DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-FR2031936863

Armis FedRAMP Edition (AFE)

Armis Federal LLC lists Armis FedRAMP Edition (AFE) on the FedRAMP Marketplace with the status FedRAMP Certified, at Moderate impact, on the Agency path under the Rev5 process. Package FR2031936863, read from the marketplace feed as of September 3, 2026.

FedRAMP CertifiedRev5Agency path

Section A. Register entry

What the marketplace records

FedRAMP package ID
FR2031936863
Cloud service provider
Armis Federal LLC
Certification status
FedRAMP Certified
Impact level
Moderate
Certification class
Class C (Moderate)
Authorization path
Agency
Certification type
Rev5
Marketplace phase
Ongoing Certification
Deployment model
Government Community Cloud
Register snapshot
September 3, 2026
Service model
SaaS
Independent assessor
Schellman Compliance, LLC
Certification date
January 9, 2023
Status date
January 9, 2023
Annual assessment
July 14, 2011
Agency authorizations
10
Recorded reuses
9
Milestones on record
3

The marketplace carries Armis FedRAMP Edition (AFE) under package FR2031936863 with 18 recorded fields. Its certification date is January 9, 2023. Schellman Compliance, LLC is named as the independent assessor, with an annual assessment date of July 14, 2011. 10 agencies are listed as having authorized it, among them Brookhaven Site Office, Cybersecurity & Infrastructure Security Agency, Department of Health and Human Services and 7 more, and the feed records 9 reuses of the package. It is delivered as SaaS on a government community cloud.

Section B. Milestones

3 entries in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
January 9, 2023Status ChangeStatus changed from PMO Review to FedRAMP Certified
July 11, 2022Status ChangeStatus changed from Agency Review to FedRAMP In Process
May 12, 2022Status ChangeStatus set to Agency Authorization In Process

Section C. Cost context

What reaching Moderate costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a Moderate authorization

Initial authorization$800,000 to $2,000,000
Continuous monitoring$150,000 to $350,000 a year
Typical timeline12 to 18 months
Control baseline325+ controls
Annual assessment$90,000 to $260,000 a year

Our published planning range for a provider pursuing Moderate. It is not a figure any listed provider has disclosed.

Read the FedRAMP Moderate cost guide / annual assessment cost / continuous monitoring cost

Path

Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost

Assessment and monitoring

An annual assessment date of July 14, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost

Section E. Agencies on the record

10 agencies listed against this package

As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.

  • Brookhaven Site Office
  • Cybersecurity & Infrastructure Security Agency
  • Department of Health and Human Services
  • Department of Labor
  • Department of State
  • Department of Veterans Affairs
  • Federal Deposit Insurance Corporation
  • National Science Foundation
  • Office of the National Coordinator for Health Information Technology
  • Tennessee Valley Authority

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

Armis FedRAMP Edition (AFE) is an agentless, enterprise-class security platform built off of the Armis Centrix™ engine to help organizations discover and secure managed, unmanaged, and IoT devices, including medical devices and industrial control systems (ICS). Armis discovers every managed, unmanaged, and IoT device in any environment, analyzes device behavior to identify risks, vulnerabilities or attacks, and protects critical business information and systems. Armis easily integrates with existing security products. AFE passively monitors wired and wireless traffic in the environment to identify every device and to understand its behavior without disruption. AFE analyzes this data in the AFE Risk Engine which uses device profiles and characteristics from the AFE Device Knowledgebase to identify each device, assess its risks & vulnerabilities, detect threats, and recommend remediation actions. Visibility: AFE closes the Continuous Diagnostic and Mitigation Dashboard visibility gap with unmanaged and IoT devices. AFE discovers and classifies every managed, unmanaged, and IoT device in the environment including servers, laptops, smartphones, VoIP phones, smart TVs, IP cameras, printers, 5G, HVAC controls, medical devices, industrial controls, and more. AFE can even identify off-network devices using Wi-Fi, Bluetooth, and other protocols in any environment. The comprehensive device inventory that AFE generates includes critical information such as device manufacturer, model, serial number, location, username, operating system, installed applications, and connections made over time. In addition to discovering and classifying a device, AFE calculates its risk score based on factors such as vulnerabilities, known attack patterns, as well as the behaviors observed of each device in the environment. This risk score helps security teams understand their attack surface and meet compliance with regulatory frameworks that require identification and prioritization of vulnerabilities. Insights: The AFE Risk Engine continuously monitors the behavior of every device in the environment for behavioral anomalies. Working with the AFE Device Knowledgebase, AFE compares the real-time behavior of each device with: ● Historical device behavior ● Behavior of similar devices in the Customer's environment ● Behavior of similar devices in other environments ● Common attack techniques ● Information from threat intelligence feeds Actions: With these types of critical device and behavioral insights, AFE is able to identify threats and attacks. When AFE detects a threat, it can alert security teams and trigger automated action to stop an attack. Through integrations with network infrastructure, as well as the Customer's existing security enforcement points like Cisco and Palo Alto Networks firewalls, and network access control (NAC) products such as Cisco ISE and Aruba ClearPass, AFE can restrict access or quarantine suspicious or malicious devices. Easy Integration: AFE requires no agents or additional hardware to deploy. AFE integrates with existing firewalls or NAC, security management systems such as SIEM, ticketing systems, and asset databases. These integrations allow AFE to leverage existing investments to achieve greater value and more automated response. VIPR Pro: Armis Centrix™ for VIPR Pro delivers a FedRAMP-authorized cyber exposure management solution that helps federal agencies bridge the gap between fragmented security data and actionable risk reduction. Built to solve extreme alert fatigue, VIPR Pro acts as a centralized aggregator that ingests, correlates, and de-duplicates static security findings; including traditional vulnerabilities, cloud misconfigurations, and application security flaws - from across an agency's existing security stack. Rather than hunting for active threats, the platform applies machine learning to consolidate disparate scan data, reducing finding volumes by up to 50-to-1. VIPR Pro contextualizes these findings by overlaying external threat intelligence, exploit likelihood, and agency-defined asset criticality to automatically prioritize the highest-impact exposures. Utilizing predictive AI to instantly determine asset ownership and initiate automated bulk-ticketing, the solution shortens manual assessment times by 80% and accelerates Mean Time to Remediation (MTTR) by up to 90%. Federal agencies can now operationalize their vulnerability management programs, orchestrate cross-departmental fixes, and maintain continuous compliance through a unified, fully auditable risk-resolution lifecycle.

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28