Skip to content

Security1 publisher2 min readPublished

FedRAMP's December 7 rules shrink the worst-case remediation window to 12 hours

FedRAMP will require daily vulnerability scans at Class D and fixes in as little as 12 hours from December 7, 2026, with a grace period to March 7, 2027. Failures in the detection pipeline now count as vulnerabilities themselves.

The Watch · Security desk

Illustration accompanying FedRAMP's December 7 rules shrink the worst-case remediation window to 12 hours

What happened

  • FedRAMP's notice responding to CISA's BOD 26-04 makes the Vulnerability Detection and Response rules mandatory for all cloud service offerings obtaining or maintaining certification on December 7, 2026.
  • Detection frequency is now set by certification class under VDR-TFR-PSD: machine-based resources scanned at least every 14 days at Class A, every 7 at B, every 3 at C, and at least daily at Class D.
  • Remediation deadlines under VDR-TFR-PVR are keyed to a vulnerability's PAIN rating and its exploitability, running from 192 days at the low end down to 12 hours at the extreme.
  • Plans of Action & Milestones have been eliminated entirely, FedRAMP writes, and replaced with a list of Accepted Weaknesses.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint A 12-hour fix deadline has to be met by someone who can be paged and who owns the change, including over a holiday weekend, so providers running vulnerability response through business-hours queues need a rota before they need a scanner.
  • exposure The system that generates compliance evidence is itself assessable, so a detection pipeline that stops quietly becomes a finding.
  • decision Programs have to decide whether to build for December 7 or for the 20x transition behind it, because the January 1 and June 11, 2027 dates land on whatever they ship first.

Take the two ends of the remediation table. The loosest deadline in VDR-TFR-PVR is 192 days, which is 4,608 hours; the tightest is 12 hours, so one rule spans a factor of 384 between its slowest and fastest clock [16]. The 12-hour case is narrow: Class D, PAIN-5, likely exploited and immediately remotely exploitable [6].

A Class D offering scans machine-based resources at least 365 times a year where a Class A offering scans about 26 times, a factor of 14 for the same asset inventory [17]. Machine verification and validation runs at least monthly for Rev5 holders and as often as every three days at the higher 20x classes [5].

A 12-hour deadline is not something a business-hours ticket queue absorbs. BleepingComputer's explainer describes it as a paging and ownership question, and one that has to hold on a holiday weekend [7]. Two other rules pull in the same direction. VER-EVA-AIA requires providers, in FedRAMP's words, "to assume exploits are automatable by default, unless they have evidence providing otherwise" [8]. Each deferral needs a defensible artifact behind it, produced at volume and on the same clock as the fixes [21]. VDR-CSO-FAV puts the pipeline itself in scope: providers "[MUST] treat problems or failures with their vulnerability detection and response processes as vulnerabilities" [9].

The System Security Plan and its appendices give way to a Certification Package Overview and a Security Decision Record [11]. Continuous Monitoring becomes Ongoing Certification, renamed, FedRAMP explains, because "continuous monitoring" had "become synonymous with 'vulnerability scans'" and the new requirements are "far broader than before" [12].

The rules become mandatory for all stakeholders on January 1, 2027, and FedRAMP stops accepting new Rev5 applications on June 11, 2027 [14]. FedRAMP calls Rev5 "a legacy FedRAMP Certification process that is being replaced entirely by FedRAMP 20x" and says providers "are expected to follow new rules and adopt new FedRAMP Practices from FedRAMP 20x into their FedRAMP Rev5 Certified cloud service offerings" [13]. Offerings operating under a corrective action plan get 90 more days, to March 7, 2027 [2][18].

BleepingComputer's argument is that work scoped as "get through December" gets rebuilt in 2027, while work scoped as the first slice of continuous validation carries over [20]. The Consolidated Rules for 2026 reorganized the program into the rulesets that December 7 draws from [19]. All rule language quoted here is FedRAMP's, as reproduced in that explainer.

What to watch

  • Whether FedRAMP publishes how offerings are assigned to Class A through D, and how PAIN-5 is scored, since those two inputs decide who lands on the 12-hour clock.
  • Whether the March 7, 2027 grace period for offerings under a corrective action plan is extended or applied narrowly.
  • Whether the June 11, 2027 cutoff for new Rev5 applications holds, and what happens to Rev5 offerings that have not adopted 20x practices by then.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories