FedRAMP Marketplace
FedRAMP products for each security function
From the FedRAMP Marketplace's public data as of October 3, 2026: 533 authorized products, 157 of them matched to a function here. A product matches by its name or by the Marketplace's own tag, and a cloud platform counts where its authorization covers the capability. Being listed here is not an endorsement, and FedXchange is not affiliated with these companies.
Getting a product through CDM? Continuous Diagnostics and Mitigation (CDM) supplies software-, platform-, and infrastructure-as-a-service products that are on this Marketplace. Choose the product from the list, and FedXchange records that it comes through CDM.
Identity and Access Management
Until you choose, your documents say “the identity provider”.
FedRAMP listings (13)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Okta IDaaS Regulated Cloud | Okta | SaaS | Moderate | 37 |
| Login.gov | General Services Administration | SaaS | Moderate | 19 |
| Duo Federal | Duo Security (a Cisco Company) | SaaS | Moderate | 14 |
| BeyondTrust Identity Security For Government | BeyondTrust | SaaS | Moderate | 9 |
| Okta IDaaS Government High Cloud (GHC) | Okta | SaaS | High | 8 |
| ID.me Identity Gateway | ID.me | SaaS | Moderate | 7 |
| SailPoint Identity Security Cloud | SailPoint Technologies, Inc. | SaaS | Moderate | 6 |
| Keeper ICAM & Identity Security Platform for Government | Keeper Security | SaaS | High | 5 |
| Saviynt Enterprise Identity Cloud (EIC) | Saviynt, Inc. | SaaS | Moderate | 5 |
| Idira Endpoint Privilege Manager for Government | Palo Alto Networks, Inc. | SaaS | High | 4 |
| Idira Identity Security Government Services Platform | Palo Alto Networks, Inc. | SaaS | High | 3 |
| IAM Advantage | UberEther | PaaS, SaaS | High | 1 |
| RSA® ID Plus for Government | RSA Security LLC | SaaS | Moderate | 1 |
Cloud platforms whose authorization covers it (4)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Azure Commercial CloudMicrosoft security services (Entra ID, Defender, Sentinel, Key Vault) run inside the Azure authorizations; check the service is in scope. | Microsoft | IaaS, PaaS, SaaS | High | 79 |
| AWS US East/WestAWS security services (IAM, KMS, Backup, Config, Security Hub) run inside the AWS authorizations; check the service is in scope. | Amazon | IaaS, PaaS, SaaS | Moderate | 69 |
| Azure Government (includes Dynamics 365)Microsoft security services (Entra ID, Defender, Sentinel, Key Vault) run inside the Azure authorizations; check the service is in scope. | Microsoft | IaaS, PaaS, SaaS | High | 61 |
| AWS GovCloudAWS security services (IAM, KMS, Backup, Config, Security Hub) run inside the AWS authorizations; check the service is in scope. | Amazon | IaaS, PaaS, SaaS | High | 51 |
Run by the government
- USAccess (General Services Administration (GSA))Personal Identity Verification (PIV) credentials and their life cycle, for more than 100 federal agencies
- Login.gov (General Services Administration (GSA))Sign-in and identity proofing for the public using agency applications
Endpoint Detection and Response
Until you choose, your documents say “the endpoint detection and response (EDR) tool”. Many agencies get this through CDM: choose the product below.
FedRAMP listings (5)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| CrowdStrike Falcon Platform for Government | CrowdStrike, Inc. | SaaS | High | 36 |
| SentinelOne Singularity Platform High | SentinelOne | SaaS | High | 7 |
| Trellix GovCloud Security Platform | Trellix | SaaS | High | 3 |
| Trend Cloud One for Government | Trend Micro Inc. | SaaS | Moderate | 1 |
| Trend Vision One for Government | Trend Micro Inc. | SaaS | Moderate | 1 |
Cloud platforms whose authorization covers it (4)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Microsoft 365 Government Community Cloud & Supporting ServicesMicrosoft 365 services such as SharePoint, Exchange Online, and Intune run inside the Microsoft 365 authorizations; check the service is in scope. | Microsoft | SaaS | Moderate | 91 |
| Azure Commercial CloudMicrosoft security services (Entra ID, Defender, Sentinel, Key Vault) run inside the Azure authorizations; check the service is in scope. | Microsoft | IaaS, PaaS, SaaS | High | 79 |
| Azure Government (includes Dynamics 365)Microsoft security services (Entra ID, Defender, Sentinel, Key Vault) run inside the Azure authorizations; check the service is in scope. | Microsoft | IaaS, PaaS, SaaS | High | 61 |
| Microsoft 365 Government Community Cloud-HighMicrosoft 365 services such as SharePoint, Exchange Online, and Intune run inside the Microsoft 365 authorizations; check the service is in scope. | Microsoft | SaaS | High | 5 |
Vulnerability Management
Until you choose, your documents say “the vulnerability scanner”. Many agencies get this through CDM: choose the product below.
