Continuous Monitoring & Persistent Validation

Under FedRAMP 20x, continuous monitoring is collaborative and ongoing rather than a monthly document drop alone. The Ongoing Certification Report (OCR) is the 20x package. Persistent validation means machine resources and KSIs are checked on published cadences, not only at authorization time.

Educational resource only. scm.cc is not a FedRAMP Recognized Independent Assessor (3PAO) and is not FedRAMP-authorized; it grants no authorization, certification, or assessment outcome. FedRAMP.gov is the authoritative source. This is not legal advice.

Technical detail

The pinned OCR schema (fedramp-ocr/0.2.0-ccm-2026) maps the CR26 CCM rule: 9 sections (changes_to_authorization_data, planned_changes_next_3_months, accepted_weaknesses, transformative_changes, security_configuration_recommendations, agency_users, reportable_incidents, lessons_learned, anonymized_feedback_summary). A section with nothing to report is marked absent, never omitted. Quarterly Review ops require next-report and next-review dates on the face of a complete release. Rev5 monthly ConMon continues in parallel during transition. Class C adds a 6-month KSI metrics window and a 3-day VDR verification cadence for machine resources.

How to implement

Publish the quarterly OCR with every mandated section present or explicitly absent. Schedule the Quarterly Review inside the 3-business-day to 14-day window. Keep monthly Rev5 packages until that path closes for the offering. Point collectors at the 3-day VDR window for Class C machine resources. Do not treat a content-addressed ConMon manifest as a cryptographic signature.

Evidence expectations

Each OCR statement links to a source record (cadence run, POA&M item, incident, or similar). A statement without a source cannot exist. Cadence due dates are derived from the tenant's due rule; missing due days are not invented.

Common mistakes

- Omitting empty OCR sections instead of marking them absent. - Releasing an OCR without posted next-report and next-review dates. - Stopping monthly ConMon the day the first 20x OCR is assembled. - Calling a hash manifest a signed package.

Cadences (sourced)

CadenceIntervalApplies
Ongoing Certification ReportQuarterly20x Collaborative Continuous Monitoring. Each OCR is paired with a Quarterly Review held 3 business days to 2 weeks after release; next report and next review dates must be posted.
Rev5 ConMon packageMonthlyOfferings still on the Rev5 path. Dual cadence with quarterly OCR during transition.
Class C KSI metrics window6 monthsFedRAMP Certification reference: Class C KSI metrics are evaluated over a six-month window. Confirm current wording on FedRAMP.gov.
Class C machine-resource verification≥ every 3 daysVulnerability Detection and Response: Class C verify machine resources at least every 3 days.

Questions teams ask

Is CCM the same as monthly ConMon?
No. CCM is the 20x collaborative model with a quarterly OCR. Monthly ConMon is the Rev5 package. Mid-transition offerings typically run both.
What is persistent validation?
Checking that KSIs and in-scope machine resources still hold on the published cadence (for Class C VDR, at least every 3 days), instead of only at a point-in-time assessment.
Can an OCR skip a section with nothing to report?
No. The section is marked absent with a reason. Silent omission is not a complete report.

Related hub pages

Primary sources

Last verified 2026-09-27. FedRAMP.gov is authoritative.

Explore the knowledge hub