Section 8.4 - Register entry
DOC-REF: FRC-MKT-FR2514624801
Checkmarx One for Government (CXG)
Checkmarx lists Checkmarx One for Government (CXG) on the FedRAMP Marketplace with the status FedRAMP Certified, at Moderate impact, on the Agency path under the Rev5 process. Package FR2514624801, read from the marketplace feed as of September 3, 2026.
Section A. Register entry
What the marketplace records
- FedRAMP package ID
- FR2514624801
- Cloud service provider
- Checkmarx
- Certification status
- FedRAMP Certified
- Impact level
- Moderate
- Certification class
- Class C (Moderate)
- Authorization path
- Agency
- Certification type
- Rev5
- Marketplace phase
- Ongoing Certification
- Deployment model
- Government Community Cloud
- Register snapshot
- September 3, 2026
- Service model
- SaaS
- Independent assessor
- Schellman Compliance, LLC
- Certification date
- June 12, 2026
- Status date
- June 12, 2026
- FedRAMP Ready date
- June 19, 2025
- Annual assessment
- April 17, 2011
- Agency authorizations
- 1
- Business categories
- Cybersecurity & Risk Management
- Small business
- Flagged on the marketplace record
- Milestones on record
- 4
The marketplace carries Checkmarx One for Government (CXG) under package FR2514624801 with 20 recorded fields. Its certification date is June 12, 2026, and a FedRAMP Ready date of June 19, 2025. Schellman Compliance, LLC is named as the independent assessor, with an annual assessment date of April 17, 2011. 1 agency is listed as having authorized it, among them National Institutes of Health. It is delivered as SaaS on a government community cloud, filed under 1 business categories including Cybersecurity & Risk Management. Checkmarx is flagged as a small business on the record.
Section B. Milestones
4 entries in the marketplace event log
Most recent first, as recorded by FedRAMP.
| Date | Category | Recorded |
|---|---|---|
| June 12, 2026 | Status Change | Status changed from PMO Review to FedRAMP Certified |
| April 24, 2026 | Status Change | Status changed from Agency Review to FedRAMP In Process |
| December 17, 2025 | Status Change | Status changed from FedRAMP Ready to Agency Authorization In Process |
| June 19, 2025 | Status Change | Status set to Legacy FedRAMP Ready |
Section C. Cost context
What reaching Moderate costs
Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.
Cost context
Budget for a Moderate authorization
Our published planning range for a provider pursuing Moderate. It is not a figure any listed provider has disclosed.
Read the FedRAMP Moderate cost guide / annual assessment cost / continuous monitoring cost
Path
Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost
Assessment and monitoring
An annual assessment date of April 17, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost
Section E. Agencies on the record
1 agency listed against this package
As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.
- National Institutes of Health
Section G. Nearest entries on the register
Comparable offerings
Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.
- Cisco ThousandEyes for Government
Cisco Systems, Inc.
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified March 5, 2026.
- Bugcrowd for Government (BCGOV)
Bugcrowd Inc.
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified February 19, 2026.
- Cribl.Cloud Government
Cribl Inc.
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified January 28, 2026.
- Check Point Infinity Platform for Government
Check Point Software Technologies, Inc.
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified September 24, 2025.
- ExtraHop RevealX Federal
ExtraHop Networks
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified September 15, 2025.
Section H. Description
As published on the marketplace
The provider's own description of the service, reproduced from the FedRAMP feed without edits.
Checkmarx One for Government (CXG) is a cutting-edge, cloud-native application security platform designed specifically for U.S. government agencies. Hosted in AWS GovCloud, CXG provides a secure, single-tenant environment that supports the most stringent compliance standards, enabling government entities to safely develop, deploy, and monitor applications in a highly secure manner. CXG offers a comprehensive suite of security modules, including Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Application Security Posture Management (ASPM). Additionally, CXG provides advanced add-ons for Malicious Package Detection, Container Security, and Infrastructure as Code (IaC) Security, all of which enable government agencies to secure applications from code to cloud and across the entire software development lifecycle (SDLC). Seamlessly integrating into developer workflows through IDE plugins (such as VSCode), CLI, API, and a web-based UI, CXG empowers developers to identify and fix vulnerabilities early in the SDLC. The platform provides actionable remediation guidance and risk-based prioritization, ensuring that vulnerabilities are addressed before they can impact mission-critical systems. CXG continuously scans proprietary code, open-source dependencies, containers, and IaC templates using Checkmarx Threat Intelligence to proactively detect exploitable risks. Its developer-first experience allows secure software development without disruption, and its compliance features ensure alignment with industry standard benchmarks for security and risk management. Hosted in AWS GovCloud and built to meet the highest U.S. government security standards, CXG automates security across DevSecOps pipelines. CXG also ensures continuous monitoring of security controls, providing real-time insights into the security posture of your applications and infrastructure. It is purpose-built to meet the unique security and compliance needs of U.S. government agencies, enabling a secure and resilient software development process in today's complex cybersecurity landscape.
Next step
What the same authorization would cost you
The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.
Provenance and independence
Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.
GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.
FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.