Continuous Monitoring & Persistent Validation
Under FedRAMP 20x, continuous monitoring is collaborative and ongoing rather than a monthly document drop alone. The Ongoing Certification Report (OCR) is the 20x package. Persistent validation means machine resources and KSIs are checked on published cadences, not only at authorization time.
Educational resource only. scm.cc is not a FedRAMP Recognized Independent Assessor (3PAO) and is not FedRAMP-authorized; it grants no authorization, certification, or assessment outcome. FedRAMP.gov is the authoritative source. This is not legal advice.
Technical detail
The pinned OCR schema (fedramp-ocr/0.2.0-ccm-2026) maps the CR26 CCM rule: 9 sections (changes_to_authorization_data, planned_changes_next_3_months, accepted_weaknesses, transformative_changes, security_configuration_recommendations, agency_users, reportable_incidents, lessons_learned, anonymized_feedback_summary). A section with nothing to report is marked absent, never omitted. Quarterly Review ops require next-report and next-review dates on the face of a complete release. Rev5 monthly ConMon continues in parallel during transition. Class C adds a 6-month KSI metrics window and a 3-day VDR verification cadence for machine resources.
How to implement
Publish the quarterly OCR with every mandated section present or explicitly absent. Schedule the Quarterly Review inside the 3-business-day to 14-day window. Keep monthly Rev5 packages until that path closes for the offering. Point collectors at the 3-day VDR window for Class C machine resources. Do not treat a content-addressed ConMon manifest as a cryptographic signature.
Evidence expectations
Each OCR statement links to a source record (cadence run, POA&M item, incident, or similar). A statement without a source cannot exist. Cadence due dates are derived from the tenant's due rule; missing due days are not invented.
Common mistakes
- Omitting empty OCR sections instead of marking them absent. - Releasing an OCR without posted next-report and next-review dates. - Stopping monthly ConMon the day the first 20x OCR is assembled. - Calling a hash manifest a signed package.
Cadences (sourced)
| Cadence | Interval | Applies |
|---|---|---|
| Ongoing Certification Report | Quarterly | 20x Collaborative Continuous Monitoring. Each OCR is paired with a Quarterly Review held 3 business days to 2 weeks after release; next report and next review dates must be posted. |
| Rev5 ConMon package | Monthly | Offerings still on the Rev5 path. Dual cadence with quarterly OCR during transition. |
| Class C KSI metrics window | 6 months | FedRAMP Certification reference: Class C KSI metrics are evaluated over a six-month window. Confirm current wording on FedRAMP.gov. |
| Class C machine-resource verification | ≥ every 3 days | Vulnerability Detection and Response: Class C verify machine resources at least every 3 days. |
Questions teams ask
- Is CCM the same as monthly ConMon?
- No. CCM is the 20x collaborative model with a quarterly OCR. Monthly ConMon is the Rev5 package. Mid-transition offerings typically run both.
- What is persistent validation?
- Checking that KSIs and in-scope machine resources still hold on the published cadence (for Class C VDR, at least every 3 days), instead of only at a point-in-time assessment.
- Can an OCR skip a section with nothing to report?
- No. The section is marked absent with a reason. Silent omission is not a complete report.
Related hub pages
Primary sources
- Collaborative Continuous Monitoring (CCM / Ongoing Certification Report) (retrieved 2026-09-27)
- FedRAMP Certification reference (classes, KSI metrics window) (retrieved 2026-09-27)
- Vulnerability Detection and Response (VDR/VER) (retrieved 2026-09-27)
- FedRAMP launches Consolidated Rules for 2026 (CR26) (retrieved 2026-09-27)
- FedRAMP 20x overview & Core Principles (retrieved 2026-09-27)
Last verified 2026-09-27. FedRAMP.gov is authoritative.