FedRAMP CR26 Explained: VDR/VER, Key Deadlines & the Move to 20x

Behind the Shield

Behind the Shield
FedRAMP CR26 Explained: VDR/VER, Key Deadlines & the Move to 20x
Sep 22, 2026 Season 1 Episode 48
InfusionPoints

FedRAMP CR26 is changing how Cloud Service Providers approach vulnerability management, continuous monitoring, compliance, and the transition to FedRAMP 20x.

In the Season 1 finale of Behind the Shield, Mike Strohecker and Aidan Fratcher break down the Consolidated Rule Set 2026 (CR26), including what CSPs need to prioritize now, how VDR and VER are changing traditional vulnerability management, and how Binding Operational Directive 26-04 is accelerating key vulnerability management requirements and timelines for CSPs.

They also dig into some of the biggest areas of confusion surrounding CR26, including the difference between “must” and “should” requirements, what FedRAMP means by obtain, maintain, and grace period deadlines, and how security, compliance, engineering, and operations teams will need to work together as FedRAMP continues moving toward a more automated, continuous model.

What You’ll Learn

• What CR26 means for Cloud Service Providers
• Why VDR and VER are among the most immediate priorities for CSPs
• How BOD 26-04 impacts VDR and VER implementation timelines
• How vulnerability management is shifting beyond traditional 30/90/180-day remediation timelines
• Why vulnerability scanning failures can become vulnerabilities themselves
• How CSPs can operationalize VDR and VER across CloudOps, SOC, engineering, and compliance teams
• What FedRAMP means by “must” and “should” requirements
• The difference between obtain, maintain, and grace period deadlines
• What upcoming CR26 deadlines mean for existing and new FedRAMP authorizations
• How CR26 supports the broader transition from Rev. 5 to FedRAMP 20x
• Why continuous security evidence and automation are becoming increasingly important to the FedRAMP model

Chapters

0:00 Introduction and Overview of CR 26
0:05 Understanding CR 26 and Its Implications
1:19 Vulnerability Management in CR 26
3:14 Prioritizing Vulnerability Management
4:43 Operationalizing Vulnerability Management
7:26 Continuous Scanning and Security Operations
9:26 Understanding Vulnerability Management in Federal Compliance
14:14 The Importance of Incident Response Plans
19:55 Navigating Must and Should Requirements
24:02 Clarifying Obtain, Maintain, and Grace Periods
29:01 Transitioning to FedRAMP 20X
31:10 Looking Ahead: Expectations for CR 27

Links: 
CR26 Whitepaper: Coming soon
Mike Strohecker: https://www.linkedin.com/in/michael-strohecker-238326172/
Aidan Fratcher: https://www.linkedin.com/in/aidanfratcher/
InfusionPoints: https://www.linkedin.com/company/infusionpoints/
Continuous Trust Platform: https://infpts.com/platform
https://infusionpoints.com/

InfusionPoints & AWS:
InfusionPoints is proud to be an Amazon Web Services Premier Tier Services Partner, supporting organizations in building, managing, and defending secure cloud environments.

About Us:
InfusionPoints is a trusted cybersecurity, cloud engineering, and compliance partner helping organizations Build, Manage, and Defend secure, mission-ready environments in highly regulated markets.
We specialize in FedRAMP, FedRAMP 20x, DoD, and enterprise security frameworks, supporting organizations from initial authorization through continuous monitoring and optimization. Our team brings deep technical expertise and real-world operational insight to every engagement.
Through our independent, security-first approach, we integrate people, processes, and technology to deliver scalable, compliant, and resilient solutions. From strategy and architecture to operations and defense, we help customers move faster without sacrificing security.

Episode Artwork FedRAMP CR26 Explained: VDR/VER, Key Deadlines & the Move to 20x 33:20 Episode Artwork The SOC That Changed Everything: 10 Years of Lessons, Growth, and Grit 1:10:43 Episode Artwork FedRAMP 20x, GRC & the Future of Compliance with Michael Peters 47:30 Episode Artwork Zero Trust Is Not a Product: Building, Proving, and Automating the Architecture 47:10 Episode Artwork Beyond the Digital Perimeter: Drones, Radar, and the Future of Physical Security 50:34 Episode Artwork Meet “Vader”: FedRAMP VDR & VER, PAIN Scores, and the New Era of Vulnerability Response 37:02 Episode Artwork Identity, AI, and the Future of FedRAMP 20x with Matt Topper 49:15 Episode Artwork FedRAMP CR26 Explained: What the 2026 Consolidated Rules Mean for CSPs 23:04 Episode Artwork Rob Hughes Returns: What AI Means for Identity, Security, and FedRAMP 20x 58:23 Episode Artwork Re-Release: From Screenshots to Signals with SK Bhachech: FedRAMP Automation and What Comes Next 47:56 Episode Artwork FedRAMP, 20x, and the Future of Federal Cloud Security with Michael Schroeder 1:06:26 Episode Artwork Built to Last: Christian Hyatt on Entrepreneurship, AI, and the Future of Cybersecurity 52:25 Episode Artwork FedRAMP 20x, GRC Engineering, and the Future of Compliance Automation with Eric Beasley 1:03:40 Episode Artwork From FedRAMP to the Future of AI: Tony Bai on Compliance, Cybersecurity, and What’s Next 58:37 Episode Artwork Breaking Into Def Tech: The Top 5 Challenges Facing Modern Companies 47:00 Episode Artwork Understanding Minimum Assessment Scope (MAS) in FedRAMP 20x 31:25 Episode Artwork From Acceleration to ATO: Navigating Defense Tech, Divestitures, and the Future of FedRAMP 1:02:38 Episode Artwork The Agentic SOC Shift: Smarter Security, Human-Led Decisions 21:59 Episode Artwork FedRAMP 20x and the Future of Compliance with Gary Guercio 1:12:02 Episode Artwork InfusionPoints Achieves FedRAMP 20x Moderate (Class C): What It Means for the Future 35:12 Episode Artwork From SQL Injection to Compliance Automation in Cybersecurity with Andrew Plato 1:02:42 Episode Artwork From Monthly Scans to Continuous Monitoring: Mastering FedRAMP Vulnerability Management 31:09 Episode Artwork From Interns to SOC Analysts: Real Cybersecurity Careers Start Here 26:09 Episode Artwork FedRAMP 20x Explained, CMMC Impact, and Real Compliance Talk with Matt Bruggeman 57:34 Episode Artwork Inside the InfusionPoints Internship Program with Rachael & Aidan 47:32