Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

FedRAMP continuous monitoring explained

FedRAMP Continuous Monitoring in 2026: A Clear Guide to 6 Rulesets

FedRAMP continuous monitoring no longer exists under that name. The FedRAMP Consolidated Rules for 2026, effective 4 July 2026, renamed it Ongoing Certification and rebuilt it as six assurance rulesets containing 76 rules, most of them keyed to the provider’s Certification Class. The monthly scan upload and the POA&M are gone; in their place are a quarterly Ongoing Certification Report to every agency using the service, vulnerability detection and response on class-specific timeframes, incident reports on clocks as short as 15 minutes, and a significant change framework with defined categories. This guide explains what FedRAMP continuous monitoring has become, ruleset by ruleset, what the timeframes are for each class, and what a provider certified under the old model has to change before its grace period ends.

FedRAMP continuous monitoring in 2026: the six Ongoing Certification rulesets
Ongoing Certification: 76 rules across AFC, CCM, IEC, IVV, SCN and VER, with vulnerability detection and response timeframes set by Certification Class.

From FedRAMP continuous monitoring to Ongoing Certification

FedRAMP’s 2026 guidance draws the provider’s journey as three stages: Preparation, Initial Implementation, Ongoing Certification. The third stage is where the certification lives, and FedRAMP’s own words on the transition are candid — “everyone knows that all the work done so far was just to get ready for everything that comes after”. Ongoing Certification is materially wider than the continuous monitoring it replaced. The old model was a monthly vulnerability scan submission, a POA&M for open findings, an annual assessment and a significant change request process routed through FedRAMP. The new model pushes the reporting to agencies directly, sets timeframes by class, and eliminates the POA&M in favour of an Accepted Weaknesses List and accepted vulnerabilities disclosed in the quarterly report. Our guide to what FedRAMP 20x changed covers the path; this post covers the ongoing rules.

The 20x assurance rulesets are six, with 76 applicable rules. Rev5 has a parallel set. The rule IDs below are from the 20x rulesets, which also apply to Rev5 offerings where the Rev5 ruleset index adopts them.

Ruleset ID Rules What it governs
Addressing FedRAMP Communication AFC 8 A reliable security contact route, urgent communications, response-time testing, routing separate from support channels
Collaborative Continuous Monitoring CCM 17 The quarterly Ongoing Certification Report and Quarterly Reviews
Incident Evaluation and Communication IEC 7 Evaluating FedRAMP Reportable Incidents and reporting them on PAIN-rated clocks
Independent Verification and Validation IVV 9 Expectations for independent assessments
Significant Change Notification SCN 16 Categories of significant change and how agencies are kept informed
Vulnerability Evaluation and Reporting VER 19 Deciding which vulnerabilities are likely to affect federal customers and reporting their status

A seventh ruleset, Vulnerability Detection and Response (VDR), sits beside them and carries the class-based timeframes for finding and fixing vulnerabilities.

The Ongoing Certification Report (CCM)

Rule CCM-OCR-AVL is the centre of the new model. Providers MUST supply an Ongoing Certification Report to all necessary parties every 3 months, covering the whole period since the previous report, in a consistent human-readable format, with a JSON version validating against FedRAMP’s schema. It must include high-level summaries of, where applicable:

  • Changes to FedRAMP Certification Data, and planned changes over at least the next 3 months
  • Accepted vulnerabilities
  • Transformative changes
  • Updated recommendations or best practices for security, configuration or usage of the offering
  • A list of all agencies directly using the product
  • FedRAMP Reportable Incidents, or an attestation that none occurred, with lessons learned and changes made

Around the report sit rules on cadence and feedback: the target date of the next report must be published with the offering’s public certification data (CCM-OCR-NRD); providers MUST offer an asynchronous feedback mechanism (CCM-OCR-FBM) and publish an anonymized summary of the questions and answers (CCM-OCR-AFS); reports SHOULD run on a regular 3-month cycle (CCM-OCR-SOR) and MUST NOT irresponsibly disclose sensitive information (CCM-OCR-LSI).

Quarterly Reviews by class

The Quarterly Review — a synchronous meeting open to all necessary parties to walk through the report — is where class first bites. Under CCM-QTR-MTG, Class A providers MAY host one, Class B SHOULD, and Class C and Class D MUST, every 3 months. Where held, providers MUST supply a registration link or calendar file (CCM-QTR-REG), MUST publish the next review date (CCM-QTR-NRD), and SHOULD schedule it at least 3 business days and within 10 business days after releasing the report (CCM-QTR-SAR). Recordings SHOULD be supplied to necessary parties and MAY be shared more widely only with all agency information removed.

Vulnerability detection and response by class (VDR)

This is where the old FedRAMP continuous monitoring scan cadence became something else. Under VDR, providers MUST “systematically, persistently, and promptly discover and identify vulnerabilities” using assessment, scanning, threat intelligence, disclosure programs, bug bounties, penetration testing, incident response, automated control testing and supply chain monitoring — and MUST treat failures in the detection process itself as vulnerabilities. Non-machine-based information resources must be verified at least every 3 months (VDR-TFR-NMV). The detection cadence for machine resources scales with class:

Detection timeframe Class A Class B Class C Class D
Resources likely to drift (VDR-TFR-PDD) Every 3 months Every month Every 14 days Every 7 days
Resources not likely to drift (VDR-TFR-PCD) Every 6 months Every 6 months Every month Every month

Remediation timeframes (VDR-TFR-PVR) run from evaluation and depend on three things: the Potential Agency Impact N-rating, or PAIN, from 5 (highest) down; whether the vulnerability is a Likely Exploitable Vulnerability (LEV); and whether it is Internet-Reachable (IRV). The Class A and B tables are identical; Class C and D tighten.

