DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-FR2001619337

Idira Identity Security Government Services Platform

Palo Alto Networks, Inc. lists Idira Identity Security Government Services Platform on the FedRAMP Marketplace with the status FedRAMP Certified, at High impact, on the Agency path under the Rev5 process. Package FR2001619337, read from the marketplace feed as of September 3, 2026.

FedRAMP CertifiedRev5Agency path

Section A. Register entry

What the marketplace records

FedRAMP package ID
FR2001619337
Cloud service provider
Palo Alto Networks, Inc.
Certification status
FedRAMP Certified
Impact level
High
Certification class
Class D (High)
Authorization path
Agency
Certification type
Rev5
Marketplace phase
Ongoing Certification
Deployment model
Public Cloud
Register snapshot
September 3, 2026
Service model
SaaS
Independent assessor
Schellman Compliance, LLC
Certification date
March 14, 2024
Status date
March 14, 2024
Annual assessment
March 23, 2011
Agency authorizations
3
Recorded reuses
7
Business categories
Cybersecurity & Risk Management
Dependent offerings
2
Milestones on record
3

The marketplace carries Idira Identity Security Government Services Platform under package FR2001619337 with 20 recorded fields. Its certification date is March 14, 2024. Schellman Compliance, LLC is named as the independent assessor, with an annual assessment date of March 23, 2011. 3 agencies are listed as having authorized it, among them Bureau of Labor Statistics, Department of Agriculture and Office of Personnel Management, and the feed records 7 reuses of the package. It is delivered as SaaS on a public cloud, filed under 1 business categories including Cybersecurity & Risk Management. 2 other offerings on the register are listed as dependent on this one, among them AutoRABIT for Public Sector - CodeScan, Guard, & ARMOR and Idira Endpoint Privilege Manager for Government.

Section B. Milestones

3 entries in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
March 14, 2024Status ChangeStatus changed from PMO Review to FedRAMP Certified
March 23, 2023Status ChangeStatus changed from Agency Review to FedRAMP In Process
March 30, 2022Status ChangeStatus set to Agency Authorization In Process

Section C. Cost context

What reaching High costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a High authorization

Initial authorization$2,500,000 to $5,000,000+
Continuous monitoring$300,000 to $600,000+ a year
Typical timeline18 to 24 months
Control baseline421+ controls
Annual assessment$180,000 to $450,000 a year

Our published planning range for a provider pursuing High. It is not a figure any listed provider has disclosed.

Read the FedRAMP High cost guide / annual assessment cost / continuous monitoring cost

Path

Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost

Assessment and monitoring

An annual assessment date of March 23, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost

Section E. Agencies on the record

3 agencies listed against this package

As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.

  • Bureau of Labor Statistics
  • Department of Agriculture
  • Office of Personnel Management

Section F. Dependent offerings

2 listed offerings build on this package

From the marketplace's dependent products view. A provider that inherits controls from a package below it carries a narrower assessment boundary of its own, which is one of the larger levers on authorization cost.

Inheritance is why boundary scope moves a budget more than headcount does. The hidden costs page sets out where scope creeps back in.

