# VER-TFR-MAV — Mark Accepted Vulnerabilities

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /requirement/ver-tfr-mav

Vulnerability Evaluation and Reporting (`VER`) · group all · subset TFR
Force: MUST

## Statement

Providers MUST categorize any vulnerability that is not or will not be fully mitigated or remediated within 192 days of evaluation as an accepted vulnerability.

## Who it binds

- Providers

## Certification classes

_Applies regardless of certification class._

## Which certifications it binds

Certification type: 20x, Rev5
Path: Program, Agency

## Machine-readable form

_This requirement names no JSON schema. FRC-CSO-JSN binds a provider to a schema only where a rule contains one._

## Artifacts

_No requirement-specific artifact is named._

## Timeframes

- {"requirementId":"VER-TFR-MAV","documentKey":"VER","documentName":"Vulnerability Evaluation and Reporting","group":"all","subset":"TFR","name":"Mark Accepted Vulnerabilities","statement":"Providers MUST categorize any vulnerability that is not or will not be fully mitigated or remediated within 192 days of evaluation as an accepted vulnerability.","force":"MUST","affects":["Providers"],"class":null,"num":192,"type":"days","sortKey":4608}

## Notifications

_This requirement demands no notification._
