FedRAMP continuous monitoring no longer exists under that name. The FedRAMP Consolidated Rules for 2026, effective 4 July 2026, renamed it Ongoing Certification and rebuilt it as six assurance rulesets containing 76 rules, most of them keyed to the provider’s Certification Class. The monthly scan upload and the POA&M are gone; in their place are a quarterly Ongoing Certification Report to every agency using the service, vulnerability detection and response on class-specific timeframes, incident reports on clocks as short as 15 minutes, and a significant change framework with defined categories. This guide explains what FedRAMP continuous monitoring has become, ruleset by ruleset, what the timeframes are for each class, and what a provider certified under the old model has to change before its grace period ends.

From FedRAMP continuous monitoring to Ongoing Certification
FedRAMP’s 2026 guidance draws the provider’s journey as three stages: Preparation, Initial Implementation, Ongoing Certification. The third stage is where the certification lives, and FedRAMP’s own words on the transition are candid — “everyone knows that all the work done so far was just to get ready for everything that comes after”. Ongoing Certification is materially wider than the continuous monitoring it replaced. The old model was a monthly vulnerability scan submission, a POA&M for open findings, an annual assessment and a significant change request process routed through FedRAMP. The new model pushes the reporting to agencies directly, sets timeframes by class, and eliminates the POA&M in favour of an Accepted Weaknesses List and accepted vulnerabilities disclosed in the quarterly report. Our guide to what FedRAMP 20x changed covers the path; this post covers the ongoing rules.
The 20x assurance rulesets are six, with 76 applicable rules. Rev5 has a parallel set. The rule IDs below are from the 20x rulesets, which also apply to Rev5 offerings where the Rev5 ruleset index adopts them.
| Ruleset | ID | Rules | What it governs |
|---|---|---|---|
| Addressing FedRAMP Communication | AFC | 8 | A reliable security contact route, urgent communications, response-time testing, routing separate from support channels |
| Collaborative Continuous Monitoring | CCM | 17 | The quarterly Ongoing Certification Report and Quarterly Reviews |
| Incident Evaluation and Communication | IEC | 7 | Evaluating FedRAMP Reportable Incidents and reporting them on PAIN-rated clocks |
| Independent Verification and Validation | IVV | 9 | Expectations for independent assessments |
| Significant Change Notification | SCN | 16 | Categories of significant change and how agencies are kept informed |
| Vulnerability Evaluation and Reporting | VER | 19 | Deciding which vulnerabilities are likely to affect federal customers and reporting their status |
A seventh ruleset, Vulnerability Detection and Response (VDR), sits beside them and carries the class-based timeframes for finding and fixing vulnerabilities.
The Ongoing Certification Report (CCM)
Rule CCM-OCR-AVL is the centre of the new model. Providers MUST supply an Ongoing Certification Report to all necessary parties every 3 months, covering the whole period since the previous report, in a consistent human-readable format, with a JSON version validating against FedRAMP’s schema. It must include high-level summaries of, where applicable:
- Changes to FedRAMP Certification Data, and planned changes over at least the next 3 months
- Accepted vulnerabilities
- Transformative changes
- Updated recommendations or best practices for security, configuration or usage of the offering
- A list of all agencies directly using the product
- FedRAMP Reportable Incidents, or an attestation that none occurred, with lessons learned and changes made
Around the report sit rules on cadence and feedback: the target date of the next report must be published with the offering’s public certification data (CCM-OCR-NRD); providers MUST offer an asynchronous feedback mechanism (CCM-OCR-FBM) and publish an anonymized summary of the questions and answers (CCM-OCR-AFS); reports SHOULD run on a regular 3-month cycle (CCM-OCR-SOR) and MUST NOT irresponsibly disclose sensitive information (CCM-OCR-LSI).
Quarterly Reviews by class
The Quarterly Review — a synchronous meeting open to all necessary parties to walk through the report — is where class first bites. Under CCM-QTR-MTG, Class A providers MAY host one, Class B SHOULD, and Class C and Class D MUST, every 3 months. Where held, providers MUST supply a registration link or calendar file (CCM-QTR-REG), MUST publish the next review date (CCM-QTR-NRD), and SHOULD schedule it at least 3 business days and within 10 business days after releasing the report (CCM-QTR-SAR). Recordings SHOULD be supplied to necessary parties and MAY be shared more widely only with all agency information removed.
