Start the clock with evaluation
FedRAMP separates detection, evaluation, response, and reporting. The rules say Class B providers should evaluate all vulnerabilities within seven days of detection. That evaluation determines internet reachability, likely exploitability, automation assumptions, and Potential Agency Impact.
The mitigation and remediation table runs from evaluation, not from a generic monthly report date. Preserve both timestamps and the evidence supporting the classification.
PAIN mitigation and remediation targets
These are maximum timeframes in the Class B table. FedRAMP says providers should act faster when practical.
| Current PAIN | Likely exploitable + internet-reachable | Likely exploitable + not internet-reachable | Not likely exploitable |
|---|---|---|---|
| N5 | 4 days | 8 days | 32 days |
| N4 | 8 days | 32 days | 64 days |
| N3 | 32 days | 64 days | 192 days |
| N2 | 96 days | 160 days | 192 days |
KEV dates remain separate
Known Exploited Vulnerabilities should be remediated according to the due dates in the CISA KEV Catalog, even when a vulnerability has been fully mitigated. A mitigation that lowers immediate risk does not automatically eliminate the underlying vulnerability.
Track the CISA due date, current PAIN, and any completed reduction as separate fields. This prevents a compensating control from being mistaken for permanent remediation.
Monthly reporting and the 192-day boundary
- Human-readable vulnerability activity must be reported at least monthly.
- Persistent reports summarize all activity since the previous report.
- Class B providers should make recent historical activity available in JSON at least monthly.
- At 192 days from evaluation, unresolved or expected-to-remain-unresolved findings must be categorized as accepted vulnerabilities.
- Acceptance needs an explanation and sufficient customer risk information; a spreadsheet flag is not the decision itself.