Continuous Diagnostics and Mitigation: A SaaS Provider Guide
For a SaaS provider, Continuous Diagnostics and Mitigation (CDM) usually surfaces in an agency security questionnaire or a request for information (RFI), with no explanation of what the program expects from a cloud provider. The answer starts with a distinction: CDM measures the agency's own network, while the Federal Risk and Authorization Management Program (FedRAMP) sets the requirements a cloud provider has to meet. The Cybersecurity and Infrastructure Security Agency (CISA) runs CDM, and about 100 federal civilian agencies report into it.
The gap matters because the Federal Information Security Modernization Act (FISMA) extends the continuous-monitoring duty on agencies to their cloud usage, and authorizing officials meet that duty partly through the monitoring data their providers deliver. A provider that understands CDM knows what its federal customer is measured on, and where its own evidence lands in that measurement.
Key Takeaways
- SaaS providers are measured rather than enrolled. CDM is an agency-side CISA program, and a SaaS provider contributes to it indirectly, through the FedRAMP monitoring evidence its federal customer relies on.
- CDM is a specific CISA program. CDM was developed in 2012, FISMA 2014 supplies its authority, and it covers federal civilian networks only.
- Four capability areas roll up into one score. Asset Management, Identity and Access Management, Network Security Management, and Data Protection Management each answer one question about an agency network. Sensor data becomes an Agency-Wide Adaptive Risk Enumeration (AWARE) score that rolls up to a federal dashboard CISA and the Office of Management and Budget (OMB) both read.
- FedRAMP serves as the provider's counterpart. CDM watches the agency side while FedRAMP governs what the provider reports. The FedRAMP Consolidated Rules for 2026 (CR26), released June 24, 2026 and mandatory for all stakeholders January 1, 2027, move Plan of Action and Milestones (POA&M) upkeep to agencies and shift providers to vulnerability detection and response reporting.
Continuous Diagnostics and Mitigation Is CISA's FISMA-Authorized Program for Federal Civilian Networks
FISMA 2014 (Pub. L. 113-283) supplied CDM's statutory footing, authorizing the Department of Homeland Security (DHS) to deploy, operate, and maintain technologies that help agencies continuously diagnose and mitigate cyber threats. CDM was developed in 2012, and CISA, a DHS component, now runs it. CISA's program page describes its purpose as providing "risk-based, consistent, and cost-effective cybersecurity solutions" to protect federal civilian networks across all organizational tiers.
Under the Chief Financial Officers (CFO) Act, the 23 civilian CFO Act agencies feed the federal dashboard, and 75 eligible non-CFO Act agencies reach CDM capabilities through the Shared Services Platform. Together they account for the roughly 100 agencies in the program.
The program delivers cybersecurity tools and integration services, and its dashboards help agencies shrink their threat surface and see more of their own networks. CDM's design premise is that a periodic audit gives no assurance between reviews, so sensors continuously enumerate assets, users, configurations, and vulnerabilities instead of taking compliance snapshots.
FISMA requires agencies to evaluate their information security programs annually, and OMB guidance issued in 2012 and 2013 retired the three-year reauthorization cycle. Agencies moved to an ongoing authorization posture, where an authorizing official judges whether continued operation is acceptable from current risk data rather than from a point-in-time Authority to Operate (ATO).
CDM sensors turn that standing obligation into four bounded questions about assets, identities, network activity, and data.
CDM Reduces Federal Cyber Risk Across Four Capability Areas
CISA organizes the program into four capability areas, each answering one question about an agency network and each addressing one class of risk. The areas replaced the older "Phase 1 through 4" labels and retain those labels in CDM Data Model v6.0.1.
- Asset Management (formerly Phase 1) answers "what is on the network?" Hardware Asset Management (HWAM) and Software Asset Management (SWAM) build the inventory everything else depends on, and configuration and vulnerability sensors check each device against federal benchmarks and known flaws. The risk addressed is unknown devices and unauthorized software.
- Identity and Access Management (formerly Phase 2) answers "who is on the network?" Its sub-capabilities cover trust determination for people granted access, security-related behavioral training, credentials and authentication, and account privileges. The risk addressed is over-privileged or unverified users.
- Network Security Management (formerly Phase 3) answers "what is happening on the network?" Network boundary controls limit unauthorized connections and report where encryption is in use, and event-handling capabilities cover detection and daily operations. The risk addressed is unmonitored traffic and undetected movement inside the network.
- Data Protection Management (formerly Phase 4) answers "how is the data protected?" The five data protection offerings cover discovery, classification, loss prevention, spillage mitigation, and information rights management. The risk addressed is critical mission data exposure.
Asset Management is the foundation the other three areas rest on. CISA's asset-management guidance states the dependency plainly: "It is impossible to check for a software asset if we do not know where it was or should be installed."
CISA zero trust alignment is planned, so the last two areas are still being defined. The Government Accountability Office (GAO) rated the program as meeting two of its four goals in June 2025, and officials from 21 of 23 agencies said they had not yet fully implemented the network security and data protection capabilities.
Each capability area produces its own stream of data, and an agency reads them as one risk picture only after they are normalized.
The CDM Dashboard Gives Agencies and CISA a Shared Operational Picture
Each participating agency runs a CDM Agency Dashboard that ingests sensor data and displays devices, users, privileges, and vulnerabilities at the object level. The dashboard applies the AWARE risk scoring methodology, which starts from a vulnerability's Common Vulnerability Scoring System (CVSS) base value and scales it logarithmically so the worst vulnerabilities dominate. Age counts as well, and a vulnerability's score doubles from its base after 90 days, measured from the Common Vulnerabilities and Exposures (CVE) publication date.
