FedRAMP continuous monitoring: what to collect and when

FedRAMP continuous monitoring is the recurring work of finding weaknesses, checking security controls, updating remediation records, and sharing current evidence with the parties who oversee a cloud service. Rev 5 includes monthly scan and POA&M materials; 20x adds ongoing evidence and quarterly reporting obligations. Neither a dashboard nor a successful sync proves a service meets FedRAMP requirements.

Product measurement: scm.cc's current FedRAMP Rev 5 Class C (Moderate) inventory contains 323 control identifiers. Its tenant dashboard counts controls with at least one recorded evidence class, not 323 controls passed, and exposes policy, provider, connector and platform-artifact contributions separately.

FedRAMP now uses Certification and Classes A-D for package baselines. During the transition through December 31, 2026, Class B (Low), Class C (Moderate) and Class D (High) pair the new class with the earlier label; Class A is a pilot. Certification does not replace an agency's own authorization to operate. Historical Rev 5 baseline identifiers in records stay unchanged.

What is in a monthly Rev 5 cycle?

A monthly cycle starts with actual scanner output, not a green dashboard. The FedRAMP Rev 5 continuous-monitoring clarification calls for sharing operating-system, database, web-application, container and service-configuration scans and an updated POA&M at least monthly. The inventory and annual independent-assessor scans have their own requirements. A missing scan should remain missing in the package, rather than be inferred from another source's successful sync.

How does 20x continuous monitoring differ?

FedRAMP 20x emphasizes measured security outcomes and automated validation where possible. Its collaborative monitoring rules describe a human-readable Ongoing Certification Report every three months with summaries such as changes, accepted vulnerabilities, incidents and lessons learned. Class C providers have a separate machine-resource verification rule of at least every three days. Do not mistake scm.cc's monthly run schedule for that 3-day validation: this production path has not been completed.

What does scm.cc actually automate?

The product has a tenant-scoped monthly run that records an evidence snapshot against a pinned baseline and shows gaps when loaders fail. A package download includes its run, findings and POA&M-related data. The public demo is labeled fixture data. Some connectors and KSI checks are implemented, but unconnected or unmeasured sources cannot produce a verified outcome. Actual coverage depends on the tenant's configured sources and records.

What does it cost, and what should a buyer test?

The current pricing page lists Free with one repo and one connector; Starter at $299 per month with ten repos and three connectors; Pro at $599 with 100 repos and six connectors; and Business at $999 with 500 repos and 12 connectors. Paid tiers are monthly. Test a source that really produces findings, a degraded sync, and an exported report before deciding whether the workflow fits. Fees buy software capacity, not an assessment, FedRAMP certification or agency authorization to operate.

Questions teams ask

Is ConMon the same as FedRAMP certification?
No. Continuous monitoring is ongoing provider and agency work. scm.cc organizes records; it is not a 3PAO, agency authorizing official, or FedRAMP certification.
Does a connected scanner mean all controls are covered?
No. A connector may have limited scope or a degraded pull. The tenant dashboard counts recorded evidence classes, not full control effectiveness or compliance.
Does scm.cc validate machine resources every three days?
Not through its current production ConMon run path. The tenant run is monthly; the 20x Class C three-day validation gap remains open.
Can a team use both Rev 5 and 20x reports?
The obligations depend on the service's actual FedRAMP path and class. A team may need transition records, but should check the official rules and its assessor or agency rather than treating one report as a substitute for another.

Primary sources

Source and product behavior reviewed September 30, 2026. Check current FedRAMP rules before relying on a schedule or submission requirement. This is product guidance, not an assessment, legal advice, certification or authorization.