# VDR-TFR-KEV — Remediate KEVs

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /requirement/vdr-tfr-kev

Vulnerability Detection and Response (`VDR`) · group all · subset TFR
Force: SHOULD

## Statement

Providers SHOULD remediate Known Exploited Vulnerabilities according to the due dates in the CISA Known Exploited Vulnerabilities Catalog (even if the vulnerability has been fully mitigated) as required by CISA Binding Operational Directive (BOD) 26-04 or any successor guidance from CISA.

## Who it binds

- Providers

## Certification classes

_Applies regardless of certification class._

## Which certifications it binds

Certification type: 20x, Rev5
Path: Program, Agency

## Machine-readable form

_This requirement names no JSON schema. FRC-CSO-JSN binds a provider to a schema only where a rule contains one._

## Artifacts

_No requirement-specific artifact is named._

## Timeframes

_This requirement states no deadline._

## Notifications

_This requirement demands no notification._
