Section 8.4 - Register entry
DOC-REF: FRC-MKT-FR1913470600
Palo Alto Networks Government Cloud Services
Palo Alto Networks, Inc. lists Palo Alto Networks Government Cloud Services on the FedRAMP Marketplace with the status FedRAMP Certified, at Moderate impact, on the Agency path under the Rev5 process. Package FR1913470600, read from the marketplace feed as of September 3, 2026.
Section A. Register entry
What the marketplace records
- FedRAMP package ID
- FR1913470600
- Cloud service provider
- Palo Alto Networks, Inc.
- Certification status
- FedRAMP Certified
- Impact level
- Moderate
- Certification class
- Class C (Moderate)
- Authorization path
- Agency
- Certification type
- Rev5
- Marketplace phase
- Ongoing Certification
- Deployment model
- Government Community Cloud
- Register snapshot
- September 3, 2026
- Service model
- SaaS
- Independent assessor
- Fortreum, LLC
- Certification date
- January 21, 2021
- Status date
- January 21, 2021
- Annual assessment
- October 9, 2011
- Agency authorizations
- 28
- Recorded reuses
- 82
- SAM.gov UEI
- KXQCTZ1GS851
- Dependent offerings
- 18
- Milestones on record
- 3
The marketplace carries Palo Alto Networks Government Cloud Services under package FR1913470600 with 20 recorded fields. Its certification date is January 21, 2021. Fortreum, LLC is named as the independent assessor, with an annual assessment date of October 9, 2011. 26 agencies are listed as having authorized it, among them Bonneville Power Administration, Commodity Futures Trading Commission, Defense Information Systems Agency and 23 more, and the feed records 82 reuses of the package. It is delivered as SaaS on a government community cloud. 18 other offerings on the register are listed as dependent on this one, among them Gen3 Data Ecosystems Platform, Electric Vehicle Infrastructure Platform for Government and Coupa Spend Management for Federal. Its SAM.gov unique entity identifier is KXQCTZ1GS851.
Section B. Milestones
3 entries in the marketplace event log
Most recent first, as recorded by FedRAMP.
| Date | Category | Recorded |
|---|---|---|
| January 21, 2021 | Status Change | Status changed from PMO Review to FedRAMP Certified |
| October 9, 2020 | Status Change | Status changed from Agency Review to FedRAMP In Process |
| November 7, 2019 | Status Change | Status set to Agency Authorization In Process |
Section C. Cost context
What reaching Moderate costs
Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.
Cost context
Budget for a Moderate authorization
Our published planning range for a provider pursuing Moderate. It is not a figure any listed provider has disclosed.
Read the FedRAMP Moderate cost guide / annual assessment cost / continuous monitoring cost
Path
Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost
Assessment and monitoring
An annual assessment date of October 9, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost
Section E. Agencies on the record
26 agencies listed against this package
As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.
- Bonneville Power Administration
- Commodity Futures Trading Commission
- Defense Information Systems Agency
- Defense Innovation Unit
- Department of Education
- Department of Energy
- Department of Health and Human Services
- Department of Transportation
- Department of Veterans Affairs
- FHFA Office of the Inspector General
- Farm Credit Administration
- Federal Aviation Administration
- Federal Deposit Insurance Corporation
- Federal Energy Regulatory Commission
- Federal Housing Finance Agency
- First Responder Network Authority
- Internal Revenue Service
- National Capital Planning Commission
- National Nuclear Security Administration / Nevada Field Office
- Nuclear Regulatory Commission
- Office of Personnel Management
- Strategic Petroleum Reserve
- U.S. International Development Finance Corporation
- U.S. Office of Special Counsel
- United States Census Bureau
- United States Patent and Trademark Office
Section F. Dependent offerings
18 listed offerings build on this package
From the marketplace's dependent products view. A provider that inherits controls from a package below it carries a narrower assessment boundary of its own, which is one of the larger levers on authorization cost.
- Gen3 Data Ecosystems Platform
- Electric Vehicle Infrastructure Platform for Government
- Coupa Spend Management for Federal
- GitLab Dedicated for Government
- ID.me Identity Gateway
- Informatica Intelligent Cloud Services (IICS)
- LabArchives for Government (LG)
- Manhattan Government Cloud
- Mathematica Cloud Support System
- Moveworks GovCloud
- Rubrik Security Cloud - Government (RSC-G)
- Somnoware
- On-Demand Security Testing Platform
- ThreatConnect For Government
- Varonis DatAdvantage Cloud
- Veracode Online Security Platform for Government
- Workday Government Cloud (WGC)
Inheritance is why boundary scope moves a budget more than headcount does. The hidden costs page sets out where scope creeps back in.
Section G. Nearest entries on the register
Comparable offerings
Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.
