DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-FR1834172478

Diligent One Platform (D1P)

Diligent, Inc. lists Diligent One Platform (D1P) on the FedRAMP Marketplace with the status FedRAMP Certified, at Moderate impact, on the Agency path under the Rev5 process. Package FR1834172478, read from the marketplace feed as of September 3, 2026.

FedRAMP CertifiedRev5Agency path

Section A. Register entry

What the marketplace records

FedRAMP package ID
FR1834172478
Cloud service provider
Diligent, Inc.
Certification status
FedRAMP Certified
Impact level
Moderate
Certification class
Class C (Moderate)
Authorization path
Agency
Certification type
Rev5
Marketplace phase
Ongoing Certification
Deployment model
Government Community Cloud
Register snapshot
September 3, 2026
Service model
SaaS
Independent assessor
Schellman Compliance, LLC
Certification date
November 20, 2019
Status date
November 20, 2019
Annual assessment
September 9, 2011
Agency authorizations
8
Recorded reuses
8
Business categories
Analytics, Collaboration, Cybersecurity & Risk Management, Data Management, Governance, Risk, and Compliance (GRC), Legal & Policy
Dependent offerings
1
Milestones on record
3

The marketplace carries Diligent One Platform (D1P) under package FR1834172478 with 20 recorded fields. Its certification date is November 20, 2019. Schellman Compliance, LLC is named as the independent assessor, with an annual assessment date of September 9, 2011. 7 agencies are listed as having authorized it, among them Defense Finance and Accounting Service, Department of Agriculture, Department of Commerce and 4 more, and the feed records 8 reuses of the package. It is delivered as SaaS on a government community cloud, filed under 6 business categories including Analytics, Collaboration, Cybersecurity & Risk Management and 3 more. 1 other offering on the register is listed as dependent on this one, among them InsightGovCloud.

Section B. Milestones

3 entries in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
November 20, 2019Status ChangeStatus changed from PMO Review to FedRAMP Certified
July 2, 2019Status ChangeStatus changed from Agency Review to FedRAMP In Process
September 19, 2018Status ChangeStatus set to Agency Authorization In Process

Section C. Cost context

What reaching Moderate costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a Moderate authorization

Initial authorization$800,000 to $2,000,000
Continuous monitoring$150,000 to $350,000 a year
Typical timeline12 to 18 months
Control baseline325+ controls
Annual assessment$90,000 to $260,000 a year

Our published planning range for a provider pursuing Moderate. It is not a figure any listed provider has disclosed.

Read the FedRAMP Moderate cost guide / annual assessment cost / continuous monitoring cost

Path

Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost

Assessment and monitoring

An annual assessment date of September 9, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost

Section E. Agencies on the record

7 agencies listed against this package

As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.

  • Defense Finance and Accounting Service
  • Department of Agriculture
  • Department of Commerce
  • Department of Health and Human Services
  • First Responder Network Authority
  • Office of Financial Systems Policy and Oversight
  • State Office of the Inspector General

Section F. Dependent offerings

1 listed offering builds on this package

From the marketplace's dependent products view. A provider that inherits controls from a package below it carries a narrower assessment boundary of its own, which is one of the larger levers on authorization cost.

Inheritance is why boundary scope moves a budget more than headcount does. The hidden costs page sets out where scope creeps back in.

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

Diligent's D1P GRC platform is the only enterprise-grade solution purpose-built to manage the full lifecycle of FedRAMP, DOD/DISA IL and CMMC compliance-from initial SSP development to ongoing POA&M updates, ConMon, and audit readiness. Designed with automation at its core and trusted by federal agencies, integrators, and 3PAOs, Diligent eliminates spreadsheet chaos and empowers teams to focus on actual security-not documentation. Purpose-Built for Complex Cybersecurity Compliance Diligent delivers deep automation and pre-configured workflows for: - FedRAMP (Low, Moderate & High) - DOD / DISA Impact Levels (2, 4, 5) - CMMC (Level 1, 2 and beyond) - NIST 800-53, NIST 800-171, SOC 2, and ISO 27001 and other major compliance frameworks - Support for custom frameworks and policy libraries Core Capabilities - Live SSP and ATO Package Management - Automatically generates and maintains OSCAL and human-readable SSPs. Track versioning, delta changes, and live control status from a single system. - Automated POA&M Generation and Updates - POA&Ms are created directly from scan data, control testing, or manual input. Linked to owners, evidence, due dates, and tracked in real time with alerting. - Continuous Monitoring, ConMon & Risk Insights - Real-time dashboards ingest data from 130+ tools including vulnerability scanners, cloud providers, HR systems, and ticketing platforms. Evidence collection is automatic and centralized for audit readiness. -Control Inheritance and Framework Mapping -Cross-map and inherit controls across frameworks. "Write once, apply many" saves time and ensures consistency for multi-standard organizations. -Multi-Tenant Partner and Reseller Enablement -Native support for MSSPs, C3PAOs, and resellers. Role-based access, tenant-level data separation, and white-labeled deployments available. -API and Integration Ecosystem -With over 130 out-of-box integrations and a robust open API, Diligent connects seamlessly to your stack-cloud, on-prem, or hybrid. Deployment & Security - Hosted on AWS GovCloud with three available options: FedRAMP moderate (primarily SLED), FedRAMP moderate and DOD IL5 (primarily for - Federal and some DOD), and FedRAMP moderate and DOD IL for DOD only (requires DoDIN access). - Built with security-first architecture, supporting unique customer keys, data segregation, and FIPS 140-2 validated encryption. What Sets Diligent Apart - FedRAMP, DOD and CMMC are core, not bolt-ons-we've built workflows around these frameworks from the ground up. - Automation beyond templates-real-time evidence ingest, compliance task enforcement, and live control dashboards. - Used by regulators, 3PAOs, integrators, and contractors-proven across the full compliance ecosystem. -Designed to scale-whether you're managing 1 ATO or 50, Diligent supports your growth.

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28