DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-F1506096710

Skyhigh Security Service Edge (SSE) Government Cloud Services (Cloud Access Security Broker (CASB) & Secure Web Gateway (SWG) for Cloud)

Skyhigh Security lists Skyhigh Security Service Edge (SSE) Government Cloud Services (Cloud Access Security Broker (CASB) & Secure Web Gateway (SWG) for Cloud) on the FedRAMP Marketplace with the status FedRAMP Certified, at High impact, on the JAB path under the Rev5 process. Package F1506096710, read from the marketplace feed as of September 3, 2026.

FedRAMP CertifiedRev5JAB path

Section A. Register entry

What the marketplace records

FedRAMP package ID
F1506096710
Cloud service provider
Skyhigh Security
Certification status
FedRAMP Certified
Impact level
High
Certification class
Class D (High)
Authorization path
JAB
Certification type
Rev5
Marketplace phase
Ongoing Certification
Deployment model
Government Community Cloud
Register snapshot
September 3, 2026
Service model
SaaS
Independent assessor
Kratos
Certification date
April 29, 2020
Status date
April 29, 2020
FedRAMP Ready date
September 6, 2019
Annual assessment
March 31, 2011
Agency authorizations
7
Recorded reuses
10
Business categories
Analytics, Communication, Content Management System (CMS), Cybersecurity & Risk Management, Data Management, Legal & Policy, Network Management, Operations Management
Dependent offerings
2
Milestones on record
3

The marketplace carries Skyhigh Security Service Edge (SSE) Government Cloud Services (Cloud Access Security Broker (CASB) & Secure Web Gateway (SWG) for Cloud) under package F1506096710 with 21 recorded fields. Its certification date is April 29, 2020, and a FedRAMP Ready date of September 6, 2019. Kratos is named as the independent assessor, with an annual assessment date of March 31, 2011. 7 agencies are listed as having authorized it, among them Department of Commerce, Federal Deposit Insurance Corporation, Idaho Operations Office and 4 more, and the feed records 10 reuses of the package. It is delivered as SaaS on a government community cloud, filed under 8 business categories including Analytics, Communication, Content Management System (CMS) and 5 more. 2 other offerings on the register are listed as dependent on this one, among them AutoRABIT for Public Sector - CodeScan, Guard, & ARMOR and T-Metrics Cloud Contact Center (TCCC).

Section B. Milestones

3 entries in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
April 29, 2020Status ChangeStatus changed from JAB Review to FedRAMP Certified
December 13, 2019Status ChangeStatus changed from FedRAMP Ready to FedRAMP In Process
September 6, 2019Status ChangeStatus set to Legacy FedRAMP Ready

Section C. Cost context

What reaching High costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a High authorization

Initial authorization$2,500,000 to $5,000,000+
Continuous monitoring$300,000 to $600,000+ a year
Typical timeline18 to 24 months
Control baseline421+ controls
Annual assessment$180,000 to $450,000 a year

Our published planning range for a provider pursuing High. It is not a figure any listed provider has disclosed.

Read the FedRAMP High cost guide / annual assessment cost / continuous monitoring cost

Path

The marketplace lists 53 offerings against the JAB path. Our JAB vs Agency page records that the JAB P-ATO path was retired in 2024 and that Agency Authorization is now the single traditional route, at $800,000 to $2,000,000 over 12 to 18 months. JAB vs Agency ATO cost

Assessment and monitoring

An annual assessment date of March 31, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost

Section E. Agencies on the record

7 agencies listed against this package

As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.

  • Department of Commerce
  • Federal Deposit Insurance Corporation
  • Idaho Operations Office
  • National Institute of Standards and Technology
  • National Nuclear Security Administration / Nevada Field Office
  • National Oceanic and Atmospheric Administration
  • Y12 Field Office

Section F. Dependent offerings

2 listed offerings build on this package

From the marketplace's dependent products view. A provider that inherits controls from a package below it carries a narrower assessment boundary of its own, which is one of the larger levers on authorization cost.

Inheritance is why boundary scope moves a budget more than headcount does. The hidden costs page sets out where scope creeps back in.

