DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-AGENCYWC2

Treasury Cloud Moderate

United States Department of the Treasury lists Treasury Cloud Moderate on the FedRAMP Marketplace with the status FedRAMP Certified, at Moderate impact, on the Agency path under the Rev5 process. Package AGENCYWC2, read from the marketplace feed as of September 3, 2026.

FedRAMP CertifiedRev5Agency path

Section A. Register entry

What the marketplace records

FedRAMP package ID
AGENCYWC2
Cloud service provider
United States Department of the Treasury
Certification status
FedRAMP Certified
Impact level
Moderate
Certification class
Class C (Moderate)
Authorization path
Agency
Certification type
Rev5
Marketplace phase
Ongoing Certification
Deployment model
Government Community Cloud
Register snapshot
September 3, 2026
Service model
PaaS, SaaS
Independent assessor
Excentium, Inc.
Certification date
May 6, 2014
Status date
May 6, 2014
Annual assessment
October 31, 2011
Agency authorizations
1
Milestones on record
3

The marketplace carries Treasury Cloud Moderate under package AGENCYWC2 with 17 recorded fields. Its certification date is May 6, 2014. Excentium, Inc. is named as the independent assessor, with an annual assessment date of October 31, 2011. 1 agency is listed as having authorized it, among them Department of the Treasury. It is delivered as PaaS and SaaS on a government community cloud.

Section B. Milestones

3 entries in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
May 6, 2014Status ChangeStatus changed from PMO Review to FedRAMP Certified
May 6, 2014Status ChangeStatus changed from Agency Review to FedRAMP In Process
November 11, 2013Status ChangeStatus set to Agency Authorization In Process

Section C. Cost context

What reaching Moderate costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a Moderate authorization

Initial authorization$800,000 to $2,000,000
Continuous monitoring$150,000 to $350,000 a year
Typical timeline12 to 18 months
Control baseline325+ controls
Annual assessment$90,000 to $260,000 a year

Our published planning range for a provider pursuing Moderate. It is not a figure any listed provider has disclosed.

Read the FedRAMP Moderate cost guide / annual assessment cost / continuous monitoring cost

Path

Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost

Assessment and monitoring

An annual assessment date of October 31, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost

Section E. Agencies on the record

1 agency listed against this package

As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.

  • Department of the Treasury

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

United States Department of the Treasury lists 2 offerings on the marketplace. The others are:

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

The Treasury Cloud Moderate (TCloud-M) System is owned and operated by the Department of the Treasury, serving as a multi-tenant IaaS/PaaS hosting environment designed to process Moderate Impact level information. TCloud-M is offered as a shared service, available in two cloud hosting models: Boundary Protected and Managed. The IaaS/PaaS provider used for this solution is Amazon Web Services (AWS) US East/West. The TCloud-M platform enables Treasury customers to concentrate on the operational and business aspects of their web presence, such as usability, information architecture, and content authoring, without the need to repeatedly configure and reinvent the technical infrastructure. This platform supports a variety of highly available services hosted on AWS and delivered to end-users through the Akamai Content Delivery Network (CDN). TCloud-M provides the following boundary protected and managed services to meet business or mission requirements: Boundary Protected Hosting Environment • Cloud account provisioning and invoicing, with transparency on service utilization with FinOps dashboards. • Intrusion Prevention Services (IPS); VPN; Direct connection with Treasury T-NET network. • Monitoring of network ingress and egress traffic. • Preconfigured networking resources. • Single Sign-On with connection to TCloud Active Directory. • IAM policies, groups, roles, preconfigured to enforce identify guardrails. • Audit trails and change monitoring that produce alerts and notifications to predetermined set of stakeholders. • Management, configuration, and provisioning of Atlassian software suite available for customers- JIRA, Confluence, Stash (BitBucket), and Bamboo. • Access to native cloud services and resources provided by the CSP. Managed Hosting Environment • Cloud account provisioning and invoicing, with transparency on service utilization with FinOps dashboards. • Remote Desktop Services. • Operating System (OS) level patching performed as part of monthly patch deployments. • Vulnerability scanning: OS, Databases, and Web application. • Identification, prioritization, and mitigation of OS and Database level vulnerabilities. • Configuration management for OS and Databases . • Intrusion Prevention Services (IPS); VPN; Web Application Firewall (WAF); Direct connection with Treasury T-NET network. • Anti-Virus and Host Based Firewall. • Endpoint Detection and Response. • Audit log ingestion and monitoring (OS Level, Database, and CSP). • Directory services, accounts and permission management provided through Microsoft Active Directory. • IAM policies, groups, roles, preconfigured to enforce identify guardrails. • IAM audit trails and change monitoring that produce alerts and notifications to predetermined set of stakeholders. • Single Sign-On with connection to TCloud Active Directory. • Monitoring of network ingress and egress traffic. • Preconfigured networking resources, with audit trails and change monitoring that produce alerts and notifications to predetermined set of stakeholders. • Unified cloud security platform that includes vulnerability management, compliance and posture management, workload protection, and container security. • Disaster recovery and Contingency Planning - Backup and restore. • Disaster recovery and Contingency Planning - Different availability zones for resiliency. • Security incident and response monitoring and coordination with appropriate stakeholders. • Management, configuration, and provisioning of Atlassian software suite available for customers- JIRA, Confluence, Stash (BitBucket), and Bamboo. • Access to native cloud services and resources provided by each CSP.

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28