Section 8.4 - Register entry
DOC-REF: FRC-MKT-FR2001619337
Idira Identity Security Government Services Platform
Palo Alto Networks, Inc. lists Idira Identity Security Government Services Platform on the FedRAMP Marketplace with the status FedRAMP Certified, at High impact, on the Agency path under the Rev5 process. Package FR2001619337, read from the marketplace feed as of September 3, 2026.
Section A. Register entry
What the marketplace records
- FedRAMP package ID
- FR2001619337
- Cloud service provider
- Palo Alto Networks, Inc.
- Certification status
- FedRAMP Certified
- Impact level
- High
- Certification class
- Class D (High)
- Authorization path
- Agency
- Certification type
- Rev5
- Marketplace phase
- Ongoing Certification
- Deployment model
- Public Cloud
- Register snapshot
- September 3, 2026
- Service model
- SaaS
- Independent assessor
- Schellman Compliance, LLC
- Certification date
- March 14, 2024
- Status date
- March 14, 2024
- Annual assessment
- March 23, 2011
- Agency authorizations
- 3
- Recorded reuses
- 7
- Business categories
- Cybersecurity & Risk Management
- Dependent offerings
- 2
- Milestones on record
- 3
The marketplace carries Idira Identity Security Government Services Platform under package FR2001619337 with 20 recorded fields. Its certification date is March 14, 2024. Schellman Compliance, LLC is named as the independent assessor, with an annual assessment date of March 23, 2011. 3 agencies are listed as having authorized it, among them Bureau of Labor Statistics, Department of Agriculture and Office of Personnel Management, and the feed records 7 reuses of the package. It is delivered as SaaS on a public cloud, filed under 1 business categories including Cybersecurity & Risk Management. 2 other offerings on the register are listed as dependent on this one, among them AutoRABIT for Public Sector - CodeScan, Guard, & ARMOR and Idira Endpoint Privilege Manager for Government.
Section B. Milestones
3 entries in the marketplace event log
Most recent first, as recorded by FedRAMP.
| Date | Category | Recorded |
|---|---|---|
| March 14, 2024 | Status Change | Status changed from PMO Review to FedRAMP Certified |
| March 23, 2023 | Status Change | Status changed from Agency Review to FedRAMP In Process |
| March 30, 2022 | Status Change | Status set to Agency Authorization In Process |
Section C. Cost context
What reaching High costs
Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.
Cost context
Budget for a High authorization
Our published planning range for a provider pursuing High. It is not a figure any listed provider has disclosed.
Read the FedRAMP High cost guide / annual assessment cost / continuous monitoring cost
Path
Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost
Assessment and monitoring
An annual assessment date of March 23, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost
Section E. Agencies on the record
3 agencies listed against this package
As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.
- Bureau of Labor Statistics
- Department of Agriculture
- Office of Personnel Management
Section F. Dependent offerings
2 listed offerings build on this package
From the marketplace's dependent products view. A provider that inherits controls from a package below it carries a narrower assessment boundary of its own, which is one of the larger levers on authorization cost.
- AutoRABIT for Public Sector - CodeScan, Guard, & ARMOR
- Idira Endpoint Privilege Manager for Government
Inheritance is why boundary scope moves a budget more than headcount does. The hidden costs page sets out where scope creeps back in.
Section G. Nearest entries on the register
Comparable offerings
Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.
Palo Alto Networks, Inc. lists 4 offerings on the marketplace. The others are:
- Scale AI Data Platform
Scale AI, Inc
FedRAMP Certified, High impact, Agency path, Rev5, certified September 9, 2024.
- SentinelOne Singularity Platform High
SentinelOne
FedRAMP Certified, High impact, Agency path, Rev5, certified September 10, 2024.
- Splunk Cloud Platform for FedRAMP High
Splunk
FedRAMP Certified, High impact, Agency path, Rev5, certified September 13, 2024.
- Palantir Federal Cloud Service
Palantir Technologies Inc.
FedRAMP Certified, High impact, Agency path, Rev5, certified November 19, 2024.
- Palantir Federal Cloud Service - Supporting Services (PFCS-SS)
Palantir Technologies
FedRAMP Certified, High impact, Agency path, Rev5, certified November 19, 2024.
Section H. Description
As published on the marketplace
The provider's own description of the service, reproduced from the FedRAMP feed without edits.