PAIN rating Class A/B: LEV + internet-reachable Class A/B: LEV, not reachable Class A/B: not likely exploitable Class D: LEV + internet-reachable
PAIN-5 4 days 8 days 32 days 12 hours
PAIN-4 8 days 32 days 64 days 2 days
PAIN-3 32 days 64 days 192 days 8 days
PAIN-2 96 days 160 days 192 days

Class C sits between: 2 days for a PAIN-5 internet-reachable LEV, 4 days for PAIN-4, 16 for PAIN-3, 48 for PAIN-2. The old FedRAMP “30/90/180 days by CVSS severity” rule is gone; severity is replaced by agency impact, exploitability and reachability, all of which the provider evaluates and must be able to defend. VER warns that providers “who regularly evaluate vulnerabilities as not likely exploitable without careful consideration are more likely to suffer from an adverse impact”, and that where this is done recklessly or deliberately “such actions will have a negative impact on a provider’s FedRAMP Certification”.

Incident reporting by class (IEC)

FedRAMP Reportable Incidents are reported to FedRAMP by email, to agency customers through their own procedures, and to all necessary parties through the provider’s trust center, with a JSON incident report validating against the schema. Under IEC-CSO-IIR the Initial Incident Report must carry the federal incident coordinator’s contact, the tracking identifier, a description, a timeline with detection time and evaluation time, the estimated PAIN rating with its reasoning, functional impact to agencies, the recovery plan and the list of likely affected agencies. Incidents are treated as PAIN-5 unless promptly rated otherwise. The clock:

Initial Incident Report Class A (SHOULD) Class B (MUST) Class C (MUST) Class D (MUST)
PAIN-5, -4, -3 6 hours 6 hours 1 hour 15 minutes
PAIN-2 1 business day 1 business day 24 hours
PAIN-1 1 business day 1 business day 1 business day

Significant changes (SCN)

The 16 SCN rules replace the significant change request that FedRAMP continuous monitoring used to route to FedRAMP for approval. Changes are organized into categories so that agencies “can understand the expected risk and make authorization decisions accordingly”, and notifications go to the agencies rather than to FedRAMP as a gate. Transformative changes also appear in the quarterly report. The practical shift is from asking permission to giving notice on a defined schedule — which means the provider needs a change classification procedure that maps its own release types to FedRAMP’s categories before the first quarterly report is due.

What a provider on the old FedRAMP continuous monitoring model has to change

The deadlines are fixed: active 20x offerings had to comply by 1 January 2027; the first independent assessment started after that date ends the grace period; and every grace period in the program expires on 1 February 2028, when non-compliant offerings lose certification with no extensions. Between now and then a provider on the old continuous monitoring model needs:

  1. The two core documents, in both forms. A Certification Package Overview and a Security Decision Record, human-readable and JSON, replacing the SSP. Our guide to the two documents that replaced the SSP covers them.
  2. An Accepted Weaknesses List instead of a POA&M. Open findings become accepted weaknesses with rationale, disclosed in the quarterly report. The POA&M format and its monthly upload end. See our guide to the POA&M and what replaced it.
  3. A quarterly reporting cycle with an agency distribution list. The Ongoing Certification Report goes to all necessary parties, which means the provider must know and reach every agency using the service.
  4. Vulnerability evaluation that records PAIN, exploitability and reachability. The remediation clocks depend on all three, and the assessor will test the evaluations.
  5. Incident reporting rebuilt around PAIN clocks. Including the trust-center route to all necessary parties and the JSON report.
  6. A tested security contact route. AFC requires urgent communications to reach the right people and response times to be tested — separate from the support desk.
  7. Organizational parameters. FedRAMP removed most of its assigned parameter values; the provider now sets and documents its own.

Frequently asked questions

Is FedRAMP continuous monitoring still required?
Under its new name, Ongoing Certification, yes — and it is wider. The Consolidated Rules for 2026 replaced the monthly scan and POA&M model with quarterly Ongoing Certification Reports, class-based vulnerability timeframes, PAIN-rated incident reporting and a significant change notification framework.

How often is the Ongoing Certification Report due?
Every 3 months, to all necessary parties, covering the whole period since the last report, in human-readable form with a JSON version (rule CCM-OCR-AVL). The next report date must be published with the offering’s certification data.

What are the vulnerability remediation deadlines?
They run from evaluation and depend on class, Potential Agency Impact rating, exploitability and internet reachability. For a Class A or B provider a PAIN-5 internet-reachable likely-exploitable vulnerability has 4 days; for Class D it has 12 hours; a PAIN-3 not-likely-exploitable vulnerability has 192 days at Class A or B.

Does FedRAMP still approve significant changes?
The 2026 model replaces the approval request with categorized notifications to agency customers under the SCN ruleset, with transformative changes also summarized in the quarterly report.

When does the old model stop being accepted?
Active 20x offerings had to comply by 1 January 2027, with the grace period ending at the first independent assessment started after that date. All grace periods expire on 1 February 2028, with no extensions.

Where this leaves you

Stop maintaining FedRAMP continuous monitoring and start building Ongoing Certification: a quarterly report and its distribution list, vulnerability evaluation that records PAIN, exploitability and reachability against the class table, incident reporting on the class clock, a change classification procedure, and a tested security contact route. Pick the class the rules put you in, and read every SHOULD as a MUST you will be asked about at the next assessment.

References

More on FedRAMP

The Ongoing Certification Report and Plan, the Accepted Weaknesses List, the Vulnerability Detail Report, the Incident Report and the Significant Change Notification — each with its JSON companion — are in the FedRAMP Toolkit (52 templates for the Consolidated Rules 2026), or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.