DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-F1403283529A

GSS One - Azure

Project Hosts Inc. lists GSS One - Azure on the FedRAMP Marketplace with the status FedRAMP Certified, at High impact, on the Agency path under the Rev5 process. Package F1403283529A, read from the marketplace feed as of September 3, 2026.

FedRAMP CertifiedRev5Agency pathSmall business

Section A. Register entry

What the marketplace records

FedRAMP package ID
F1403283529A
Cloud service provider
Project Hosts Inc.
Certification status
FedRAMP Certified
Impact level
High
Certification class
Class D (High)
Authorization path
Agency
Certification type
Rev5
Marketplace phase
Ongoing Certification
Deployment model
Hybrid Cloud
Register snapshot
September 3, 2026
Service model
PaaS, SaaS
Independent assessor
Lunarline, Inc.
Certification date
March 16, 2026
Status date
March 16, 2026
Annual assessment
February 26, 2011
Agency authorizations
6
Recorded reuses
41
Business categories
Collaboration, Communication, Content Management System (CMS), Customer Service, Cybersecurity & Risk Management, Data Management, Development Tools, Network Management, Operations Management, Storage
Small business
Flagged on the marketplace record
Dependent offerings
13
Milestones on record
3

The marketplace carries GSS One - Azure under package F1403283529A with 21 recorded fields. Its certification date is March 16, 2026. Lunarline, Inc. is named as the independent assessor, with an annual assessment date of February 26, 2011. 6 agencies are listed as having authorized it, among them Defense Counterintelligence and Security Agency, Defense Information Systems Agency, Defense Security Cooperation Agency and 3 more, and the feed records 41 reuses of the package. It is delivered as PaaS and SaaS on a hybrid cloud, filed under 10 business categories including Collaboration, Communication, Content Management System (CMS) and 7 more. 13 other offerings on the register are listed as dependent on this one, among them AvePoint Online Services for US Government (AOS-UG), Aztec Learning System and Federal Immersive Learning Management System (FED-ILMS). Project Hosts Inc. is flagged as a small business on the record.

Section B. Milestones

3 entries in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
March 16, 2026Status ChangeStatus changed from PMO Review to FedRAMP Certified
February 26, 2026Status ChangeStatus changed from Agency Review to FedRAMP In Process
January 29, 2024Status ChangeStatus set to Agency Authorization In Process

Section C. Cost context

What reaching High costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a High authorization

Initial authorization$2,500,000 to $5,000,000+
Continuous monitoring$300,000 to $600,000+ a year
Typical timeline18 to 24 months
Control baseline421+ controls
Annual assessment$180,000 to $450,000 a year

Our published planning range for a provider pursuing High. It is not a figure any listed provider has disclosed.

Read the FedRAMP High cost guide / annual assessment cost / continuous monitoring cost

Path

Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost

Assessment and monitoring

An annual assessment date of February 26, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost

Section E. Agencies on the record

6 agencies listed against this package

As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.

  • Defense Counterintelligence and Security Agency
  • Defense Information Systems Agency
  • Defense Security Cooperation Agency
  • Defense Threat Reduction Agency
  • Federal Energy Regulatory Commission
  • United States Air Force

Section F. Dependent offerings

13 listed offerings build on this package

From the marketplace's dependent products view. A provider that inherits controls from a package below it carries a narrower assessment boundary of its own, which is one of the larger levers on authorization cost.

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

Project Hosts Inc. lists 2 offerings on the marketplace. The others are:

