Skip to main content
All answers

What is FedRAMP ConMon?

FedRAMP ConMon (Continuous Monitoring) is the post-authorization monitoring program required of all FedRAMP-authorized cloud services. It implements NIST 800-53 CA-7 for federal cloud workloads. ConMon requires monthly vulnerability and configuration scan submissions, with annual control-set reassessment. Continuous CIS benchmark scanning is a core ConMon deliverable for configuration-based controls.

The longer answer.

After authorization, a cloud service provider keeps its authorization by sending monitoring deliverables to its authorizing official: monthly vulnerability and configuration scan results, updates to its plan of action and milestones (POA&M), and an annual assessment of a subset of controls by a third-party assessor.

CISGuard covers the configuration-scan part of that cycle: continuous CIS benchmark results, drift detection between monthly submissions, and an exception register whose entries can feed POA&M items. It does not produce the POA&M itself or submit deliverables to FedRAMP.

More questions on Frameworks?

Our compliance engineers can show you exactly how CISGuard handles Frameworks in a briefing scoped to your environment.