Vulnerability detection and response by class (VDR)
This is where the old FedRAMP continuous monitoring scan cadence became something else. Under VDR, providers MUST “systematically, persistently, and promptly discover and identify vulnerabilities” using assessment, scanning, threat intelligence, disclosure programs, bug bounties, penetration testing, incident response, automated control testing and supply chain monitoring — and MUST treat failures in the detection process itself as vulnerabilities. Non-machine-based information resources must be verified at least every 3 months (VDR-TFR-NMV). The detection cadence for machine resources scales with class:
| Detection timeframe | Class A | Class B | Class C | Class D |
|---|---|---|---|---|
| Resources likely to drift (VDR-TFR-PDD) | Every 3 months | Every month | Every 14 days | Every 7 days |
| Resources not likely to drift (VDR-TFR-PCD) | Every 6 months | Every 6 months | Every month | Every month |
Remediation timeframes (VDR-TFR-PVR) run from evaluation and depend on three things: the Potential Agency Impact N-rating, or PAIN, from 5 (highest) down; whether the vulnerability is a Likely Exploitable Vulnerability (LEV); and whether it is Internet-Reachable (IRV). The Class A and B tables are identical; Class C and D tighten.
| PAIN rating | Class A/B: LEV + internet-reachable | Class A/B: LEV, not reachable | Class A/B: not likely exploitable | Class D: LEV + internet-reachable |
|---|---|---|---|---|
| PAIN-5 | 4 days | 8 days | 32 days | 12 hours |
| PAIN-4 | 8 days | 32 days | 64 days | 2 days |
| PAIN-3 | 32 days | 64 days | 192 days | 8 days |
| PAIN-2 | 96 days | 160 days | 192 days | — |
Class C sits between: 2 days for a PAIN-5 internet-reachable LEV, 4 days for PAIN-4, 16 for PAIN-3, 48 for PAIN-2. The old FedRAMP “30/90/180 days by CVSS severity” rule is gone; severity is replaced by agency impact, exploitability and reachability, all of which the provider evaluates and must be able to defend. VER warns that providers “who regularly evaluate vulnerabilities as not likely exploitable without careful consideration are more likely to suffer from an adverse impact”, and that where this is done recklessly or deliberately “such actions will have a negative impact on a provider’s FedRAMP Certification”.
Incident reporting by class (IEC)
FedRAMP Reportable Incidents are reported to FedRAMP by email, to agency customers through their own procedures, and to all necessary parties through the provider’s trust center, with a JSON incident report validating against the schema. Under IEC-CSO-IIR the Initial Incident Report must carry the federal incident coordinator’s contact, the tracking identifier, a description, a timeline with detection time and evaluation time, the estimated PAIN rating with its reasoning, functional impact to agencies, the recovery plan and the list of likely affected agencies. Incidents are treated as PAIN-5 unless promptly rated otherwise. The clock:
| Initial Incident Report | Class A (SHOULD) | Class B (MUST) | Class C (MUST) | Class D (MUST) |
|---|---|---|---|---|
| PAIN-5, -4, -3 | 6 hours | 6 hours | 1 hour | 15 minutes |
| PAIN-2 | 1 business day | 1 business day | 24 hours | — |
| PAIN-1 | 1 business day | 1 business day | 1 business day | — |
Significant changes (SCN)
The 16 SCN rules replace the significant change request that FedRAMP continuous monitoring used to route to FedRAMP for approval. Changes are organized into categories so that agencies “can understand the expected risk and make authorization decisions accordingly”, and notifications go to the agencies rather than to FedRAMP as a gate. Transformative changes also appear in the quarterly report. The practical shift is from asking permission to giving notice on a defined schedule — which means the provider needs a change classification procedure that maps its own release types to FedRAMP’s categories before the first quarterly report is due.
