
Adam Shnider
EVP, Assessment Services, Coalfire
FedRAMP®


At the heart of the issue is a fundamental misalignment: POA&Ms, as explained in detail in Pete Waterman’s recent GitHub post “A POA&M for POA&Ms”, were born from resource and capital planning principles, to “correct any material weaknesses”. The Office of Management and Budget (OMB) defines a “material weakness” as a deficiency that could lead to a significant misstatement in financial reports. OMB extended this to cybersecurity—but the translation has been clumsy at best with less definition and open to agency interpretation where deficiencies in cybersecurity controls create a reasonable possibility that a material misstatement in financial reports, a significant operational failure, or a major non-compliance with laws and regulations will not be prevented or detected in a timely manner.
The FSCAC’s August 2025 meeting could be a turning point in providing the FedRAMP PMO with insight into the challenge and drive real change to the POA&M standards or even redefine the requirement of focus on the FedRAMP Authorization Act to track risks. In preparation for the FSCAC meeting I met with over a dozen CSPs of all sizes and met with seasoned assessors and ConMon experts to ensure I had a broad sense of the challenge to answer the main questions being asked. The following highlights the questions asked of the FSCAC members and some of the feedback from the research performed.
Based on the community feedback, it is clear they are calling for a radical shift—from compliance checklists to dynamic risk management. The final question was related to recommended changes that address the pain points and increase the benefits of the process.
Cloud Service Providers (CSPs) are drowning in administrative overhead. The current POA&M model feels like it may be rewarding volume over value—counting vulnerabilities instead of contextualizing risk. Monthly reporting cycles churn out outdated data, while security teams are forced to prioritize spreadsheet hygiene over threat modeling and secure design.
Agencies, meanwhile, are left with a false sense of security. They receive rigid Excel templates filled with binary thresholds and vulnerability counts, but lack insight into exploitability, asset criticality, or environmental context. The result? Misprioritized threats, delayed remediation, and a growing gap between compliance and actual security.
FedRAMP’s RFC 0012 is a pivotal step toward transforming continuous monitoring (ConMon) from a data dump into a strategic asset. The current POA&M model often absorbs raw scan data without context, overwhelming agencies and obscuring real risk because it is so heavily focused on rigid timelines, vulnerability counts and non-contextual CVSS scores.
RFC 12 proposes a smarter approach: use continuous monitoring to classify risk based on exploitability, environmental context, and asset criticality. While the RFC was not perfect, it seems to acknowledge a shift from beyond CVSS scores and embracing dynamic, real-world indicators that could be accomplished with VEX and EPSS. When done right, ConMon becomes a more valuable threat indicator—not just an unvetted list of CVSS scores.
It is absolutely critical to get the new ConMon standards right in order to empower CSPs to prioritize remediation efforts based on actual threat potential, and give agencies a clearer picture of what truly matters. It’s not just about finding vulnerabilities—it’s about understanding which ones could actually hurt you. This will make the real risks identified to be translated into POA&Ms to track “material weaknesses” not just a list of vulnerabilities as required in the original intent of the POA&M as it relates to cybersecurity.
One of the most dramatic recommendations from my preparation is to decouple continuous monitoring from POA&M reporting. Here’s why:
This separation allows ConMon to serve its purpose—continuous visibility—while POA&Ms become a targeted tool for managing and mitigating significant risks.
The irony is rich: we need a POA&M to fix POA&Ms. But this isn’t just about tweaking templates or updating guidance. It’s about reimagining how we define, manage, and communicate risk in a cloud-first world.
FedRAMP has the opportunity to lead—not just in compliance, but in real cybersecurity.