DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-FR2032665434

Cloud Security Platform powered by Isolation Core

Menlo Security lists Cloud Security Platform powered by Isolation Core on the FedRAMP Marketplace with the status FedRAMP Certified, at Moderate impact, on the Agency path under the Rev5 process. Package FR2032665434, read from the marketplace feed as of September 3, 2026.

FedRAMP CertifiedRev5Agency pathSmall business

Section A. Register entry

What the marketplace records

FedRAMP package ID
FR2032665434
Cloud service provider
Menlo Security
Certification status
FedRAMP Certified
Impact level
Moderate
Certification class
Class C (Moderate)
Authorization path
Agency
Certification type
Rev5
Marketplace phase
Ongoing Certification
Deployment model
Government Community Cloud
Register snapshot
September 3, 2026
Service model
SaaS
Independent assessor
Schellman Compliance, LLC
Certification date
January 9, 2023
Status date
January 9, 2023
Annual assessment
November 15, 2011
Agency authorizations
1
Business categories
Cybersecurity & Risk Management
Small business
Flagged on the marketplace record
Milestones on record
3

The marketplace carries Cloud Security Platform powered by Isolation Core under package FR2032665434 with 19 recorded fields. Its certification date is January 9, 2023. Schellman Compliance, LLC is named as the independent assessor, with an annual assessment date of November 15, 2011. 1 agency is listed as having authorized it, among them Department of Energy. It is delivered as SaaS on a government community cloud, filed under 1 business categories including Cybersecurity & Risk Management. Menlo Security is flagged as a small business on the record.

Section B. Milestones

3 entries in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
January 9, 2023Status ChangeStatus changed from PMO Review to FedRAMP Certified
August 8, 2022Status ChangeStatus changed from Agency Review to FedRAMP In Process
December 16, 2021Status ChangeStatus set to Agency Authorization In Process

Section C. Cost context

What reaching Moderate costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a Moderate authorization

Initial authorization$800,000 to $2,000,000
Continuous monitoring$150,000 to $350,000 a year
Typical timeline12 to 18 months
Control baseline325+ controls
Annual assessment$90,000 to $260,000 a year

Our published planning range for a provider pursuing Moderate. It is not a figure any listed provider has disclosed.

Read the FedRAMP Moderate cost guide / annual assessment cost / continuous monitoring cost

Path

Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost

Assessment and monitoring

An annual assessment date of November 15, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost

Section E. Agencies on the record

1 agency listed against this package

As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.

  • Department of Energy

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

Menlo Security is the pioneer of browser security and stops evasive threats such as phishing and ransomware, delivering on the promise of cloud-based security and enabling zero trust application access. The Menlo Secure Enterprise Browser solution prevents attacks while being invisible to end users who can use their preferred web browser, enhancing productivity. Deploy browser security policies in a single click, securing internet access and protecting organizational data down to the last mile. Menlo Secure Enterprise Browser Solution Instantiated for each browser session, the Menlo Secure Cloud Browser secures access to the web, preventing malware, ransomware, and unauthorized access and ensures that data security policies are enforced to prevent malicious or unintentional data theft with multiple Data Loss Prevention (DLP) features. Defending against highly evasive adaptive threats (HEAT), Menlo leverages machine learning and AI-based URL analysis to identify and block the most sophisticated phishing sites. Menlo remote browser isolation (RBI) offers significant performance enhancements in comparison to all other RBI offerings with patented Adaptive Clientless Rendering (ACR). ACR enables web page rendering, including interactive animations such as scrolling, to be performed on the endpoint browser using optimized desktop hardware and browser software, while the full browser feature set-including copy-paste, find in page, and printing-is maintained. The administrative policy defines whether any site is isolated. Isolation may be managed with traditional categories which should be familiar and easy to use by administrators of Secure Web Gateways (SWG). Unlike a SWG, however, Menlo enables isolation by threat types and/or vulnerable web services. Mitigating the security blindspot posted by mandated transport level encryption (TLS), Menlo Browsing Forensics offers policy-based capture of browsing sessions. Captures are stored in customer data stores, not accessible to Menlo Security. The Browsing Forensics Viewer enables the Security Operations Center (SOC), incident response, and even security awareness training teams to review users' sessions including clicks, scrolls and text inputs. Policy controls manage whether password entries are retained, whether a user is notified of recording and screen capture rates. Files and archives are delivered with browser protocols. The Menlo Secure Cloud Browser includes comprehensive file and archive inspection. Archives are opened, and each file is subject to hash checks and anti-virus examinations. The safe content of both clean and infected files can be presented as a safe PDF to the user. Policy governs whether any original file or archive may be downloaded from the Secure Cloud Browser. File security checks can be selectively bypassed. Traffic steering to the Menlo Cloud supports proxy chaining from, for example, existing SWG or Cloud Access Security Brokers (CASB), as well as PAC file deployment or firewall redirecting. Menlo Browser Security is fully compatible with Secure Access Service Edge (SASE) and Security Service Edge (SSE) deployments. Common use cases for Menlo Browser Security include: comprehensive zero-hour phishing prevention, ransomware prevention, administrative governance of Generative AI, and comprehensive governance of SaaS using workflows similar to CASB, but including SaaS property isolation and comprehensive file upload and download controls applicable on a per-application basis.

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28