Section 8.4 - Register entry
DOC-REF: FRC-MKT-FR2300457485
GSS One AWS
Project Hosts Inc. lists GSS One AWS on the FedRAMP Marketplace with the status FedRAMP Certified, at High impact, on the Agency path under the Rev5 process. Package FR2300457485, read from the marketplace feed as of September 3, 2026.
Section A. Register entry
What the marketplace records
- FedRAMP package ID
- FR2300457485
- Cloud service provider
- Project Hosts Inc.
- Certification status
- FedRAMP Certified
- Impact level
- High
- Certification class
- Class D (High)
- Authorization path
- Agency
- Certification type
- Rev5
- Marketplace phase
- Ongoing Certification
- Deployment model
- Government Community Cloud
- Register snapshot
- September 3, 2026
- Service model
- SaaS, PaaS
- Independent assessor
- Lunarline, Inc.
- Sponsoring agency
- Defense Information Systems Agency
- Certification date
- April 6, 2026
- Status date
- April 6, 2026
- FedRAMP Ready date
- December 21, 2022
- Annual assessment
- March 10, 2011
- Agency authorizations
- 1
- Recorded reuses
- 3
- Business categories
- Collaboration, Communication, Content Management System (CMS), Customer Service, Cybersecurity & Risk Management
- SAM.gov UEI
- FQLLNM449KF1
- Dependent offerings
- 3
- Milestones on record
- 4
The marketplace carries GSS One AWS under package FR2300457485 with 23 recorded fields. Its certification date is April 6, 2026, and a FedRAMP Ready date of December 21, 2022. Lunarline, Inc. is named as the independent assessor, with an annual assessment date of March 10, 2011. Defense Information Systems Agency is recorded as the sponsoring agency. 1 agency is listed as having authorized it, among them National Heart, Lung, and Blood Institute, and the feed records 3 reuses of the package. It is delivered as SaaS and PaaS on a government community cloud, filed under 5 business categories including Collaboration, Communication, Content Management System (CMS) and 2 more. 3 other offerings on the register are listed as dependent on this one, among them Caveonix, H2O.AI and ESChat. Its SAM.gov unique entity identifier is FQLLNM449KF1.
Section B. Milestones
4 entries in the marketplace event log
Most recent first, as recorded by FedRAMP.
| Date | Category | Recorded |
|---|---|---|
| April 6, 2026 | Status Change | Status changed from PMO Review to FedRAMP Certified |
| March 26, 2026 | Status Change | Status changed from Agency Review to FedRAMP In Process |
| January 10, 2025 | Status Change | Status changed from FedRAMP Ready to Agency Authorization In Process |
| December 21, 2022 | Status Change | Status set to Legacy FedRAMP Ready |
Section C. Cost context
What reaching High costs
Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.
Cost context
Budget for a High authorization
Our published planning range for a provider pursuing High. It is not a figure any listed provider has disclosed.