FedRAMP listings (4)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Tenable Government Solutions | Tenable Public Sector (TPS) | SaaS | Moderate | 20 |
| Qualys Cloud Platform | Qualys | SaaS | Moderate | 17 |
| Qualys Government Platform | Qualys, Inc. | SaaS | High | 2 |
| InsightGovCloud | Rapid7 | SaaS | Moderate | 1 |
Run by the government
- Cyber Hygiene Vulnerability Scanning and Web Application Scanning (CISA)Free external scanning of internet-facing hosts and public web applications, with weekly and monthly reports
SIEM and Log Management
Until you choose, your documents say “the security information and event management (SIEM) system”. Many agencies get this through CDM: choose the product below.
FedRAMP listings (9)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Splunk Cloud Platform for FedRAMP Moderate | Splunk | SaaS | Moderate | 21 |
| Datadog for Government | Datadog, Inc. | SaaS | High | 13 |
| Dynatrace Platform | Dynatrace | SaaS | Moderate | 9 |
| Elastic Cloud | Elastic | SaaS | Moderate | 8 |
| Splunk Cloud Platform for FedRAMP High | Splunk | SaaS | High | 8 |
| New Relic | New Relic | SaaS | Moderate | 6 |
| Sumo Logic | Sumo Logic | SaaS | Moderate | 3 |
| Cribl.Cloud Government | Cribl Inc. | SaaS | Moderate | 1 |
| Elastic Cloud Hosted - High | Elastic Cloud Hosted | SaaS | High | 1 |
Cloud platforms whose authorization covers it (2)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Azure Commercial CloudMicrosoft security services (Entra ID, Defender, Sentinel, Key Vault) run inside the Azure authorizations; check the service is in scope. | Microsoft | IaaS, PaaS, SaaS | High | 79 |
| Azure Government (includes Dynamics 365)Microsoft security services (Entra ID, Defender, Sentinel, Key Vault) run inside the Azure authorizations; check the service is in scope. | Microsoft | IaaS, PaaS, SaaS | High | 61 |
Run by the government
- Logging Made Easy (CISA)Free, open-source log management for organizations without a SIEM
Mobile Device Management / Endpoint Configuration
Until you choose, your documents say “the mobile device management (MDM) tool”.
FedRAMP listings (3)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Ivanti Neurons for MDM (Formerly MobileIron) | Ivanti | SaaS | Moderate | 4 |
| NinjaOne for Government | NinjaOne | SaaS | Moderate | 2 |
| Omnissa Government Services | Omnissa | SaaS | High | 1 |
Cloud platforms whose authorization covers it (2)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Microsoft 365 Government Community Cloud & Supporting ServicesMicrosoft 365 services such as SharePoint, Exchange Online, and Intune run inside the Microsoft 365 authorizations; check the service is in scope. | Microsoft | SaaS | Moderate | 91 |
| Microsoft 365 Government Community Cloud-HighMicrosoft 365 services such as SharePoint, Exchange Online, and Intune run inside the Microsoft 365 authorizations; check the service is in scope. | Microsoft | SaaS | High | 5 |
Network Security and Web Gateway
Until you choose, your documents say “the secure web gateway”.
FedRAMP listings (14)
Run by the government
- Protective DNS (CISA)DNS filtering that blocks known or suspected malicious destinations; available to federal civilian executive branch agencies
IT Service Management / Ticketing
Until you choose, your documents say “the ticketing system”.
FedRAMP listings (6)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Government Community Cloud | ServiceNow | PaaS, SaaS | High | 90 |
| Atlassian Government Cloud | Atlassian | SaaS | Moderate | 11 |
| Zendesk Customer Support and Help Desk Platform | Zendesk | SaaS | LI-SaaS | 5 |
| BMC Helix | BMC Helix, Inc. | SaaS | Moderate | 4 |
| Ivanti Neurons for ITSM (Formerly Service Manager) | Ivanti | SaaS | Moderate | 3 |
| ITMX Platform featuring Service & Asset Management, Universal Discovery, CMDB and Project & Portfolio Management | OpenText | PaaS, SaaS | Moderate | 1 |
Governance, Risk, and Compliance
Until you choose, your documents say “the GRC system”.
