DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-FR2629068833

Immuta Federal

Immuta lists Immuta Federal on the FedRAMP Marketplace with the status Initial Implementation, at no impact level listed, on the Program path under the 20x process. Package FR2629068833, read from the marketplace feed as of September 3, 2026.

Initial Implementation20xProgram path

Section A. Register entry

What the marketplace records

FedRAMP package ID
FR2629068833
Cloud service provider
Immuta
Certification status
Initial Implementation
Impact level
Not listed
Certification class
Class C (Moderate)
Authorization path
Program
Certification type
20x
Marketplace phase
Initial Implementation
Deployment model
Government Community Cloud
Register snapshot
September 3, 2026
Service model
SaaS
Independent assessor
Fortreum
Status date
July 22, 2026
Business categories
Data Management, Governance, Risk, and Compliance (GRC)
SAM.gov UEI
47-1877648
Milestones on record
1

The marketplace carries Immuta Federal under package FR2629068833 with 16 recorded fields. Its current status was set on July 22, 2026. Fortreum is named as the independent assessor. No agency authorizations are listed against it in the current feed. It is delivered as SaaS on a government community cloud, filed under 2 business categories including Data Management and Governance, Risk, and Compliance (GRC). Its SAM.gov unique entity identifier is 47-1877648.

Section B. Milestones

1 entry in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
July 22, 2026Status ChangeStatus set to Initial Implementation

Section C. Cost context

What reaching this stage costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

No range published for this level

The marketplace lists no impact level here, so no cost range is quoted. Our impact level reference sets out what each baseline costs to reach.

Read the impact level reference / continuous monitoring cost

Path

The marketplace records 80 offerings on the Program path, 76 of them 20x. Our 20x page covers what that model is estimated to cost. FedRAMP 20x cost analysis

20x

This package is on the 20x track. Our 20x page puts an early estimate of $100,000 to $300,000 on a Low or Moderate authorization under 20x against $500,000 to $2,000,000+ on the traditional path. Those are estimates from early pilot data, not observed invoices. 20x cost analysis

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

Immuta's SaaS platform, the Immuta Data Security Platform, provides a number of capabilities that enable customers to govern and provision data access, automating how data is delivered to both human and non-human consumers while maintaining continuous compliance. These capabilities are managed through Immuta's web-based interface and Application Programming Interface (API). Authentication to Immuta's service is controlled via a variety of Single Sign-on (SSO) and directory systems maintained by the customer or a third party. Management of each customer's Immuta environment is split into a number of roles so that customers desiring a separation of duties for governance purposes can limit users to specific roles to achieve that goal. User attributes can be defined within the platform's identity manager or synced from an external identity management system. This functionality is central to implementing attribute-based access and control (ABAC) of data, which is a key capability of the platform. Users allowed to act under the application admin role may register metadata from their cloud data warehouse systems, such as Snowflake, Databricks, Starburst, Redshift, Synapse, and BigQuery, etc., with Immuta. Selected tables from these warehouses then appear as entries in Immuta's metadata catalog interface, where users can add documentation, discuss the data, and tag tables and columns. Tables, called Data Sources in Immuta, can further be grouped into Immuta Projects, which are a logical collection of Data Sources, users, documentation, and clearly defined purposes. Immuta Projects ensure that customers can use data in accordance with laws and regulations that require traceability to the legitimate reasons that sensitive data is used in the various distinct contexts that permeate each organization. Registered metadata is also analyzed by the platform's Sensitive Data Discovery functionality, which can determine if data in a column is in one of a number of categories, such as personally identifiable information (PII) or "PII First Name," that are commonly used to drive data access policies. Analysis of this data occurs completely in the customer's data platform; no data ever leaves back to Immuta. This information is used to tag data within Immuta. Additionally, for customers who have successfully cataloged data in other systems, this kind of information can be synced to Immuta from a variety of common external catalogs. As users, data, and their attributes are registered with Immuta, users are allowed to act under the Data Owner and Governance roles, and can use Immuta's natural language policy builder to apply access control policies to the data at the data set and row levels, and minimize access to data through Privacy Enhancing Technologies (PETs). Each Data Owner can manage such policies for the data they own. Users in the Governance role can manage policies at a global level. This global policy capability allows governors to review policies for compliance and set up policies that automatically impact new data and new users as they are added to the system. Based on these policies, Immuta connects to the customer cloud data warehouse and administers those policies into the data platform in question, keeping Immuta out of the data path but still enforcing policy. Users query data in the systems they are already using, but Immuta enforces their access based on the defined policies. Immuta also extends this policy-driven model to AI agents acting on behalf of users. When an agent requests data, Immuta evaluates the request in real time and provisions a temporary, scoped role in the underlying data platform - reflecting only the permissions relevant to that specific task. This access is automatically removed once the task is complete, so no standing privilege persists. Because the agent acts on behalf of a human user rather than as that user, Immuta maintains a dual-identity audit trail showing both the human who delegated the request and the agent that acted. Finally, Immuta provides robust auditing of actions taken within the platform to allow customers to document their data controls and have evidence for compliance purposes. For certain cloud warehouses, such as Databricks or Starburst, this examination extends to queries users perform in the source data systems. For others, Immuta logs and warehouse logs can easily produce an organization's complete compliance picture when combined in their existing log aggregation and analysis system. This audit trail extends to agent activity, distinguishing human actions, agent actions, and agent-on-behalf-of-user actions.

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28