FedRAMP mandates VDR and VER rules for cloud service offerings
Public Sector Action
Summary
Hide ▲
Show ▼
FedRAMP issued mandatory VDR and VER rules for FedRAMP Certification, forcing cloud service offerings to meet new detection, remediation, and evidence requirements on a fixed timeline. The change takes effect on December 7, 2026, with a March 7, 2027 grace period for offerings on a corrective action plan. It replaces the older monthly-scan-and-POA&M model with tighter, class-based validation and response obligations. Cloud providers now have to operationalize compliance as an ongoing control program rather than a periodic paperwork exercise.
Related Happenings
CISA orders federal agencies to patch Linux kernel flaws
Public Sector Action
H score30
First: 21.09.2026 23:12
Last: 21.09.2026 23:12
Sources 1
About this happening:
CISA ordered federal agencies to apply security updates and mitigations for three Linux kernel flaws by end of today, putting the response on an urgent federal...
CISA orders federal agencies to patch Linux kernel flaws
Public Sector ActionAbout this happening: CISA ordered federal agencies to apply security updates and mitigations for three Linux kernel flaws by end of today, putting the response on an urgent federal...
Linux kernel active exploitation wave (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)
Exploitation Wave
H score35
First: 21.09.2026 23:12
Last: 21.09.2026 23:12
Sources 1
About this happening:
CISA has warned that three Linux kernel vulnerabilities are being exploited in attacks, including one critical flaw, creating immediate risk for exposed systems. The w...
Linux kernel active exploitation wave (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)
Exploitation WaveAbout this happening: CISA has warned that three Linux kernel vulnerabilities are being exploited in attacks, including one critical flaw, creating immediate risk for exposed systems. The w...
CISA adds Linux kernel flaws to KEV catalog under BOD 26-04
Public Sector Action
H score36
First: 19.09.2026 09:24
Last: 19.09.2026 09:24
Sources 1
About this happening:
CISA added three Linux kernel flaws to its KEV catalog after evidence of active exploitation, forcing federal remediation prioritization. Under BOD 26-04, FC...
CISA adds Linux kernel flaws to KEV catalog under BOD 26-04
Public Sector ActionAbout this happening: CISA added three Linux kernel flaws to its KEV catalog after evidence of active exploitation, forcing federal remediation prioritization. Under BOD 26-04, FC...
Linux kernel actively exploited flaws (multiple vulnerabilities)
Vulnerability
H score46
First: 19.09.2026 09:24
Last: 19.09.2026 09:24
Sources 1
About this happening:
Three Linux kernel vulnerabilities—CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964—were added to CISA KEV after evidence of active exploitation. The fla...
Linux kernel actively exploited flaws (multiple vulnerabilities)
VulnerabilityAbout this happening: Three Linux kernel vulnerabilities—CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964—were added to CISA KEV after evidence of active exploitation. The fla...
CISA BOD 26-04 patch directive for CVE-2026-16232
Public Sector Action
H score37
First: 23.07.2026 11:13
Last: 23.07.2026 11:13
Sources 1
About this happening:
CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25*...
CISA BOD 26-04 patch directive for CVE-2026-16232
Public Sector ActionAbout this happening: CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25*...
Timeline
-
24.09.2026 17:02 1 articles · 2h ago
FedRAMP makes VDR and VER mandatory for cloud service offerings
Initial DisclosureFedRAMP's notice responding to CISA's BOD 26-04 announces that the Vulnerability Detection and Response rules will be mandatory for all cloud service offerings obtaining or maintaining FedRAMP Certification, with a grace period through March 7, 2027 for offerings operating under a corrective action plan.
Show sources
- FedRAMP VDR & VER: Daily Scans Are Only the Beginning — www.bleepingcomputer.com — 24.09.2026 17:02
-
24.09.2026 17:02 2 articles · 2h ago
FedRAMP's VDR and VER rules take effect for cloud service offerings
Legal Policy Action UpdateThe Vulnerability Detection and Response and Verification and Evidence rules become mandatory for cloud service offerings obtaining or maintaining FedRAMP Certification, replacing the old monthly-scan-and-POA&M model with tiered detection, remediation clocks ranging from 192 days to 12 hours, and an Assume It's Automatable evidence standard.
Show sources
- FedRAMP VDR & VER: Daily Scans Are Only the Beginning — www.bleepingcomputer.com — 24.09.2026 17:02
- FedRAMP VDR & VER: Daily Scans Are Only the Beginning — www.bleepingcomputer.com — 24.09.2026 17:02
-
24.09.2026 17:02 1 articles · 2h ago
FedRAMP's corrective-action grace period ends for VDR and VER compliance
Legal Policy Action UpdateCloud service offerings operating under a corrective action plan reach the end of the grace period for FedRAMP's mandatory VDR and VER rules, closing the March 7, 2027 extension stated in the notice.
Show sources
- FedRAMP VDR & VER: Daily Scans Are Only the Beginning — www.bleepingcomputer.com — 24.09.2026 17:02