Skip to content

Diligent, Inc.: Diligent One Platform (D1P)

FedRAMP AuthorizedRev5Moderate · since November 20, 2019

What its stage means

An agency or the FedRAMP program authorized it. Agencies can reuse that authorization.

See it on the FedRAMP Marketplace

Share this page:LinkedInXEmail

The provider's description

Diligent’s D1P GRC platform is the only enterprise-grade solution purpose-built to manage the full lifecycle of FedRAMP, DOD/DISA IL and CMMC compliance—from initial SSP development to ongoing POA&M updates, ConMon, and audit readiness. Designed with automation at its core and trusted by federal agencies, integrators, and 3PAOs, Diligent eliminates spreadsheet chaos and empowers teams to focus on actual security—not documentation.

Purpose-Built for Complex Cybersecurity Compliance

Diligent delivers deep automation and pre-configured workflows for:

- FedRAMP (Low, Moderate & High) - DOD / DISA Impact Levels (2, 4, 5) - CMMC (Level 1, 2 and beyond) - NIST 800-53, NIST 800-171, SOC 2, and ISO 27001 and other major compliance frameworks - Support for custom frameworks and policy libraries

Core Capabilities

- Live SSP and ATO Package Management - Automatically generates and maintains OSCAL and human-readable SSPs. Track versioning, delta changes, and live control status from a single system. - Automated POA&M Generation and Updates - POA&Ms are created directly from scan data, control testing, or manual input. Linked to owners, evidence, due dates, and tracked in real time with alerting. - Continuous Monitoring, ConMon & Risk Insights - Real-time dashboards ingest data from 130+ tools including vulnerability scanners, cloud providers, HR systems, and ticketing platforms. Evidence collection is automatic and centralized for audit readiness. -Control Inheritance and Framework Mapping -Cross-map and inherit controls across frameworks. “Write once, apply many” saves time and ensures consistency for multi-standard organizations. -Multi-Tenant Partner and Reseller Enablement -Native support for MSSPs, C3PAOs, and resellers. Role-based access, tenant-level data separation, and white-labeled deployments available. -API and Integration Ecosystem -With over 130 out-of-box integrations and a robust open API, Diligent connects seamlessly to your stack—cloud, on-prem, or hybrid.

Deployment & Security

- Hosted on AWS GovCloud with three available options: FedRAMP moderate (primarily SLED), FedRAMP moderate and DOD IL5 (primarily for - Federal and some DOD), and FedRAMP moderate and DOD IL for DOD only (requires DoDIN access). - Built with security-first architecture, supporting unique customer keys, data segregation, and FIPS 140-2 validated encryption.

What Sets Diligent Apart

- FedRAMP, DOD and CMMC are core, not bolt-ons—we’ve built workflows around these frameworks from the ground up. - Automation beyond templates—real-time evidence ingest, compliance task enforcement, and live control dashboards. - Used by regulators, 3PAOs, integrators, and contractors—proven across the full compliance ecosystem. -Designed to scale—whether you’re managing 1 ATO or 50, Diligent supports your growth.

What FedXchange has recorded

  1. Diligent One Platform (D1P) from Diligent, Inc. gained 2 agency authorizations, 8 in all.