DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-FR2618648262

Midwatch

Defense Cybersecurity Group lists Midwatch on the FedRAMP Marketplace with the status Legacy FedRAMP Ready, at Moderate impact, on the Agency path under the Rev5 process. Package FR2618648262, read from the marketplace feed as of September 3, 2026.

Legacy FedRAMP ReadyRev5Agency pathSmall business

Section A. Register entry

What the marketplace records

FedRAMP package ID
FR2618648262
Cloud service provider
Defense Cybersecurity Group
Certification status
Legacy FedRAMP Ready
Impact level
Moderate
Certification class
Class C (Moderate)
Authorization path
Agency
Certification type
Rev5
Marketplace phase
Legacy FedRAMP Ready
Deployment model
Government Community Cloud
Register snapshot
September 3, 2026
Service model
IaaS, SaaS
Independent assessor
Coalfire Systems, Inc.
Status date
April 16, 2026
FedRAMP Ready date
April 16, 2026
Business categories
Collaboration, Communication, Cybersecurity & Risk Management, Data Management, Design & Multimedia, Development Tools, Mobile Device Management (MDM), Operations Management, Research, Storage
SAM.gov UEI
X8M3VQX188Y8
Small business
Flagged on the marketplace record
Milestones on record
1

The marketplace carries Midwatch under package FR2618648262 with 18 recorded fields. Its current status was set on April 16, 2026, and a FedRAMP Ready date of April 16, 2026. Coalfire Systems, Inc. is named as the independent assessor. No agency authorizations are listed against it in the current feed. It is delivered as IaaS and SaaS on a government community cloud, filed under 10 business categories including Collaboration, Communication, Cybersecurity & Risk Management and 7 more. Its SAM.gov unique entity identifier is X8M3VQX188Y8. Defense Cybersecurity Group is flagged as a small business on the record.

Section B. Milestones

1 entry in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
April 16, 2026Status ChangeStatus set to Legacy FedRAMP Ready

Section C. Cost context

What reaching Moderate costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a Moderate authorization

Initial authorization$800,000 to $2,000,000
Continuous monitoring$150,000 to $350,000 a year
Typical timeline12 to 18 months
Control baseline325+ controls
Annual assessment$90,000 to $260,000 a year

Our published planning range for a provider pursuing Moderate. It is not a figure any listed provider has disclosed.

Read the FedRAMP Moderate cost guide / annual assessment cost / continuous monitoring cost

Path

Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost

Assessment and monitoring

No annual assessment date is on the record. Assessment recurs annually for as long as a package stays listed. Annual assessment cost / continuous monitoring cost

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

Midwatch is a secure enclave engineered for the protection of Controlled Unclassified Information (CUI). It provides Federal Agencies and the Defense Industrial Base (DIB) with a secure environment to handle and share sensitive data requiring moderate security controls. Through the use of Virtual Desktop Infrastructure (VDI), Midwatch ensures strict logical separation between secure workloads and an organization's broader enterprise information systems. Midwatch enables secure, high-performance collaboration across several critical workflows, including: Sensitive Data Collaboration: Secure co-authoring and collaboration on sensitive information and complex documentation stacks. Advanced Engineering: Specialized support for CAD workflows and AI/ML GPU-accelerated workloads. Software Engineering: Secure Software Development and DevSecOps via an integrated Gitflow platform, implemented in alignment with the Secure Software Development Framework (SSDF). Operational Management: Integrated project management and secure task orchestration. Remote Device Management: Midwatch ViPR provides a secure gateway between the VDI infrastructure and physical office or workshop floors, facilitating controlled and audited file transfers to engineering peripheral devices. The Midwatch authorization boundary consists of a DevSecOps platform, VDI infrastructure, Midwatch ViPR remote access services, workflow automation, and vulnerability management tools, all hosted within a dedicated cloud organization. The environment is hardened through a segmented VPC architecture with Google Cloud Armor edge protection, the implementation of a Zero Trust Network Architecture (ZTNA) for all access requests, and robust data protection featuring centralized logging and Customer-Managed Encryption Keys (CMEK). Midwatch is deployed as a government-community cloud within the Google Cloud Platform (GCP) using US-only data centers. The system utilizes a microservices-based architecture powered by Docker and K3s/K8s/GKE Autopilot.

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28