contract clocks separate. A provider that also serves DoD or holds CUI obligations now runs FedRAMP’s VDR/VER model alongside the DFARS and CMMC obligations that the KEV catalog reaches separately. They are different regimes with different consequences; assuming one workflow satisfies both is how a program fails an assessment.

Where this fits

NTC-0014 is one of the operational pieces of the Consolidated Rules for 2026, alongside the NTC-0012 incident-communications overhaul and the structural Rev 5 baseline overhaul in NTC-0013. The throughline across all three is a FedRAMP that scores by risk, hands more judgment to the provider, and attaches firmer consequences — here, the firmest of the set.

Our FedRAMP and DoD CC SRG practice builds the continuous-monitoring program that actually satisfies an assessor — the detection, the risk scoring, the KEV-driven remediation track, and the evidence that the priorities were followed — rather than a monthly scan that meets the letter of an obligation FedRAMP just retired. If you hold a FedRAMP certification, the revocation clock on VDR/VER starts in December; a scoping conversation will surface honestly where your vulnerability pipeline sits against the new model and what it takes to be operating, not just compliant on paper, before your date.

Related reading: CISA BOD 26-04 and defense contractors · NTC-0012 incident communications overhaul · FedRAMP Rev 5 baseline overhaul (NTC-0013) · IL5 assessment controls that burn CSPs · FedRAMP framework overview