Section 8.4 - Register entry
DOC-REF: FRC-MKT-FR2013059515
Cofense PhishMe
Cofense lists Cofense PhishMe on the FedRAMP Marketplace with the status FedRAMP Certified, at Moderate impact, on the Agency path under the Rev5 process. Package FR2013059515, read from the marketplace feed as of September 3, 2026.
Section A. Register entry
What the marketplace records
- FedRAMP package ID
- FR2013059515
- Cloud service provider
- Cofense
- Certification status
- FedRAMP Certified
- Impact level
- Moderate
- Certification class
- Class C (Moderate)
- Authorization path
- Agency
- Certification type
- Rev5
- Marketplace phase
- Ongoing Certification
- Deployment model
- Government Community Cloud
- Register snapshot
- September 3, 2026
- Service model
- SaaS
- Independent assessor
- Coalfire Systems, Inc.
- Certification date
- February 12, 2021
- Status date
- February 12, 2021
- Annual assessment
- October 2, 2011
- Agency authorizations
- 8
- Recorded reuses
- 7
- Business categories
- Cybersecurity & Risk Management, Education & Training
- Milestones on record
- 3
The marketplace carries Cofense PhishMe under package FR2013059515 with 19 recorded fields. Its certification date is February 12, 2021. Coalfire Systems, Inc. is named as the independent assessor, with an annual assessment date of October 2, 2011. 8 agencies are listed as having authorized it, among them Alcohol and Tobacco Tax and Trade Bureau, Department of Education, Department of Health and Human Services and 5 more, and the feed records 7 reuses of the package. It is delivered as SaaS on a government community cloud, filed under 2 business categories including Cybersecurity & Risk Management and Education & Training.
Section B. Milestones
3 entries in the marketplace event log
Most recent first, as recorded by FedRAMP.
| Date | Category | Recorded |
|---|---|---|
| February 12, 2021 | Status Change | Status changed from PMO Review to FedRAMP Certified |
| October 2, 2020 | Status Change | Status changed from Agency Review to FedRAMP In Process |
| March 16, 2020 | Status Change | Status set to Agency Authorization In Process |
Section C. Cost context
What reaching Moderate costs
Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.
Cost context
Budget for a Moderate authorization
Our published planning range for a provider pursuing Moderate. It is not a figure any listed provider has disclosed.
Read the FedRAMP Moderate cost guide / annual assessment cost / continuous monitoring cost
Path
Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost
Assessment and monitoring
An annual assessment date of October 2, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost
Section E. Agencies on the record
8 agencies listed against this package
As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.
- Alcohol and Tobacco Tax and Trade Bureau
- Department of Education
- Department of Health and Human Services
- Federal Deposit Insurance Corporation
- General Services Administration
- Immigration and Customs Enforcement
- Social Security Administration
- Surface Transportation Board
Section G. Nearest entries on the register
Comparable offerings
Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.
- Exterro E-Discovery and Legal Software Platform
Exterro, Inc.
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified April 20, 2021.
- Knox Systems
Knox Systems, Inc.
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified June 21, 2017.
- SPROUT
MDRC
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified October 7, 2020.
- Fusion Cloud
Oracle
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified January 13, 2020.
- iboss Government Cloud Platform (IGCP)
iBoss
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified July 25, 2022.
Section H. Description
As published on the marketplace
The provider's own description of the service, reproduced from the FedRAMP feed without edits.
Cofense PhishMe enables organizations to improve employee resiliency to phishing attacks through real-life simulated phishing scenarios. Thousands of the world's largest organizations in both public and private sector rely on PhishMe to condition employees to recognize and report phishing attacks. PhishMe enables trained awareness and compliance personnel to run simulated attacks using email templates that look like actual phishing attacks and includes on-the-spot educational content that displays when recipients click on one of the simulated phishing emails. For example, a scenario email might alert recipients that their (e.g. banking) credentials were compromised and ask the recipients to click a link in the email to reset their password. If a recipient does click the link, PhishMe displays educational content to help that individual recognize the characteristics of a phishing email. Through these safe examples, PhishMe customers can help their employees develop an awareness of the risks that real phishing emails pose and reduce their susceptibility of engaging with such emails in the future. To maximize the effectiveness of simulation campaigns and reduce the burden on awareness teams, Cofense PhishMe provides a combination of unique capabilities: - Content is based on real phishing attacks gleaned from real threat intelligence. That means that the scenarios you run are as realistic as possible, ensuring your organization is conditioned to the latest threats. - Responsive Delivery allows simulation operators to deliver phishing simulations while the user is active in their inbox, which drives higher scenario engagement. - Predefined playbooks with scenario recommendations based on user behavior and best practices. - PhishMe helps organizations transform their employees into the last line of active defense against phishing attacks - the leading cause of data breaches - through education, ongoing simulations, and an easy to use reporting tool, Cofense Reporter, so organizations can swiftly detect, respond to and thwart phishing attacks in their tracks.
Next step
What the same authorization would cost you
The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.
Provenance and independence
Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.
GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.
FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.