FedRAMP listings (13)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Diligent One Platform (D1P) | Diligent, Inc. | SaaS | Moderate | 7 |
| TalaTek intelligent Governance and Risk Integrated Solution (TiGRIS) | TalaTek, LLC | SaaS | Moderate | 4 |
| RegScale CCM | RegScale | SaaS | High | 3 |
| Xacta SaaS | Telos Corporation | SaaS | High | 2 |
| ComplySyncATO | ASSYST | SaaS | 20x Moderate | 1 |
| Drata Trust Management Platform | Drata | SaaS | 20x Low | 1 |
| IntelliGRC | IntelliGRC, Inc. | SaaS | 20x Low | 1 |
| ITAM | Continuum GRC, Inc. | SaaS | Moderate | 1 |
| Onspring GovCloud | Onspring Technologies, LLC | SaaS | Moderate | 1 |
| Paramify Cloud | Paramify | SaaS | 20x Moderate | 1 |
| Vanta Government Cloud | Vanta | SaaS | 20x Moderate | 1 |
| Vanta Trust Management Platform | Vanta | SaaS | 20x Low | 1 |
| XBU40 | InfusionPoints | PaaS, SaaS | 20x Moderate | 1 |
Cloud platforms whose authorization covers it (1)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Government Community CloudServiceNow Integrated Risk Management runs inside the ServiceNow Government Community Cloud authorization; check the module is in scope. | ServiceNow | PaaS, SaaS | High | 90 |
Run by the government
- JCAM (formerly CSAM) (Department of Justice)Assessment and authorization application with inventory, configuration, and vulnerability management, offered to other agencies
Cloud Infrastructure Platform
Until you choose, your documents say “the cloud platform”.
FedRAMP listings (8)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Azure Commercial Cloud | Microsoft | IaaS, PaaS, SaaS | High | 79 |
| AWS US East/West | Amazon | IaaS, PaaS, SaaS | Moderate | 69 |
| Azure Government (includes Dynamics 365) | Microsoft | IaaS, PaaS, SaaS | High | 61 |
| AWS GovCloud | Amazon | IaaS, PaaS, SaaS | High | 51 |
| Google Services (Google Cloud Platform Products and underlying Infrastructure) | IaaS, PaaS, SaaS | High | 24 | |
| CG-TTS - Cloud.Gov | 18F - 18F Cloud.gov | PaaS | Moderate | 19 |
| Oracle Cloud Infrastructure-Government Cloud | Oracle | IaaS, PaaS | High | 16 |
| IBM Cloud for Government | IBM | IaaS, PaaS | High | 4 |
Backup and Recovery
Until you choose, your documents say “the backup service”.
FedRAMP listings (6)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Druva Data Resiliency Cloud | Druva, Inc. | SaaS | Moderate | 13 |
| AvePoint Online Services for US Government (AOS-UG) | AvePoint Inc. | SaaS | Moderate | 8 |
| Commvault Cloud for Government | Commvault Systems, Inc. | SaaS | High | 7 |
| Own Government Cloud | OwnBackup | SaaS | Moderate | 6 |
| Rubrik Security Cloud - Government (RSC-G) | Rubrik | SaaS | Moderate | 4 |
| Cohesity Cloud Services for Government | Cohesity | SaaS | Moderate | 1 |
Cloud platforms whose authorization covers it (4)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Azure Commercial CloudMicrosoft security services (Entra ID, Defender, Sentinel, Key Vault) run inside the Azure authorizations; check the service is in scope. | Microsoft | IaaS, PaaS, SaaS | High | 79 |
| AWS US East/WestAWS security services (IAM, KMS, Backup, Config, Security Hub) run inside the AWS authorizations; check the service is in scope. | Amazon | IaaS, PaaS, SaaS | Moderate | 69 |
| Azure Government (includes Dynamics 365)Microsoft security services (Entra ID, Defender, Sentinel, Key Vault) run inside the Azure authorizations; check the service is in scope. | Microsoft | IaaS, PaaS, SaaS | High | 61 |
| AWS GovCloudAWS security services (IAM, KMS, Backup, Config, Security Hub) run inside the AWS authorizations; check the service is in scope. | Amazon | IaaS, PaaS, SaaS | High | 51 |
Encryption and Key Management
Until you choose, your documents say “the key management service”.