Palo Alto Networks, Inc. lists 4 offerings on the marketplace. The others are:
- ID.me Identity Gateway
ID.me
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified June 10, 2021.
- Geotab Telematics Platform Government (GTP Gov)
Geotab
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified July 21, 2020.
- The Data Cloud on AWS US East/West
Snowflake Inc.
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified July 2, 2020.
- Somnoware
Somnoware Healthcare Systems
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified December 6, 2021.
- Rescale Platform
Rescale
FedRAMP Certified, Moderate impact, Agency path, Rev5, certified January 31, 2022.
Section H. Description
As published on the marketplace
The provider's own description of the service, reproduced from the FedRAMP feed without edits.
Strata Network Security Platform Secure users, apps, and data anywhere- on-premises, in the cloud, or hybrid. Get complete Zero Trust network security to see and secure everything from your headquarters to branch offices and data centers, as well as your mobile workforce. Prisma Access - a Secure Access Service Edge (SASE) that provides scalable, cloud-delivered networking and security to branch offices and remote users. With Prisma Access, agencies are able to rapidly enable consistent, secure connectivity for remote locations and employees. Prisma SD-WAN - a product that provides deep application visibility, with Layer 7 intelligence for network policy creation and traffic engineering. It automates operations and problem avoidance using machine learning and data science methodologies. Prisma SD-WAN enables branch services such as networking and security to be delivered from the cloud, simplifying WAN management. ZTNA Connector - The Zero Trust Network Access (ZTNA) Connector lets you connect Prisma Access to your organization's private apps simply and securely. ZTNA Connector provides mobile users and users at branch locations access to your private apps using an automated secure tunnel. Because the ZTNA Connector sets up the tunnels automatically, you don't have to manually set up IPSec tunnels and routing to the data center or headquarters locations, public cloud locations, and partner networks where your private apps are located. Colo Connect - Colo-Connect builds on the Colo-based performance hub concept, offering high-bandwidth (up to 20 Gbps) private connections along with seamless Layer 2/3 connectivity to Prisma Access from existing performance hubs. Traffic Replication - We partnered with Google Cloud Platform (GCP) to enable Google Cloud Packet Mirroring outside the Prisma Access security processing node so it wouldn't interfere with the security inspection efficacy and overall performance of Prisma Access.Google Cloud Packet Mirroring clones the traffic and delivers a line-rate performance with zero impact on current operations. As with any GCP service, traffic cloning enables Prisma Access Traffic Replication to elastically manage the scale of traffic volume for any of the largest organizations. 5g SASE - Prisma SASE 5G extends comprehensive zero-trust security to enterprise 5G deployments. Prisma SASE 5G feature integrates zero-trust security with 5G networks, enabling service providers to offer comprehensive SASE services for 5G-connected devices without the complexity of agents or inline hardware. Explicit Proxy - Prisma Access provides a complete cloud Secure Web Gateway (SWG) capability, including an Explicit Proxy connection method based in the cloud. If your organization's existing network already uses explicit proxy and deploys PAC files on your client endpoints, you can smoothly migrate from legacy proxy-based SWG solutions to Prisma Access to secure mobile users' outbound internet traffic. You can also use an Explicit Proxy if you need to use a proxy for compliance purposes. Cloud Manager for Prisma Access - a cloud delivered solution used by customers to manage Prisma Access from Palo Alto Networks' Hub. Fawkes allows customers to quickly onboard branches and mobile users through an intuitive and function oriented user experience. Fawkes also provides configuration management of Prisma Access' security policies. Strata Logging Service (SLS, formerly CDL) - collects, normalizes, and integrates data from Palo Alto Networks products with public cloud scale. WildFire - an analysis and prevention engine for highly evasive zero-day exploits and malware. The cloud-based service employs a unique multi-technique approach combining dynamic and static analysis and innovative machine learning techniques to detect and prevent even the most evasive threats. It is a subscription service that works with the Palo Alto Networks Next Generation Firewalls (including VM-Series and CN-Series), Prisma Access, Prisma Cloud, Cortex XSIAM, and Cortex XDR. Advanced URL Filtering - Advanced URL Filtering is a comprehensive URL filtering solution that protects your network and users from web-based threats. Combining the capabilities of PAN-DB with a web security engine powered by machine learning, Advanced URL Filtering categorizes and blocks malicious URLs in real-time. With an Advanced URL Filtering license (or legacy URL filtering license), you can restrict access to websites and control user interactions with web content. For example, you can prevent users from accessing websites known to host malware or entering corporate credentials into websites in specific categories. SaaS Security (API, Inline, SSPM) - is an integrated CASB (Cloud Access Security Broker) solution that helps Security teams meet the challenges of protecting the growing availability of sanctioned and unsanctioned SaaS applications and maintaining compliance consistently in the cloud while stopping threats to sensitive information, users and resources. SaaS