Section 8.4 - Register entry
DOC-REF: FRC-MKT-FR2629068833
Immuta Federal
Immuta lists Immuta Federal on the FedRAMP Marketplace with the status Initial Implementation, at no impact level listed, on the Program path under the 20x process. Package FR2629068833, read from the marketplace feed as of September 3, 2026.
Section A. Register entry
What the marketplace records
- FedRAMP package ID
- FR2629068833
- Cloud service provider
- Immuta
- Certification status
- Initial Implementation
- Impact level
- Not listed
- Certification class
- Class C (Moderate)
- Authorization path
- Program
- Certification type
- 20x
- Marketplace phase
- Initial Implementation
- Deployment model
- Government Community Cloud
- Register snapshot
- September 3, 2026
- Service model
- SaaS
- Independent assessor
- Fortreum
- Status date
- July 22, 2026
- Business categories
- Data Management, Governance, Risk, and Compliance (GRC)
- SAM.gov UEI
- 47-1877648
- Milestones on record
- 1
The marketplace carries Immuta Federal under package FR2629068833 with 16 recorded fields. Its current status was set on July 22, 2026. Fortreum is named as the independent assessor. No agency authorizations are listed against it in the current feed. It is delivered as SaaS on a government community cloud, filed under 2 business categories including Data Management and Governance, Risk, and Compliance (GRC). Its SAM.gov unique entity identifier is 47-1877648.
Section B. Milestones
1 entry in the marketplace event log
Most recent first, as recorded by FedRAMP.
| Date | Category | Recorded |
|---|---|---|
| July 22, 2026 | Status Change | Status set to Initial Implementation |
Section C. Cost context
What reaching this stage costs
Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.
Cost context
No range published for this level
The marketplace lists no impact level here, so no cost range is quoted. Our impact level reference sets out what each baseline costs to reach.
Read the impact level reference / continuous monitoring cost
Path
The marketplace records 80 offerings on the Program path, 76 of them 20x. Our 20x page covers what that model is estimated to cost. FedRAMP 20x cost analysis
20x
This package is on the 20x track. Our 20x page puts an early estimate of $100,000 to $300,000 on a Low or Moderate authorization under 20x against $500,000 to $2,000,000+ on the traditional path. Those are estimates from early pilot data, not observed invoices. 20x cost analysis
Section G. Nearest entries on the register
Comparable offerings
Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.
- Partos for Government
Partos Inc.
Initial Implementation, no impact level listed, Program path, 20x.
- Certivo Compliance Platform
Certivo, Inc.
Initial Implementation, no impact level listed, Program path, 20x.
- SunStone Artemis Platform
SunStone Secure, LLC
Initial Implementation, no impact level listed, Program path, 20x.
- Tarly Cowork
Pincus Technologies Inc
Initial Implementation, no impact level listed, Program path, 20x.
- ComplianceAide Government Cloud
ComplianceAid INC.
Initial Implementation, no impact level listed, Program path, 20x.
Section H. Description
As published on the marketplace
The provider's own description of the service, reproduced from the FedRAMP feed without edits.
Immuta's SaaS platform, the Immuta Data Security Platform, provides a number of capabilities that enable customers to govern and provision data access, automating how data is delivered to both human and non-human consumers while maintaining continuous compliance. These capabilities are managed through Immuta's web-based interface and Application Programming Interface (API). Authentication to Immuta's service is controlled via a variety of Single Sign-on (SSO) and directory systems maintained by the customer or a third party. Management of each customer's Immuta environment is split into a number of roles so that customers desiring a separation of duties for governance purposes can limit users to specific roles to achieve that goal. User attributes can be defined within the platform's identity manager or synced from an external identity management system. This functionality is central to implementing attribute-based access and control (ABAC) of data, which is a key capability of the platform. Users allowed to act under the application admin role may register metadata from their cloud data warehouse systems, such as Snowflake, Databricks, Starburst, Redshift, Synapse, and BigQuery, etc., with Immuta. Selected tables from these warehouses then appear as entries in Immuta's metadata catalog interface, where users can add documentation, discuss the data, and tag tables and columns. Tables, called Data Sources in Immuta, can further be grouped into Immuta Projects, which are a logical collection of Data Sources, users, documentation, and clearly defined purposes. Immuta Projects ensure that customers can use data in accordance with laws and regulations that require traceability to the legitimate reasons that sensitive data is used in the various distinct contexts that permeate each organization. Registered metadata is also analyzed by the platform's Sensitive Data Discovery functionality, which can determine if data in a column is in one of a number of categories, such as personally identifiable information (PII) or "PII First Name," that are commonly used to drive data access policies. Analysis of this data occurs completely in the customer's data platform; no data ever leaves back to Immuta. This information is used to tag data within Immuta. Additionally, for customers who have successfully cataloged data in other systems, this kind of information can be synced to Immuta from a variety of common external catalogs. As users, data, and their attributes are registered with Immuta, users are allowed to act under the Data Owner and Governance roles, and can use Immuta's natural language policy builder to apply access control policies to the data at the data set and row levels, and minimize access to data through Privacy Enhancing Technologies (PETs). Each Data Owner can manage such policies for the data they own. Users in the Governance role can manage policies at a global level. This global policy capability allows governors to review policies for compliance and set up policies that automatically impact new data and new users as they are added to the system. Based on these policies, Immuta connects to the customer cloud data warehouse and administers those policies into the data platform in question, keeping Immuta out of the data path but still enforcing policy. Users query data in the systems they are already using, but Immuta enforces their access based on the defined policies. Immuta also extends this policy-driven model to AI agents acting on behalf of users. When an agent requests data, Immuta evaluates the request in real time and provisions a temporary, scoped role in the underlying data platform - reflecting only the permissions relevant to that specific task. This access is automatically removed once the task is complete, so no standing privilege persists. Because the agent acts on behalf of a human user rather than as that user, Immuta maintains a dual-identity audit trail showing both the human who delegated the request and the agent that acted. Finally, Immuta provides robust auditing of actions taken within the platform to allow customers to document their data controls and have evidence for compliance purposes. For certain cloud warehouses, such as Databricks or Starburst, this examination extends to queries users perform in the source data systems. For others, Immuta logs and warehouse logs can easily produce an organization's complete compliance picture when combined in their existing log aggregation and analysis system. This audit trail extends to agent activity, distinguishing human actions, agent actions, and agent-on-behalf-of-user actions.
Next step
What the same authorization would cost you
The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.
Provenance and independence
Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.
GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.
FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.