Behind the Shield
FedRAMP CR26 Explained: VDR/VER, Key Deadlines & the Move to 20x
Sep 22, 2026
Season 1
Episode 48
InfusionPoints
FedRAMP CR26 is changing how Cloud Service Providers approach vulnerability management, continuous monitoring, compliance, and the transition to FedRAMP 20x.
In the Season 1 finale of Behind the Shield, Mike Strohecker and Aidan Fratcher break down the Consolidated Rule Set 2026 (CR26), including what CSPs need to prioritize now, how VDR and VER are changing traditional vulnerability management, and how Binding Operational Directive 26-04 is accelerating key vulnerability management requirements and timelines for CSPs.
They also dig into some of the biggest areas of confusion surrounding CR26, including the difference between “must” and “should” requirements, what FedRAMP means by obtain, maintain, and grace period deadlines, and how security, compliance, engineering, and operations teams will need to work together as FedRAMP continues moving toward a more automated, continuous model.
What You’ll Learn
• What CR26 means for Cloud Service Providers
• Why VDR and VER are among the most immediate priorities for CSPs
• How BOD 26-04 impacts VDR and VER implementation timelines
• How vulnerability management is shifting beyond traditional 30/90/180-day remediation timelines
• Why vulnerability scanning failures can become vulnerabilities themselves
• How CSPs can operationalize VDR and VER across CloudOps, SOC, engineering, and compliance teams
• What FedRAMP means by “must” and “should” requirements
• The difference between obtain, maintain, and grace period deadlines
• What upcoming CR26 deadlines mean for existing and new FedRAMP authorizations
• How CR26 supports the broader transition from Rev. 5 to FedRAMP 20x
• Why continuous security evidence and automation are becoming increasingly important to the FedRAMP model
Chapters
0:00 Introduction and Overview of CR 26
0:05 Understanding CR 26 and Its Implications
1:19 Vulnerability Management in CR 26
3:14 Prioritizing Vulnerability Management
4:43 Operationalizing Vulnerability Management
7:26 Continuous Scanning and Security Operations
9:26 Understanding Vulnerability Management in Federal Compliance
14:14 The Importance of Incident Response Plans
19:55 Navigating Must and Should Requirements
24:02 Clarifying Obtain, Maintain, and Grace Periods
29:01 Transitioning to FedRAMP 20X
31:10 Looking Ahead: Expectations for CR 27
Links:
CR26 Whitepaper: Coming soon
Mike Strohecker: https://www.linkedin.com/in/michael-strohecker-238326172/
Aidan Fratcher: https://www.linkedin.com/in/aidanfratcher/
InfusionPoints: https://www.linkedin.com/company/infusionpoints/
Continuous Trust Platform: https://infpts.com/platform
https://infusionpoints.com/
InfusionPoints & AWS:
InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments.
About Us:
InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.
We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.
Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.