DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-F1301101857

OpenText™ Core Application Security (Fortify On Demand)

OpenText lists OpenText™ Core Application Security (Fortify On Demand) on the FedRAMP Marketplace with the status FedRAMP Certified, at Moderate impact, on the JAB path under the Rev5 process. Package F1301101857, read from the marketplace feed as of September 3, 2026.

FedRAMP CertifiedRev5JAB path

Section A. Register entry

What the marketplace records

FedRAMP package ID
F1301101857
Cloud service provider
OpenText
Certification status
FedRAMP Certified
Impact level
Moderate
Certification class
Class C (Moderate)
Authorization path
JAB
Certification type
Rev5
Marketplace phase
Ongoing Certification
Deployment model
Government Community Cloud
Register snapshot
September 3, 2026
Service model
SaaS
Independent assessor
Lunarline, Inc.
Certification date
February 4, 2015
Status date
February 4, 2015
Annual assessment
October 1, 2011
Agency authorizations
7
Recorded reuses
10
Dependent offerings
1
Milestones on record
2

The marketplace carries OpenText™ Core Application Security (Fortify On Demand) under package F1301101857 with 19 recorded fields. Its certification date is February 4, 2015. Lunarline, Inc. is named as the independent assessor, with an annual assessment date of October 1, 2011. 7 agencies are listed as having authorized it, among them Bureau of Labor Statistics, Department of Homeland Security, Federal Aviation Administration and 4 more, and the feed records 10 reuses of the package. It is delivered as SaaS on a government community cloud. 1 other offering on the register is listed as dependent on this one, among them Axonius Asset Cloud.

Section B. Milestones

2 entries in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
February 4, 2015Status ChangeStatus changed from JAB Review to FedRAMP Certified
February 7, 2014Status ChangeStatus set to FedRAMP In Process

Section C. Cost context

What reaching Moderate costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a Moderate authorization

Initial authorization$800,000 to $2,000,000
Continuous monitoring$150,000 to $350,000 a year
Typical timeline12 to 18 months
Control baseline325+ controls
Annual assessment$90,000 to $260,000 a year

Our published planning range for a provider pursuing Moderate. It is not a figure any listed provider has disclosed.

Read the FedRAMP Moderate cost guide / annual assessment cost / continuous monitoring cost

Path

The marketplace lists 53 offerings against the JAB path. Our JAB vs Agency page records that the JAB P-ATO path was retired in 2024 and that Agency Authorization is now the single traditional route, at $800,000 to $2,000,000 over 12 to 18 months. JAB vs Agency ATO cost

Assessment and monitoring

An annual assessment date of October 1, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost

Section E. Agencies on the record

7 agencies listed against this package

As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.

  • Bureau of Labor Statistics
  • Department of Homeland Security
  • Federal Aviation Administration
  • National Telecommunications and Information Administration
  • State Office of the Inspector General
  • United States Air Force
  • United States Army

Section F. Dependent offerings

1 listed offering builds on this package

From the marketplace's dependent products view. A provider that inherits controls from a package below it carries a narrower assessment boundary of its own, which is one of the larger levers on authorization cost.

Inheritance is why boundary scope moves a budget more than headcount does. The hidden costs page sets out where scope creeps back in.

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

The OpenText™ Core Application Security (FoD) for US Public Sector performs security assessments of application code and web site/web services testing without any software to install or manage. Static Code Scanning of code such as Java, .NET and other major programming languages for security defects are performed in the FoD System at the code layer followed by an audit review by a OpenText Fortify Static auditor. Dynamic Web Site and Web Services testing use OpenText Fortify's WebInspect software as the scan engine, followed by a review from a OpenText Fortify Dynamic tester.

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28