Detection is broader than a scanner
VDR includes assessment, scanning, threat intelligence, vulnerability disclosure, bug bounties, penetration testing, incident response, automated control testing, supply-chain monitoring, and other relevant capabilities.
FedRAMP also treats outdated security statements and failures in the vulnerability-management process as vulnerabilities. The operating model therefore needs coverage for technical findings, control drift, and process failures.
Context changes prioritization
| Legacy-oriented question | 2026 VDR / VER question |
|---|---|
| What is the CVSS severity? | What is the Potential Agency Impact in this service? |
| Is the host public? | Can internet-originated data reach the vulnerable resource directly or indirectly? |
| Is exploitation known? | Is exploitation likely here, and is there evidence it cannot be automated? |
| When is the patch due? | What completed reduction lowers PAIN, and what is the next planned reduction? |
| Is it on the monthly POA&M? | Has all activity since the prior report been shared in the required form? |
Response remains active after mitigation
FedRAMP distinguishes mitigation from remediation. Mitigation reduces risk or impact; remediation eliminates the vulnerability. A fully mitigated issue may remain present and still require tracking, evidence, verification, validation, and eventual remediation.
The record should preserve historical PAIN, current PAIN, completed reduction events, the next target, final disposition, and any accepted-vulnerability decision.
Evidence should come from operations
- Consume data from the teams and systems that actively maintain the cloud service.
- Link findings to resource populations, change records, tests, and validation results.
- Keep sensitive exploit-enabling detail out of broadly shared reports while providing enough information for risk decisions.
- Use current FedRAMP JSON schemas rather than inventing a machine-readable format.
- Preserve human review and independent verification instead of treating automation output as a conclusion.