DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-FR2304757473A

Cisco Security Cloud for Government

Cisco Systems Inc. lists Cisco Security Cloud for Government on the FedRAMP Marketplace with the status FedRAMP Certified, at High impact, on the Agency path under the Rev5 process. Package FR2304757473A, read from the marketplace feed as of September 3, 2026.

FedRAMP CertifiedRev5Agency path

Section A. Register entry

What the marketplace records

FedRAMP package ID
FR2304757473A
Cloud service provider
Cisco Systems Inc.
Certification status
FedRAMP Certified
Impact level
High
Certification class
Class D (High)
Authorization path
Agency
Certification type
Rev5
Marketplace phase
Ongoing Certification
Deployment model
Government Community Cloud
Register snapshot
September 3, 2026
Service model
SaaS
Independent assessor
Coalfire Systems, Inc.
Certification date
August 6, 2026
Status date
August 6, 2026
Annual assessment
June 4, 2011
Agency authorizations
3
Recorded reuses
2
Milestones on record
3

The marketplace carries Cisco Security Cloud for Government under package FR2304757473A with 18 recorded fields. Its certification date is August 6, 2026. Coalfire Systems, Inc. is named as the independent assessor, with an annual assessment date of June 4, 2011. 3 agencies are listed as having authorized it, among them Department of State, Federal Communications Commission and National Endowment for the Arts, and the feed records 2 reuses of the package. It is delivered as SaaS on a government community cloud.

Section B. Milestones

3 entries in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
August 6, 2026Status ChangeStatus changed from Agency Review to FedRAMP Certified
June 12, 2026Status ChangeStatus set to Agency Authorization In Process
June 12, 2026Status ChangeStatus changed from Agency Review to FedRAMP In Process

Section C. Cost context

What reaching High costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a High authorization

Initial authorization$2,500,000 to $5,000,000+
Continuous monitoring$300,000 to $600,000+ a year
Typical timeline18 to 24 months
Control baseline421+ controls
Annual assessment$180,000 to $450,000 a year

Our published planning range for a provider pursuing High. It is not a figure any listed provider has disclosed.

Read the FedRAMP High cost guide / annual assessment cost / continuous monitoring cost

Path

Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost

Assessment and monitoring

An annual assessment date of June 4, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost

Section E. Agencies on the record

3 agencies listed against this package

As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.

  • Department of State
  • Federal Communications Commission
  • National Endowment for the Arts

