01

Start the clock with evaluation

FedRAMP separates detection, evaluation, response, and reporting. The rules say Class B providers should evaluate all vulnerabilities within seven days of detection. That evaluation determines internet reachability, likely exploitability, automation assumptions, and Potential Agency Impact.

The mitigation and remediation table runs from evaluation, not from a generic monthly report date. Preserve both timestamps and the evidence supporting the classification.

02

PAIN mitigation and remediation targets

These are maximum timeframes in the Class B table. FedRAMP says providers should act faster when practical.

Current PAINLikely exploitable + internet-reachableLikely exploitable + not internet-reachableNot likely exploitable
N54 days8 days32 days
N48 days32 days64 days
N332 days64 days192 days
N296 days160 days192 days
03

KEV dates remain separate

Known Exploited Vulnerabilities should be remediated according to the due dates in the CISA KEV Catalog, even when a vulnerability has been fully mitigated. A mitigation that lowers immediate risk does not automatically eliminate the underlying vulnerability.

Track the CISA due date, current PAIN, and any completed reduction as separate fields. This prevents a compensating control from being mistaken for permanent remediation.

04

Monthly reporting and the 192-day boundary

  • Human-readable vulnerability activity must be reported at least monthly.
  • Persistent reports summarize all activity since the previous report.
  • Class B providers should make recent historical activity available in JSON at least monthly.
  • At 192 days from evaluation, unresolved or expected-to-remain-unresolved findings must be categorized as accepted vulnerabilities.
  • Acceptance needs an explanation and sufficient customer risk information; a spreadsheet flag is not the decision itself.