FedRAMP · September 2026
FedRAMP eliminated POA&Ms. Here's what replaced them — and who still has to keep them.
4 September 2026 · Kenio Shirley
On 4 July 2026, FedRAMP's Consolidated Rules for 2026 took effect. Among a long list of changes, one sentence on fedramp.gov does something the compliance industry has been circling for a decade:
“Plans of Action & Milestones (POA&Ms) have been eliminated entirely and replaced with a list of Accepted Weaknesses"
Not simplified. Not modernised. Eliminated.
One caveat on the name, because it matters if you are building to this. The narrative page on fedramp.gov says Accepted Weaknesses. The machine-readable rules and the JSON schema both say Accepted Vulnerability — FRD-ACV and VER-RPT-AVI. That is a real conflict between two FedRAMP sources, not a typo on either side. If you are writing code against this, build to the JSON.
If you maintain a FedRAMP package, advise someone who does, or assess one, this changes the artefact your continuous monitoring process produces. It has had remarkably little coverage, so here is the transition in full: what changed, what replaced it, who is exempt, and the dates that matter.
Correction · 5 September 2026
This article was first published on 4 September 2026. After checking it against FedRAMP's machine-readable ruleset rather than the narrative pages, four things needed changing:
- • The replacement artefact is called Accepted Vulnerability in the rules and schema, not Accepted Weaknesses. Both terms are in use; the sources disagree with each other.
- • The remediation window runs from 12 hours, not 2 days. Two days is the Class C figure; 12 hours is Class D at N5, internet-reachable.
- • The 31 December 2028 Rev5 expiry is stated inconsistently across fedramp.gov and appears nowhere in the rules file. The confirmed date is 11 June 2027, after which no new Rev5 applications are accepted.
- • The Certification Class rename is not FIPS 200 alignment. FRD-CCL defines the classes as assurance categories and never mentions impact.
The vocabulary changed too
POA&Ms weren't the only casualty. The 2026 rules also retire a set of terms that have been load-bearing since FedRAMP began:
| Was | Is now | Stated reason |
|---|---|---|
| FedRAMP authorization | FedRAMP Certification | Avoids confusion with an agency's authorization to operate |
| Impact Levels — Low, Moderate, High | Certification Class — A, B, C, D | FRD-CCL defines the classes as assurance categories; the Low/Moderate/High mapping falls out of the Rev5 baselines rather than the definition |
| Continuous Monitoring | Ongoing Certification | Signals requirements broader than vulnerability scanning |
| System Security Plan and appendices | Certification Package Overview and Security Decision Record | Providers document the security decisions they actually made, not the implementation they planned |
That last one is more than cosmetic. A System Security Plan describes intent. A Security Decision Record describes what you decided and why. It is a different genre of document, and it is harder to write in advance and forget about.
Why POA&Ms were eliminated
The stated reasoning is worth sitting with, because it is unusually candid for a government programme describing its own instrument.
POA&Ms had become, in practice, a mechanism for accepting weaknesses over the long term rather than planning action. Anyone who has maintained one for three years recognises this immediately. A row goes on the POA&M. It gets a scheduled completion date. The date moves. It gets a new date. The item accrues comments, deviation requests and vendor-dependency check-ins, and the one thing it never does is close.
The instrument designed to track remediation had become the instrument for deferring it, and everyone involved knew.
Replacing it with an explicit list of Accepted Weaknesses is, at minimum, more honest. It says the quiet part in the artefact rather than in the hallway.
What replaced it
Two rulesets now do the work POA&Ms used to do: VDR (Vulnerability Detection and Response) and VER (Vulnerability Evaluation and Reporting).
The most consequential change inside them is that CVSS severity buckets are gone. The old model — Critical and High in 30 days, Moderate in 90, Low in 180, measured from discovery — treated an internet-facing exploitable flaw identically to the same CVE buried deep in a private subnet.
The new model scores on PAIN (potential agency impact) crossed with two questions: is it likely exploitable, and is it reachable from the internet. The remediation windows that fall out run from 12 hours to 192 days — 12 hours at Class D, N5, internet-reachable; two days is the Class C figure.
New remediation window
12 hours – 192 days
Depends on PAIN, exploitability, and internet reachability — not CVSS alone.
01
Burden of proof shifted
Providers must assume exploitation can be automated unless they hold evidence proving otherwise. Previously "we don't think that's practically exploitable" was an argument. Now it is a claim requiring support.
