Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

Control index

allMUST
Providers MUST report vulnerability detection and response activity (including persistent verification and validation) to all necessary parties persistently, summarizing ALL activity since the previous report; these reports are FedRAMP Certification Data and are subject to FedRAMP Certification Data Sharing rules.

Who it binds

Controls whose FedRAMP guidance points at VER (10)

Their guidance names the Vulnerability Evaluation and Reporting rules as a whole, not this requirement — so this is where to read from, not a mapping to this clause. Controls no KSI reaches have no page and are not listed.

Which certifications it binds

Certification type
20x · Rev5
Path
Program · Agency

Machine-readable form

FedRAMP Vulnerability Detail Report (VER-RPT-VDT)

https://fedramp.gov/schemas/fedramp-vulnerability-detail-report-schema-2026-06-24.json

Evidence this requirement demands

No requirement-specific artifacts — but the defaults below still apply.

5 default artifacts owed by every FRR requirement
  • Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.
  • Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.
  • Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.
  • Independent verification.
  • Independent validation.

Group all, subset RPT of Vulnerability Evaluation and Reporting. See all obligations on /obligations or the full evidence plan on /evidence.