Summary data and AWARE scores flow up to the CDM Federal Dashboard, which gives CISA and OMB visibility across all federal networks, while enriched vulnerability data and data calls flow back down. Binding Operational Directive (BOD) 23-01 changed the sharing model, requiring a dashboard configuration that exposes object-level vulnerability data to CISA analysts. It also set the automation cadence: asset discovery every 7 days, vulnerability scans every 14 days, and results uploaded generally within 72 hours.
CISA keeps the scores out of public view. Former CDM program manager Kevin Cox said adversaries "will be looking to see which agencies are having problems so they can go target them."
A shared picture of agency-owned assets still leaves out the cloud services agencies buy, which is where the statutory monitoring duty reaches next.
CDM Fulfills FISMA's Continuous Monitoring Mandate for Federal Cloud Systems
For cloud, OMB M-24-15 (July 2024) requires agencies to "Continuously diagnose and mitigate against cyber threats and vulnerabilities associated with usage of cloud service offerings." That duty splits along one line: CDM sensors inventory agency-side assets, while FedRAMP continuous compliance governs the monitoring reports a provider submits to the agency authorizing official.
Within CDM, diagnostics means sensors enumerate each asset and its configuration while identifying vulnerabilities. The program's second half, mitigation, covers what happens next, and BOD 26-04 distinguishes two forms of it: remediation eliminates the vulnerability by patching or decommissioning the system, while removing an asset from the internet is a valid mitigation that leaves the flaw in place.
That division between agency diagnostics and provider reporting determines what SaaS providers must supply after authorization.
SaaS Providers Entering the Federal Market Must Support CDM-Compatible Monitoring
When CDM appears in an agency questionnaire or an RFI, a provider should treat it as an agency monitoring requirement rather than a request to operate the program. The practical response is to confirm four things with the agency authorizing official: the required inventory scope, the vulnerability evidence expected, the reporting cadence, and the delivery route. The program neither requires a provider to join it nor displaces the FedRAMP obligations the provider already carries.
CDM's Data Model Reaches Cloud Assets Ahead of the Program Itself
CDM's data model already reaches third-party-managed SaaS, while the operational program has not caught up. CDM Data Model v6.0.1 covers SaaS offerings managed by third parties, and it carries a required IsEphemeral device attribute that marks a device as a container or a SaaS offering managed by a third party. CISA's Secure Cloud Business Applications (SCuBA) project publishes secure configuration baselines and assessment tooling for Microsoft 365 and Google Workspace.
GAO's 2025 review found that CISA has not finalized its plan for CDM support of cloud asset management, so cloud coverage exists on paper ahead of practice.
FedRAMP Deliverables Are the Provider's Side of the Same Obligation
The provider's side of the monitoring obligation runs through FedRAMP. Under the transitional FedRAMP Continuous Monitoring Playbook v1.0 (November 17, 2025), a provider uploads an updated POA&M and an updated inventory every month, and uploads raw vulnerability scan files where agency agreements require them.
The provider submits these deliverables to the FedRAMP secure repository, which the agency authorizing official reviews against Continuous ATO requirements. Under CR26, providers instead use vulnerability detection and response reporting while agencies maintain POA&Ms, and that reporting becomes mandatory December 7, 2026. BOD 26-04 ties that reporting to a deadline: an agency's remediation clock starts when CISA adds a vulnerability to the Known Exploited Vulnerabilities (KEV) Catalog or when the agency records it in the CDM Dashboard, whichever comes first.
FedRAMP has stated that providers following its Vulnerability Detection and Response rules will meet or exceed BOD 26-04 expectations. During the transition, the provider's continuous monitoring submissions give the agency authorizing official monthly inventory and vulnerability data for ongoing review.
Reliable provider evidence therefore decides how much of an agency's continuous picture is actually current.
Continuous Diagnostics and Mitigation Measures a Provider's Evidence, Not Its Participation
The word "continuous" in CDM describes the agency's obligation. What a provider controls is how reliably its FedRAMP evidence arrives and how fast its vulnerabilities close, and an agency's continuous picture is only ever as current as that evidence.
Knox Systems' government cloud platform operates a pre-authorized FedRAMP boundary. Eligible providers inherit 60% to 80% of the required National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Rev5 controls and reach authorization in approximately 90 days at approximately 90% less cost than traditional methods. Knox's automated continuous monitoring platform generates each month's evidence from live system data.
If monthly monitoring deliverables are consuming engineering cycles, book a meeting to map what changes when that evidence is generated rather than assembled.
FAQs about Continuous Diagnostics and Mitigation
Must a SaaS Provider Join the CDM Program?
No. CDM is an agency-side CISA program. A SaaS provider supports the customer's obligations through FedRAMP monitoring evidence and any additional data requirements established by the agency agreement.
Can an Agency Require CDM Data Directly from a SaaS Provider?
Yes, but through the agency agreement rather than through the CDM program itself. An agency agreement can require data beyond the FedRAMP monitoring package, including asset inventory detail or scan output in a specified format, so providers confirm scope with the agency authorizing official.
How Often Must Agencies Report KEV Status Manually?
Agencies, not SaaS providers, submit manual KEV status reports every two weeks when vulnerability reporting is not fully automated. Providers should maintain current vulnerability evidence because agency dashboard records can affect remediation timing.
Does a Provider Send FedRAMP Monitoring Reports Directly to CISA?
No. The provider submits its monitoring deliverables to the FedRAMP secure repository for review by the agency authorizing official. Agency CDM dashboards separately share the required agency data with CISA.
What Changes for Provider Continuous Monitoring Under CR26?
Providers move from monthly POA&M submissions to vulnerability detection and response reporting, and agencies take over POA&M upkeep. That reporting becomes mandatory December 7, 2026, ahead of full CR26 adoption on January 1, 2027.