The Idira™ Identity Security Government Services Platform by Palo Alto Networks is a comprehensive solution designed to secure identities across the entire IT ecosystem, ensuring government agencies can confidently protect their most critical assets. By integrating privileged access management (PAM), access management (AM), the platform delivers a unified approach to identity security that aligns with federal compliance requirements. The Idira Identity Security Government Services Platform is a FedRAMP High Authorized solution that integrates Privileged Access Management (PAM), Access Management (AM) into a unified identity security platform for federal agencies. The platform enforces least privilege, secures privileged credentials, and manages access across on-premises, cloud, and hybrid federal environments in alignment with NIST SP 800-53 Rev 5, FISMA, and EO 14028 Zero Trust requirements. The platform provides robust capabilities to secure human identities, enforce least privilege, and manage access across complex infrastructures. It includes advanced tools for securing privileged credentials, automating identity lifecycle management, and applying adaptive authentication policies based on risk. Key features include: ● Privileged Access Management (PAM): Secure, monitor, and manage privileged accounts and sessions to prevent unauthorized access and mitigate insider threats. Includes capabilities such as credential vaulting, session isolation, and real-time session recording with keystroke logging. ● Access Management (AM): Enable secure access to applications, devices, and infrastructure with single sign-on (SSO), multi-factor authentication (MFA), and lifecycle management. Supports protocols like SAML, OpenID Connect (OIDC), and SCIM for seamless integration with third-party applications. ● Hybrid and Multi-Cloud Support: Provides secure access and identity management across on-premises, cloud, and hybrid environments, with support for AWS, Azure, Google Cloud, and private cloud infrastructures. The Idira Identity Security Government Services Platform is designed to meet the unique needs of government organizations, providing a scalable, secure, and compliant solution to protect against evolving cyber threats. Idira Identity Security Government Services Platform: Unified Access & Identity Management Idira Identity Security Government Services Platform is a cloud-based platform that unifies essential services like Single Sign-On (SSO) and Multi-Factor Authentication (MFA) into a single interface. Designed for Government Organizations, it secures access to critical resources (applications, devices, IaaS, PaaS, and VPNs) across on-premises, cloud, and hybrid environments. SSO and Application Gateway: The platform features a catalog with thousands of pre-configured application connections. Administrators can easily add custom applications via templates using SAML, OpenID Connect (OIDC), OAuth2, WS-FED, or traditional credentials. For legacy environments, the App Gateway provides secure, VPN-less access to on-prem applications, allowing for granular, per-user, and per-application access control. Phishing-Resistant MFA and High-Assurance Authentication: Idira supports a broad range of authentication methods, including FIDO2/Passkeys, Security Keys, Smart Cards, and Magic Links. These protections extend across the entire infrastructure, covering Windows and Mac workstations, servers, virtual desktops, VPNs, RADIUS servers, and 3rd-party IDPs. Adaptive MFA enhances this by evaluating real-time risk signals such as device posture, location, and network context, to apply dynamic, situation-aware authentication policies. Unified Directory Services and Hybrid Integration: Idira provides a hybrid architecture that unifies Active Directory, LDAP, and cloud-native users into a single source of truth. By utilizing a secure, outbound-only connector, agencies can bridge on-premises repositories for real-time authentication without the need for VPNs or invasive firewall modifications. This creates a centralized, high-availability identity hub that ensures consistent enterprise-wide policy enforcement while keeping sensitive identity data protected. Privileged Access Manager SaaS for Government Idira Privileged Access Manager SaaS by Palo Alto Networks is a FedRAMP High Authorized, cloud-native solution that enables federal agencies to secure, monitor, and manage privileged access across on-premises, cloud and hybrid environments. The Service is hosted on FedRAMP-compliant infrastructure and supports agency compliance with NIST SP 800-53 Rev 5, FISMA, FIPS 140-2/140-3, OMB M-22-09, EO 14028, and CISA Zero Trust guidance. With Idira Privileged Access Manager SaaS, government organizations can secure, monitor, and manage privileged credentials and sessions across complex infrastructures. The solution enables rapid onboarding of privileged accounts, enforces least privilege policies, and provides real-time session monitoring and recording to detect and respond to suspicious activity. This supports Cloud-Native Architecture that further simplifies deployment and reduces infrastructure overhead while ensuring high availability and scalability. It is built on a microservices architecture with containerized components for rapid updates and resilience. Key capabilities include: ● Discovery and Onboarding: Automatically discover and onboard privileged accounts across on-premises, cloud, and hybrid environments. Supports integrations with Active Directory (AD), LDAP, and cloud directories like Azure AD. ● Session Monitoring and Recording: Monitor and record privileged sessions in real time to detect and respond to anomalous behavior. Includes features like live session termination, command filtering, and session playback for forensic analysis. ● Audit and Compliance Reporting: Generate detailed audit logs and compliance reports to meet regulatory requirements, including OMB, FIPS, FISMA, and CISA guidelines. ● Credential Management and Rotation: Securely vault and automatically rotate privileged credentials across on-premises, cloud, and hybrid environments to eliminate static passwords. Includes features like automated rotation based on flexible policies, SSH key management, and the ability to verify credential synchronization to prevent unauthorized access and lateral movement. Idira Privileged Access Manager SaaS empowers government organizations to strengthen their security posture, reduce operational complexity, and ensure compliance with federal regulations, all while protecting their ecosystem from advanced cyber threats.
Next step
What the same authorization would cost you
The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.
Provenance and independence
Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.
GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.
FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.