Read the FedRAMP High cost guide / annual assessment cost / continuous monitoring cost
Path
Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost
Assessment and monitoring
An annual assessment date of March 10, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost
Section D. Services in scope
10 services listed inside the assessment boundary
GSSOne AWS Core
Available from April 6, 2026
The GSSOne AWS Core provides a standardized set of centrally managed services that support secure application deployment and operations, including access control, authentication, auditing, monitoring, scanning, patching, configuration management, malware prevention, intrusion prevention, incident response, backup, and disaster recovery. Security Category: High, Certification Class: D
GSSOne Admin/ User Portal
Available from April 6, 2026
GSSOne Admin/ User Portal provides a centralized interface for customer onboarding, account provisioning, access management, billing visibility, and authorized administrative activities. Administrative actions are governed through role-based access controls and documented approval workflows.Security Category: High, Certification Class: D
GSSOne SMTP Service
Available from April 6, 2026
Provides centrally managed email relay and routing services for applications operating within the authorization boundary. The service supports controlled delivery, encryption, authentication, logging, and monitoring of system-generated email. Security Category: High, Certification Class: D
GSSOne Certificate Authority
Available from April 6, 2026
Provides centralized certificate issuance, validation, renewal, revocation, and lifecycle management for system components. It supports trusted encrypted communications and consistent certificate governance across the environment. Security Category: High, Certification Class: D
GSSOne CertForge
Available from April 6, 2026
Automates the generation, deployment, renewal, and tracking of TLS certificates used by authorized applications and infrastructure. Automation reduces expired-certificate risk while supporting approved cryptographic and certificate-management requirements. Security Category: High, Certification Class: D
GSSOne Illumination/ Inventory
Available from April 6, 2026
Provides automated discovery and inventory of cloud resources, configurations, and security-relevant attributes within the environment. The service supports continuous compliance validation, evidence generation, configuration-drift identification, and centralized reporting. Security Category: High, Certification Class: D
JAMIS Prime ERP
Available from June 14, 2026
Provided and managed by JAMIS software, JAMIS Prime ERP is a platform that provides browser and mobile access to finance, project accounting, contract management, billing, and operational workflows for U.S. government contractors. The system supports core functions including job cost/project accounting, contract and subcontract management, budgeting and forecasting, general ledger, cash management, accounts receivable/payable, timecards, expense reporting, fixed assets, distribution management, and project manufacturing. JAMIS Prime streamlines contract management and billing by centralizing documents, automating workflows and approvals, tracking contract actions and funding, supporting government-compliant billing across common contract types, and managing revenue recognition, cost ceilings, retention, labor categories, markups, ACRN funding, and contract-specific billing rules. These capabilities help improve visibility, collaboration, invoice accuracy, and timely payment processing across the contract lifecycle. Security Category: High, Certification Class: D
Siemens Federal Cloud (SFC)
Available from June 14, 2026
Provided and Managed by Siemens Government Technology, The primary software application suite within SFC consists of the Teamcenter Product Lifecycle Management (PLM) software, which is a product and process digital thread management system. Teamcenter PLM provides full product lifecycle data management services for a customer authored end item (to include requirements, product(s) and processes) and enables customer teams to better connect with each other on relevant data needed to make informed decisions throughout a product's lifecycle. Teamcenter offers integration capabilities with various CAD products, serving as the central hub for managing design data throughout the product lifecycle. Teamcenter ensures that all CAD models, assemblies, and drawings are securely stored, version-controlled, and accessible within the environment. This integration allows engineers to work directly within their preferred CAD authoring tools while benefiting from Teamcenter's data management, workflow automation, and collaboration features. Security Category: High, Certification Class: D
Chainbridge Perseus™
Available from August 17, 2026
Provided and managed by Chainbridge Solutions Inc., Perseus™ is a cloud-native SaaS product purpose-built to transform personnel security (PERSEC) workflows across the federal government. Blending deep PERSEC expertise with the scalability and performance of commercial software, Perseus™ streamlines clearance processes, enables Trusted Workforce readiness, and equips agencies with the clarity, efficiency, and confidence they need to deliver from day one. Security Category: High, Certification Class: D
FutureFeed
Available from August 17, 2026
Provided and managed by Continuous Compliance, there are two main components that make up the FutureFeed environment. FutureFeed is a robust, SaaS-based compliance management platform. Using FutureFeed's powerful automation and reporting capabilities, organizations create a security-oriented culture that permeates the organization. Organizations use FutureFeed to create and maintain information security programs that comply with legal and regulatory requirements, and to prove compliance at any time. Cyber Illumination is a supply chain communication, risk identification, and risk management tool. Federal agencies, government contractors, and commercial entities can use Cyber Illumination to gain better insight into and control over the risks, including cybersecurity risks, associated with their vendors and business partners. Clients can leverage Cyber Illumination's built-in questionnaires, or create custom questionnaires, to gain the knowledge they need to better manage their supply chain risks. When a client's vendor also uses FutureFeed, the vendor and the client enjoy seamless integration and robust, automated information sharing that takes the hassles out of supply chain risk management. Security Category: High, Certification Class: D
Section E. Agencies on the record
1 agency listed against this package
As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.
