DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-FR2221161553

SecurityScorecard Security Ratings

SecurityScorecard, LLC lists SecurityScorecard Security Ratings on the FedRAMP Marketplace with the status Legacy FedRAMP Ready, at Moderate impact, on the Agency path under the Rev5 process. Package FR2221161553, read from the marketplace feed as of September 3, 2026.

Legacy FedRAMP ReadyRev5Agency path

Section A. Register entry

What the marketplace records

FedRAMP package ID
FR2221161553
Cloud service provider
SecurityScorecard, LLC
Certification status
Legacy FedRAMP Ready
Impact level
Moderate
Certification class
Class C (Moderate)
Authorization path
Agency
Certification type
Rev5
Marketplace phase
Legacy FedRAMP Ready
Deployment model
Public Cloud
Register snapshot
September 3, 2026
Service model
SaaS
Independent assessor
Schellman Compliance, LLC
Status date
February 17, 2026
FedRAMP Ready date
February 17, 2026
Business categories
Analytics, Cybersecurity & Risk Management, Data Management, Network Management, Operations Management, System Administration
Milestones on record
1

The marketplace carries SecurityScorecard Security Ratings under package FR2221161553 with 16 recorded fields. Its current status was set on February 17, 2026, and a FedRAMP Ready date of February 17, 2026. Schellman Compliance, LLC is named as the independent assessor. No agency authorizations are listed against it in the current feed. It is delivered as SaaS on a public cloud, filed under 6 business categories including Analytics, Cybersecurity & Risk Management, Data Management and 3 more.

Section B. Milestones

1 entry in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
February 17, 2026Status ChangeStatus set to Legacy FedRAMP Ready

Section C. Cost context

What reaching Moderate costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a Moderate authorization

Initial authorization$800,000 to $2,000,000
Continuous monitoring$150,000 to $350,000 a year
Typical timeline12 to 18 months
Control baseline325+ controls
Annual assessment$90,000 to $260,000 a year

Our published planning range for a provider pursuing Moderate. It is not a figure any listed provider has disclosed.

Read the FedRAMP Moderate cost guide / annual assessment cost / continuous monitoring cost

Path

Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost

Assessment and monitoring

No annual assessment date is on the record. Assessment recurs annually for as long as a package stays listed. Annual assessment cost / continuous monitoring cost

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

SecurityScorecard Security Ratings monitors the security posture of millions of companies by calculating a risk score derived from publicly available data. Companies are assigned A-F ratings across risk factors including domain name system (DNS) health, internet protocol (IP) reputation, web application security, network security, leaked information, hacker chatter, endpoint security, and patching cadence. This data is provided to customers via the Security Ratings web application. Customers use the Security Ratings web application to review security ratings and detailed security reports. Users access Security Ratings through a standard web browser and leverage identity federation for authentication. Within the application, users search for companies of interest and review security reports developed by SecurityScorecard. These ratings and reports allow customers to evaluate the cybersecurity risk for companies of interest using data-driven, objective, and continuously evolving metrics that provide visibility into information security control weaknesses as well as potential vulnerabilities throughout the supply chain ecosystem. Users can also create "portfolios" to group together companies of interest and easily compare vendors to help make procurement decisions, evaluate acquisition targets, conduct industry benchmarking, and more. Additional capabilities and data points (collected from publicly available data sources) in the Security Ratings web application include: • IP attribution to company domain(s) • Security vulnerability monitoring by company and security factors • Security risk benchmarking and scoring by company and industry • Alerts for changes in risk scores • Executive and detailed company scorecard reports • Workflow for collaboration and remediation with monitored suppliers

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28