FedRAMP listings (3)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Keyfactor for Government | Keyfactor | SaaS | Moderate | 1 |
| Vaultara Flare Services | Vaultara, LLC | SaaS | Moderate | 1 |
| Virtru Data Security Platform | Virtru | SaaS | Moderate | 1 |
Cloud platforms whose authorization covers it (4)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Azure Commercial CloudMicrosoft security services (Entra ID, Defender, Sentinel, Key Vault) run inside the Azure authorizations; check the service is in scope. | Microsoft | IaaS, PaaS, SaaS | High | 79 |
| AWS US East/WestAWS security services (IAM, KMS, Backup, Config, Security Hub) run inside the AWS authorizations; check the service is in scope. | Amazon | IaaS, PaaS, SaaS | Moderate | 69 |
| Azure Government (includes Dynamics 365)Microsoft security services (Entra ID, Defender, Sentinel, Key Vault) run inside the Azure authorizations; check the service is in scope. | Microsoft | IaaS, PaaS, SaaS | High | 61 |
| AWS GovCloudAWS security services (IAM, KMS, Backup, Config, Security Hub) run inside the AWS authorizations; check the service is in scope. | Amazon | IaaS, PaaS, SaaS | High | 51 |
Email and Communication Security
Until you choose, your documents say “the email security gateway”.
FedRAMP listings (8)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Trellix Email Security GovCloud | Trellix | SaaS | Moderate | 6 |
| Proofpoint Email and Information Protection Service | Proofpoint, Inc. | SaaS | Moderate | 5 |
| Proofpoint Targeted Attack Protection | Proofpoint, Inc. | SaaS | Moderate | 4 |
| Proofpoint Email Archive | Proofpoint, Inc. | SaaS | Moderate | 3 |
| Valimail Enforce Platform | Valimail | SaaS | LI-SaaS | 3 |
| Abnormal AI for Government | Abnormal AI | SaaS | Moderate | 1 |
| Cyber AI Mission Defense and Email Protection | Darktrace Federal Inc. | SaaS | High | 1 |
| Incydr Gov | Mimecast | SaaS | Moderate | 1 |
Cloud platforms whose authorization covers it (3)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Microsoft 365 Government Community Cloud & Supporting ServicesMicrosoft 365 services such as SharePoint, Exchange Online, and Intune run inside the Microsoft 365 authorizations; check the service is in scope. | Microsoft | SaaS | Moderate | 91 |
| Google WorkspaceGmail runs inside the Google Workspace authorization. | SaaS | High | 19 | |
| Microsoft 365 Government Community Cloud-HighMicrosoft 365 services such as SharePoint, Exchange Online, and Intune run inside the Microsoft 365 authorizations; check the service is in scope. | Microsoft | SaaS | High | 5 |
Asset Management and Discovery
Until you choose, your documents say “the asset inventory tool”. Many agencies get this through CDM: choose the product below.
FedRAMP listings (7)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Armis FedRAMP Edition (AFE) | Armis Federal LLC | SaaS | Moderate | 11 |
| Tanium Cloud for US Government (TC-USG) | Tanium | SaaS | Moderate | 5 |
| Axonius Asset Cloud | Axonius Federal Systems | SaaS | Moderate | 4 |
| Asset Management Suite (AMS) | Bridge Intelligence LLC. dba AssetIntel | SaaS | Moderate | 1 |
| Forescout for Government | Forescout Technologies, Inc. | SaaS | High | 1 |
| ITMX Platform featuring Service & Asset Management, Universal Discovery, CMDB and Project & Portfolio Management | OpenText | PaaS, SaaS | Moderate | 1 |
| Sunflower Asset Management Cloud (SAMC) | CGI Federal | SaaS | Moderate | 1 |
Cloud platforms whose authorization covers it (1)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Government Community CloudServiceNow Discovery and the CMDB run inside the ServiceNow Government Community Cloud authorization; check the module is in scope. | ServiceNow | PaaS, SaaS | High | 90 |
Security Awareness Training
Until you choose, your documents say “the security awareness platform”.
FedRAMP listings (2)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| KnowBe4 Platform | KnowBe4, Inc. | SaaS | Moderate | 22 |
| Cofense PhishMe | Cofense | SaaS | Moderate | 8 |
Continuous Monitoring and Posture Management
Until you choose, your documents say “the cloud security posture tool”. Many agencies get this through CDM: choose the product below.