- National Heart, Lung, and Blood Institute
Section F. Dependent offerings
3 listed offerings build on this package
From the marketplace's dependent products view. A provider that inherits controls from a package below it carries a narrower assessment boundary of its own, which is one of the larger levers on authorization cost.
Inheritance is why boundary scope moves a budget more than headcount does. The hidden costs page sets out where scope creeps back in.
Section G. Nearest entries on the register
Comparable offerings
Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.
Project Hosts Inc. lists 2 offerings on the marketplace. The others are:
- Knox Systems FedRAMP High Managed Platform
Knox Systems
FedRAMP Certified, High impact, Agency path, Rev5, certified March 30, 2026.
- H2O.AI
H2O.AI for Government
FedRAMP Certified, High impact, Agency path, Rev5, certified April 16, 2026.
- Omnissa Government Services
Omnissa
FedRAMP Certified, High impact, Agency path, Rev5, certified May 4, 2026.
- Koniag Government Services Electronic Health Record System (KGS EHRS)
Koniag Government Services
FedRAMP Certified, High impact, Agency path, Rev5, certified June 17, 2026.
- BlackBerry Cloud - AtHoc Services for Government (High)
BlackBerry
FedRAMP Certified, High impact, Agency path, Rev5, certified April 11, 2025.
Section H. Description
As published on the marketplace
The provider's own description of the service, reproduced from the FedRAMP feed without edits.
The GSSOne AWS is a General Support System (GSS) operated by Project Hosts and deployed within AWS GovCloud. The platform is designed as a secure, multi-tenant PaaS/SaaS environment that enables federal, DoD, state, local, and tribal agencies, as well as government contractors, members of the DIB and the public to deploy and operate applications in compliance with federal security requirements. The GSSOne AWS Core provides a standardized set of centrally managed services that support secure application deployment and operations, including: access control, authentication, auditing, monitoring, scanning, patching, configuration management, malware prevention, intrusion prevention, incident response, backup, and disaster recovery. These capabilities are implemented and managed by Project Hosts and are leveraged by applications deployed on the platform to meet security and compliance requirements. GSSOne AWS supports two primary application deployment models: **1. Applications Included Within the GSS One Authorization Boundary** Certain SaaS applications are incorporated directly into the GSSOne AWS authorization boundary and are assessed and certified as part of the GSSOne AWS system. **2. Applications Supported on the Platform** GSSOne AWS also supports customer and Independent Software Vendor (ISV) applications that are deployed on the platform but maintain their own authorization boundary (e.g., agency ATO or ISV-owned system). In this model, Project Hosts provides the underlying infrastructure, security services, and operational support, while the application owner maintains responsibility for their system authorization and application-specific controls. This flexible deployment model allows agencies to either leverage existing SaaS capabilities or deploy their own applications within a secure, FedRAMP-authorized environment. **Applications Included Within the GSS One Authorization Boundary** These applications are deployed, secured, and operated as part of the GSSOne AWS system and certification. The following SaaS applications are currently included within the GSSOne AWS authorization boundary: - **GSSOne AWS Portal/Admin Page** Provided by Project Hosts this application provides user and administrative interfaces for account management, access provisioning, and operational support activities - **JAMIS Prime ERP** Provided and managed by JAMIS software, JAMIS Prime ERP is a platform that provides browser and mobile access to finance, project accounting, contract management, billing, and operational workflows for U.S. government contractors. The system supports core functions including job cost/project accounting, contract and subcontract management, budgeting and forecasting, general ledger, cash management, accounts receivable/payable, timecards, expense reporting, fixed assets, distribution management, and project manufacturing. JAMIS Prime streamlines contract management and billing by centralizing documents, automating workflows and approvals, tracking contract actions and funding, supporting government-compliant billing across common contract types, and managing revenue recognition, cost ceilings, retention, labor categories, markups, ACRN funding, and contract-specific billing rules. These capabilities help improve visibility, collaboration, invoice accuracy, and timely payment processing across the contract lifecycle. - **Siemens Federal Cloud (SFC)** Provided