Section 8.4 - Register entry
DOC-REF: FRC-MKT-FR2434074613
Third-Party Risk Intelligence System (TRIS)'s
NormShield, Inc. DBA Black Kite lists Third-Party Risk Intelligence System (TRIS)'s on the FedRAMP Marketplace with the status Legacy FedRAMP Ready, at Moderate impact, on the Agency path under the Rev5 process. Package FR2434074613, read from the marketplace feed as of September 3, 2026.
Section A. Register entry
What the marketplace records
- FedRAMP package ID
- FR2434074613
- Cloud service provider
- NormShield, Inc. DBA Black Kite
- Certification status
- Legacy FedRAMP Ready
- Impact level
- Moderate
- Certification class
- Class C (Moderate)
- Authorization path
- Agency
- Certification type
- Rev5
- Marketplace phase
- Legacy FedRAMP Ready
- Deployment model
- Public Cloud
- Register snapshot
- September 3, 2026
- Service model
- SaaS
- Independent assessor
- Linford & Company
- Status date
- March 25, 2026
- FedRAMP Ready date
- March 25, 2026
- Business categories
- Analytics, Cybersecurity & Risk Management
- Small business
- Flagged on the marketplace record
- Milestones on record
- 1
The marketplace carries Third-Party Risk Intelligence System (TRIS)'s under package FR2434074613 with 17 recorded fields. Its current status was set on March 25, 2026, and a FedRAMP Ready date of March 25, 2026. Linford & Company is named as the independent assessor. No agency authorizations are listed against it in the current feed. It is delivered as SaaS on a public cloud, filed under 2 business categories including Analytics and Cybersecurity & Risk Management. NormShield, Inc. DBA Black Kite is flagged as a small business on the record.
Section B. Milestones
1 entry in the marketplace event log
Most recent first, as recorded by FedRAMP.
| Date | Category | Recorded |
|---|---|---|
| March 25, 2026 | Status Change | Status set to Legacy FedRAMP Ready |
Section C. Cost context
What reaching Moderate costs
Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.
Cost context
Budget for a Moderate authorization
Our published planning range for a provider pursuing Moderate. It is not a figure any listed provider has disclosed.
Read the FedRAMP Moderate cost guide / annual assessment cost / continuous monitoring cost
Path
Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost
Assessment and monitoring
No annual assessment date is on the record. Assessment recurs annually for as long as a package stays listed. Annual assessment cost / continuous monitoring cost
Section G. Nearest entries on the register
Comparable offerings
Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.
- Adaptiva Onesite Platform
Adaptive Protocols, Inc. (Adaptiva)
Legacy FedRAMP Ready, Moderate impact, Agency path, Rev5.
- SecurityScorecard Security Ratings
SecurityScorecard, LLC
Legacy FedRAMP Ready, Moderate impact, Agency path, Rev5.
- Minuet
Inteum Company
Legacy FedRAMP Ready, Moderate impact, Agency path, Rev5.
- Net-Inspect Enterprise Quality Management (EQM)
Net-Inspect LLC
Legacy FedRAMP Ready, Moderate impact, Agency path, Rev5.
- Federal ZenGRC
Steel Patriot Partners
Legacy FedRAMP Ready, Moderate impact, Agency path, Rev5.
Section H. Description
As published on the marketplace
The provider's own description of the service, reproduced from the FedRAMP feed without edits.
Black Kite is delivered as a SaaS offering using a multi-tenant public cloud computing environment. It is available to the public, federal, state, local, and tribal governments, as well as research institutions, federal contractors, government contractors etc. Black Kite offers a separate configuration for federal/public sector customers to maintain the highest possible level of information security. Black Kite provides a defensive platform that spans the entirety of the third-party risk management life cycle for cyber risk professionals looking to quantify and maintain visibility of their risk exposure. Black Kite's core application, is a multi-user, transaction-based application suite that gives a three-dimensional risk picture of a company and its vendors through: • A cyber risk technical assessment. • A factor analysis of information risk (FAIR) analysis (the probable financial impact of a breach caused by a vendor). • An external estimate of compliance (assessing that vendors have appropriate policies and processes in place). • Executives get an easy-to-understand "Cyber Risk Report" with letter grade scores. • IT security teams can drill down to the technical details behind each risk category. • Risks/vulnerabilities are prioritized by severity so that security engineers can quickly identify critical issues and mitigate them. • Industry benchmarks and comparisons are provided to help identify trends and pinpoint areas for improvement. • Grading is based on industry standards and best practices (NIST, MITRE CVSS, FAIR, etc.)
Next step
What the same authorization would cost you
The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.
Provenance and independence
Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.
GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.
FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.