Section 8.4 - Register entry
DOC-REF: FRC-MKT-FR2122038682
iboss Government Cloud Platform (IGCP)
iBoss lists iboss Government Cloud Platform (IGCP) on the FedRAMP Marketplace with the status FedRAMP Certified, at Moderate impact, on the Agency path under the Rev5 process. Package FR2122038682, read from the marketplace feed as of September 3, 2026.
Section A. Register entry
What the marketplace records
- FedRAMP package ID
- FR2122038682
- Cloud service provider
- iBoss
- Certification status
- FedRAMP Certified
- Impact level
- Moderate
- Certification class
- Class C (Moderate)
- Authorization path
- Agency
- Certification type
- Rev5
- Marketplace phase
- Ongoing Certification
- Deployment model
- Government Community Cloud
- Register snapshot
- September 3, 2026
- Service model
- SaaS
- Independent assessor
- A-LIGN Compliance and Security, Inc. dba A-LIGN
- Sponsoring agency
- International Trade Administration
- Certification date
- July 25, 2022
- Status date
- July 25, 2022
- Annual assessment
- August 17, 2011
- Agency authorizations
- 3
- Recorded reuses
- 2
- Business categories
- Cybersecurity & Risk Management, Education & Training, Health & Wellness, Law Enforcement, Learning Management, Legal & Policy, Mobile Device Management (MDM), Network Management, System Administration, Virtual Private Network (VPN)
- Small business
- Flagged on the marketplace record
- Milestones on record
- 3
The marketplace carries iboss Government Cloud Platform (IGCP) under package FR2122038682 with 21 recorded fields. Its certification date is July 25, 2022. A-LIGN Compliance and Security, Inc. dba A-LIGN is named as the independent assessor, with an annual assessment date of August 17, 2011. International Trade Administration is recorded as the sponsoring agency. 2 agencies are listed as having authorized it, among them Defense Nuclear Facilities Safety Board and Office of Personnel Management, and the feed records 2 reuses of the package. It is delivered as SaaS on a government community cloud, filed under 10 business categories including Cybersecurity & Risk Management, Education & Training, Health & Wellness and 7 more. iBoss is flagged as a small business on the record.
Section B. Milestones
3 entries in the marketplace event log
Most recent first, as recorded by FedRAMP.
| Date | Category | Recorded |
|---|---|---|
| July 25, 2022 | Status Change | Status changed from PMO Review to FedRAMP Certified |
| February 7, 2022 | Status Change | Status changed from Agency Review to FedRAMP In Process |
| August 10, 2021 | Status Change | Status set to Agency Authorization In Process |
Section C. Cost context
What reaching Moderate costs
Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.
Cost context
Budget for a Moderate authorization
Our published planning range for a provider pursuing Moderate. It is not a figure any listed provider has disclosed.
Read the FedRAMP Moderate cost guide / annual assessment cost / continuous monitoring cost
Path
Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost
Assessment and monitoring
An annual assessment date of August 17, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost
Section E. Agencies on the record
2 agencies listed against this package
As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.
- Defense Nuclear Facilities Safety Board
- Office of Personnel Management
Section G. Nearest entries on the register
Comparable offerings
Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.
- BeyondTrust Identity Security For Government
BeyondTrust
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified April 17, 2024.
- Juniper Mist
Juniper Networks
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified March 28, 2025.
- Axonius Asset Cloud
Axonius Federal Systems
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified April 3, 2025.
- NEOGOV Cloud
NEOGOV
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified August 25, 2025.
- Zscaler Private Access - Government (Zero Trust Exchange - VPN Replacement)
Zscaler, Inc.
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified November 7, 2022.
Section H. Description
As published on the marketplace
The provider's own description of the service, reproduced from the FedRAMP feed without edits.