and Managed by Siemens Government Technology,The primary software application suite within SFC consists of the Teamcenter Product Lifecycle Management (PLM) software, which is a product and process digital thread management system. Teamcenter PLM provides full product lifecycle data management services for a customer authored end item (to include requirements, product(s) and processes) and enables customer teams to better connect with each other on relevant data needed to make informed decisions throughout a product's lifecycle. Teamcenter offers integration capabilities with various CAD products, serving as the central hub for managing design data throughout the product lifecycle. Teamcenter ensures that all CAD models, assemblies, and drawings are securely stored, version-controlled, and accessible within the environment. This integration allows engineers to work directly within their preferred CAD authoring tools while benefiting from Teamcenter's data management, workflow automation, and collaboration features. - **Perseus™** Provided and managed by Chainbridge Solutions Inc., Perseus™ is a cloud-native SaaS product purpose-built to transform personnel security (PERSEC) workflows across the federal government. Blending deep PERSEC expertise with the scalability and performance of commercial software, Perseus™ streamlines clearance processes, enables Trusted Workforce readiness, and equips agencies with the clarity, efficiency, and confidence they need to deliver from day one. - **FutureFeed and Cyber Illumination Application Environment (FutureFeed)** Provided and managed by Continuous Compliance, There are two main components that make up the FutureFeed environment. FutureFeed is a robust, SaaS-based compliance management platform. Using FutureFeed's powerful automation and reporting capabilities, organizations create a security-oriented culture that permeates the organization. Organizations use FutureFeed to create and maintain information security programs that comply with legal and regulatory requirements, and to prove compliance at any time. Cyber Illumination is a supply chain communication, risk identification, and risk management tool. Federal agencies, government contractors, and commercial entities can use Cyber Illumination to gain better insight into and control over the risks, including cybersecurity risks, associated with their vendors and business partners. Clients can leverage Cyber Illumination's built-in questionnaires, or create custom questionnaires, to gain the knowledge they need to better manage their supply chain risks. When a client's vendor also uses FutureFeed, the vendor and the client enjoy seamless integration and robust, automated information sharing that takes the hassles out of supply chain risk management. **Applications Supported on the Platform** GSSOne AWS also supports customer and Independent Software Vendor (ISV) applications that are deployed on the platform but maintain their own authorization boundary (e.g., agency ATO or ISV-owned system). Each of the systems below have been vetted and meets the FedRAMP requirements and are ready to pursue FedRAMP certification or have been certified under their own listing and are viewable under the dependent product list. Examples of supported applications include: - 1Factory (1Factory) - 202 Group/ BlueVoyant Government Services (Supply Chain Command) - Brightly (Brightly Software) - Caveonix (Caveonix Platform) - CloudApper (Cloudapper.ai) - H2O.ai (H2O.ai Cloud for Government) - Invicti (Invicti AppSec Platform) - Microsoft (Office, Dynamics, Power BI Server, Project Server, SharePoint, SSRS) - ProSymmetry - San Luis Aviation, Inc. (ESChat) - TELCLOUD (TELCLOUD) - TCP Software (TimeClock Plus) - WordPress (WordPress CMS) - WordPress As a Service (WPaaS) For each of these applications, Project Hosts provides deployment, security, and operational support services for these applications, enabling customers to leverage the GSSOne AWS platform while maintaining flexibility in how their systems are authorized and managed. Performing these functions on the partner's behalf allows the software vendors to focus on their core business model in delivering a secure, highly functional application to the agency while Project Hosts handles the security/ compliance requirements. In either scenario, GSSOne AWS customers also are provided with access to the following systems running on the GSS One Azure system. **GSS One Command Center (GSSOCC)** The GSS One Command Center is a centralized compliance and operations platform that gives agencies and CSP partners real-time visibility into system security, risk, and authorization status. Designed to meet FedRAMP Rev. 5 BIRs and aligned with the direction of FedRAMP 20x, the GSSOCC supports a shift toward continuous, evidence-driven validation rather than static, point-in-time assessments. It serves as a