Security Inline helps discover and manage risks posed by unsanctioned SaaS applications while SaaS Security Posture Management (SSPM) helps detect and remediate misconfigured security settings in sanctioned SaaS applications through continuous monitoring. Inline DLP - serves as a data security service integrated with various Palo Alto Networks services (called channels) such as SaaS Security, Prisma Access, Prisma Cloud, and the Next Generation Firewall platform to provide data security at these various enforcement points. These channels send files to the DLP service via APIs, where DLP will scan the file, perform analysis to detect sensitive data in violation of customer policies in the file, and return this verdict and other data back to the channel. The channel then uses this information to take remedial action in order to protect sensitive data. Email DLP - Enterprise DLP prevents exfiltration of emails containing sensitive information with AI/ML powered data detections. For example, Enterprise DLP can prevent exfiltration of sensitive data over an outbound email sent from a salesperson within your organization to their personal email. ACE - a generic platform that enables the firewall or Panorama to download App-IDs from the cloud for applications that do not have specific predefined App-IDs from the Palo Alto Networks content releases. CIE - Identity-based security controls are a foundational requirement to achieve Zero Trust. Palo Alto Networks Cloud Identity Engine is an entirely new cloud-based architecture for identity-based security that can consistently authenticate and authorize your users, regardless of location and where user identity stores live - on-premises, in the cloud, or hybrid. As a result, security teams can effortlessly allow all users access to applications and data everywhere and quickly move toward a Zero Trust security posture. IoT Security - Protects your IoT attack surface with the industry's smartest IoT Security solution delivering ML-powered visibility, prevention, and zero-trust enforcement in a single platform. IoT Edge Cloud now included. Device Security - a unified, AI-first solution that provides comprehensive protection and monitoring across your entire attack surface. To achieve this, it discovers all connected devices, as well as identifies and mitigates hidden risks that would otherwise remain invisible. Prisma SD-WAN - a product that provides deep application visibility, with Layer 7 intelligence for network policy creation and traffic engineering. It automates operations and problem avoidance using machine learning and data science methodologies. Prisma SD-WAN enables branch services such as networking and security to be delivered from the cloud, simplifying WAN management. Strata® Cloud Manager (SCM) for Prisma Access - AI-powered unified solution for managing and operating the entire network security infrastructure. It transforms how organizations oversee their NGFW & SASE deployments, aggregating telemetry from every enforcement point to deliver actionable insights. By combining AI-driven intelligence, automated operations, and integrated threat intelligence, it helps security teams stay ahead of emerging risks, maintain optimal performance, and reduce operational costs. Strata Cloud Manager is available in Essentials and Pro (paid) tiers. Cloud Next-Generation Firewall (CNGFW) - Cloud NGFW is Palo Alto Networks ML-powered Next-Generation Firewall (NGFW) capability delivered as a fully managed cloud-native service by Palo Alto Networks on the Amazon Web Services (AWS) and Azure platforms. This deployment model combines the power of the Palo Alto NGFW with the ease of use. The Cloud NGFW service provides advanced application visibility and access control using Palo Alto Networks' App-ID and URL filtering technologies. It provides threat prevention and detection through cloud-delivered security services and threat prevention signatures. MSP for Prisma SASE - a set of two services (pa-passthru-api-service and pa-custom-api-service) that provide APIs to support the following functionality: Aggregate application, application usage, threats and URL metrics across tenants in a tenant hierarchy Constrain the list of tenants being aggregated to the list of tenants that are authorized for the user in question. AIOps - AIOps harnesses big data from operational appliances and has the unique ability to detect and respond to issues instantaneously. Using the power of ML, AIOps strategizes using the various forms of data it compiles to yield automated insights that work to refine and iterate continually. AIOps seeks to address a quickly evolving IT landscape using the convenience of machine learning, automation and big data. Remote Browser Isolation (RBI) - Fully isolate zero-day web attacks far away from local devices and browsers. Deliver superior browser isolation without sacrificing web performance with Palo Alto Network's RBI, which combines the latest isolation technologies with proprietary technologies and creates a no-code execution channel between users and web content. Advanced Threat Prevention (ATP) - Advanced Threat Prevention Powered by Precision AI defends your network against both commodity threats-which are pervasive but not sophisticated-and targeted, advanced threats perpetuated by organized cyber adversaries. Advanced Threat Prevention includes comprehensive exploit, malware, and command-and-control protection, and Palo Alto Networks frequently publishes updates that equip the firewall with the very latest threat intelligence. Prisma Access Browser (PAB) - The Prisma Access Secure Enterprise Browser (Prisma Access Browser) is a browser designed specifically for enterprise use and is fortified with security features to protect users and organizations against cyber