Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
FedRAMP's POA&M Shift: An Incident Waiting to HappenGovernance & Controls
4 min readFor Compliance Officers

FedRAMP's POA&M Shift: An Incident Waiting to Happen

Understanding the Shift

On July 4, 2026, FedRAMP's Consolidated Rules took effect, shifting the responsibility for Plans of Action & Milestones (POA&Ms) from cloud service providers (CSPs) to government agencies. POA&Ms didn't disappear; they became a tool for agencies to manage risks they accept from CSPs. CSPs must now evaluate vulnerabilities using a PAIN N1, N5 rating system and report them in machine-readable JSON format. The old model, where CSPs could document a weakness and defer remediation under a POA&M, is over. If your team still relies on this outdated approach, you risk losing certification when the grace period ends on February 1, 2028.

This isn't a typical breach. It's a compliance framework shift that will lead to failures if you're stuck in the old model.

Key Dates

July 4, 2026: FedRAMP Consolidated Rules take effect. POA&Ms become Agency POA&Ms, no longer a CSP compliance document.

January 1, 2027: CR 2026 becomes mandatory. CSPs can't submit traditional POA&Ms for certification.

February 1, 2028: Grace period ends. CSPs still using the old POA&M model risk losing certification.

During this period, CSPs must transition. Many won't realize the change until they're already non-compliant.

Procedural and Governance Failures

The failure here is procedural, not technical.

Vulnerability Evaluation: Previously, you identified a weakness, wrote a POA&M, and submitted it. Now, you must evaluate each vulnerability across eight factors: criticality, reachability, exploitability, detectability, prevalence, privilege level, proximity to other vulnerabilities, and known threats. If your team treats vulnerability management as just documentation, you're using the wrong control framework.

Machine-readable Reporting: The new rules require JSON data for vulnerability reporting. Using spreadsheet templates means you're not compliant. This isn't about format preference; it's a compliance mandate for automated agency risk assessment.

Remediation Timelines: A Class D CSP with a high-risk PAIN-5 vulnerability must fix it within 12 hours. If your processes can't support this, you lack the controls needed for certification under CR 2026.

Assumption of Automated Exploitation: CSPs must assume vulnerabilities can be exploited by automated tools unless proven otherwise. If your threat modeling assumes manual attacks, you're underestimating exposure.

FedRAMP's New Requirements

FedRAMP's Consolidated Rules for 2026 set three core requirements replacing the POA&M process:

Vulnerability Evaluation: CSPs must evaluate vulnerabilities in the context of their cloud service offering to determine exploitability and internet reachability. Each vulnerability gets a PAIN N1, N5 rating based on potential agency impact.

Reporting to Agencies: If a CSP identifies a risk they can't mitigate, they report it to agency partners. The agency evaluates the risk and, if needed, creates their own POA&M.

Remediation Windows: Timelines vary by CSP class and vulnerability characteristics. High-PAIN, internet-reachable risks for Class D providers require action within 12 hours. Low-PAIN vulnerabilities for Class B providers allow up to 192 hours for remediation or classification as accepted weaknesses.

The standard prohibits agencies from asking CSPs to create agency POA&Ms: "Cloud service providers should not be expected to convert their vulnerability lists, product security roadmaps, accepted vulnerability records, or internal risk tracking into agency POA&Ms."

Action Items for Your Team

Audit Your Workflow: If you're still using the POA&M template, you're documenting compliance in an outdated format. Compare your process against the eight contextual evaluation factors and identify gaps.

Integrate PAIN Ratings: Your scanners produce CVE scores and severity ratings. You need a system that translates these into PAIN N1, N5 ratings based on your cloud service context. This can't be a manual task.

Transition to JSON Reporting: If your vulnerability data is in spreadsheets or PDFs, start transitioning to machine-readable output that agencies can use.

Test 12-hour Remediation: Conduct a tabletop exercise on a non-critical system: a PAIN-5, internet-reachable vulnerability is found. Can your team evaluate, report, and mitigate within 12 hours? If not, you lack the operational maturity for Class D certification under CR 2026.

Redefine "Accepted Weakness": Previously, a POA&M meant "we'll fix this later." Now, an accepted weakness is a risk the agency chooses to accept after you've reported it. Your documentation must support agency decision-making.

Review Agency Contracts: Some agencies may still use the old model during the grace period. Clarify responsibilities and transition timelines. Don't assume your agency partner has updated their processes.

The shift from CSP-managed POA&Ms to agency-managed Accepted Weaknesses isn't just a terminology change. It's a fundamental reallocation of risk ownership. If you're still deferring vulnerabilities, you're heading toward a certification failure in February 2028.

FedRAMP Consolidated Rules

Application Security Isn’t Optional Anymore.

You Might Also Like