single pane of glass for managing the full lifecycle of authorization and operations, bringing together system documentation, vulnerability data, incident tracking, change control, and monitoring into one integrated experience. By linking controls directly to supporting evidence and operational data, the GSSOCC reduces the overhead of maintaining compliance and enables faster, more transparent ATO decisions for agencies. **GSS One Support Center:** Project Hosts has configured a customer-facing support portal for creating and managing support tickets powered by Atlassian Jira. This allows customers to view all of their relevant tickets, create tickets, submit change control requests, upload screenshots, review knowledgebases and communicate with PH staff through a secure channel. ## FedRAMP Certification and Marketplace Metadata - **Cloud Service Offering:** GSS One AWS - **Cloud Service Provider:** Project Hosts Inc. - **FedRAMP Package ID:** FR2300457485 - **FedRAMP Certification Status:** FedRAMP Certified - **Certification Type:** Rev5 - **Certification Path:** Agency - **Certification Class:** Class D - **Security Impact Level:** High - **Certified Since:** April 6, 2026 - **Lifecycle Phase:** Ongoing Certification - **Authorizing Agency:** U.S. Department of Health and Human Services (HHS) - National Heart, Lung, and Blood Institute (NHLBI) - **Agency Authorizations:** 1 - **Recorded Dependent Product / Reuse Relationships:** 3 - **Independent Assessor / 3PAO:** Lunarline, Inc. - **Assessor ID:** 137004 ### ## Certified Services The following services are included as Certified Services within the GSS One AWS certification. Unless otherwise noted, each service operates within the GSS One AWS authorization boundary at the **High** security impact level and under **Certification Class D**. ### **GSSOne AWS Core** - **Date Available:** April 6, 2026 - **Security Impact Level:** High - **Certification Class:** D The GSSOne AWS Core provides a standardized set of centrally managed services that support secure application deployment and operations, including access control, authentication, auditing, monitoring, scanning, patching, configuration management, malware prevention, intrusion prevention, incident response, backup, and disaster recovery. ### **GSSOne Admin/User Portal** - **Date Available:** April 6, 2026 - **Security Impact Level:** High - **Certification Class:** D GSSOne Admin/User Portal provides a centralized interface for customer onboarding, account provisioning, access management, billing visibility, and authorized administrative activities. Administrative actions are governed through role-based access controls and documented approval workflows. ### **GSSOne SMTP Service** - **Date Available:** April 6, 2026 - **Security Impact Level:** High - **Certification Class:** D Provides centrally managed email relay and routing services for applications operating within the authorization boundary. The service supports controlled delivery, encryption, authentication, logging, and monitoring of system-generated email. ### **GSSOne Certificate Authority** - **Date Available:** April 6, 2026 - **Security Impact Level:** High - **Certification Class:** D Provides centralized certificate issuance, validation, renewal, revocation, and lifecycle management for system components. It supports trusted encrypted communications and consistent certificate governance across the environment. ### **GSSOne CertForge** - **Date Available:** April 6, 2026 - **Security Impact Level:** High - **Certification Class:** D Automates the generation, deployment, renewal, and tracking of TLS certificates used by authorized applications and infrastructure. Automation reduces expired-certificate risk while supporting approved cryptographic and certificate-management requirements. ### **GSSOne Illumination/Inventory** - **Date Available:** April 6, 2026 - **Security Impact Level:** High - **Certification Class:** D Provides automated discovery and inventory of cloud resources, configurations, and security-relevant attributes within the environment. The service supports continuous compliance validation, evidence generation, configuration-drift identification, and centralized reporting. ### **JAMIS Prime ERP** - **Date Available:** June 14, 2026 - **Security Impact Level:** High - **Certification Class:** D Provided and managed by JAMIS Software, JAMIS Prime ERP is a platform that provides browser and mobile access to finance, project accounting, contract management, billing, and operational workflows for U.S. government contractors. The system supports core functions including job cost/project accounting, contract and subcontract management, budgeting and forecasting, general ledger, cash management, accounts receivable/payable, timecards, expense reporting, fixed assets, distribution management, and project manufacturing. JAMIS Prime streamlines