Section 8.4 - Register entry
DOC-REF: FRC-MKT-FR2001619708
Idira Endpoint Privilege Manager for Government
Palo Alto Networks, Inc. lists Idira Endpoint Privilege Manager for Government on the FedRAMP Marketplace with the status FedRAMP Certified, at High impact, on the Agency path under the Rev5 process. Package FR2001619708, read from the marketplace feed as of September 3, 2026.
Section A. Register entry
What the marketplace records
- FedRAMP package ID
- FR2001619708
- Cloud service provider
- Palo Alto Networks, Inc.
- Certification status
- FedRAMP Certified
- Impact level
- High
- Certification class
- Class D (High)
- Authorization path
- Agency
- Certification type
- Rev5
- Marketplace phase
- Ongoing Certification
- Deployment model
- Public Cloud
- Register snapshot
- September 3, 2026
- Service model
- SaaS
- Independent assessor
- Schellman Compliance, LLC
- Certification date
- March 14, 2024
- Status date
- March 14, 2024
- Annual assessment
- March 23, 2011
- Agency authorizations
- 4
- Recorded reuses
- 6
- Business categories
- Cybersecurity & Risk Management
- Dependent offerings
- 1
- Milestones on record
- 3
The marketplace carries Idira Endpoint Privilege Manager for Government under package FR2001619708 with 20 recorded fields. Its certification date is March 14, 2024. Schellman Compliance, LLC is named as the independent assessor, with an annual assessment date of March 23, 2011. 4 agencies are listed as having authorized it, among them Bureau of Labor Statistics, Department of Agriculture, Department of Transportation and 1 more, and the feed records 6 reuses of the package. It is delivered as SaaS on a public cloud, filed under 1 business categories including Cybersecurity & Risk Management. 1 other offering on the register is listed as dependent on this one, among them Idira Identity Security Government Services Platform.
Section B. Milestones
3 entries in the marketplace event log
Most recent first, as recorded by FedRAMP.
| Date | Category | Recorded |
|---|---|---|
| March 14, 2024 | Status Change | Status changed from PMO Review to FedRAMP Certified |
| March 23, 2023 | Status Change | Status changed from Agency Review to FedRAMP In Process |
| March 30, 2022 | Status Change | Status set to Agency Authorization In Process |
Section C. Cost context
What reaching High costs
Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.
Cost context
Budget for a High authorization
Our published planning range for a provider pursuing High. It is not a figure any listed provider has disclosed.
Read the FedRAMP High cost guide / annual assessment cost / continuous monitoring cost
Path
Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost
Assessment and monitoring
An annual assessment date of March 23, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost
Section E. Agencies on the record
4 agencies listed against this package
As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.
- Bureau of Labor Statistics
- Department of Agriculture
- Department of Transportation
- United States Securities and Exchange Commission
Section F. Dependent offerings
1 listed offering builds on this package
From the marketplace's dependent products view. A provider that inherits controls from a package below it carries a narrower assessment boundary of its own, which is one of the larger levers on authorization cost.
Inheritance is why boundary scope moves a budget more than headcount does. The hidden costs page sets out where scope creeps back in.
Section G. Nearest entries on the register
Comparable offerings
Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.
Palo Alto Networks, Inc. lists 4 offerings on the marketplace. The others are:
- Scale AI Data Platform
Scale AI, Inc
FedRAMP Certified, High impact, Agency path, Rev5, certified September 9, 2024.
- SentinelOne Singularity Platform High
SentinelOne
FedRAMP Certified, High impact, Agency path, Rev5, certified September 10, 2024.
- Splunk Cloud Platform for FedRAMP High
Splunk
FedRAMP Certified, High impact, Agency path, Rev5, certified September 13, 2024.
- Palantir Federal Cloud Service
Palantir Technologies Inc.
FedRAMP Certified, High impact, Agency path, Rev5, certified November 19, 2024.
- Palantir Federal Cloud Service - Supporting Services (PFCS-SS)
Palantir Technologies
FedRAMP Certified, High impact, Agency path, Rev5, certified November 19, 2024.
Section H. Description
As published on the marketplace
The provider's own description of the service, reproduced from the FedRAMP feed without edits.
With Idira™ Endpoint Privilege Manager by Palo Alto Networks, government organizations can confidently defend against attacks by automatically removing local admin rights, enforcing least privilege, enabling policy-based comprehensive conditional application control, maintaining application catalog, and protecting the entire endpoint security stack from tampering - in line with a number of recent CISA alerts, advisories and recommendations, and starting day one. The Idira Endpoint Privilege Manager secure and flexible SaaS management console allows for centralized policy-based and role-based management to ensure automated, robust and differentiated application of policies based on the user's role. Automatic elevation of known good programs requiring elevation, including those legacy and not-UAC-aware, significantly cuts down on the IT Service Desk requests, while optional automatic access restriction (for example, network connectivity restriction) for unknown applications significantly reduces the area of attack and helps break ransomware kill chain. Out-of-the-box anti-ransomware policy allows to add additional layer of security around sensitive data and prevent data corruption even in the event of successful asset compromise and ransomware execution. Additional critical capabilities include blocking credentials, private keys, secrets, passwords, hashes, cookies and other sensitive information from memory, browsers, operating system and credential stores, effectively blocking most attacks based on credential compromise. Idira Endpoint Privilege Manager helps with audit and compliance by addressing specific regulation requirements and creating audit trail for identity and privilege events on the endpoints. The following customer side components are authorized as part of the Idira Endpoint Privilege Manager for Government offering: Idira Endpoint Privilege Manager Windows Agent, Idira Endpoint Privilege Manager macOS Agent, Idira Endpoint Privilege Manager Linux Agent.
Next step
What the same authorization would cost you
The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.
Provenance and independence
Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.
GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.
FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.