Free XLSX + JSON sample 2026 VDR / VER rules

FedRAMP Vulnerability
Reporting Kit.

Turn vulnerability findings into contextual evaluations, response evidence, monthly reporting, and current machine-readable fields—without uploading scanner data or trusting an empty early-access promise.

.xlsx · 6 worksheets · 5 completed examples · 3 JSON samples · no upload · no payment

Why this window exists

Legacy monthly scanning is no longer the operating model.

FedRAMP made the 2026 Vulnerability Detection and Response and Vulnerability Evaluation and Reporting rules mandatory for obtaining or maintaining certification beginning December 7, 2026. The transition grace period ends March 7, 2027.

The new model prioritizes service context: internet reachability, likely exploitability, automation, Potential Agency Impact, completed reductions, and accountable reporting. FedRAMP explicitly states that the legacy monthly-scanning process is insufficient.

Inside the free workbook

A working sample, not a locked preview.

The sample is intentionally small enough to inspect and large enough to test the operating model. Replace the synthetic demonstration data with evidence-backed records only after confirming your applicable rules and disclosure boundaries.

01

Start Here

Official-source links, scope boundaries, workflow, and formula-driven sample counts.

02

Vulnerability Register

Five completed example records with reachability, exploitability, PAIN, response, acceptance, ownership, and evidence fields.

03

Monthly Report

A human-readable activity summary with live counts and explicit review state.

04

Evidence Index

Nine synthetic evidence-reference examples with source, owner, approved location, review state, and sensitivity.

05

JSON Field Map

Workbook-to-schema paths for active, accepted, and historical vulnerability reporting.

06

Evaluation Guide

Questions and evidence examples for criticality, reachability, exploitability, automation, prevalence, privilege, and response.

Reporting model

What the register forces you to decide.

  1. 01 Tracking Provider-assigned ID, detection time, and detection source.
  2. 02 Context Internet reachability, likely exploitability, automation evidence, and evaluation factors.
  3. 03 Impact Historical and current Potential Agency Impact N-rating.
  4. 04 Response Completed reductions, projected next reduction, target rating, and final disposition.
  5. 05 Timing Evaluation timing, overdue state, and the 192-day accepted-vulnerability boundary.
  6. 06 Evidence Traceable artifacts, owners, review state, and responsible disclosure notes.
Schema-aligned examples

Inspect the JSON separately.

Each file is readable in a text editor and uses synthetic example data. The examples were checked against the public FedRAMP schemas dated June 24, 2026.

Official schemas can change. Validate actual exports against fedramp.gov/schemas.

Full-kit direction

Built from real workflow demand.

  • Expanded blank register and report periods
  • PAIN reduction history and grouped-resource workflow
  • Accepted-vulnerability decision and review pack
  • Current JSON export templates and validation checklist
  • Scanner and vulnerability-platform field mapping
  • Consultant-friendly evidence request and review views

No checkout today. Early access is requested by email.

Not positioned as

A substitute for judgment.

  • Not an official FedRAMP, CISA, or GSA product
  • Not an assessor opinion or submission package
  • Not a vulnerability scanner or evidence repository
  • Not a risk acceptance decision
  • Not legal, regulatory, procurement, or contracting advice
  • Not a guarantee of certification, authorization, or compliance
Practical guides

Research the rule before using the file.

Questions

Clear boundaries before use.

Is this an official FedRAMP template?

No. It is an independent tcinfra.dev implementation aid. It is not affiliated with, certified by, or endorsed by FedRAMP, CISA, GSA, or the U.S. government.

Are the sample findings real vulnerabilities?

No. They are safe demonstration scenarios populated with synthetic data so you can inspect the workflow before replacing them with your own evidence-backed records. The sample contains no exploit payloads or customer data.

Do the JSON files pass the current public schemas?

The three included samples were checked against the FedRAMP schemas dated June 24, 2026. You must still validate every actual export against the current schema before submission or sharing.

Do I upload scanner results or evidence to tcinfra.dev?

No. The downloadable workbook and JSON examples are local files. The page has no upload form, account, payment integration, or evidence vault.

What does early access require?

Only an email. The direct sample downloads are ungated; email is used only to request the proposed full-kit scope and availability.

Free evidence and reporting sample

Download first. Email only if it fits.

The XLSX and JSON files are direct downloads. Early access requests use email; there is no payment integration and no scanner-data upload.

Direct files · No account · No payment · No upload · [email protected]