FedRAMP Authorized Zero Trust Security Service Edge for Government, Defense, and Defense Industrial Base The iboss Government Cloud Platform (IGCP) is a state-of-the-art, FedRAMP Moderate Authorized solution designed to provide Zero Trust Security Service Edge (SSE/SASE) for U.S. Federal agencies, defense contractors, Managed Security Service Providers (MSSPs), and organizations entrusted with Controlled Unclassified Information (CUI). IGCP's architecture is built to deliver Zero Trust Network Access (ZTNA), aligning with Cybersecurity Maturity Model Certification (CMMC) requirements and NIST 800-171/172 controls. This ensures compliance and robust security for sensitive government data. ===== DEPLOYMENT FLEXIBILITY ===== Direct Agency Deployment: Federal agencies can deploy IGCP directly as their Zero Trust SASE platform, with full control over policies, configurations, and security operations through the unified management console. MSSP Service Delivery: MSSPs can leverage IGCP's multi-tenant architecture to deliver managed security services to multiple defense contractors and federal customers from a single platform, streamlining compliance and security operations. ===== COMPLIANCE FRAMEWORKS SUPPORTED ===== • CMMC 2.0 Requirements (addresses 78 of 110 NIST SP 800-171 controls) • NIST SP 800-171 (Protecting CUI) • NIST SP 800-172 (Enhanced Security Requirements for CUI) • NIST SP 800-207 (Zero Trust Architecture) • NIST Cybersecurity Framework (CSF) • DFARS 7012 (Safeguarding Covered Defense Information) • CJIS (Criminal Justice Information Services) • HIPAA (Health Insurance Portability and Accountability Act) • ITAR (International Traffic in Arms Regulations) • EAR (Export Administration Regulations) Government agencies and defense contractors are constantly challenged by evolving cyber threats, increasing renewal costs, and the complexity of managing multiple legacy security products. To address these issues, iboss offers both direct deployment for agencies and Managed Security Service Provider (MSSP) solutions. By delivering a SaaS-based Zero Trust SASE platform and comprehensive managed security services, iboss enables organizations to shift their security focus from physical buildings to the continuous protection of people and resources, regardless of where work occurs. ===== FEDERAL MSSP SASE PLATFORM FEATURES ===== Purpose-built for both direct agency use and MSSP operations, the Federal MSSP SASE Platform streamlines and enhances service delivery through several key features: For MSSPs: • Multi-Tenant Management: Allows MSSPs to manage all customers from a single, unified interface • Pooled Device Licensing: Enables licenses to be shared across tenants, providing greater flexibility • Billing in Arrears: Monthly billing cycles designed to align seamlessly with MSP operations • Audit-Ready Compliance Reports: Pre-configured CMMC and NIST 800-171 compliance reports for each tenant For Direct Agency Deployment: • Unified Management Console: Single pane of glass for policy management, threat monitoring, and compliance reporting • Zero Trust Policy Engine: Centralized policy creation and enforcement across all users, devices, and applications • Real-Time Security Analytics: Comprehensive visibility into all network traffic and security events • Automated Compliance Monitoring: Continuous assessment against FedRAMP, CMMC, and NIST requirements This structure supports rapid scaling while maintaining profitability and operational efficiency in the federal compliance market. ===== CORE CAPABILITIES ===== Zero Trust Architecture (NIST 800-207 Aligned): Enforces least-privilege access and continuous verification for users, devices, and applications, eliminating implicit trust throughout the network. Implements all core Zero Trust principles including identity-based segmentation, encrypted traffic, and continuous monitoring. Secure Access Service Edge (SASE): Integrates advanced cloud security functions with wide-area networking to ensure secure and optimized connectivity for both remote and on-premises users. Converges networking and security into a unified cloud-delivered service. Zero Trust Network Access (ZTNA) & VPN Replacement: Offers granular, identity-based access to applications without exposing the network, effectively replacing traditional VPNs with a secure, modern alternative. Provides application-level access control with continuous authentication and authorization. Integrated SD-WAN Capabilities: IGCP provides native SD-WAN functionality for secure, optimized WAN connectivity, enabling intelligent traffic routing, application prioritization, and multi-link failover. Additionally, IGCP seamlessly integrates with existing third-party SD-WAN solutions, allowing organizations to enhance their current infrastructure with advanced Zero Trust security without requiring a complete replacement of their networking architecture. Secure Web Gateway (SWG): Advanced URL filtering, SSL/TLS inspection, malware detection, and content filtering to protect users from web-based threats. Cloud Access Security Broker (CASB): Comprehensive visibility and control over SaaS applications, shadow IT discovery, and data loss prevention for cloud services. Firewall as a Service (FWaaS): Next-generation