contract management and billing by centralizing documents, automating workflows and approvals, tracking contract actions and funding, supporting government-compliant billing across common contract types, and managing revenue recognition, cost ceilings, retention, labor categories, markups, ACRN funding, and contract-specific billing rules. These capabilities help improve visibility, collaboration, invoice accuracy, and timely payment processing across the contract lifecycle. ### **Siemens Federal Cloud (SFC)** - **Date Available:** June 14, 2026 - **Security Impact Level:** High - **Certification Class:** D Provided and managed by Siemens Government Technologies, the primary software application suite within SFC consists of the Teamcenter Product Lifecycle Management (PLM) software, which is a product and process digital-thread management system. Teamcenter PLM provides full product lifecycle data management services for a customer-authored end item, including requirements, products, and processes, and enables customer teams to better connect with each other using the relevant data needed to make informed decisions throughout a product's lifecycle. Teamcenter offers integration capabilities with various CAD products, serving as the central hub for managing design data throughout the product lifecycle. Teamcenter ensures that CAD models, assemblies, and drawings are securely stored, version-controlled, and accessible within the environment. This integration allows engineers to work directly within their preferred CAD authoring tools while benefiting from Teamcenter's data management, workflow automation, and collaboration features. ### **Chainbridge Perseus™** - **Date Available:** August 17, 2026 - **Security Impact Level:** High - **Certification Class:** D Provided and managed by Chainbridge Solutions Inc., Perseus™ is a cloud-native SaaS product purpose-built to transform personnel security (PERSEC) workflows across the federal government. Blending deep PERSEC expertise with the scalability and performance of commercial software, Perseus™ streamlines clearance processes, enables Trusted Workforce readiness, and equips agencies with the clarity, efficiency, and confidence needed to support personnel security operations from day one. ### **FutureFeed** - **Date Available:** August 17, 2026 - **Security Impact Level:** High - **Certification Class:** D Provided and managed by Continuous Compliance, the FutureFeed environment consists of two primary components: FutureFeed and Cyber Illumination. FutureFeed is a SaaS-based compliance management platform. Using FutureFeed's automation and reporting capabilities, organizations can create and maintain information security programs that comply with applicable legal and regulatory requirements and provide evidence of compliance. Cyber Illumination is a supply-chain communication, risk-identification, and risk-management tool. Federal agencies, government contractors, and commercial entities can use Cyber Illumination to gain greater insight into and control over risks, including cybersecurity risks, associated with vendors and business partners. Clients can leverage Cyber Illumination's built-in questionnaires or create custom questionnaires to obtain information needed to manage supply-chain risks. When a client's vendor also uses FutureFeed, the vendor and client can use integrated and automated information sharing to improve the efficiency of supply-chain risk management. ## Agency Authorization and Reuse Relationships GSS One AWS maintains an Agency certification path associated with the **U.S. Department of Health and Human Services (HHS), National Heart, Lung, and Blood Institute (NHLBI)**. The FedRAMP Marketplace metadata associated with the certification: - **Agency Authorizations:** 1 - **Dependent Product / Reuse Relationships:** 3 - **Certification Path:** Agency - **Certification Class:** Class D (High) - **Certified Since:** April 6, 2026 GSS One AWS also serves as an underlying authorized platform for applications and cloud service offerings that leverage GSS One AWS security, infrastructure, and operational capabilities. Depending on the application deployment and authorization model, these relationships may be represented as included Certified Services, dependent products, reuse relationships, or separately authorized customer systems. The information in this section is included to preserve visibility into the certification and authorization relationships associated with GSS One AWS where corresponding structured Marketplace fields are not currently displayed.
Next step
What the same authorization would cost you
The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.
Provenance and independence
Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.
GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.
FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.