DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-FR2414158717

RegScale CCM

RegScale lists RegScale CCM on the FedRAMP Marketplace with the status FedRAMP Certified, at High impact, on the Agency path under the Rev5 process. Package FR2414158717, read from the marketplace feed as of September 3, 2026.

FedRAMP CertifiedRev5Agency pathSmall business

Section A. Register entry

What the marketplace records

FedRAMP package ID
FR2414158717
Cloud service provider
RegScale
Certification status
FedRAMP Certified
Impact level
High
Certification class
Class D (High)
Authorization path
Agency
Certification type
Rev5
Marketplace phase
Ongoing Certification
Deployment model
Public Cloud
Register snapshot
September 3, 2026
Service model
SaaS
Certification date
June 24, 2025
Status date
June 24, 2025
Annual assessment
May 22, 2011
Agency authorizations
3
Recorded reuses
6
Business categories
Collaboration, Cybersecurity & Risk Management, Governance, Risk, and Compliance (GRC)
SAM.gov UEI
LYMKBNFHJXH7
Small business
Flagged on the marketplace record
Dependent offerings
1
Milestones on record
3

The marketplace carries RegScale CCM under package FR2414158717 with 22 recorded fields. Its certification date is June 24, 2025. A-LIGN Compliance and Security, Inc. dba A-LIGN is named as the independent assessor, with an annual assessment date of May 22, 2011. 3 agencies are listed as having authorized it, among them Department of Homeland Security, Environmental Management Consolidated Business Center and United States Patent and Trademark Office, and the feed records 6 reuses of the package. It is delivered as SaaS on a public cloud, filed under 3 business categories including Collaboration, Cybersecurity & Risk Management and Governance, Risk, and Compliance (GRC). 1 other offering on the register is listed as dependent on this one, among them MAXIMUS Cloud. Its SAM.gov unique entity identifier is LYMKBNFHJXH7. RegScale is flagged as a small business on the record.

Section B. Milestones

3 entries in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
June 24, 2025Status ChangeStatus changed from PMO Review to FedRAMP Certified
May 27, 2025Status ChangeStatus changed from Agency Review to FedRAMP In Process
May 23, 2025Status ChangeStatus set to Agency Authorization In Process

Section C. Cost context

What reaching High costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a High authorization

Initial authorization$2,500,000 to $5,000,000+
Continuous monitoring$300,000 to $600,000+ a year
Typical timeline18 to 24 months
Control baseline421+ controls
Annual assessment$180,000 to $450,000 a year

Our published planning range for a provider pursuing High. It is not a figure any listed provider has disclosed.

Read the FedRAMP High cost guide / annual assessment cost / continuous monitoring cost

Path

Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost

Assessment and monitoring

An annual assessment date of May 22, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost

Section E. Agencies on the record

3 agencies listed against this package

As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.

  • Department of Homeland Security
  • Environmental Management Consolidated Business Center
  • United States Patent and Trademark Office

Section F. Dependent offerings

1 listed offering builds on this package

From the marketplace's dependent products view. A provider that inherits controls from a package below it carries a narrower assessment boundary of its own, which is one of the larger levers on authorization cost.

Inheritance is why boundary scope moves a budget more than headcount does. The hidden costs page sets out where scope creeps back in.

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

The RegScale Continuous Controls Monitoring (CCM) Platform is delivered as a Software-as-a-Service (SaaS) offering, hosted in a multi-tenant public cloud computing environment. Built on Microsoft Azure, RegScale provides next-generation Governance, Risk, and Compliance (GRC) capabilities that allow organizations to automate and accelerate the management of cybersecurity programs such as FISMA, FedRAMP, CMMC, PCI, HIPAA, and others. RegScale helps organizations address their most difficult compliance challenges by enabling customers-via robust API integrations-to manage controls, upload evidence documentation, perform system assessments, and maintain certifications and authorizations. This is all centralized within a single platform, offering a "single pane of glass" experience. Automation ensures that data and compliance posture are updated in near real-time. RegScale ensures that security and privacy-related controls are properly identified, implemented, and maintained throughout the System Development Lifecycle (SDLC) for systems, applications, services, processes, and related initiatives. The platform enables customers to establish and maintain an information assurance capability, including Control Validation Testing, to verify that appropriate controls are operational and risks are managed prior to production deployment. While RegScale may be designated a major application for many large organizations, it is not typically classified as mission-critical. RegScale is a modern, cloud-native application, designed to scale using Docker containers, which are micro-segmented and orchestrated using Microsoft Azure services. The system is designed to be hosted in any environment, with security-focused runtime configuration through environmental variable injection.

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28