DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-FR2605341343

IntelliGRC

IntelliGRC, Inc. lists IntelliGRC on the FedRAMP Marketplace with the status FedRAMP Certified, at Low impact, on the Program path under the 20x process. Package FR2605341343, read from the marketplace feed as of September 3, 2026.

FedRAMP Certified20xProgram pathSmall business

Section A. Register entry

What the marketplace records

FedRAMP package ID
FR2605341343
Cloud service provider
IntelliGRC, Inc.
Certification status
FedRAMP Certified
Impact level
Low
Certification class
Class B (Low)
Authorization path
Program
Certification type
20x
Marketplace phase
Ongoing Certification
Deployment model
Public Cloud
Register snapshot
September 3, 2026
Service model
SaaS
Certification date
December 5, 2025
Status date
December 5, 2025
Annual assessment
December 12, 2011
Agency authorizations
1
Business categories
Cybersecurity & Risk Management, Governance, Risk, and Compliance (GRC)
Small business
Flagged on the marketplace record
Milestones on record
3

The marketplace carries IntelliGRC under package FR2605341343 with 19 recorded fields. Its certification date is December 5, 2025. A-LIGN Compliance and Security, Inc. dba A-LIGN is named as the independent assessor, with an annual assessment date of December 12, 2011. 1 agency is listed as having authorized it, among them Federal Risk and Authorization Management Program. It is delivered as SaaS on a public cloud, filed under 2 business categories including Cybersecurity & Risk Management and Governance, Risk, and Compliance (GRC). IntelliGRC, Inc. is flagged as a small business on the record.

Section B. Milestones

3 entries in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
December 5, 2025Status ChangeStatus changed from Final Program Review to FedRAMP Certified
November 24, 2025Status ChangeStatus changed from Initial Program Review to FedRAMP In Process
November 24, 2025Status ChangeStatus set to FedRAMP In Process

Section C. Cost context

What reaching Low costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a Low authorization

Initial authorization$350,000 to $500,000
Continuous monitoring$60,000 to $120,000 a year
Typical timeline9 to 12 months
Control baselineup to 125 controls

Our published planning range for a provider pursuing Low. It is not a figure any listed provider has disclosed.

Read the FedRAMP Low cost guide / continuous monitoring cost

Path

The marketplace records 80 offerings on the Program path, 76 of them 20x. Our 20x page covers what that model is estimated to cost. FedRAMP 20x cost analysis

20x

This package is on the 20x track. Our 20x page puts an early estimate of $100,000 to $300,000 on a Low or Moderate authorization under 20x against $500,000 to $2,000,000+ on the traditional path. Those are estimates from early pilot data, not observed invoices. 20x cost analysis

Section E. Agencies on the record

1 agency listed against this package

As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.

  • Federal Risk and Authorization Management Program

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

IntelliGRC, Inc. lists 2 offerings on the marketplace. The others are:

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

IntelliGRC is an AI-powered, all US-based and developed FedRAMP-aligned multi-tenant Governance, Risk, and Compliance (GRC) SaaS platform purpose-built for Service Providers (MSPs/MSSPs), cybersecurity consultants, and regulated organizations that must achieve, manage and maintain audit-ready compliance at scale. The platform combines asset-centric scoping, context-aware control mapping, intelligent automation, bidirectional cross tenant shared implementations, and practitioner-trained AI features to streamline assessments, evidence collection, ongoing monitoring, and compliance program management across multiple frameworks. Designed with deep operational expertise from cybersecurity assessors and compliance practitioners, IntelliGRC enables service providers to deliver consistent, repeatable, and high-caliber compliance outcomes for their customers while reducing manual effort and SME dependency. IntelliGRC is widely used by organizations across the Defense Industrial Base (DIB), research institutions, and service providers supporting CMMC, NIST SP 800-171, NIST CSF, HIPAA, ISO 27001, SOC 2, and FedRAMP-related requirements. Used in over 30+ CMMC L2 Certification Assessments. A fully multi-tenant architecture allows providers to centrally manage multiple customer environments, distribute governance content, standardize workflows, and operationalize compliance-as-a-service (GRCaaS). IntelliGRC's integrated AI assistant-trained on IntelliGRC methodologies and cybersecurity compliance best practices-supports evidence analysis, control interpretation, gap evaluation, and documentation generation. Our mission is to make authentic, tangible, actionable, high-caliber, and scalable cybersecurity compliance accessible.

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28