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

The GSSOne Azure is a General Support System (GSS) operated by Project Hosts and deployed within Azure Government. The platform is designed as a secure, multi-tenant PaaS/SaaS environment that enables federal, DoD, state, local, and tribal agencies, as well as government contractors, members of the DIB and the public to deploy and operate applications in compliance with federal security requirements. The GSSOne Azure Core provides a standardized set of centrally managed services that support secure application deployment and operations, including access control, authentication, auditing, monitoring, scanning, patching, configuration management, malware prevention, intrusion prevention, incident response, backup, and disaster recovery. These capabilities are implemented and managed by Project Hosts and are leveraged by applications deployed on the platform to meet security and compliance requirements. The GSSOne Azure supports two primary application deployment models: 1. Applications Included Within the GSS One Authorization Boundary Certain SaaS applications are incorporated directly into the GSSOne Azure authorization boundary and are assessed and certified as part of the GSSOne Azure system. 2. Applications Supported on the Platform GSSOne Azure also supports customer and Independent Software Vendor (ISV) applications that are deployed on the platform but maintain their own authorization boundary (e.g., agency ATO or ISV-owned system). In this model, Project Hosts provides the underlying infrastructure, security services, and operational support, while the application owner maintains responsibility for their system authorization and application-specific controls. This flexible deployment model allows agencies to either leverage existing SaaS capabilities or deploy their own applications within a secure, FedRAMP-authorized environment. Applications Included Within the GSS One Authorization Boundary These applications are deployed, secured, and operated as part of the GSSOne Azure system and certification. - GSSOne Azure Portal/Admin Page Provided by Project Hosts this application provides user and administrative interfaces for account management, access provisioning, and operational support activities. - GSSOne Command Center (GSSOCC) The GSS One Azure Command Center is a one stop shop for agency and CSP customers to view relevant information for their system and aid in implementing and maintaining ConMon requirements including a document repo for SSP and appendixes, POA&Ms and vulnerability scans, allows them to manage training, track incidents, track vulnerabilities and other corrective actions, track red teaming activities, view availability monitoring alerts, change control ticketing, link controls to artifacts and evidence to speed up ATO times and provide continuous monitoring/ Trust Center views for agencies leveraging their systems. - GSS One Azure Support Center: Project Hosts has configured a customer-facing support portal for creating and managing support tickets powered by Atlassian Jira. This allows customers to view all of their relevant tickets, create tickets, upload screenshots and communicate with PH staff through a secure channel. - Quest Security Management Platform (Quest-SMP): The Quest-SMP is a browser-based application with different agents that can be deployed on the agency devices/systems based on their individual use case. The Quest-SMP contains two major components: - Quest Identity Recovery for Entra ID: Quest Identity Recovery for Entra ID is a SaaS-based backup and recovery solution for Microsoft Entra ID and Microsoft 365 that extends protection beyond native Microsoft tools. It enables fast, secure restoration of users, groups, attributes, and memberships from a single cloud interface. Administrators can compare backups, view changes, and recover only what's needed-reducing manual errors and downtime. All recovery actions are logged and auditable to support compliance requirements. Hybrid Active Directory and Entra ID recovery is also supported through built-in integration with on-premises Quest Recovery Manager for Active Directory. Delivered as a secure, high-availability cloud service, Quest Identity Recovery for Entra ID helps federal agencies simplify directory recovery, maintain continuity, and meet governance standards without the need for on-premises infrastructure. - Quest Identity Defense: Quest Identity Defense is a hybrid Active Directory and Microsoft Entra ID security and audit platform that helps federal agencies strengthen identity threat detection, containment, and response while reducing risk of exposure and downtime. It identifies Tier Zero and other privileged objects across Active Directory and Entra ID to pinpoint where the greatest risks reside. The platform continually assesses identity environments for problematic configurations and drift from best-practice baselines, helping maintain compliance and operational integrity. Quest Identity Defense provides enhanced threat detection and observability for directory changes and protects Tier Zero assets from malicious in-memory modification-supporting zero trust and mission continuity across hybrid identity systems. Applications Supported on the Platform GSSOne Azure also supports customer and Independent Software Vendor (ISV) applications that are deployed on the platform but maintain their own authorization boundary (e.g., agency ATO or ISV-owned system). Each of the systems below have been vetted and meets the FedRAMP requirements and are ready to pursue FedRAMP certification or have been certified under their own listing and are viewable under the dependent product list. Examples of supported applications include: - AI Enabled Wordpress - Archive360 (Archive360 Platform) - AudioCodes (AudioCodes Live Platform) - AvePoint (AvePoint Online Services for US Government) - Aztec (Aztec Learning System) - Bingli (Bingli) - Blue Prism (Blue Prism) - BrightWork (BrightWork SharePoint-based Project Management) - C3 AI (C3 AI Suite) - CTERA Networks (CTERA Edge Filer, CTERA Drive, CTERA Portal) - CloudApper (Cloudapper.ai) - Conga (Contract Lifecycle Management, X-Author and Conga Approvals) - Creative Veteran Productions (Fed ILMS) - CyberSTAR Software (CyberSTAR™) - Distributed Solutions Inc. (AEON) - Drupal (Drupal CMS) - Eminent IT (Drupal Enclave) - Feith Systems and Software Inc. (RMA iQ™) - FlowVU (FlowVU Collaboration) - Idea Entity (RhyBus Platform) - Image Trend (Elite, Report Writer (RW), Continuum (CT), Licensure, Slate) - Invoke (UiPath Orchestrator and RPA) - Ivanti (MDM, Access, Neurons) - LMI (ATLAS by LMI) - Librestream Technology (Onsight Now) - Microsoft (Office, Dynamics, Power BI Server, Project Server, SharePoint, SSRS) - NIBS/ OM Group Inc. (ProjNet™) - Nintex (K2 Five, Workflow Cloud, DocGen) - Nintex (Nintex Automation GE Platform) - Nuance (Dragon Suite, DAX CoPilot) - OnePlan.ai (OnePlan) - OneSpan (OneSpan Sign) - Orbus Software (OrbusINFINITY) - Permuta (Defense Ready) - Power Settlements Consulting and Software, LLC (PowerCore™) - ProSymmetry - Relocation Management Worldwide (Virtual Employee Network) - Synergist Technology, LLC (AFFIRM Solution for AI Compliance, SAS® VIYA®) - Teamviewer (TeamViewer Digital Employee Experience (TMV DEX) for Government) - UMT360 (SharePoint-based Enterprise Portfolio Management) - Unison Software (Program Management Suite (PMSuite) - Wellspring (Accolade Enterprise Innovation Management, Sophia, Evolve) - WordPress (WordPress CMS) - WordPress As a Service (WPaaS) For each of these applications, Project Hosts provides deployment, security, and operational support services for these applications, enabling customers to leverage the GSSOne Azure platform while maintaining flexibility in how their systems are authorized and managed. Performing these functions on the partner's behalf allows the software vendors to focus on their core business model in delivering a secure, highly functional application to the agency while Project Hosts handles the security/ compliance requirements. For customers not deployed on the GSS One Azure, Project Hosts offers dedicated continuous monitoring services leveraging the GSS One Azure Command Center and scanners operated by Project Hosts engineers to configure, scan and provide continuous monitoring services to those external customers and their respective agencies to meet FedRAMP requirements.

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28