Acme Cloud
FedRAMP 20x · Program · Class B
- Automated checks
- Rules version
- 2026.07.14.01
- Certification
- 20x · Program · B
Every provider, Rev 5 included, must detect, respond, evaluate, and report continuously under the 2026 Consolidated Rules. zenibit tracks those rules against your live evidence and publishes the result as a trust center agencies can actually verify.
Consolidated Rules v2026.07.14.01 · one engine · Rev 5 and 20x
Acme Cloud
The deadline
The Vulnerability Detection & Response and Vulnerability Evaluation & Reporting rules apply to every FedRAMP certification, whether obtaining or maintaining, on Rev 5 or 20x. Waiting for your 20x transition to start caring about them means missing the date.
Providers may adopt VDR and VER early and report under the new rules.
VDR and VER become mandatory for every FedRAMP certification under CISA BOD 26-04.
The default grace window closes. After this, non-compliance is exposure with no cover.
The trust center
Every zenibit customer gets a public trust center on its own URL. It is not a brochure: everything on it comes from the engine, so what an agency reads is what your evidence actually supports.
Certification type, path, and class, stated from your evaluated posture rather than a marketing claim.
The share of requirements verified by automation, shown as a percentage on the page.
Publish openly or mark NDA-only, per document, with secure time-limited download links.
Every page carries when it was last evaluated and the exact Consolidated Rules version it was evaluated against.
Monthly activity reports published where agencies expect them, on the cadence VER requires.
Your trust center is provisioned with your account. No servers, no static-site pipeline, no separate vendor.
The rules, specifically
The 2026 rules redefined vulnerability: an out-of-date control statement, drift, or an unverified control now carries the same detection and remediation obligations as a CVE. BOD 26-04 replaced scan-and-file with cadences and clocks, and these are the ones that catch providers out. zenibit tracks each against your evidence and surfaces exactly where you stand.
| Rule | Obligation | What zenibit does |
|---|---|---|
| VDR-TFR-KEV | Remediate Known Exploited VulnerabilitiesBy the due dates in the CISA KEV Catalog. | Keeps KEV due dates in view beside the rest of your remediation queue. |
| VER-TFR-MHR | Report activity monthlyIn a consistent, human-readable format, to all necessary parties. | Tracks the cadence so a missed month is visible before an assessor finds it. |
| VER-TFR-MAV | The 192-day clockAnything not fully mitigated or remediated within 192 days of evaluation must be categorized as accepted. | Surfaces the clock on every open finding so nothing drifts into acceptance unnoticed. |
| VDR-TFR-MVF | Persistent machine verificationMachine-based verification and validation, a Rev 5 obligation in its own right. | Continuous evaluation is the default posture, not a scheduled scan. |
| VDR-TFR-NMV | Verify non-machine resourcesAt least once every 3 months. | Tracks the quarterly cadence alongside the machine-based one. |
Evaluated against the live Consolidated Rules datafile · currently v2026.07.14.01
The accelerator
20x and Rev 5 differ in which requirements apply, not in how evidence is evaluated. zenibit runs one validator engine against both rule sets, so the work you do for Rev 5 today is the same work 20x will ask for.
COMPLY NOW
ARRIVE READY
Meet Rev 5 now. Arrive at 20x already compliant. Switching paths is a rule-set change in zenibit, not a re-platform and not a second compliance program.