Skip to content
Capability/Functional Capabilities

Continuous Monitoring

Real-time compliance posture and drift detection

01 / Overview
72 hours
Allowed to ingest vulnerability results into the CDM Agency Dashboard

CISA BOD 23-01 required actions: automated ingestion of vulnerability enumeration results within 72 hours of discovery completion.

Continuous monitoring provides real-time visibility into compliance posture with automated drift detection and alerting. Thalorin monitors control effectiveness, configuration compliance, and evidence freshness to maintain security authorization between formal assessments.

The word continuous is being quietly retired from federal continuous monitoring. The FedRAMP Consolidated Rules for 2026, launched on 24 June 2026, define a term of art — persistently — and the definition carries a note stating that it aligns generally with historical misuse of continuous in federal information security policies. Two weeks earlier, on 10 June 2026, CISA revoked BOD 22-01 and BOD 19-02 and replaced both with BOD 26-04, Prioritizing Security Updates Based on Risk. Two of the most cited authorities in this field changed inside a fortnight.

There is no longer one cadence to hit. BOD 26-04 derives remediation urgency from four decision points — whether the asset is publicly exposed, whether the CVE sits in the KEV Catalog, whether an adversary can automate the exploit, and how much control exploitation yields — following the SSVC methodology rather than a flat severity band. FedRAMP scales detection frequency by certification class and by whether a resource is likely to drift at all, and the monthly ConMon package gives way to an Ongoing Certification Report every three months plus a Quarterly Review, binding on 20x certifications since 4 July 2026 and on Rev5 from 1 January 2027.

The clock is the part that surprises people. Under BOD 26-04 the remediation timeline begins at whichever comes first: CISA adding the vulnerability to the KEV Catalog, or the agency enumerating it on an asset under BOD 23-01 and updating the CDM dashboard. Your own scanner starts your own clock. Scope is the second surprise — BOD 23-01 requires automated asset discovery every seven days and vulnerability enumeration every fourteen, but excludes ephemeral assets such as containers and third-party-managed SaaS, which is where a great deal of the estate now lives.

What Thalorin watches is the control, not the scanner. Each control carries the assets that satisfy it, the evidence that last demonstrated it and the date that evidence was produced, so a configuration change, an expiring artifact and a newly listed CVE all resolve to one object: the controls whose standing has moved, and the authorization decisions that rested on them. Freshness becomes a property of the evidence rather than a report somebody has to remember to run.

02 / Challenges

Compliance operations need modern infrastructure

A revoked directive in the runbook

BOD 26-04 revoked BOD 22-01 and BOD 19-02 on 10 June 2026. Procedures, dashboards and contract language written against the older flat timelines now cite an authority CISA has withdrawn.

Two clocks, and the earlier one wins

A remediation deadline starts when CISA lists the CVE or when your own enumeration reports it into the CDM dashboard, whichever happens first. Detecting something early shortens the window rather than buying time.

Ephemeral assets fall outside the floor

The discovery and enumeration intervals BOD 23-01 mandates exclude containers and third-party-managed SaaS. Meeting the directive exactly still leaves the fastest-moving part of the estate unmeasured by it.

Cadence now depends on drift

FedRAMP asks how likely a resource is to change and sets detection frequency from that and the certification class. A single organisation-wide scan interval no longer maps onto what is being asked of a provider.

03 / Capabilities

How Thalorin helps

NIST 800-137FedRAMP ConMon

Real-time compliance dashboards

Show the control population by current standing rather than by the date something was last reported, with every figure resolving to the assets and evidence sitting behind it.

Configuration drift detection

Compare running configuration against the state the control asserts, in the direction FedRAMP's Evaluating Configurations indicator sets, where the configuration of machine-based resources, especially infrastructure as code, is persistently evaluated and tested.

Control effectiveness monitoring

Separate a control that is implemented from a control that is working, by holding the assessment procedure and its result rather than an implementation statement written once.

Evidence freshness tracking

Give every artifact the interval within which it is expected to be renewed, and raise the control rather than the document when that interval lapses.

Automated alerting

Route a change to the authorization decision it affects, so a KEV listing or a failed check arrives as authorization impact rather than as another undifferentiated ticket.

Trend analysis and reporting

Produce the recurring summary a programme owes its stakeholders — including a three-monthly report in the shape FedRAMP's Ongoing Certification Report expects — from the monitoring record itself.

Questions

Continuous Monitoring: common questions

Is CISA BOD 22-01 still in effect?

No. BOD 26-04, Prioritizing Security Updates Based on Risk, issued 10 June 2026, supersedes and revokes both BOD 22-01 from November 2021 and BOD 19-02 from April 2019. The KEV Catalog continues — CISA maintains it under the new directive — but the flat remediation timelines are gone, replaced by timeframes derived from asset exposure, KEV status, whether exploitation is automatable, and technical impact. An agency vulnerability management policy written against BOD 22-01 now names a revoked authority.

How often are federal agencies required to scan for vulnerabilities?

BOD 23-01, still in force, requires automated asset discovery every seven days covering the agency's entire IPv4 space, and vulnerability enumeration across all discovered assets every fourteen days. Detection signatures must be no more than twenty-four hours behind the vendor's last release, and results must be ingested into the CDM Agency Dashboard within seventy-two hours of discovery completion. Enumeration on managed endpoints and network devices must use privileged credentials or an agent wherever the technology supports it.

Did FedRAMP replace monthly continuous monitoring reporting?

Yes, under the Consolidated Rules for 2026. Providers must supply an Ongoing Certification Report every three months covering the whole period since the previous one, in a consistent human-readable format, together with the target date for the next report and an asynchronous mechanism for agencies to raise questions. A synchronous Quarterly Review is required for Class C and Class D certifications, recommended for Class B and optional for Class A, and should follow the report within ten business days. The rules bind 20x certifications from 4 July 2026 and Rev5 from 1 January 2027.

Why does FedRAMP say persistently instead of continuously?

Because most activity described as continuous is not. FedRAMP defines persistently as recurring in a firm, steady way over a long period, allowing that cycles may be irregular and may include interruptions, provided those attributes are intentional, documented and understood and the status is always known. Its note says the term aligns generally with historical misuse of continuous in federal policy. The practical effect is that you must declare your cycle and evidence its status, not assert an unbroken one.

Is NIST SP 800-137 still the reference for continuous monitoring?

Yes. SP 800-137, published September 2011, remains the ISCM guideline, with SP 800-137A from May 2020 supplying a methodology for assessing an ISCM programme and NIST IR 8212 from March 2021 supplying ISCMAx, a reference implementation of that assessment. ISCMAx is a macro-enabled Excel workbook that runs on Windows only, and NIST states plainly that it is not intended to be a production-level product — a fair measure of how much of this remains the organisation's to build.

Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.

05 / Get Started

Talk to us about Continuous Monitoring.

See how one evidence artifact satisfies Continuous Monitoring requirements alongside every other framework you carry.