Skip to content

Keyboard shortcuts

Go

  • Scope — the control cataloggm
  • Plan — your last certification classgp
  • Collect — the recipe indexgc
  • The control you are workinggw
  • Startgh

Move

  • Next rowj
  • Previous rowk
  • Previous in this run[
  • Next in this run]
  • Filter this page's list/
  • Search everythingK

Act

  • Copy this page's permalinky
  • Toggle dark moded
  • This sheet?

Rows are whatever the current page lists — controls on Scope, recipes on Plan and Collect.

Control index

allvaries by class: a, b, c, d

The statement for this requirement varies by certification class — see the per-class deadlines below.

Who it binds

Controls whose FedRAMP guidance points at VER (10)

Their guidance names the Vulnerability Evaluation and Reporting rules as a whole, not this requirement — so this is where to read from, not a mapping to this clause. Controls no KSI reaches have no page and are not listed.

Deadlines (4)

ClassTimeframeStatement
D2 daysProviders with Class D Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 2 days of detection.
C5 daysProviders with Class C Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 5 days of detection.
B7 daysProviders with Class B Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 7 days of detection.
A14 daysProviders with Class A Certifications SHOULD evaluate ALL vulnerabilities as required by VER-EVA (Evaluation) within 14 days of detection.

Which certifications it binds

Certification type
20x · Rev5
Path
Program · Agency

Evidence this requirement demands

No requirement-specific artifacts — but the defaults below still apply.

5 default artifacts owed by every FRR requirement
  • Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.
  • Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.
  • Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.
  • Independent verification.
  • Independent validation.

Group all, subset TFR of Vulnerability Evaluation and Reporting. See all obligations on /obligations or the full evidence plan on /evidence.