Section 8.4 - Register entry
DOC-REF: FRC-MKT-FR2231052341
Qualys Government Platform
Qualys, Inc. lists Qualys Government Platform on the FedRAMP Marketplace with the status FedRAMP Certified, at High impact, on the Agency path under the Rev5 process. Package FR2231052341, read from the marketplace feed as of September 3, 2026.
Section A. Register entry
What the marketplace records
- FedRAMP package ID
- FR2231052341
- Cloud service provider
- Qualys, Inc.
- Certification status
- FedRAMP Certified
- Impact level
- High
- Certification class
- Class D (High)
- Authorization path
- Agency
- Certification type
- Rev5
- Marketplace phase
- Ongoing Certification
- Deployment model
- Public Cloud
- Register snapshot
- September 3, 2026
- Service model
- SaaS
- Independent assessor
- Coalfire Systems, Inc.
- Sponsoring agency
- Drug Enforcement Administration
- Certification date
- August 14, 2025
- Status date
- August 14, 2025
- FedRAMP Ready date
- January 19, 2023
- Annual assessment
- July 30, 2011
- Agency authorizations
- 2
- Recorded reuses
- 3
- Business categories
- Cybersecurity & Risk Management
- Dependent offerings
- 2
- Milestones on record
- 4
The marketplace carries Qualys Government Platform under package FR2231052341 with 22 recorded fields. Its certification date is August 14, 2025, and a FedRAMP Ready date of January 19, 2023. Coalfire Systems, Inc. is named as the independent assessor, with an annual assessment date of July 30, 2011. Drug Enforcement Administration is recorded as the sponsoring agency. 2 agencies are listed as having authorized it, among them Consumer Product Safety Commission and Drug Enforcement Administration, and the feed records 3 reuses of the package. It is delivered as SaaS on a public cloud, filed under 1 business categories including Cybersecurity & Risk Management. 2 other offerings on the register are listed as dependent on this one, among them AutoRABIT for Public Sector - CodeScan, Guard, & ARMOR and EY Grants Accelerator.
Section B. Milestones
4 entries in the marketplace event log
Most recent first, as recorded by FedRAMP.
| Date | Category | Recorded |
|---|---|---|
| August 14, 2025 | Status Change | Status changed from PMO Review to FedRAMP Certified |
| July 31, 2025 | Status Change | Status changed from Agency Review to FedRAMP In Process |
| March 7, 2025 | Status Change | Status changed from FedRAMP Ready to Agency Authorization In Process |
| January 19, 2023 | Status Change | Status set to Legacy FedRAMP Ready |
Section C. Cost context
What reaching High costs
Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.
Cost context
Budget for a High authorization
Our published planning range for a provider pursuing High. It is not a figure any listed provider has disclosed.
Read the FedRAMP High cost guide / annual assessment cost / continuous monitoring cost
Path
Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost
Assessment and monitoring
An annual assessment date of July 30, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost
Section E. Agencies on the record
2 agencies listed against this package
As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.
- Consumer Product Safety Commission
- Drug Enforcement Administration
Section F. Dependent offerings
2 listed offerings build on this package
From the marketplace's dependent products view. A provider that inherits controls from a package below it carries a narrower assessment boundary of its own, which is one of the larger levers on authorization cost.
Inheritance is why boundary scope moves a budget more than headcount does. The hidden costs page sets out where scope creeps back in.
Section G. Nearest entries on the register
Comparable offerings
Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.
- IBM Federal ATOM
IBM
FedRAMP Certified, High impact, Agency path, Rev5, certified November 13, 2025.
- Ark.ai
Govini
FedRAMP Certified, High impact, Agency path, Rev5, certified April 29, 2025.
- Knox Systems FedRAMP High Managed Platform
Knox Systems
FedRAMP Certified, High impact, Agency path, Rev5, certified March 30, 2026.
- Riverbed Platform for Government (RP4G)
Riverbed Technology
FedRAMP Certified, High impact, Agency path, Rev5, certified May 19, 2026.
- DSS Health Cloud (DSSHC)
Document Storage Systems, Inc. (DSS, Inc.)
FedRAMP Certified, High impact, Agency path, Rev5, certified July 27, 2026.
Section H. Description
As published on the marketplace
The provider's own description of the service, reproduced from the FedRAMP feed without edits.
Qualys Government Platform (QGP) consists of a suite of Information Technology (IT) security and compliance solutions delivered via a SaaS deployment model that leverages a highly scalable multi-tenant cloud infrastructure. The below services are part of the QGP platform - Vulnerability Management, Detection, and Response (VMDR) service enables customers to discover, assess, prioritize, and patch critical vulnerabilities and misconfigurations in near real-time and across your global hybrid-IT landscape all-in-one subscription. Policy Compliance (PC) service provides the ability to run compliance scans and create compliance reports on hosts (IP addresses) that have been added to the Policy Compliance account. File Integrity Monitoring (FIM) service enables monitoring critical files, directories, and registry paths for changes in near real-time, and helps adhere to compliance mandates such as FedRAMP. Container Security (CS) service provides discovery, tracking, and continuously protecting container environments. Addresses vulnerability management for images and containers in their DevOps pipeline and deployments across cloud and on-premises environments. Certificate View (CertView) service provides a comprehensive view of all the SSL/TLS certificates across the enterprise and cloud-hosted assets. CyberSecurity Asset Management (CSAM) service continuously gathers information on all assets, listing systems and hardware details, running services, open ports, installed software and user accounts. Asset discovery and inventory collection is done through a combination of Qualys Sensors, which together can collect comprehensive data from across on-premises or cloud infrastructure as well as remote endpoints. Web Application Scanning (WAS) service enables organisation's to assess, track and remediate web application vulnerabilities to keep their web applications secure. Patch Management (PM) service is used to patch and apply post-patch configuration changes to operating systems, mobile devices, and 3rd-party applications from a large variety of vendors, all from a central dashboard.
Next step
What the same authorization would cost you
The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.
Provenance and independence
Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.
GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.
FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.