FedRAMP guide
FedRAMP continuous monitoring requirements
Authorization is the beginning, not the end. A FedRAMP-authorized cloud service owes continuous monitoring for as long as it holds the authorization. This guide summarizes the obligations from FedRAMP's own Continuous Monitoring Playbook and related documents.
The monthly rhythm
ConMon runs on a monthly cycle. Per the FedRAMP Continuous Monitoring Playbook and the vulnerability scanning requirements in RA-5, the recurring obligations are:
- Vulnerability scanning, monthly. Operating system and infrastructure scans, plus web application (including APIs) and database scans, every month. Container images are scanned where applicable.
- Remediation on fixed windows. High-risk vulnerabilities mitigated within 30 days of discovery, moderate-risk within 90 days, low-risk within 180 days.
- POA&M update, monthly. The Plan of Action and Milestones reflects every open weakness, its remediation plan, and its age. See the POA&M workflow guide.
- Monthly submission. Scan results and the updated POA&M go to the reviewing body: the agency ISSO for agency authorizations, the FedRAMP PMO for PMO-issued authorizations.
FedRAMP also expects evidence that outstanding high-risk items are being worked: updated artifacts every 30 days showing progress on open highs. The full monthly checklist is in monthly ConMon deliverables.
The annual rhythm
- Annual assessment. A third-party assessment organization (3PAO) tests a subset of controls each year. FedRAMP designates core controls that are always in scope; the rest rotates.
- Annual attestation and updated artifacts. Refreshed system documentation where it changed, plus the annual assessment report.
Event-driven obligations
- Significant change. Major system changes (new data types, architecture changes, new service offerings in boundary) require notification and, depending on scope, assessment before deployment. Routine changes are logged and reported; significant ones are coordinated in advance.
- Incident reporting. Security incidents are reported under the FedRAMP incident communication procedures, on short timelines, not in the monthly bundle.
Where teams actually fail
The pattern in revoked and suspended authorizations is not exotic. It is missed monthly submissions, POA&M items aging past their milestones with no documented progress, scan scopes that quietly drifted from the authorized boundary, and significant changes deployed before review. ConMon is an operations discipline: the organizations that treat it as a calendar with owners and evidence, rather than a document, are the ones that keep their authorizations.
Frequently asked questions
How often are FedRAMP vulnerability scans required?
Monthly for operating system and infrastructure scans and for web application (including APIs) and database scans, per FedRAMP's RA-5 scanning requirements. Container images are scanned as applicable.
What are the FedRAMP remediation timelines?
High-risk vulnerabilities must be mitigated within 30 days of discovery, moderate-risk within 90 days, and low-risk within 180 days, per FedRAMP's vulnerability scanning requirements.
Who receives the monthly ConMon package?
For agency authorizations, the agency ISSO or designated reviewer. For FedRAMP PMO authorizations, the PMO. Either way the content is the same: scan results, updated POA&M, and supporting artifacts.
Is the annual assessment a full reassessment?
No. The 3PAO tests a subset of controls annually, including FedRAMP-designated core controls, with the remainder rotating across years. Monthly ConMon fills the space between assessments.
Sources
- FedRAMP Continuous Monitoring Playbook: fedramp.gov
- FedRAMP documents library: fedramp.gov/resources/documents
- NIST SP 800-53 control reference: csrc.nist.gov