Section 8.4 - Register entry
DOC-REF: FRC-MKT-FR2214150164
Quzara Cybertorch (SOC-as-a-Service)
Quzara, LLC. lists Quzara Cybertorch (SOC-as-a-Service) on the FedRAMP Marketplace with the status FedRAMP Certified, at High impact, on the Agency path under the Rev5 process. Package FR2214150164, read from the marketplace feed as of September 3, 2026.
Section A. Register entry
What the marketplace records
- FedRAMP package ID
- FR2214150164
- Cloud service provider
- Quzara, LLC.
- Certification status
- FedRAMP Certified
- Impact level
- High
- Certification class
- Class D (High)
- Authorization path
- Agency
- Certification type
- Rev5
- Marketplace phase
- Ongoing Certification
- Deployment model
- Government Community Cloud
- Register snapshot
- September 3, 2026
- Service model
- SaaS
- Independent assessor
- Schellman Compliance, LLC
- Certification date
- November 20, 2025
- Status date
- November 20, 2025
- FedRAMP Ready date
- April 4, 2023
- Annual assessment
- October 27, 2011
- Agency authorizations
- 1
- Business categories
- Analytics, Cybersecurity & Risk Management, Data Management, Operations Management
- Small business
- Flagged on the marketplace record
- Milestones on record
- 4
The marketplace carries Quzara Cybertorch (SOC-as-a-Service) under package FR2214150164 with 20 recorded fields. Its certification date is November 20, 2025, and a FedRAMP Ready date of April 4, 2023. Schellman Compliance, LLC is named as the independent assessor, with an annual assessment date of October 27, 2011. 1 agency is listed as having authorized it, among them Department of the Treasury. It is delivered as SaaS on a government community cloud, filed under 4 business categories including Analytics, Cybersecurity & Risk Management, Data Management and 1 more. Quzara, LLC. is flagged as a small business on the record.
Section B. Milestones
4 entries in the marketplace event log
Most recent first, as recorded by FedRAMP.
| Date | Category | Recorded |
|---|---|---|
| November 20, 2025 | Status Change | Status changed from PMO Review to FedRAMP Certified |
| October 27, 2025 | Status Change | Status changed from Agency Review to FedRAMP In Process |
| June 12, 2025 | Status Change | Status changed from FedRAMP Ready to Agency Authorization In Process |
| April 4, 2023 | Status Change | Status set to Legacy FedRAMP Ready |
Section C. Cost context
What reaching High costs
Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.
Cost context
Budget for a High authorization
Our published planning range for a provider pursuing High. It is not a figure any listed provider has disclosed.
Read the FedRAMP High cost guide / annual assessment cost / continuous monitoring cost
Path
Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost
Assessment and monitoring
An annual assessment date of October 27, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost
Section E. Agencies on the record
1 agency listed against this package
As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.
- Department of the Treasury
Section G. Nearest entries on the register
Comparable offerings
Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.
- Datadog for Government
Datadog, Inc.
FedRAMP Certified, High impact, Agency path, Rev5, certified May 5, 2026.
- Aqua Platform for Government
Aqua Security Software Inc.
FedRAMP Certified, High impact, Agency path, Rev5, certified March 31, 2025.
- Cloudflare for Government - High
Cloudflare
FedRAMP Certified, High impact, Agency path, Rev5, certified August 6, 2026.
- Palantir Federal Cloud Service
Palantir Technologies Inc.
FedRAMP Certified, High impact, Agency path, Rev5, certified November 19, 2024.
- Palantir Federal Cloud Service - Supporting Services (PFCS-SS)
Palantir Technologies
FedRAMP Certified, High impact, Agency path, Rev5, certified November 19, 2024.
Section H. Description
As published on the marketplace
The provider's own description of the service, reproduced from the FedRAMP feed without edits.
Cybertorch™ is a FedRAMP High Authorized, cloud-native security platform specializing in Sovereign Security Operations and Incident Response for the federal mission. Built and operated by U.S.-based cleared personnel, Cybertorch combines telemetry from Microsoft security, vulnerability management, and infrastructure logs with AI-assisted analytics to unify threat detection, response, and continuous compliance support for mission-critical workloads across cloud, hybrid, and on-premises environments. Core Service Components Managed Security Services 1. Managed Extended Detection & Response (MXDR) Provides 24x7x365 monitoring, investigation, and response across cloud, hybrid, and on-premises workloads. MXDR is operated by cleared U.S. analysts and uses correlation, behavioral analytics, and AI-assisted triage to link Endpoint Detection and Response (EDR), identity, email, and cloud telemetry and rapidly identify and contain advanced threats. 2. Managed Microsoft Security Services End-to-end deployment, configuration, and 24x7 management of Microsoft security capabilities, including EDR and XDR, across Commercial, GCC, and GCC High tenants. Services include tuning, alert triage, incident handling support, and alignment with agency-specific security and compliance requirements, with AI-informed detections and policies incorporated where appropriate. 3. Managed Vulnerability Management Expert-driven vulnerability management services leveraging FedRAMP-authorized Tenable solutions. Cybertorch delivers Tenable-based high managed services, including scan strategy design, continuous assessments, AI-assisted risk scoring and prioritization, remediation guidance, and integration of vulnerability data into SOC workflows and executive reporting. 4. Curated Threat Intelligence Actionable, curated threat intelligence sourced from government, commercial, and internal hunting activities. SOC analysts incorporate this intelligence into detections, investigations, and proactive threat hunting, using AI-supported enrichment and pattern analysis to track evolving campaigns, techniques, and sector-relevant threats. Continuous Assurance Module 1. The Continuous Assurance Module helps agencies maintain an ongoing picture of how security controls are performing in practice. It correlates alerts, vulnerability data, and configuration baselines with NIST-based control frameworks used for FISMA, FedRAMP, and CMMC. The AI-enabled module provides workflows to assist with updating RMF documentation, assembling supporting evidence, and tracking changes in residual risk over time. Its AI-assisted analysis approach, informed by our NISTcompliance.ai platform, is used to highlight trends, gaps, and control drift, adding automation and consistency while preserving existing governance, review, and approval processes.
Next step
What the same authorization would cost you
The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.
Provenance and independence
Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.
GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.
FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.