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

Skyhigh Security Service Edge (SSE) GovCloud, is a FedRAMP-authorized, Zero Trust, cloud-native security platform purpose-built for U.S. federal agencies. It enables fast, secure, direct-to-internet access across websites, email, SaaS applications, IaaS environments, and even shadow IT, all governed through a single, unified enforcement point. The result is a simpler, more resilient architecture that protects highly sensitive data while staying ahead of increasingly sophisticated, cloud-driven threats. Rather than stitching together disconnected tools, Skyhigh SSE GovCloud consolidates essential security capabilities into one cohesive platform, providing real-time visibility, threat prevention, and data protection across every vector, all managed through a centralized console. Its integrated capabilities include: ● Skyhigh Secure Web Gateway (SWG) for Cloud ● Skyhigh Cloud Access Security Broker (CASB) ● Skyhigh Data Security Posture Management (DSPM) ● Skyhigh Advanced Data Loss Prevention (Adv DLP) ● Skyhigh Data Loss Prevention (DLP) ● Skyhigh Remote Browser Isolation (RBI) Built to meet the most rigorous federal security standards, Skyhigh SSE GovCloud invites agencies to rethink how they defend, detect, and respond. It accelerates Zero Trust adoption while supporting compliance with Executive Order 14028 and other critical cybersecurity mandates, enabling agencies not just to keep up with the threat landscape, but to get ahead of it. Skyhigh Data Security Posture Management (DSPM) - Authorized March, 2026 The greatest risk to federal data is not always lack of control, but the false sense of control created by fragmented environments. Federal agencies and contractors today are engaged in protecting ever-expanding volumes of mission-critical data, while operating under rigorous mandates like NIST and CMMC. Yet beyond compliance the real challenge is clarity. Fragmented security tools, hidden pockets of shadow data and AI usage, and rapidly evolving cloud vulnerabilities create an environment where visibility is partial and control is reactive. Skyhigh DSPM confronts this reality by unifying what has long been disconnected. Embedded within a broader Secure Service Edge (SSE) framework, it brings together data classification and real-time policy enforcement across SaaS, IaaS, web, email, and private applications. The result is comprehensive visibility backed by meaningful insight, reducing false positives while strengthening control over sensitive data. Crucially, this approach extends to emerging risks, including generative AI, ensuring sensitive information is not unintentionally exposed or ingested into AI models. It shifts the paradigm from chasing risk to anticipating it, giving agencies the ability to see, understand, and act with confidence in an increasingly complex digital landscape. This translates into: ● Continuous compliance monitoring aligned with federal mandates (NIST, CMMC). ● Centralized visibility into data usage, movement and residence across cloud environments. ● Advanced protection of sensitive data (CUI/PII) using OCR and data matching. ● Granular access controls based on user, device, and location. ● Real-time threat detection, response, and remediation for stronger security posture. With unified intelligence, decisions shift from reactive defense to proactive action, protecting data, ensuring compliance, and mitigating data risks. Skyhigh Remote Browser Isolation (RBI) The safest web session is the one where untrusted content never reaches the endpoint. Skyhigh Remote Browser Isolation (RBI) achieves this reality by fundamentally changing how agencies interact with the web. Rather than allowing web content to execute directly on user devices, RBI renders browsing sessions in a secure, isolated cloud environment and delivers only a safe visual stream to the endpoint. Embedded within the broader Skyhigh Security Service Edge (SSE) framework, RBI extends security beyond simple URL filtering and malware detection. It enables agencies to safely access unknown, risky, or uncategorized websites without compromising sensitive systems or data. Combined with integrated DLP, CASB, and SWG capabilities, RBI provides granular control over user interactions, preventing unauthorized downloads, uploads, copy-and-paste actions, and data exfiltration attempts. Crucially, this isolation-first model protects against both known and unknown threats, including zero-day malware, malicious scripts, ransomware, and sophisticated phishing attacks. This translates into: ● Complete isolation of web content from agency devices and networks. ● Secure access to unknown, risky, or uncategorized websites. ● Integrated DLP controls for downloads, uploads, copy/paste, and data sharing. ● Reduced attack surface without impacting user productivity or browsing experience. ● Consistent Zero Trust enforcement across users, devices, and web destinations. ● With RBI, agencies move beyond reactive web security toward proactive threat prevention, ensuring users can safely access the internet while protecting mission-critical systems, sensitive data, and operational continuity. Skyhigh Secure Web Gateway (SWG) for Cloud What if every click, every web request, every cloud interaction, was inspected, understood, and secured in real-time? Skyhigh SWG for Cloud redefines how federal agencies protect users in an increasingly borderless digital environment. Acting as a powerful, cloud-native enforcement layer, it sits inline between users and the internet, continuously analyzing traffic to block malicious destinations, stop zero-day threats before they take hold, and prevent sensitive data from ever leaving the organization. With 99.999% uptime and seamless integration of Remote Browser Isolation (RBI), Gateway Anti-Malware (GAM), CASB (Cloud Access Security Broker), Data Loss Prevention (DLP), and Data Security Posture Management (DSPM), Skyhigh SWG delivers uninterrupted, high-assurance connectivity without compromising security. Flexible deployment