DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-FR2308034636A

Wiz for U.S. Government

Wiz, Inc. lists Wiz for U.S. Government on the FedRAMP Marketplace with the status FedRAMP Certified, at High impact, on the Agency path under the Rev5 process. Package FR2308034636A, read from the marketplace feed as of September 3, 2026.

FedRAMP CertifiedRev5Agency path

Section A. Register entry

What the marketplace records

FedRAMP package ID
FR2308034636A
Cloud service provider
Wiz, Inc.
Certification status
FedRAMP Certified
Impact level
High
Certification class
Class D (High)
Authorization path
Agency
Certification type
Rev5
Marketplace phase
Ongoing Certification
Deployment model
Public Cloud
Register snapshot
September 3, 2026
Service model
SaaS
Independent assessor
Fortreum, LLC
Certification date
September 25, 2025
Status date
September 25, 2025
Annual assessment
September 25, 2011
Agency authorizations
7
Recorded reuses
6
Business categories
Analytics, Cybersecurity & Risk Management, Data Management, Research
Milestones on record
3

The marketplace carries Wiz for U.S. Government under package FR2308034636A with 19 recorded fields. Its certification date is September 25, 2025. Fortreum, LLC is named as the independent assessor, with an annual assessment date of September 25, 2011. 7 agencies are listed as having authorized it, among them Cybersecurity & Infrastructure Security Agency, Department of Agriculture, Department of State and 4 more, and the feed records 6 reuses of the package. It is delivered as SaaS on a public cloud, filed under 4 business categories including Analytics, Cybersecurity & Risk Management, Data Management and 1 more.

Section B. Milestones

3 entries in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
September 25, 2025Status ChangeStatus changed from PMO Review to FedRAMP Certified
September 11, 2025Status ChangeStatus changed from Agency Review to FedRAMP In Process
September 10, 2025Status ChangeStatus set to Agency Authorization In Process

Section C. Cost context

What reaching High costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a High authorization

Initial authorization$2,500,000 to $5,000,000+
Continuous monitoring$300,000 to $600,000+ a year
Typical timeline18 to 24 months
Control baseline421+ controls
Annual assessment$180,000 to $450,000 a year

Our published planning range for a provider pursuing High. It is not a figure any listed provider has disclosed.

Read the FedRAMP High cost guide / annual assessment cost / continuous monitoring cost

Path

Agency Authorization is the route for 578 of the offerings on the marketplace. Our cost pages put it at $800,000 to $2,000,000 over 12 to 18 months for Moderate. Agency authorization cost

Assessment and monitoring

An annual assessment date of September 25, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost

Section E. Agencies on the record

7 agencies listed against this package

As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.

  • Cybersecurity & Infrastructure Security Agency
  • Department of Agriculture
  • Department of State
  • Department of the Navy
  • Internal Revenue Service
  • Office of Personnel Management
  • Tennessee Valley Authority

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

Wiz for U.S. Government Wiz for U.S. Government ("Wiz for Gov") is a cloud-native environment and product line that delivers a unified view of risk across a customer's full cloud environment, from code to production. Wiz for Gov helps public sector agencies meet FedRAMP and FISMA compliance needs by focusing on the issues that matter most. The Wiz for Gov unified product line has three different components to secure your stack: Wiz Cloud for Gov Wiz Cloud focuses on assessing and prioritizing risk by analyzing vulnerabilities, misconfigurations, malware, identities, network paths, data, and AI risks. At its core is the Wiz Security Graph, which maps relationships between cloud resources to find "toxic combinations" that represent real risk. This approach automates risk assessments in alignment with OMB A-130's definition of risk as a function of the magnitude of harm and the likelihood of occurrence. It prioritizes these risks and routes them to relevant teams, providing a clear view of the attack path, blast radius, and recommended remediation steps. Wiz Code for Gov Wiz Code extends visibility into the development lifecycle to help enforce secure-by-design practices. By connecting directly to code repositories, Wiz provides full traceability from production issues back to the corresponding source code and owner. Wiz also integrates with CI/CD pipelines to enforce policies during image scanning and Infrastructure as Code (IaC) reviews, helping to identify risks earlier and accelerate time to production readiness. This shared view helps security and development teams collaborate, ensuring accountability and reducing mean time to remediation (MTTR). Wiz Defend for Gov Wiz Defend modernizes cloud threat detection and response by reducing alert fatigue and surfacing the root cause of issues faster. It leverages a cloud native runtime sensor, logs, and threat intelligence to identify malicious activity and enrich detected events with cloud context, providing SOC analysts with the information needed to assess threat impact and blast radius. This enhances active cyber defense across the full environment-including identity, workload runtime, network, data, and control plane components-and helps teams align response actions with the MITRE ATT&CK framework.

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28