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

The Idira™ Identity Security Government Services Platform by Palo Alto Networks is a comprehensive solution designed to secure identities across the entire IT ecosystem, ensuring government agencies can confidently protect their most critical assets. By integrating privileged access management (PAM), access management (AM), the platform delivers a unified approach to identity security that aligns with federal compliance requirements. The Idira Identity Security Government Services Platform is a FedRAMP High Authorized solution that integrates Privileged Access Management (PAM), Access Management (AM) into a unified identity security platform for federal agencies. The platform enforces least privilege, secures privileged credentials, and manages access across on-premises, cloud, and hybrid federal environments in alignment with NIST SP 800-53 Rev 5, FISMA, and EO 14028 Zero Trust requirements. The platform provides robust capabilities to secure human identities, enforce least privilege, and manage access across complex infrastructures. It includes advanced tools for securing privileged credentials, automating identity lifecycle management, and applying adaptive authentication policies based on risk. Key features include: ● Privileged Access Management (PAM): Secure, monitor, and manage privileged accounts and sessions to prevent unauthorized access and mitigate insider threats. Includes capabilities such as credential vaulting, session isolation, and real-time session recording with keystroke logging. ● Access Management (AM): Enable secure access to applications, devices, and infrastructure with single sign-on (SSO), multi-factor authentication (MFA), and lifecycle management. Supports protocols like SAML, OpenID Connect (OIDC), and SCIM for seamless integration with third-party applications. ● Hybrid and Multi-Cloud Support: Provides secure access and identity management across on-premises, cloud, and hybrid environments, with support for AWS, Azure, Google Cloud, and private cloud infrastructures. The Idira Identity Security Government Services Platform is designed to meet the unique needs of government organizations, providing a scalable, secure, and compliant solution to protect against evolving cyber threats. Idira Identity Security Government Services Platform: Unified Access & Identity Management Idira Identity Security Government Services Platform is a cloud-based platform that unifies essential services like Single Sign-On (SSO) and Multi-Factor Authentication (MFA) into a single interface. Designed for Government Organizations, it secures access to critical resources (applications, devices, IaaS, PaaS, and VPNs) across on-premises, cloud, and hybrid environments. SSO and Application Gateway: The platform features a catalog with thousands of pre-configured application connections. Administrators can easily add custom applications via templates using SAML, OpenID Connect (OIDC), OAuth2, WS-FED, or traditional credentials. For legacy environments, the App Gateway provides secure, VPN-less access to on-prem applications, allowing for granular, per-user, and per-application access control. Phishing-Resistant MFA and High-Assurance Authentication: Idira supports a broad range of authentication methods, including FIDO2/Passkeys, Security Keys, Smart Cards, and Magic Links. These protections extend across the entire infrastructure, covering Windows and Mac workstations, servers, virtual desktops, VPNs, RADIUS servers, and 3rd-party IDPs. Adaptive MFA enhances this by evaluating real-time risk signals such as device posture, location, and network context, to apply dynamic, situation-aware authentication policies. Unified Directory Services and Hybrid Integration: Idira provides a hybrid architecture that unifies Active Directory, LDAP, and cloud-native users into a single source of truth. By utilizing a secure, outbound-only connector, agencies can bridge on-premises repositories for real-time authentication without the need for VPNs or invasive firewall modifications. This creates a centralized, high-availability identity hub that ensures consistent enterprise-wide policy enforcement while keeping sensitive identity data protected. Privileged Access Manager SaaS for Government Idira Privileged Access Manager SaaS by Palo Alto Networks is a FedRAMP High Authorized, cloud-native solution that enables federal agencies to secure, monitor, and manage privileged access across on-premises, cloud and hybrid environments. The Service is hosted on FedRAMP-compliant infrastructure and supports agency compliance with NIST SP 800-53 Rev 5, FISMA, FIPS 140-2/140-3, OMB M-22-09, EO 14028, and CISA Zero Trust guidance. With Idira Privileged Access Manager SaaS, government organizations can secure, monitor, and manage privileged credentials and sessions across complex infrastructures. The solution enables rapid onboarding of privileged accounts, enforces least privilege policies, and provides real-time session monitoring and recording to detect and respond to suspicious activity. This supports Cloud-Native Architecture that further simplifies deployment and reduces infrastructure overhead while ensuring high availability and scalability. It is built on a microservices architecture with containerized components for rapid updates and resilience. Key capabilities include: ● Discovery and Onboarding: Automatically discover and onboard privileged accounts across on-premises, cloud, and hybrid environments. Supports integrations with Active Directory (AD), LDAP, and cloud directories like Azure AD. ● Session Monitoring and Recording: Monitor and record privileged sessions in real time to detect and respond to anomalous behavior. Includes features like live session termination, command filtering, and session playback for forensic analysis. ● Audit and Compliance Reporting: Generate detailed audit logs and compliance reports to meet regulatory requirements, including OMB, FIPS, FISMA, and CISA guidelines. ● Credential Management and Rotation: Securely vault and automatically rotate privileged credentials across on-premises, cloud, and hybrid environments to eliminate static passwords. Includes features like automated rotation based on flexible policies, SSH key management, and the ability to verify credential synchronization to prevent unauthorized access and lateral movement. Idira Privileged Access Manager SaaS empowers government organizations to strengthen their security posture, reduce operational complexity, and ensure compliance with federal regulations, all while protecting their ecosystem from advanced cyber threats.

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28