DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-FR2513256853

The Armory

StackArmor lists The Armory on the FedRAMP Marketplace with the status FedRAMP Certified, at High impact, on the Agency path under the Rev5 process. Package FR2513256853, read from the marketplace feed as of September 3, 2026.

FedRAMP CertifiedRev5Agency pathSmall business

Section A. Register entry

What the marketplace records

FedRAMP package ID
FR2513256853
Cloud service provider
StackArmor
Certification status
FedRAMP Certified
Impact level
High
Certification class
Class D (High)
Authorization path
Agency
Certification type
Rev5
Marketplace phase
Ongoing Certification
Deployment model
Government Community Cloud
Register snapshot
September 3, 2026
Service model
SaaS
Independent assessor
Emagine IT
Certification date
August 21, 2026
Status date
August 21, 2026
FedRAMP Ready date
March 28, 2025
Annual assessment
July 21, 2011
Agency authorizations
1
Business categories
Cybersecurity & Risk Management, Data Management, Network Management, Operations Management, Storage, System Administration
SAM.gov UEI
Z553Q1FPWYK5
Small business
Flagged on the marketplace record
Milestones on record
3

The marketplace carries The Armory under package FR2513256853 with 21 recorded fields. Its certification date is August 21, 2026, and a FedRAMP Ready date of March 28, 2025. Emagine IT is named as the independent assessor, with an annual assessment date of July 21, 2011. 1 agency is listed as having authorized it, among them Department of Commerce. It is delivered as SaaS on a government community cloud, filed under 6 business categories including Cybersecurity & Risk Management, Data Management, Network Management and 3 more. Its SAM.gov unique entity identifier is Z553Q1FPWYK5. StackArmor is flagged as a small business on the record.

Section B. Milestones

3 entries in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
August 21, 2026Status ChangeStatus changed from PMO Review to FedRAMP Certified
December 8, 2025Status ChangeStatus changed from FedRAMP Ready to Agency Authorization In Process
March 28, 2025Status ChangeStatus set to Legacy FedRAMP Ready

Section C. Cost context

What reaching High costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a High authorization

Initial authorization$2,500,000 to $5,000,000+
Continuous monitoring$300,000 to $600,000+ a year
Typical timeline18 to 24 months
Control baseline421+ controls
Annual assessment$180,000 to $450,000 a year

Our published planning range for a provider pursuing High. It is not a figure any listed provider has disclosed.

Read the FedRAMP High cost guide / annual assessment cost / continuous monitoring cost

Path

Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost

Assessment and monitoring

An annual assessment date of July 21, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost

Section E. Agencies on the record

1 agency listed against this package

As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.

  • Department of Commerce

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

StackArmor lists 4 offerings on the marketplace. The others are:

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

The Armory is a purpose-built General Support System (GSS) cloud service offering (CSO) that delivers security and compliance services aligned to the FedRAMP High risk categorization baseline. The Armory accelerates the ability for Independent Software Vendors (ISVs) and Enterprises to meet complex regulatory requirements on the Google Cloud Platform (GCP). The Armory delivers and continuously monitors FedRAMP compliant, risk-mitigated cloud solutions to government agencies and their partners through either a hosted or managed delivery model by: • providing full compliance architecture, engineering, documentation and audit support, • reducing the burden to both agencies and SaaS providers, and - expanding the catalog of mission-critical cloud solutions available to agencies. The Armory is built on the FedRAMP authorized Assured Workloads Google Cloud Platform and includes configuration managed Google resources such as VPCs (Virtual Private Clouds), networking components, security controls, identity and access management (IAM) policies, and logging and monitoring mechanisms. The system also provides access to in-boundary tools for automation, configuration management, and account management. Each of these mechanisms has been configured to meet specific regulatory requirements such as International Traffic in Arms Regulations (ITAR), FedRAMP High, and Department of Defense (DoD) Impact Levels 4/5 (IL 4/5). The Armory provides ISVs, Enterprises and Agencies with access to pre-production staging environments and Google "Landing Zones". These are securely architected environments that enable quick and compliant deployments, and a scalable foundation for their regulated cloud workloads. This secure standardized approach to creating and managing deployments allows government agencies and customers to easily deploy and manage their workloads while maintaining security, governance, and compliance. ISV Partners: Qanapi - As our inaugural ISV Partner, Qanapi's FIPS-validated API service delivers state-of-the-art encryption and protection at the data level. Designed to safeguard sensitive, industry-regulated, and mission-critical data, Qanapi's API seamlessly integrates into any software, device, or network. Built on a zero-trust architecture, it ensures robust security across organizations of all sizes, in both the public and commercial sectors. With Qanapi, organizations can achieve the highest level of data protection and compliance, regardless of their environment. Discover more at qanapi.com MxDR for Government - Accenture Federal Services' MxDR for Government is a managed security service designed specifically for federal agencies. Powered by Google SecOps, it offers 24/7 continuous threat detection, automated response, and threat-centric case management to help agencies rapidly neutralize cyber threats while maintaining strict regulatory compliance. Discover more at: https://www.accenture.com/us-en/industries/accenture-federal-services/cybersecurity/mxdr-government

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28