FedRAMP's vulnerability rules go mandatory on December 7.

Every provider, Rev 5 included, must detect, respond, evaluate, and report continuously under the 2026 Consolidated Rules. zenibit tracks those rules against your live evidence and publishes the result as a trust center agencies can actually verify.

Consolidated Rules v2026.07.14.01 · one engine · Rev 5 and 20x

The deadline

Rev 5 is not a waiting room.

The Vulnerability Detection & Response and Vulnerability Evaluation & Reporting rules apply to every FedRAMP certification, whether obtaining or maintaining, on Rev 5 or 20x. Waiting for your 20x transition to start caring about them means missing the date.

2026-07-04

Optional adoption opened

Providers may adopt VDR and VER early and report under the new rules.

2026-12-07

Required to obtain and maintain

VDR and VER become mandatory for every FedRAMP certification under CISA BOD 26-04.

2027-03-07

Grace period ends

The default grace window closes. After this, non-compliance is exposure with no cover.

The trust center

The page agencies check instead of emailing you.

Every zenibit customer gets a public trust center on its own URL. It is not a brochure: everything on it comes from the engine, so what an agency reads is what your evidence actually supports.

status

Live authorization status

Certification type, path, and class, stated from your evaluated posture rather than a marketing claim.

coverage

Automated-check coverage

The share of requirements verified by automation, shown as a percentage on the page.

documents

Package documents, gated your way

Publish openly or mark NDA-only, per document, with secure time-limited download links.

freshness

A timestamp you can point to

Every page carries when it was last evaluated and the exact Consolidated Rules version it was evaluated against.

vulnerability

Vulnerability posture, current

Monthly activity reports published where agencies expect them, on the cadence VER requires.

zero setup

Nothing to host

Your trust center is provisioned with your account. No servers, no static-site pipeline, no separate vendor.

The rules, specifically

Standing obligations, tracked as first-class requirements.

The 2026 rules redefined vulnerability: an out-of-date control statement, drift, or an unverified control now carries the same detection and remediation obligations as a CVE. BOD 26-04 replaced scan-and-file with cadences and clocks, and these are the ones that catch providers out. zenibit tracks each against your evidence and surfaces exactly where you stand.

RuleObligationWhat zenibit does
VDR-TFR-KEV Remediate Known Exploited VulnerabilitiesBy the due dates in the CISA KEV Catalog. Keeps KEV due dates in view beside the rest of your remediation queue.
VER-TFR-MHR Report activity monthlyIn a consistent, human-readable format, to all necessary parties. Tracks the cadence so a missed month is visible before an assessor finds it.
VER-TFR-MAV The 192-day clockAnything not fully mitigated or remediated within 192 days of evaluation must be categorized as accepted. Surfaces the clock on every open finding so nothing drifts into acceptance unnoticed.
VDR-TFR-MVF Persistent machine verificationMachine-based verification and validation, a Rev 5 obligation in its own right. Continuous evaluation is the default posture, not a scheduled scan.
VDR-TFR-NMV Verify non-machine resourcesAt least once every 3 months. Tracks the quarterly cadence alongside the machine-based one.

Evaluated against the live Consolidated Rules datafile · currently v2026.07.14.01

The accelerator

Both paths. One engine.

20x and Rev 5 differ in which requirements apply, not in how evidence is evaluated. zenibit runs one validator engine against both rule sets, so the work you do for Rev 5 today is the same work 20x will ask for.

FedRAMP Rev 5

COMPLY NOW

  • Immediate 2026 obligations tracked: vulnerability rules, secure configuration guide, communication and marketplace requirements
  • Continuous evaluation instead of point-in-time assessment prep
  • Evidence gaps surfaced as needs evidence, never a false pass

FedRAMP 20x

ARRIVE READY

  • Key Security Indicators evaluated from the same evidence base
  • Machine-readable status agencies can consume directly
  • Certification path and class resolved per the Consolidated Rules applicability model

Meet Rev 5 now. Arrive at 20x already compliant. Switching paths is a rule-set change in zenibit, not a re-platform and not a second compliance program.