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

Cisco Security Cloud for Government provides cloud-based security solutions with multiple component products. Cisco Umbrella for Government Cisco Umbrella for Government delivers advanced, cloud-native cybersecurity, ensuring protection and compliance for government agencies to support their mission. It significantly uplevels government cybersecurity, offering comprehensive protection that meets the unique needs of government agencies. Cisco Umbrella for Government provides a comprehensive security suite with DNS-layer security and Secure Internet Gateway (SIG) capabilities, such as secure web gateway (SWG) , cloud-delivered firewall and intrusion prevention (Snort IPS), cloud access security broker (CASB), and data loss prevention (DLP), and integration with CISA Protective DNS. The feature set is comparable to the Cisco Umbrella product in use by over 30,000 Enterprise customers. Cisco Secure Access for Government includes more robust SSE capabilities than Cisco Umbrella for Government. Agencies looking for ZTNA and a high-performance architecture should choose Secure Access for Government. Cisco Secure Access for Government Cisco Secure Access for Government is a comprehensive Security Service Edge solution grounded in Zero Trust, that empowers Federal, State, and Local agencies to secure their workforce and data, simplify operations, and advance their mission with confidence. Its adaptive security capabilities, powered by Cisco Talos and AI, enable real-time threat detection, behavioral analysis, and predictive defense-ensuring proactive protection of your people and data against evolving cyber risks. With a comprehensive zero trust approach and a unique unified client, users gain seamless, secure access to critical applications across devices and locations-without compromising usability or performance. When paired with Catalyst® SD-WAN, Cisco Secure Access for Government delivers a holistic SASE solution. Enhanced integration with Catalyst SD-WAN will be available in 2026. Key capabilities include: A single platform for IT teams that centralizes management, streamlines policy enforcement, and reduces overhead. AI-driven automation accelerates response times and reduces human error, which integrates with solutions like Duo and Cisco SD-WAN will enable a compliant, Zero Trust architecture tailored for public sector needs. Cloud-native and continuously updated, Cisco Secure Access removes hardware complexity and scales effortlessly to meet the demands of dynamic government environments. The result: stronger security, improved user experience, and simplified operations-all built to protect the mission and serve the public. Secure Access for Government includes the following: Secure Internet Access (SIA) and Secure Private Access (SPA). Both products have Essentials and Advantage SKUs. Offers robust protection against modern-day cyber threats through Zero Trust Network Access, DNS security, Secure Web Gateway (SWG), Data Loss Prevention (DLP), Cloud-Delivered Firewall (FWaaS), Cloud Access Security Broker (CASB), VPN as-a-Service (VPNaaS), Advanced Malware Protection, and Talos® Threat Intelligence capabilities. Extends DNS security with an Integration with the Cybersecurity and Infrastructure Security Agency (CISA's) Protective DNS (PDNS). Cisco Security Cloud Control Cisco Security Cloud Control is a security platform that allows you to manage your security products and achieve security outcomes from a single integrated interface. Integrating security products in the platform is a streamlined experience. Within Security Cloud Control, user and group management occurs at the platform level. Roles are assigned to these users and groups to define their privileges for administering Security Cloud Control and the integrated products. Navigation between products and tools is intuitive and standardized with a common platform menu and toolbar for all integrated products. Cisco Security Cloud Control - Firewall Management for Government Cisco Security Cloud Control - Firewall Management for Government delivers cloud-native firewall policy and device management through a unified management plane accessible through an intuitive web-based console. It enables centralized, scalable, and secure orchestration of Cisco next-generation firewalls (NGFWs) - including ASA and Secure Firewall Threat Defense (FTD) devices - across hybrid, cloud, and on-premises environments. With real-time visibility into traffic and threats, automated policy and object updates, and zero-touch provisioning for remote deployments - Security Cloud Control Firewall Management for Government reduces operational complexity for IT teams while strengthening cyber resilience and enabling secure modernization across mission-critical infrastructure. This product will now also include AIOps features like Policy Analyzer & Optimizer, Feature adoption, and a summary dashboard for customers to ensuring faster and accurate anomaly detection using Artificial Intelligence. A SAL Eventing License Utilization Dashboard will also be available to the customers. Cisco Multicloud Defense for Government Cisco Multicloud Defense for Government is designed to provide consistent, automated protection across multicloud environments, including AWS, Azure, GCP, and OCI. It integrates network security with multicloud networking, offering multi-directional protection to stop inbound attacks, prevent lateral movement, and block data exfiltration. With its centralized SaaS control plane, Cisco Multicloud Defense simplifies security management, enabling organizations to create and enforce unified security policies across all cloud environments in real-time. By leveraging advanced features such as dynamic policy management, continuous asset discovery, and automation, Cisco Multicloud Defense empowers organizations to reduce complexity, enhance operational efficiency, and maintain robust security across their multi-cloud infrastructure. Cisco Secure Email Threat Defense for Government Cisco Secure Email Threat Defense for Government exemplifies our ongoing commitment to delivering trusted, government-grade email security for agencies, contractors, and organizations handling regulated or sensitive data. Secure Email Threat Defense, a cloud-scale advanced email security layer, harnesses AI powered detections to provide comprehensive protection against advanced email threats, integrated as an API-based supplemental control or with the addition of new pre-delivery inline gateway protection. Beyond the governance and compliance benefits, Cisco Secure Email Threat Defense for Government delivers a set of advanced protection capabilities that align directly with real-world email threat risks - especially for organizations that are particularly sensitive to BEC, phishing, QR Code/Quishing Detection, brand impersonation, or high-risk personnel. Duo Federal Duo's Federal Editions can verify the identity of users with secure and easy to use two-factor authentication methods that helps public sector entities satisfy NIST 800-63-3 and 53/63/171 authentication requirements. In addition to verifying users' identities, Duo's solution checks the security health of every device authenticating into the environment, at the time of access. Admins can use Duo to enforce stricter device and application access policies, such as blocking login requests based on location or anonymous networks. Duo ensures only trusted users and devices can access protected applications. This complete security solution prevents modern attackers that often target multiple areas - including credential theft and the exploitation of known software vulnerabilities affecting outdated software versions.

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28