Section 8.4 - Register entry
DOC-REF: FRC-MKT-FR2614247985
Ironclad CLM
Ironclad Inc. lists Ironclad CLM on the FedRAMP Marketplace with the status Legacy FedRAMP Ready, at Moderate impact, on the Agency path under the Rev5 process. Package FR2614247985, read from the marketplace feed as of September 3, 2026.
Section A. Register entry
What the marketplace records
- FedRAMP package ID
- FR2614247985
- Cloud service provider
- Ironclad Inc.
- Certification status
- Legacy FedRAMP Ready
- Impact level
- Moderate
- Certification class
- Class C (Moderate)
- Authorization path
- Agency
- Certification type
- Rev5
- Marketplace phase
- Legacy FedRAMP Ready
- Deployment model
- Public Cloud
- Register snapshot
- September 3, 2026
- Service model
- SaaS
- Independent assessor
- Tevora Business Solutions, Inc.
- Status date
- February 25, 2026
- FedRAMP Ready date
- February 25, 2026
- Business categories
- Collaboration, Legal & Policy
- Milestones on record
- 1
The marketplace carries Ironclad CLM under package FR2614247985 with 16 recorded fields. Its current status was set on February 25, 2026, and a FedRAMP Ready date of February 25, 2026. Tevora Business Solutions, Inc. is named as the independent assessor. No agency authorizations are listed against it in the current feed. It is delivered as SaaS on a public cloud, filed under 2 business categories including Collaboration and Legal & Policy.
Section B. Milestones
1 entry in the marketplace event log
Most recent first, as recorded by FedRAMP.
| Date | Category | Recorded |
|---|---|---|
| February 25, 2026 | Status Change | Status set to Legacy FedRAMP Ready |
Section C. Cost context
What reaching Moderate costs
Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.
Cost context
Budget for a Moderate authorization
Our published planning range for a provider pursuing Moderate. It is not a figure any listed provider has disclosed.
Read the FedRAMP Moderate cost guide / annual assessment cost / continuous monitoring cost
Path
Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost
Assessment and monitoring
No annual assessment date is on the record. Assessment recurs annually for as long as a package stays listed. Annual assessment cost / continuous monitoring cost
Section G. Nearest entries on the register
Comparable offerings
Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.
- Icertis Contract Intelligence (ICI) for Government
Icertis Inc.
Legacy FedRAMP Ready, Moderate impact, Agency path, Rev5.
- Federal ZenGRC
Steel Patriot Partners
Legacy FedRAMP Ready, Moderate impact, Agency path, Rev5.
- TechnoMile GovCloud Platform
TechnoMile
Legacy FedRAMP Ready, Moderate impact, Agency path, Rev5.
- VisibleThread
VisibleThread
Legacy FedRAMP Ready, Moderate impact, Agency path, Rev5.
- Valid Eval
Valid Evaluation, Inc.
Legacy FedRAMP Ready, Moderate impact, Agency path, Rev5.
Section H. Description
As published on the marketplace
The provider's own description of the service, reproduced from the FedRAMP feed without edits.
An authorization boundary provides a diagrammatic illustration of a CSO's internal services, components, and other devices, along with connections to external services and systems. Please note that external services include external cloud services that are not FedRAMP Authorized, corporate shared services, and the external entities to which the system must connect to receive updates for products installed within the system boundary. An authorization boundary accounts for all federal information, data, and metadata that flow through a CSO. If the CSO has strong configuration management and change management built into the system development life cycle, the development environment can be outside the CSO boundary. This means that there is a 3PAO validated, reproducible and effective way to make service changes without impacting the production environment. The authorization boundary diagram displays all in-scope system components for the Ironclad FedRAMP environment and is depicted with a prominent red border. All components outside of the authorization boundary are shown externally to the red border. The authorization boundary encompasses the Ironclad application and supporting infrastructure hosted entirely within GCP in the us-central1 region. All components depicted within the boundary directly support the operation, security, monitoring, and administration of the CLM system. Within the authorization boundary, the FedRAMP environment consists of customer-facing application services, internal application services, and data storage components deployed on GCP. Application components communicate with one another using Google-managed networking services and all internal data flows are encrypted in transit using TLS 1.2 or higher. Data at rest within the authorization boundary is encrypted using customer-specific encryption keys and uses FIPS 140-2-validated cryptographic modules or higher where available. Ingress and egress to the authorization boundary are controlled through a load balancer and WAF that provide a single logical entry point for external connections. The WAF is configured to restrict and allow traffic based on approved ports, protocols, and services defined in the PPSM list. Network traffic entering or leaving the environment traverses these boundary protection mechanisms, and all external communications are encrypted in transit using TLS 1.2 or higher. Development and test environments are depicted and logically separated from the production environment. Access to development and test environments is restricted to authorized Ironclad personnel. Backup storage is provided through Google-managed backup services within the authorized environment and is depicted on the diagram. Backup data is encrypted at rest and in transit using FIPS-validated cryptographic modules.
Next step
What the same authorization would cost you
The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.
Provenance and independence
Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.
GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.
FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.