Skip to content

iBoss: iboss Government Cloud Platform (IGCP)

FedRAMP AuthorizedRev5Moderate · since July 25, 2022

What its stage means

An agency or the FedRAMP program authorized it. Agencies can reuse that authorization.

See it on the FedRAMP Marketplace

Share this page:LinkedInXEmail

The provider's description

FedRAMP Authorized Zero Trust Security Service Edge for Government, Defense, and Defense Industrial Base The iboss Government Cloud Platform (IGCP) is a state-of-the-art, FedRAMP Moderate Authorized solution designed to provide Zero Trust Security Service Edge (SSE/SASE) for U.S. Federal agencies, defense contractors, Managed Security Service Providers (MSSPs), and organizations entrusted with Controlled Unclassified Information (CUI). IGCP's architecture is built to deliver Zero Trust Network Access (ZTNA), aligning with Cybersecurity Maturity Model Certification (CMMC) requirements and NIST 800-171/172 controls. This ensures compliance and robust security for sensitive government data.

===== DEPLOYMENT FLEXIBILITY ===== Direct Agency Deployment: Federal agencies can deploy IGCP directly as their Zero Trust SASE platform, with full control over policies, configurations, and security operations through the unified management console. MSSP Service Delivery: MSSPs can leverage IGCP's multi-tenant architecture to deliver managed security services to multiple defense contractors and federal customers from a single platform, streamlining compliance and security operations. ===== COMPLIANCE FRAMEWORKS SUPPORTED ===== • CMMC 2.0 Requirements (addresses 78 of 110 NIST SP 800-171 controls) • NIST SP 800-171 (Protecting CUI) • NIST SP 800-172 (Enhanced Security Requirements for CUI) • NIST SP 800-207 (Zero Trust Architecture) • NIST Cybersecurity Framework (CSF) • DFARS 7012 (Safeguarding Covered Defense Information) • CJIS (Criminal Justice Information Services) • HIPAA (Health Insurance Portability and Accountability Act) • ITAR (International Traffic in Arms Regulations) • EAR (Export Administration Regulations) Government agencies and defense contractors are constantly challenged by evolving cyber threats, increasing renewal costs, and the complexity of managing multiple legacy security products. To address these issues, iboss offers both direct deployment for agencies and Managed Security Service Provider (MSSP) solutions. By delivering a SaaS-based Zero Trust SASE platform and comprehensive managed security services, iboss enables organizations to shift their security focus from physical buildings to the continuous protection of people and resources, regardless of where work occurs.

===== FEDERAL MSSP SASE PLATFORM FEATURES ===== Purpose-built for both direct agency use and MSSP operations, the Federal MSSP SASE Platform streamlines and enhances service delivery through several key features: For MSSPs: • Multi-Tenant Management: Allows MSSPs to manage all customers from a single, unified interface • Pooled Device Licensing: Enables licenses to be shared across tenants, providing greater flexibility • Billing in Arrears: Monthly billing cycles designed to align seamlessly with MSP operations • Audit-Ready Compliance Reports: Pre-configured CMMC and NIST 800-171 compliance reports for each tenant

For Direct Agency Deployment: • Unified Management Console: Single pane of glass for policy management, threat monitoring, and compliance reporting • Zero Trust Policy Engine: Centralized policy creation and enforcement across all users, devices, and applications • Real-Time Security Analytics: Comprehensive visibility into all network traffic and security events • Automated Compliance Monitoring: Continuous assessment against FedRAMP, CMMC, and NIST requirements This structure supports rapid scaling while maintaining profitability and operational efficiency in the federal compliance market.

===== CORE CAPABILITIES ===== Zero Trust Architecture (NIST 800-207 Aligned): Enforces least-privilege access and continuous verification for users, devices, and applications, eliminating implicit trust throughout the network. Implements all core Zero Trust principles including identity-based segmentation, encrypted traffic, and continuous monitoring. Secure Access Service Edge (SASE): Integrates advanced cloud se

What FedXchange has recorded

No change since FedXchange began following it on April 14, 2026. Each change of stage, impact level, or number of authorizations appears here.