# VER-EVA-GRV — Group Vulnerabilities

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /requirement/ver-eva-grv

Vulnerability Evaluation and Reporting (`VER`) · group all · subset EVA
Force: SHOULD

## Statement

Providers SHOULD evaluate detected vulnerabilities, considering the context of the cloud service offering, to identify logical groupings of affected information resources that may improve the efficiency and effectiveness of vulnerability response by consolidating further activity; FedRAMP Vulnerability Detection and Response rules are then applied to these consolidated groupings of vulnerabilities instead of each individual detected instance.

## Who it binds

- Providers

## Certification classes

_Applies regardless of certification class._

## Which certifications it binds

Certification type: 20x, Rev5
Path: Program, Agency

## Machine-readable form

_This requirement names no JSON schema. FRC-CSO-JSN binds a provider to a schema only where a rule contains one._

## Artifacts

_No requirement-specific artifact is named._

## Timeframes

_This requirement states no deadline._

## Notifications

_This requirement demands no notification._
