FedRAMP checklist
FedRAMP monthly ConMon deliverables checklist
The monthly submission is the heartbeat of FedRAMP continuous monitoring. Miss it or pad it and reviewers notice; keep it complete and boring and ConMon becomes routine. Print this or copy it into your runbook.
Every month
- Operating system and infrastructure vulnerability scan results, raw output, full authorized boundary in scope
- Web application (including APIs) and database scan results
- Container image scan results, where containers are in the boundary
- Updated POA&M: every open weakness with current status, milestone dates, and age from discovery
- Remediation evidence for anything closed since last month (a re-scan showing the finding gone)
- Progress artifacts for outstanding high-risk items older than 30 days
- Significant change log entries for the month, even if the entry is "none"
- Any incident reports filed under the incident communication procedures
POA&M hygiene reviewers check first
- High-risk items within the 30-day mitigation window, moderate within 90, low within 180
- Vendor-dependent items checked within the last 30 days (the completion guide requires a vendor status check at least every 30 days while the remedy is pending)
- No POA&M item with a milestone date in the past and no explanation
- Deviation requests (false positives, risk adjustments, operational requirements) documented and approved, not silently applied
- Closure evidence attached for everything marked complete
Quarterly and annual anchors
- Quarterly: confirm scan scope still matches the authorized boundary after any architecture change
- Annually: schedule the 3PAO assessment early enough that results land inside the annual window
- Annually: refresh system documentation that changed during the year
Common reviewer flags
- Scan coverage smaller than the authorized boundary (a new account or cluster that never got added)
- POA&M items re-dated instead of remediated
- "Recurring" findings closed and reopened month after month with no root-cause note
- Missing raw scan files when only summaries were submitted
Frequently asked questions
When is the monthly ConMon package due?
Monthly, on the schedule set with your reviewing body (agency ISSO or the FedRAMP PMO). The cadence is not optional; missed submissions are a compliance issue, not a paperwork slip.
Do we submit raw scan files or summaries?
Raw results. Reviewers expect the scanner output itself, with the POA&M providing the management view. Summaries without raw files get sent back.
What if a finding is a false positive?
Document it as a deviation request with evidence, and get it approved through the proper channel. Marking it closed without the documented deviation is what turns into a finding later.
Sources
- FedRAMP Continuous Monitoring Playbook: fedramp.gov
- FedRAMP POA&M Template Completion Guide: help.fedramp.gov