01

The operating deadline

  • August 7, 2026: agency policies must support ongoing vulnerability remediation.
  • December 7, 2026: agencies begin evaluation and remediation using the BOD 26-04 timelines.
  • December 7, 2026: FedRAMP VDR and VER become mandatory for offerings obtaining or maintaining certification.
  • March 7, 2027: the FedRAMP corrective-action grace period ends.
02

How FedRAMP maps the directive

BOD 26-04 signalFedRAMP implementation
Public exposureEvaluate internet reachability, including indirect payload paths.
Known exploitationUse KEV status and remediate according to CISA due dates.
Exploit automationAssume automation is possible unless evidence proves otherwise.
Technical impactAssign contextual Potential Agency Impact from N1 through N5.
Ongoing remediationTrack completed reductions, next targets, mitigation, and remediation persistently.
03

Why a KEV-only tracker is not enough

KEV status is one prioritization input. The FedRAMP evaluation also considers reachability, exploitability, criticality, detectability, prevalence, privilege, proximate vulnerabilities, and known threats.

A useful operating record needs to show why a vulnerability matters to the actual cloud service, what changed its impact, and how the result was verified and validated.

04

What to prepare before December

  • An inventory that supports grouping materially equivalent resources.
  • Detection sources beyond recurring infrastructure scans.
  • A seven-day contextual evaluation workflow with evidence.
  • PAIN-based response targets plus CISA KEV due dates.
  • Monthly human-readable activity reporting.
  • Schema-aligned active, accepted, and historical JSON outputs.
  • Responsible-disclosure review before reports reach broader audiences.