FedRAMP guide

FedRAMP continuous monitoring requirements

By the ShipReady Metrics research team. Published September 22, 2026. Sources are cited inline at the end of each page.

Authorization is the beginning, not the end. A FedRAMP-authorized cloud service owes continuous monitoring for as long as it holds the authorization. This guide summarizes the obligations from FedRAMP's own Continuous Monitoring Playbook and related documents.

The monthly rhythm

ConMon runs on a monthly cycle. Per the FedRAMP Continuous Monitoring Playbook and the vulnerability scanning requirements in RA-5, the recurring obligations are:

FedRAMP also expects evidence that outstanding high-risk items are being worked: updated artifacts every 30 days showing progress on open highs. The full monthly checklist is in monthly ConMon deliverables.

The annual rhythm

Event-driven obligations

Where teams actually fail

The pattern in revoked and suspended authorizations is not exotic. It is missed monthly submissions, POA&M items aging past their milestones with no documented progress, scan scopes that quietly drifted from the authorized boundary, and significant changes deployed before review. ConMon is an operations discipline: the organizations that treat it as a calendar with owners and evidence, rather than a document, are the ones that keep their authorizations.

Frequently asked questions

How often are FedRAMP vulnerability scans required?

Monthly for operating system and infrastructure scans and for web application (including APIs) and database scans, per FedRAMP's RA-5 scanning requirements. Container images are scanned as applicable.

What are the FedRAMP remediation timelines?

High-risk vulnerabilities must be mitigated within 30 days of discovery, moderate-risk within 90 days, and low-risk within 180 days, per FedRAMP's vulnerability scanning requirements.

Who receives the monthly ConMon package?

For agency authorizations, the agency ISSO or designated reviewer. For FedRAMP PMO authorizations, the PMO. Either way the content is the same: scan results, updated POA&M, and supporting artifacts.

Is the annual assessment a full reassessment?

No. The 3PAO tests a subset of controls annually, including FedRAMP-designated core controls, with the remainder rotating across years. Monthly ConMon fills the space between assessments.

Sources