Find notable cyber news and cases, enriched with sources, timelines, and signals.

FedRAMP mandates VDR and VER rules for cloud service offerings

Public Sector Action
First reported
Last updated
Happening score
H score 24
1 unique sources, 1 articles

Summary

Hide ▲

FedRAMP issued mandatory VDR and VER rules for FedRAMP Certification, forcing cloud service offerings to meet new detection, remediation, and evidence requirements on a fixed timeline. The change takes effect on December 7, 2026, with a March 7, 2027 grace period for offerings on a corrective action plan. It replaces the older monthly-scan-and-POA&M model with tighter, class-based validation and response obligations. Cloud providers now have to operationalize compliance as an ongoing control program rather than a periodic paperwork exercise.

Related Happenings

CISA orders federal agencies to patch Linux kernel flaws

Public Sector Action
H score30 First: 21.09.2026 23:12 Last: 21.09.2026 23:12 Sources 1

About this happening: CISA ordered federal agencies to apply security updates and mitigations for three Linux kernel flaws by end of today, putting the response on an urgent federal...

Linux kernel active exploitation wave (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)

Exploitation Wave
H score35 First: 21.09.2026 23:12 Last: 21.09.2026 23:12 Sources 1

About this happening: CISA has warned that three Linux kernel vulnerabilities are being exploited in attacks, including one critical flaw, creating immediate risk for exposed systems. The w...

CISA adds Linux kernel flaws to KEV catalog under BOD 26-04

Public Sector Action
H score36 First: 19.09.2026 09:24 Last: 19.09.2026 09:24 Sources 1

About this happening: CISA added three Linux kernel flaws to its KEV catalog after evidence of active exploitation, forcing federal remediation prioritization. Under BOD 26-04, FC...

Linux kernel actively exploited flaws (multiple vulnerabilities)

Vulnerability
H score46 First: 19.09.2026 09:24 Last: 19.09.2026 09:24 Sources 1

About this happening: Three Linux kernel vulnerabilities—CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964—were added to CISA KEV after evidence of active exploitation. The fla...

CISA BOD 26-04 patch directive for CVE-2026-16232

Public Sector Action
H score37 First: 23.07.2026 11:13 Last: 23.07.2026 11:13 Sources 1

About this happening: CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25*...

Timeline

  1. 24.09.2026 17:02 1 articles · 2h ago

    FedRAMP makes VDR and VER mandatory for cloud service offerings

    Initial Disclosure

    FedRAMP's notice responding to CISA's BOD 26-04 announces that the Vulnerability Detection and Response rules will be mandatory for all cloud service offerings obtaining or maintaining FedRAMP Certification, with a grace period through March 7, 2027 for offerings operating under a corrective action plan.

    Show sources
  2. 24.09.2026 17:02 2 articles · 2h ago

    FedRAMP's VDR and VER rules take effect for cloud service offerings

    Legal Policy Action Update

    The Vulnerability Detection and Response and Verification and Evidence rules become mandatory for cloud service offerings obtaining or maintaining FedRAMP Certification, replacing the old monthly-scan-and-POA&M model with tiered detection, remediation clocks ranging from 192 days to 12 hours, and an Assume It's Automatable evidence standard.

    Show sources
  3. 24.09.2026 17:02 1 articles · 2h ago

    FedRAMP's corrective-action grace period ends for VDR and VER compliance

    Legal Policy Action Update

    Cloud service offerings operating under a corrective action plan reach the end of the grace period for FedRAMP's mandatory VDR and VER rules, closing the March 7, 2027 extension stated in the notice.

    Show sources