VER-TFR-MRHHistorical Activity
allvaries by class: a, b, c, d
The statement for this requirement varies by certification class — see the per-class deadlines below.
Who it binds
Controls whose FedRAMP guidance points at VER (10)
Their guidance names the Vulnerability Evaluation and Reporting rules as a whole, not this requirement — so this is where to read from, not a mapping to this clause. Controls no KSI reaches have no page and are not listed.
Deadlines (4)
| Class | Timeframe | Statement |
|---|---|---|
| D | 7 days | Providers with Class D Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every 7 days. |
| C | 14 days | Providers with Class C Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every 14 days. |
| A | 1 month | Providers with Class A Certifications MAY make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information MAY be updated persistently, at least once every month. |
| B | 1 month | Providers with Class B Certifications SHOULD make all recent historical vulnerability detection and response activity available in JSON format for automated retrieval by all necessary parties (e.g. using an API service or similar); this information SHOULD be updated persistently, at least once every month. |
Which certifications it binds
- Certification type
- 20x · Rev5
- Path
- Program · Agency
Machine-readable form
FedRAMP Historical Vulnerability Evaluation and Reporting Activity (VER-TFR-MRH)
https://fedramp.gov/schemas/fedramp-historical-ver-activity-schema-2026-06-24.json
Evidence this requirement demands
- URL and access instructions for historical vulnerability detection and response activity in machine readable formatclass a
- URL and access instructions for historical vulnerability detection and response activity in machine readable formatclass b
- or an explanation of why machine readable content is not being providedclass b
- URL and access instructions for historical vulnerability detection and response activity in machine readable formatclass c
- or an explanation of why machine readable content is not being providedclass c
- URL and access instructions for historical vulnerability detection and response activity in machine readable formatclass d
- or an explanation of why machine readable content is not being providedclass d
5 default artifacts owed by every FRR requirement
- Explanation of how the rule is followed, or an explanation of the reason and resulting risk to customers for not following the rule.
- Verification that the implementation is appropriate for the rule, or that the reason for not implementing is accepted by a senior official.
- Validation that the implementation is in place and working as intended, or that the reason for not implementing is accepted by a senior official.
- Independent verification.
- Independent validation.
Group all, subset TFR of Vulnerability Evaluation and Reporting. See all obligations on /obligations or the full evidence plan on /evidence.