Federal compliance
DefectDojo Pro can run the vulnerability management side of a federal compliance program. It keeps a FedRAMP-style Plan of Action and Milestones (POA&M) for each system, produces monthly Continuous Monitoring (ConMon) deliverables in the official Excel and OSCAL formats, scores CMMC Level 2 self-assessments, and shows which NIST 800-53 controls your scanners actually exercise.
Everything described in this section lives on the Compliance tab of an Asset.
Enabling the feature
Federal Compliance ships behind the Compliance feature flag, which is in beta and off by default. An administrator turns it on from the feature flags menu — see Feature Flags. Once enabled, a Compliance tab appears on each Asset.
Beta: confirm results before you rely on them
This feature is in beta. The bundled NIST 800-171 and 800-53 control statements, the DoD SPRS point weights, and the POA&M-eligibility rules are provided to help you track and estimate your posture, and are pending independent validation against the authoritative source documents.
SPRS scores, conditional-eligibility results, and control coverage are advisory. Confirm them against the official DoD NIST SP 800-171 Assessment Methodology and current FedRAMP guidance before you rely on them for a certification, an assessment submission, or any contractual purpose.
In this section
| Page | What it covers |
|---|---|
| Compliance Profile | Enrolling an Asset as a system and setting the facts that appear on every deliverable |
| The POA&M Ledger | How POA&M items are created from findings, and the conventions the ledger follows |
| ConMon Snapshots | Monthly deliverables in FedRAMP Excel and OSCAL, and the optional OSCAL validation service |
| Remediation Deadlines | The FedRAMP Rev 5 and FedRAMP VDR SLA presets |
| CMMC Level 2 Assessments | Scoring a self-assessment against NIST 800-171 Rev 2 |
| Control Coverage | Which 800-53 controls your scanners test, and open weaknesses per control |
Score a self-assessment against NIST 800-171 Rev 2
Enroll an Asset as a system and set the facts that appear on every deliverable
Monthly deliverables in FedRAMP Excel and OSCAL, and the optional OSCAL validation service
Which 800-53 controls your scanners test, and open weaknesses per control
The FedRAMP Rev 5 and FedRAMP VDR SLA presets
How POA&M items are created from findings, and the conventions the ledger follows