FedRAMP listings (4)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Wiz for U.S. Government | Wiz, Inc. | SaaS | High | 7 |
| Aqua Platform for Government | Aqua Security Software Inc. | SaaS | High | 1 |
| Orca Cloud Security Platform | Orca Security | SaaS | Moderate | 1 |
| Tenable Cloud Security for US Government - Ermetic | Tenable | SaaS | Moderate | 1 |
Cloud platforms whose authorization covers it (4)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Azure Commercial CloudMicrosoft security services (Entra ID, Defender, Sentinel, Key Vault) run inside the Azure authorizations; check the service is in scope. | Microsoft | IaaS, PaaS, SaaS | High | 79 |
| AWS US East/WestAWS security services (IAM, KMS, Backup, Config, Security Hub) run inside the AWS authorizations; check the service is in scope. | Amazon | IaaS, PaaS, SaaS | Moderate | 69 |
| Azure Government (includes Dynamics 365)Microsoft security services (Entra ID, Defender, Sentinel, Key Vault) run inside the Azure authorizations; check the service is in scope. | Microsoft | IaaS, PaaS, SaaS | High | 61 |
| AWS GovCloudAWS security services (IAM, KMS, Backup, Config, Security Hub) run inside the AWS authorizations; check the service is in scope. | Amazon | IaaS, PaaS, SaaS | High | 51 |
Run by the government
- ScubaGear (Secure Cloud Business Applications) (CISA)Free tool that checks a Microsoft 365 tenant (Entra ID, Exchange Online, SharePoint, Teams, and others) against CISA's secure configuration baselines
Document Management / Policy Library
Until you choose, your documents say “the document library”.
FedRAMP listings (7)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Microsoft 365 Government Community Cloud & Supporting Services | Microsoft | SaaS | Moderate | 91 |
| Box Enterprise Cloud Content Collaboration Platform | Box Inc. | PaaS, SaaS | High | 50 |
| Google Workspace | SaaS | High | 19 | |
| Kiteworks Federal Cloud | Kiteworks USA, LLC | SaaS | Moderate | 16 |
| Microsoft 365 Government Community Cloud-High | Microsoft | SaaS | High | 5 |
| NetDocuments Document Management System (DMS) | NetDocuments Software, Inc. | SaaS | Moderate | 5 |
| OpenText Cloud for Government | OpenText | PaaS, SaaS | Moderate | 2 |
Vulnerability Disclosure Platform
Until you choose, your documents say “the vulnerability disclosure platform”.
FedRAMP listings (3)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| On-Demand Security Testing Platform | Synack | SaaS | Moderate | 4 |
| HackerOne Continuous Security Testing Platform | HackerOne | SaaS | LI-SaaS | 3 |
| Bugcrowd for Government (BCGOV) | Bugcrowd Inc. | SaaS | Moderate | 1 |
Run by the government
- Vulnerability Disclosure Policy Platform (CISA)Report intake, triage, and researcher communication for agency vulnerability disclosure programs; more than 50 civilian agencies take part
Learning Management System
Until you choose, your documents say “the learning management system (LMS)”.
FedRAMP listings (13)
| Product | Company | Model | Impact level | Agencies authorized |
|---|---|---|---|---|
| Cornerstone Galaxy | Cornerstone OnDemand | SaaS | Moderate | 22 |
| PowerTrain Government Learning Enclave - SaaS | PowerTrain Inc. | SaaS | Moderate | 16 |
| Percipio | Skillsoft | SaaS | Moderate | 12 |
| Blackboard LMS | Blackboard | SaaS | Moderate | 9 |
| Knox Systems | CoSo Cloud, LLC. | SaaS | Moderate | 6 |
| Private Cloud | Skillsoft | SaaS | Moderate | 4 |
| Totara Talent Development Government Cloud Platform | Totara Learning Inc. | SaaS | Moderate | 4 |
| Adobe Learning Manager | Adobe | SaaS | LI-SaaS | 2 |
| Aztec Learning System | Aztec Software | SaaS | Moderate | 1 |
| Docebo Learning Platform for Gov (DCBO-GOV) | Docebo | SaaS | Moderate | 1 |
| Federal Immersive Learning Management System (FED-ILMS) | Creative Veteran Productions | SaaS | Moderate | 1 |
| Meridian LMS | Meridian Knowledge Solutions, LLC | SaaS | 20x Moderate | 1 |
| TRAIN Learning Network | Public Health Foundation | SaaS | Low | 1 |
Run by the government
- FedTalent (Department of the Interior, Interior Business Center)Talent management system combining learning management and performance management