The operating deadline
- August 7, 2026: agency policies must support ongoing vulnerability remediation.
- December 7, 2026: agencies begin evaluation and remediation using the BOD 26-04 timelines.
- December 7, 2026: FedRAMP VDR and VER become mandatory for offerings obtaining or maintaining certification.
- March 7, 2027: the FedRAMP corrective-action grace period ends.
How FedRAMP maps the directive
| BOD 26-04 signal | FedRAMP implementation |
|---|---|
| Public exposure | Evaluate internet reachability, including indirect payload paths. |
| Known exploitation | Use KEV status and remediate according to CISA due dates. |
| Exploit automation | Assume automation is possible unless evidence proves otherwise. |
| Technical impact | Assign contextual Potential Agency Impact from N1 through N5. |
| Ongoing remediation | Track completed reductions, next targets, mitigation, and remediation persistently. |
Why a KEV-only tracker is not enough
KEV status is one prioritization input. The FedRAMP evaluation also considers reachability, exploitability, criticality, detectability, prevalence, privilege, proximate vulnerabilities, and known threats.
A useful operating record needs to show why a vulnerability matters to the actual cloud service, what changed its impact, and how the result was verified and validated.
What to prepare before December
- An inventory that supports grouping materially equivalent resources.
- Detection sources beyond recurring infrastructure scans.
- A seven-day contextual evaluation workflow with evidence.
- PAIN-based response targets plus CISA KEV due dates.
- Monthly human-readable activity reporting.
- Schema-aligned active, accepted, and historical JSON outputs.
- Responsible-disclosure review before reports reach broader audiences.