# FedRAMP Rev5

Published articles for FedRAMP Rev5.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## FedRAMP VDR and VER Require Continuous Vulnerability Detection, Remediation, and Evidence

DevFeed: [FedRAMP VDR and VER Require Continuous Vulnerability Detection, Remediation, and Evidence](<https://devfeed.tech/articles/fedramp-vdr-ver-daily-scans-are-only-the-beginning-59225.md>)

Original publisher: [Read original article](<https://www.bleepingcomputer.com/news/security/fedramp-vdr-and-ver-daily-scans-are-only-the-beginning/>)

Author: Sponsored by Anecdotes

Published: 2026-09-24T14:02:12Z

Content type: article

Language: en

Sources: [BleepingComputer](<https://devfeed.tech/sources/bleepingcomputer.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [anecdotes](<https://devfeed.tech/tags/anecdotes.md>), [automated](<https://devfeed.tech/tags/automated.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [computer-help](<https://devfeed.tech/tags/computer-help.md>), [computer-security](<https://devfeed.tech/tags/computer-security.md>), [computers](<https://devfeed.tech/tags/computers.md>), [continuous](<https://devfeed.tech/tags/continuous.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-rev5](<https://devfeed.tech/tags/fedramp-rev5.md>), [infosec](<https://devfeed.tech/tags/infosec.md>), [linux](<https://devfeed.tech/tags/linux.md>), [mac](<https://devfeed.tech/tags/mac.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-removal](<https://devfeed.tech/tags/malware-removal.md>), [security](<https://devfeed.tech/tags/security.md>), [spyware](<https://devfeed.tech/tags/spyware.md>), [support](<https://devfeed.tech/tags/support.md>), [tech-support](<https://devfeed.tech/tags/tech-support.md>), [technical-support](<https://devfeed.tech/tags/technical-support.md>), [virus](<https://devfeed.tech/tags/virus.md>), [virus-removal](<https://devfeed.tech/tags/virus-removal.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

FedRAMP's VDR and VER requirements introduce more frequent vulnerability scanning, tighter remediation deadlines, and stronger evidence requirements. The article explains how these rules affect engineering ownership, automation, and the reliability of detection and response processes.

### Source excerpt

FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated compliance validation. [...]

## FedRAMP & CMMC in 2026: what actually changed for your Authority to Operate (ATO)

DevFeed: [FedRAMP & CMMC in 2026: what actually changed for your Authority to Operate (ATO)](<https://devfeed.tech/articles/fedramp-cmmc-in-2026-what-actually-changed-for-your-authority-to-operate-ato-61721.md>)

Original publisher: [Read original article](<https://anchore.com/blog/fedramp-cmmc-in-2026-what-actually-changed-for-your-ato/>)

Author: teamanchore

Published: 2026-09-22T12:00:00Z

Content type: article

Language: en

Sources: [Anchore](<https://devfeed.tech/sources/anchore.md>)

Topics: [FedRAMP Rev 5](<https://devfeed.tech/topics/fedramp-rev-5.md>), [authority to operate](<https://devfeed.tech/topics/authority-to-operate.md>), [ato in a box](<https://devfeed.tech/topics/ato-in-a-box.md>), [chainguard fedramp solution](<https://devfeed.tech/topics/chainguard-fedramp-solution.md>), [internal developer platform](<https://devfeed.tech/topics/internal-developer-platform.md>)

Tags: [2](<https://devfeed.tech/tags/2.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cmmc-phase-2](<https://devfeed.tech/tags/cmmc-phase-2.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [fedramp-rev5](<https://devfeed.tech/tags/fedramp-rev5.md>), [government](<https://devfeed.tech/tags/government.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [stig](<https://devfeed.tech/tags/stig.md>)

### AI overview

The article explains 2026 changes to FedRAMP and CMMC, including new FedRAMP certification terminology and the suspension of CMMC Phase 2. It says contractors should continue maintaining evidence of security controls such as vulnerability scans, a software bill of materials, and STIG compliance while program requirements are reviewed.

### Source excerpt

The post FedRAMP & CMMC in 2026: what actually changed for your Authority to Operate (ATO) appeared first on Anchore.If you sell software to the U.S. government, the last few months have been a lot. FedRAMP rev5 still holds until September 2027 but FedRAMP 20x moves to be the new standard. CMMC Phase 2, the requirement for third-party C3PAO certifications, got put on pause. Two of the biggest compliance frameworks a contractor has to [...]