Start Here
Official-source links, scope boundaries, workflow, and formula-driven sample counts.
Turn vulnerability findings into contextual evaluations, response evidence, monthly reporting, and current machine-readable fields—without uploading scanner data or trusting an empty early-access promise.
.xlsx · 6 worksheets · 5 completed examples · 3 JSON samples · no upload · no payment
FedRAMP made the 2026 Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules mandatory for obtaining or maintaining certification beginning December 7, 2026. The transition grace period ends March 7, 2027.
The new model prioritizes service context: internet reachability, likely exploitability, automation, Potential Agency Impact, completed reductions, and accountable reporting. FedRAMP explicitly states that the legacy monthly-scanning process is insufficient.
The sample is intentionally small enough to inspect and large enough to test the operating model. Replace the synthetic demonstration data with evidence-backed records only after confirming your applicable rules and disclosure boundaries.
Official-source links, scope boundaries, workflow, and formula-driven sample counts.
Five completed example records with reachability, exploitability, PAIN, response, acceptance, ownership, and evidence fields.
A human-readable activity summary with live counts and explicit review state.
Nine synthetic evidence-reference examples with source, owner, approved location, review state, and sensitivity.
Workbook-to-schema paths for active, accepted, and historical vulnerability reporting.
Questions and evidence examples for criticality, reachability, exploitability, automation, prevalence, privilege, and response.
Each file is readable in a text editor and uses synthetic example data. The examples were checked against the public FedRAMP schemas dated June 24, 2026.
Official schemas can change. Validate actual exports against fedramp.gov/schemas.
No checkout today. Early access is requested by email.
No. It is an independent tcinfra.dev implementation aid. It is not affiliated with, certified by, or endorsed by FedRAMP, CISA, GSA, or the U.S. government.
No. They are safe demonstration scenarios populated with synthetic data so you can inspect the workflow before replacing them with your own evidence-backed records. The sample contains no exploit payloads or customer data.
The three included samples were checked against the FedRAMP schemas dated June 24, 2026. You must still validate every actual export against the current schema before submission or sharing.
No. The downloadable workbook and JSON examples are local files. The page has no upload form, account, payment integration, or evidence vault.
Only an email. The direct sample downloads are ungated; email is used only to request the proposed full-kit scope and availability.
The XLSX and JSON files are direct downloads. Early access requests use email; there is no payment integration and no scanner-data upload.
Direct files · No account · No payment · No upload · [email protected]