threats like phishing, malware, eavesdropping, and data exfiltration. Prisma Access Browser is the only solution that secures both managed and unmanaged devices, through a natively integrated enterprise browser that extends protection to the devices by placing security in the browser. RBI (Remote Browser Isolation): RBI is an isolation solution that can isolate all malware, including zero-day attacks that result from browsing and web activity, away from your end users and your network. Natively integrated with Prisma Access, RBI allows you to easily apply isolation profiles to existing security policies. With isolation profiles, you can control what browser actions are permitted for your users. All traffic in isolation undergoes analysis and threat prevention provided by Cloud-Delivered Security Services such as Advanced Threat Prevention, Advanced WildFire, Advanced URL Filtering, DNS Security, and SaaS Security. App Services (Hub, API Gateway, Visualization & Reporting, Prisma Access Insights) ● API Gateway supports unified access to the open APIs of PANW SASE applications. Currently, API Gateway is used by Cloud Management Prisma Access, SD-WAN, Cortex Data Lake (CDL), and Prisma Access Insights customers. Working in conjunction with PANW Global IdP (Identity Provider), which provides authentication services, API Gateway provides authorization services for RESTful API and routing those APIs to multiple applications and regions. ● Prisma Access Insights is a comprehensive platform for global visibility and monitoring for the Prisma Access service. It continuously monitors the health and performance of your Prisma Access environment with Insights in the Prisma Access app. ● Visualization & Reporting is the security visualization and reporting product for network security use cases. It provides dashboards to end users to monitor and understand the security of their networks and how different security subscriptions from Palo Alto Networks are performing. Cortex Palo Alto Networks offers the industry's most comprehensive product portfolio for security operations, empowering organizations and agencies with best-in-class detection, investigation, automation, and response capabilities. Cortex XDR - a cloud-based service providing a prevention, detection and response platform that integrates network, endpoint, and cloud data to stop sophisticated attacks. Cortex XDR leverages logs, alerts, and information from Palo Alto Networks and third-party security products. It also enforces security policies on endpoints, preventing malware and data loss. Cortex XDR correlates security alerts and network logs with the endpoint processes that generated the alerts, allowing customers to investigate security alerts, as well as search for and remotely respond to threats. Cortex Xpanse - an active attack surface management solution that helps your organization discover, understand and respond to unknown risks in all internet-connected systems and services. Xpanse scans the entire internet automatically and continuously, discovering and indexing previously unknown risks, using supervised ML models to continuously map your attack surface and prioritize remediation efforts, while reducing MTTR with the help of built-in automated playbooks. Cortex XSIAM - a cloud-delivered, integrated SOC platform that unifies key functions, including EDR, XDR, SOAR, ASM, UEBA, TIP, and SIEM, consolidating multiple products into a single, integrated platform. XSIAM delivers an intelligent data foundation by integrating telemetry from any source, providing unified security operations across any hybrid IT architecture. Cortex XSOAR - a comprehensive security orchestration, automation, and response (SOAR) platform that unifies case management, automation, real-time collaboration, and threat intelligence management to serve security teams across the incident lifecycle. Cortex Cloud - a unified security platform that enhances application security, cloud posture management and runtime protection. It integrates AppSec, identity, data, cloud infrastructure, and workload security while providing a code-to-cloud-to-runtime-to-SOC approach. With a strong shift-left strategy, it enables proactive remediation using both in-house and third-party tools. The Cloud Detection and Response (CDR) capabilities leverage multiple data sources to deliver real-time threat detection, protection and automated response. Prisma Cloud Enterprise (SaaS) - We secure applications from code to cloud, enabling security and DevOps teams to collaborate effectively and accelerate secure cloud-native application development and deployment. Prisma Cloud - a cloud-native security platform that consistently provides comprehensive visibility into misconfiguration and over-permissive roles, with threat detection and compliance assurance across multi-cloud environments. ● CSPM ● Agentless Workload Security ● CIEM ● API Visibility ● Secret Security ● SCA ● IaC Security Prisma Cloud Compute (Delivered via Prisma Cloud) - a cloud-native platform that delivers cloud workload protection. Prisma Cloud Compute provides holistic protection across hosts, containers, and serverless deployments in any cloud, throughout the software lifecycle. Prisma Cloud Compute protects all workloads regardless of their underlying compute technology or the cloud in which they run. In addition, it provides Web Application and API Security (WAAS) for any cloud native architecture. ● Cloud Workload Protection ● Web Application API Security
Next step
What the same authorization would cost you
The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.
Provenance and independence
Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.
GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.
FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.