ConMon Agent
Runs your monthly continuous monitoring cycle. Scans, scores, and drafts the monthly report.
Automates the FedRAMP / CMMC continuous monitoring workflow — vulnerability scan triage, POA&M status updates, monthly reporting, significant change identification, and control effectiveness review. Produces the monthly ConMon package.
Try a sample prompt:
FedRAMP Moderate · Monthly ConMon Package · 2026-05
Executive Summary
Risk trend: Stable (was improving last month — 2 new high vulnerabilities offset 3 closures)
ATO impact: No re-authorization required this cycle
Significant changes: 1 reviewed (analysis below) — does not trigger ATO refresh
1. Vulnerability Scan Triage
New Findings (since last submission)
| ID | Asset | Severity | CVE | Days Open | Status |
| V-2026-0501 | app-prod-01 | Critical | CVE-2026-2341 | 4 | Patched 2026-05-08 ✓ |
| V-2026-0512 | db-prod-02 | Critical | CVE-2026-1899 | 1 | Patch scheduled 2026-05-12 |
| V-2026-0509 | web-prod-03 | High | CVE-2026-3122 | 7 | In progress — vendor fix expected 2026-05-22 |
| V-2026-0519 | mon-prod-01 | High | CVE-2026-2089 | 14 | Escalating — ROD pending |
CISA KEV Cross-Reference
2 of 4 critical findings overlap with CISA KEV (V-2026-0501, V-2026-0512). Both within KEV remediation due dates.
Persistent Findings (>30 days)
3 medium findings rolled forward from April:
- M-2026-0312 (CIS benchmark drift on 4 EC2) — process gap, not technical
- M-2026-0328 (TLS 1.0 enabled on legacy LB) — deprecation in progress
- M-2026-0401 (default M365 token lifetime) — exception filed, accepted by AO
2. POA&M Status Update
Total open: 23 (down 2 from April)
Milestones met this month: 7
Milestones missed: 2 (re-baselining attached as POAM-EXT-0026-05)
Items Past Milestone
| ID | Control | Original Due | Proposed New Due | Justification |
| POAM-0019 | CM-8(3) | 2026-05-01 | 2026-07-01 | Vendor inventory tool delivery delayed |
| POAM-0027 | RA-5(11) | 2026-04-30 | 2026-06-15 | Public-facing scan tool selection in progress |
Closed This Month
POAM-0014, POAM-0017, POAM-0021, POAM-0025, POAM-0029, POAM-0033, POAM-0038
Closure evidence attached as separate ZIP.
3. Significant Change Analysis
Change: Migration of identity provider from Auth0 to Okta (Acme-CR-2026-0428)
Analysis against FedRAMP Significant Change Procedure §3.2:
| Criterion | Determination |
| New authorization boundary asset class | NO — Okta already in inventory as backup IdP |
| Change in cryptographic module FIPS validation | NO — both FIPS 140-2 validated |
| New external system interconnection | NO — same IdP function, vendor swap |
| Change in data type or sensitivity | NO |
| Significant decrease in compensating controls | NO — coverage increases |
Determination: NOT a significant change per PMO Significant Change Procedures. Documented as a routine change in change register. No SAR refresh required. AO notified for awareness only.
4. Control Effectiveness Spot Check
Sampled 5 controls this month: AC-2, AC-7, AU-6, CM-3, CP-9.
- AC-2: ✓ Q2 review completed, evidence current
- AC-7: ✓ Lockout policy enforced, sample tests passed
- AU-6: ⚠ Alert review SLA missed for 2 of 30 alerts (response > 5 business days). Process update issued.
- CM-3: ✓ Change approvals 100% sampled, all attested
- CP-9: ✓ Last successful backup test 2026-04-15, restore validated
Net assessment: All controls operating. One minor SLA gap (AU-6) corrected this cycle.