# VER-AGM-MAP — Maintain Agency Plans of Action and Milestones

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /requirement/ver-agm-map

Vulnerability Evaluation and Reporting (`VER`) · group all · subset AGM
Force: SHOULD

## Statement

Agencies SHOULD use vulnerability information reported by the Provider to maintain Plans of Action and Milestones for agency security programs when relevant according to agency security policies (such as if the agency takes action to mitigate the risk of exploitation or authorized the continued use of a cloud service with accepted vulnerabilities that put agency information systems at risk).

## Who it binds

- Agencies

## Certification classes

_Applies regardless of certification class._

## Which certifications it binds

Certification type: 20x, Rev5
Path: Program, Agency

## Machine-readable form

_This requirement names no JSON schema. FRC-CSO-JSN binds a provider to a schema only where a rule contains one._

## Artifacts

_No requirement-specific artifact is named._

## Timeframes

_This requirement states no deadline._

## Notifications

_This requirement demands no notification._
