DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-FR2535459082

The Armory20x

stackArmor lists The Armory20x on the FedRAMP Marketplace with the status FedRAMP Certified, at Low impact, on the Program path under the 20x process. Package FR2535459082, read from the marketplace feed as of September 3, 2026.

FedRAMP Certified20xProgram pathSmall business

Section A. Register entry

What the marketplace records

FedRAMP package ID
FR2535459082
Cloud service provider
stackArmor
Certification status
FedRAMP Certified
Impact level
Low
Certification class
Class B (Low)
Authorization path
Program
Certification type
20x
Marketplace phase
Ongoing Certification
Deployment model
Government Community Cloud
Register snapshot
September 3, 2026
Service model
SaaS
Independent assessor
Kratos
Certification date
December 5, 2025
Status date
December 5, 2025
Annual assessment
December 12, 2011
Agency authorizations
1
Business categories
Development Tools
Small business
Flagged on the marketplace record
Milestones on record
3

The marketplace carries The Armory20x under package FR2535459082 with 19 recorded fields. Its certification date is December 5, 2025. Kratos is named as the independent assessor, with an annual assessment date of December 12, 2011. 1 agency is listed as having authorized it, among them Federal Risk and Authorization Management Program. It is delivered as SaaS on a government community cloud, filed under 1 business categories including Development Tools. stackArmor is flagged as a small business on the record.

Section B. Milestones

3 entries in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
December 5, 2025Status ChangeStatus changed from Final Program Review to FedRAMP Certified
November 13, 2025Status ChangeStatus changed from Initial Program Review to FedRAMP In Process
September 26, 2025Status ChangeStatus set to FedRAMP In Process

Section C. Cost context

What reaching Low costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a Low authorization

Initial authorization$350,000 to $500,000
Continuous monitoring$60,000 to $120,000 a year
Typical timeline9 to 12 months
Control baselineup to 125 controls

Our published planning range for a provider pursuing Low. It is not a figure any listed provider has disclosed.

Read the FedRAMP Low cost guide / continuous monitoring cost

Path

The marketplace records 80 offerings on the Program path, 76 of them 20x. Our 20x page covers what that model is estimated to cost. FedRAMP 20x cost analysis

20x

This package is on the 20x track. Our 20x page puts an early estimate of $100,000 to $300,000 on a Low or Moderate authorization under 20x against $500,000 to $2,000,000+ on the traditional path. Those are estimates from early pilot data, not observed invoices. 20x cost analysis

Section E. Agencies on the record

1 agency listed against this package

As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.

  • Federal Risk and Authorization Management Program

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

stackArmor lists 4 offerings on the marketplace. The others are:

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

Armory20x is a purpose-built solution hosted on Google Cloud Platform (GCP) that provides cloud service providers (CSPs) and independent software vendors (ISVs) a deployment landing zone within an Armory20x tenant to deploy workloads that store, process, and/or transmit federal data categorized at the FedRAMP 20x Low baseline. The tenant leverages the security and General Support System (GSS) services of The Armory | FedRAMP Marketplace to provide a known-secure deployment location, leveraging a majority of GCP FedRAMP authorized native cloud and in-boundary security services, for CSPs seeking authorization under 20x. As part of the FedRAMP 20x Pilot, CSPs must report their Key Security Indicator (KSI) status as defined by the FedRAMP 20x Key Security Indicators | FedRAMP.gov. Armory20x leverages stackArmor's automated assessment solution to provide status for all required KSIs for a CSP deployed within a 20x tenant. Tenants are heavily customizable, allowing Armory20x customers to deploy workloads that are suited to their particular application and service needs. stackArmor personnel assist CSPs/ISVs with deploying services in a manner that meets FedRAMP 20x KSI requirements and helps ensure an authorizable status under the 20x program.

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28