02
192 days is the acceptance line
A vulnerability unresolved past that point must be reclassified as accepted — reported with rationale and risk context, but without a remediation date or milestones. It stops pretending to be a plan.
03
Watch the path of least resistance
That is a defensible design. It also makes acceptance the path of least resistance at exactly the point where remediation has proven hard, which is worth watching.
Who still has POA&Ms
This is the part most commentary is getting wrong. POA&Ms are not gone everywhere.
Rev5 providers keep them
Monthly scans plus monthly POA&M updates continue, using the FedRAMP template. No new Rev5 applications are accepted after 11 June 2027 — that date is confirmed. The often-quoted 31 December 2028 expiry is not: fedramp.gov states it three different ways and the rules file contains no 2028 date at all.
Agencies keep them, narrowed
FedRAMP's guidance to agencies is direct: create POA&Ms "only when there are actions the agency needs to take, track, fund, manage, or accept." And, explicitly, "provider-maintained vulnerability information is not automatically an agency POA&M."
“provider-maintained vulnerability information is not automatically an agency POA&M.”
That second sentence quietly ends a widespread practice. Agencies have routinely required providers to convert vulnerability lists into agency POA&M rows, duplicating the same weakness across every agency leveraging the same service. FedRAMP is telling them to stop.
The result is that the agency-side POA&M and the provider-side weakness register are now structurally different objects. One is a register of decisions an agency owns. The other is a list of weaknesses a provider maintains. Conflating them was always a category error; now it is also non-compliant.
The dates
| Date | What happens |
|---|---|
| 4 July 2026 | Consolidated Rules 2026 take effect. POA&Ms eliminated for providers on the new track. |
| 30 September 2026 | Machine-readable submission requirements reported to take effect, with no grace period for new providers. This date comes from a secondary source and is not confirmed in the rules file — treat it as indicative. |
| 7 December 2026 | Mandatory VDR/VER adoption, accelerated from June 2027 in response to CISA BOD 26-04. |
| 7 March 2027 | Grace period ends. |
| 11 June 2027 | No new Rev5 applications. This is the confirmed Rev5 cut-off. |
| 31 December 2028 | Widely cited as the Rev5 expiry, but fedramp.gov states it inconsistently — elsewhere as the date Rev5 remains active until, and elsewhere as the expiry of the 2026 ruleset itself. The rules JSON contains no 2028 date at all. |
What this means if you are mid-Rev5
For roughly two years, most of this market runs both models simultaneously — a Rev5 POA&M on the old template, and a VDR/VER-shaped weakness register on the new one. They describe overlapping facts with different granularity, different severity models and different acceptance rules.
Three practical consequences.
01
Severity is no longer a property of the vulnerability
Under the new rules, remediation urgency depends on exploitability and internet-reachability, which means it depends on your network topology. A vulnerability programme that cannot answer "is this reachable from outside" cannot compute its own deadlines. Most cannot, today.
02
Milestones lost their structured home and still matter
The Rev5 POA&M template removed the discrete Planned Milestones and Milestone Changes columns in its November 2025 revision, folding them into free text. Assessors still reject vague remediation plans without dated milestones and named owners. So you need to model milestones properly regardless of the fact that the template can no longer express them.
03
Machine-readable is arriving faster than planned
The 30 September 2026 requirement is reported to carry no grace period for new providers — that date comes from a secondary source rather than the rules file, so treat it as indicative. Either way, if your POA&M lives in a spreadsheet that a person edits, you have a migration ahead of you, not a formatting change.
The through-line
The instrument changed, but the underlying obligation did not, and it is worth stating plainly.
For any weakness in a system you are responsible for, you must be able to show what it was, when it was found, who owned it, what was done, who approved that, when, and against which control — durably enough that someone can re-test it a year later.
POA&Ms were one way of holding those facts together. They held them badly, in a spreadsheet, maintained by hand. FedRAMP has now said so out loud.
Whatever replaces them in your programme, that list of facts is the specification.
Kenio Shirley is the founder of Keystone and runs hireken.io. CISSP, CISM. Seventeen years in enterprise technology across 50+ audits covering SOC 2, HITRUST, FedRAMP, PCI DSS, SOX and IRAP.
Rebuilding your weakness register?
Keystone captures the facts POA&Ms used to hold — and keeps them machine-readable.