What a provider on the old FedRAMP continuous monitoring model has to change
The deadlines are fixed: active 20x offerings had to comply by 1 January 2027; the first independent assessment started after that date ends the grace period; and every grace period in the program expires on 1 February 2028, when non-compliant offerings lose certification with no extensions. Between now and then a provider on the old continuous monitoring model needs:
- The two core documents, in both forms. A Certification Package Overview and a Security Decision Record, human-readable and JSON, replacing the SSP. Our guide to the two documents that replaced the SSP covers them.
- An Accepted Weaknesses List instead of a POA&M. Open findings become accepted weaknesses with rationale, disclosed in the quarterly report. The POA&M format and its monthly upload end. See our guide to the POA&M and what replaced it.
- A quarterly reporting cycle with an agency distribution list. The Ongoing Certification Report goes to all necessary parties, which means the provider must know and reach every agency using the service.
- Vulnerability evaluation that records PAIN, exploitability and reachability. The remediation clocks depend on all three, and the assessor will test the evaluations.
- Incident reporting rebuilt around PAIN clocks. Including the trust-center route to all necessary parties and the JSON report.
- A tested security contact route. AFC requires urgent communications to reach the right people and response times to be tested — separate from the support desk.
- Organizational parameters. FedRAMP removed most of its assigned parameter values; the provider now sets and documents its own.
Frequently asked questions
Is FedRAMP continuous monitoring still required?
Under its new name, Ongoing Certification, yes — and it is wider. The Consolidated Rules for 2026 replaced the monthly scan and POA&M model with quarterly Ongoing Certification Reports, class-based vulnerability timeframes, PAIN-rated incident reporting and a significant change notification framework.
How often is the Ongoing Certification Report due?
Every 3 months, to all necessary parties, covering the whole period since the last report, in human-readable form with a JSON version (rule CCM-OCR-AVL). The next report date must be published with the offering’s certification data.
What are the vulnerability remediation deadlines?
They run from evaluation and depend on class, Potential Agency Impact rating, exploitability and internet reachability. For a Class A or B provider a PAIN-5 internet-reachable likely-exploitable vulnerability has 4 days; for Class D it has 12 hours; a PAIN-3 not-likely-exploitable vulnerability has 192 days at Class A or B.
Does FedRAMP still approve significant changes?
The 2026 model replaces the approval request with categorized notifications to agency customers under the SCN ruleset, with transformative changes also summarized in the quarterly report.
When does the old model stop being accepted?
Active 20x offerings had to comply by 1 January 2027, with the grace period ending at the first independent assessment started after that date. All grace periods expire on 1 February 2028, with no extensions.
Where this leaves you
Stop maintaining FedRAMP continuous monitoring and start building Ongoing Certification: a quarterly report and its distribution list, vulnerability evaluation that records PAIN, exploitability and reachability against the class table, incident reporting on the class clock, a change classification procedure, and a tested security contact route. Pick the class the rules put you in, and read every SHOULD as a MUST you will be asked about at the next assessment.
References
- FedRAMP Consolidated Rules for 2026: Collaborative Continuous Monitoring — The CCM ruleset: Ongoing Certification Report and Quarterly Review rules.
- FedRAMP Consolidated Rules for 2026: Vulnerability Detection and Response — The VDR ruleset: detection cadence and PAIN remediation timeframes by class.
- FedRAMP Consolidated Rules for 2026: Incident Evaluation and Communication — The IEC ruleset: Initial Incident Report content and clocks by class.
- FedRAMP Consolidated Rules for 2026: Assurance Rulesets — The six assurance rulesets and their rule counts.
More on FedRAMP
- FedRAMP continuous monitoring in 2026 — you are here
- FedRAMP authorization: what FedRAMP 20x changed
- What replaced the FedRAMP SSP
- The POA&M and what replaced it
- The FedRAMP compliance checklist for 2027
- FedRAMP certification cost in 2026
The Ongoing Certification Report and Plan, the Accepted Weaknesses List, the Vulnerability Detail Report, the Incident Report and the Significant Change Notification — each with its JSON companion — are in the FedRAMP Toolkit (52 templates for the Consolidated Rules 2026), or start with the free templates.