# VER-TFR-MHR — Monthly Activity Report

> FedRAMP Consolidated Rules for 2026 v2026.07.14.01 · updated 2026-07-14
> Canonical page: /requirement/ver-tfr-mhr

Vulnerability Evaluation and Reporting (`VER`) · group all · subset TFR
Force: MUST

## Statement

Providers MUST report vulnerability detection and response activity to all necessary parties in a consistent format that is human readable at least monthly.

## Who it binds

- Providers

## Certification classes

_Applies regardless of certification class._

## Which certifications it binds

Certification type: 20x, Rev5
Path: Program, Agency

## Machine-readable form

_This requirement names no JSON schema. FRC-CSO-JSN binds a provider to a schema only where a rule contains one._

## Artifacts

- {"text":"A recent vulnerability report or a sample vulnerability report","scope":"all","class":null,"source":"requirement"}

## Timeframes

- {"requirementId":"VER-TFR-MHR","documentKey":"VER","documentName":"Vulnerability Evaluation and Reporting","group":"all","subset":"TFR","name":"Monthly Activity Report","statement":"Providers MUST report vulnerability detection and response activity to all necessary parties in a consistent format that is human readable at least monthly.","force":"MUST","affects":["Providers"],"class":null,"num":1,"type":"months","sortKey":730.5}

## Notifications

_This requirement demands no notification._