firewall capabilities delivered from the cloud, including intrusion prevention, application control, and threat intelligence integration. Data Loss Prevention (DLP): Protects CUI and FCI from unauthorized disclosure through content inspection, contextual analysis, and policy-based blocking. Integrates with Microsoft Purview for enhanced data classification. Advanced Threat Protection: Multi-layered defense including anti-malware, ransomware protection, sandboxing, and threat intelligence feeds to detect and prevent sophisticated attacks. Containerized Cloud Architecture: Patented isolation technology ensuring each organization's traffic is processed in dedicated containerized gateways, guaranteeing data never mixes with other customers-critical for federal data protection requirements. ===== DEFENSE CONTRACTOR ENABLEMENT ===== IGCP supports organizations within the Defense Industrial Base (DIB) by securing CUI, FCI, and ITAR data flows. This enables compliance with Department of Defense mandates, CMMC 2.0 requirements, and the Presidential Executive Order on Cybersecurity (EO 14028). With pre-mapped controls addressing 78 of the 110 NIST SP 800-171 requirements, IGCP significantly accelerates the path to CMMC Level 2 certification. CMMC Control Family Coverage: • Access Control (AC): 82% coverage • Audit and Accountability (AU): 100% coverage • Identification and Authentication (IA): 100% coverage • System and Communications Protection (SC): 94% coverage • System and Information Integrity (SI): 90% coverage • Incident Response (IR): 83% coverage ===== KEY BENEFITS ===== ✓ FedRAMP Moderate Authorized Zero Trust SASE for government-grade security ✓ CMMC 2.0 Compliance Accelerator addressing 78 of 110 required controls ✓ NIST 800-207 Zero Trust Architecture fully aligned with federal mandates ✓ Cloud-native architecture providing scalability and resilience without hardware ✓ Rapid deployment for hybrid and remote workforces (cloud-delivered, no appliances) ✓ Comprehensive compliance for CMMC, NIST 800-171/172, DFARS, CJIS, HIPAA, and ITAR ✓ Unified Zero Trust Platform with integrated ZTNA, SWG, CASB, FWaaS, DLP, and SD-WAN ✓ Containerized data isolation ensuring federal data never mixes with other customers ✓ Continuous monitoring with real-time threat detection and automated incident response ✓ Cost optimization by consolidating 5-8 security point products into one platform ===== USE CASES ===== Federal Agency Modernization: Replace legacy VPNs and security appliances with cloud-native Zero Trust, enabling secure hybrid work while reducing infrastructure costs. Defense Contractor CMMC Compliance: Achieve CMMC Level 2 certification faster with pre-mapped controls, audit-ready documentation, and integrated CUI protection. MSSP Service Delivery: Deliver FedRAMP-authorized managed security services to multiple defense contractors from a single multi-tenant platform. Remote Workforce Security: Secure access to applications and data for teleworking federal employees and contractors from any device, anywhere. Cloud Migration Security: Protect agencies migrating to AWS, Azure, Google Cloud, and other cloud environments with consistent security policies. Branch Office Connectivity: Connect distributed offices, remote sites, and field operations with secure SD-WAN and Zero Trust access. Third-Party Access: Provide secure, time-limited access to contractors, partners, and vendors without VPN credentials or network exposure. Incident Response: Rapidly isolate compromised users or devices, block threats in real-time, and generate forensic audit trails for security investigations. ===== TECHNICAL ARCHITECTURE ===== Deployment Model: Cloud-delivered Security Access Service Edge (SASE) Agent Options: Native agents for Windows, macOS, Linux, iOS, Android; agentless options for managed devices Identity Integration: Supports SAML, OAuth, OIDC, Active Directory, Azure AD, Okta, Ping Identity, PIV/CAC cards SIEM Integration: Native integration with Splunk, QRadar, ArcSight, Microsoft Sentinel, and other SIEM platforms API Access: RESTful APIs for automation, orchestration, and integration with existing security tools Performance: Processes over 150 billion daily transactions globally with sub-10ms latency Availability: 99.99% uptime SLA with automated failover and geo-redundant infrastructure ===== SUPPORT & SERVICES ===== Federal Support Team: Dedicated 24/7/365 support team with federal expertise and cleared personnel Onboarding Services: Comprehensive deployment planning, configuration, and migration services Compliance Assistance: Guidance on CMMC assessments, NIST control implementation, and audit preparation Continuous Monitoring: FedRAMP-required continuous monitoring with monthly POA&M updates Security Operations: Optional 24/7 managed security services including threat hunting and incident response Training & Enablement: Administrator training, user awareness programs, and best practice workshops
Next step
What the same authorization would cost you
The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.
Provenance and independence
Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.
GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.
FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.