options ensure agencies can rapidly transition to the cloud while maintaining compliance with existing proxy infrastructures and legacy protocols. Key capabilities include: ● Intelligent web filtering that enables secure, policy-driven access to the web and cloud, from any device, anywhere ● Risk-free browsing with RBI, rendering web sessions via visual stream to eliminate malware exposure and reduce false positives ● Integrated DLP within RBI sessions, providing full visibility and control over how sensitive data is accessed and shared ● Advanced threat protection, leveraging machine learning, zero-day detection, GAM, and Global Threat Intelligence (GTI) ● SSL decryption for deep inspection of encrypted traffic, and more. ● Skyhigh SWG for Cloud doesn't just secure web access, it challenges the assumption that speed, usability, and security must be trade-offs. Instead, it delivers all three, empowering agencies to move faster while staying firmly in control. Skyhigh Advanced DLP Security gaps aren't obvious, but they're where federal data is truly at risk. The real data challenge today is not just securing sensitive data, it is doing so with precision and confidence across increasingly complex hybrid environments. Traditional DLP solutions often leave blind spots, generate excessive false positives, and struggle to enforce consistent policies, creating gaps in protection that can put mission-critical data at risk. Skyhigh Advanced DLP, transforms how federal organizations protect sensitive data across cloud, web, email, and applications. By combining Exact Data Matching (EDM) and Indexed Document Matching (IDM), it fingerprints structured and unstructured data with high accuracy, while AI-driven classifiers automate policy creation and reduce noise. OCR-enabled scanning ensures even large files and images are accurately analyzed, leaving no critical data overlooked. This unified approach extends across sanctioned and shadow environments, providing consistent enforcement and centralized incident management. Advanced DLP helps agencies enforce risk-based access, prevent sensitive data from flowing into unsanctioned SaaS and AI tools, and reduce the attack surface, all in real-time. This leads to: ● Proactive Threat Prevention detects and stops sensitive data misuse before it becomes a breach. ● Automated Policy Management streamlines policy creation and enforcement, reducing administrative overhead and human error. ● Consistent Enforcement Across Shadow IT monitors unsanctioned applications and services to eliminate blind spots. ● Enhanced Incident Response centralized visibility and automated remediation accelerate threat response and reduce risk exposure. ● Unified Data Protection enforces consistent DLP policies across cloud, SaaS, web, and email from a single platform. ● Skyhigh Advanced DLP enables federal teams to move beyond reactive protection, ensuring sensitive data is accurately identified, consistently safeguarded, and never unintentionally exposed, even in the face of evolving AI and cloud risks. Skyhigh Cloud Access Security Broker (CASB) Skyhigh CASB offers a powerful lens into how you can truly operate in the cloud. It provides a comprehensive view into how cloud environments are actually being used and managed. In complex, multi-cloud ecosystems, it moves beyond basic visibility to correlate user activity, behavior, and data movement, surfacing patterns that are critical to security, compliance, and operational resilience. Its readiness ratings equip system and data owners with objective, evidence-based insights, enabling them to assess cloud risk with greater confidence and accountability. When potential threats or anomalies emerge, Skyhigh CASB provides the contextual intelligence needed for rapid, informed decision-making. This is essential in environments where timely response is critical to protecting sensitive data and maintaining operational integrity. Control is not static; through inline deployment options such as forward proxy, reverse proxy, and cloud app isolation, agencies can enforce real-time access policies across both authorized applications and the wide range of unsanctioned tools that often enter the environment. For sanctioned cloud services, API-based integrations extend visibility deeper into user activity, data flows, and system interactions. This supports advanced capabilities such as user and entity behavior analytics (UEBA), tenant-level controls, collaboration governance, and both continuous and on-demand scanning. Together, these capabilities help federal organizations strengthen data protection, enforce policy, and maintain oversight across increasingly dynamic environments. Its feature set reflects a broader shift in security thinking: ● Scaling trust through deep visibility, delivering measurable insights grounded in comprehensive, end-to-end visibility. ● Extensive cloud service registry, 40,000+ cloud services enables broad visibility into tools and dependencies across the environment. ● Granular and adaptive data protection, driven by sophisticated classification and a mature DLP engine. ● Quantifiable risk across applications and users through machine learning and behavioral analytics. ● AI augments human judgment, from generating complex classification patterns to detecting subtle anomalies. In cloud-first federal environments, success depends on real-time visibility, understanding, and response, moving beyond blocking to intelligent, adaptive security and compliance. Available Products from Skyhigh Security: ● Skyhigh Security Service Edge (SSE) ● Skyhigh Secure Web Gateway for Cloud (SWG Cloud) ● Skyhigh Cloud Access Security Broker for Gov Cloud (CASB Gov Cloud) ● Skyhigh Data Security Posture Management (DSPM) ● Skyhigh Advanced Data Loss Prevention (Adv DLP) ● Skyhigh Data Loss Prevention (DLP) ● Skyhigh Remote Browser Isolation (RBI) Request a Demo: https://www.skyhighsecurity.com/forms/demo-request-form.html Visit Skyhigh Security for Public Sector for further details

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28