Section 8.4 - Register entry
DOC-REF: FRC-MKT-FR1919750997
HackerOne Continuous Security Testing Platform
HackerOne lists HackerOne Continuous Security Testing Platform on the FedRAMP Marketplace with the status FedRAMP Certified, at LI-SaaS impact, on the Agency path under the Rev5 process. Package FR1919750997, read from the marketplace feed as of September 3, 2026.
Section A. Register entry
What the marketplace records
- FedRAMP package ID
- FR1919750997
- Cloud service provider
- HackerOne
- Certification status
- FedRAMP Certified
- Impact level
- LI-SaaS
- Certification class
- Class B (Low)
- Authorization path
- Agency
- Certification type
- Rev5
- Marketplace phase
- Ongoing Certification
- Deployment model
- Public Cloud
- Register snapshot
- September 3, 2026
- Service model
- SaaS
- Independent assessor
- Schellman Compliance, LLC
- Certification date
- May 6, 2020
- Status date
- May 6, 2020
- Annual assessment
- February 28, 2011
- Agency authorizations
- 3
- Recorded reuses
- 48
- Small business
- Flagged on the marketplace record
- Dependent offerings
- 2
- Milestones on record
- 3
The marketplace carries HackerOne Continuous Security Testing Platform under package FR1919750997 with 20 recorded fields. Its certification date is May 6, 2020. Schellman Compliance, LLC is named as the independent assessor, with an annual assessment date of February 28, 2011. 3 agencies are listed as having authorized it, among them Consumer Financial Protection Bureau, Department of State and General Services Administration, and the feed records 48 reuses of the package. It is delivered as SaaS on a public cloud. 2 other offerings on the register are listed as dependent on this one, among them GitHub Enterprise Cloud and KnowBe4 Platform. HackerOne is flagged as a small business on the record.
Section B. Milestones
3 entries in the marketplace event log
Most recent first, as recorded by FedRAMP.
| Date | Category | Recorded |
|---|---|---|
| May 6, 2020 | Status Change | Status changed from PMO Review to FedRAMP Certified |
| April 24, 2020 | Status Change | Status changed from Agency Review to FedRAMP In Process |
| May 8, 2019 | Status Change | Status set to Agency Authorization In Process |
Section C. Cost context
What reaching this stage costs
Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.
Cost context
No range published for this level
This site does not publish a separate budget range for LI-SaaS, so no figure is quoted here. The impact level reference sets out how the tailored low baseline differs from Low.
Read the impact level reference / continuous monitoring cost
Path
Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost
Assessment and monitoring
An annual assessment date of February 28, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost
Section E. Agencies on the record
3 agencies listed against this package
As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.
- Consumer Financial Protection Bureau
- Department of State
- General Services Administration
Section F. Dependent offerings
2 listed offerings build on this package
From the marketplace's dependent products view. A provider that inherits controls from a package below it carries a narrower assessment boundary of its own, which is one of the larger levers on authorization cost.
Inheritance is why boundary scope moves a budget more than headcount does. The hidden costs page sets out where scope creeps back in.
Section G. Nearest entries on the register
Comparable offerings
Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.
- Zendesk Customer Support and Help Desk Platform
Zendesk
FedRAMP Certified, LI-SaaS impact, Agency path, Rev5, certified May 14, 2020.
- QGenda
Qgenda, LLC
FedRAMP Certified, LI-SaaS impact, Agency path, Rev5, certified March 23, 2020.
- WorldShare Management Services
OCLC Incorporated
FedRAMP Certified, LI-SaaS impact, Agency path, Rev5, certified July 1, 2020.
- Adobe Learning Manager
Adobe
FedRAMP Certified, LI-SaaS impact, Agency path, Rev5, certified October 11, 2019.
- Adobe Analytics
Adobe
FedRAMP Certified, LI-SaaS impact, Agency path, Rev5, certified September 18, 2019.
Section H. Description
As published on the marketplace
The provider's own description of the service, reproduced from the FedRAMP feed without edits.
HackerOne is a multi-tenant Vulnerability Disclosure and crowdsourced Bug Bounty platform. Organizations rely on HackerOne to detect unknown security vulnerabilities in public-facing systems as well as sensitive assets that are not publicly disclosed. This is done by giving customers access to the world's largest community of crowdsourced security researchers. Researchers then conduct remote, internet based, crowdsourced vulnerability discovery and disclosure services against internet-accessible assets, including public-facing websites, networks, systems, and applications.
Next step
What the same authorization would cost you
The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.
Provenance and independence
Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.
GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.
FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.