DOC-REF: FRC-2026-04-28Rev 04 / 2026

Section 8.4 - Register entry

DOC-REF: FRC-MKT-FR2227062482

Zscaler Internet Access - Government (Secure Web Gateway - vTIC) - High

Zscaler, Inc. lists Zscaler Internet Access - Government (Secure Web Gateway - vTIC) - High on the FedRAMP Marketplace with the status FedRAMP Certified, at High impact, on the JAB path under the Rev5 process. Package FR2227062482, read from the marketplace feed as of September 3, 2026.

FedRAMP CertifiedRev5JAB path

Section A. Register entry

What the marketplace records

FedRAMP package ID
FR2227062482
Cloud service provider
Zscaler, Inc.
Certification status
FedRAMP Certified
Impact level
High
Certification class
Class D (High)
Authorization path
JAB
Certification type
Rev5
Marketplace phase
Ongoing Certification
Deployment model
Government Community Cloud
Register snapshot
September 3, 2026
Service model
SaaS
Independent assessor
Schellman Compliance, LLC
Certification date
July 2, 2022
Status date
July 2, 2022
FedRAMP Ready date
November 4, 2021
Annual assessment
June 23, 2011
Agency authorizations
14
Recorded reuses
14
Business categories
Cybersecurity & Risk Management, Data Management, Legal & Policy, Network Management, Operations Management
Dependent offerings
1
Milestones on record
3

The marketplace carries Zscaler Internet Access - Government (Secure Web Gateway - vTIC) - High under package FR2227062482 with 21 recorded fields. Its certification date is July 2, 2022, and a FedRAMP Ready date of November 4, 2021. Schellman Compliance, LLC is named as the independent assessor, with an annual assessment date of June 23, 2011. 13 agencies are listed as having authorized it, among them Centers for Disease Control and Prevention, Cybersecurity & Infrastructure Security Agency, Department of State and 10 more, and the feed records 14 reuses of the package. It is delivered as SaaS on a government community cloud, filed under 5 business categories including Cybersecurity & Risk Management, Data Management, Legal & Policy and 2 more. 1 other offering on the register is listed as dependent on this one, among them Cyber AI Mission Defense and Email Protection.

Section B. Milestones

3 entries in the marketplace event log

Most recent first, as recorded by FedRAMP.

Event log
DateCategoryRecorded
July 2, 2022Status ChangeStatus changed from JAB Review to FedRAMP Certified
March 15, 2022Status ChangeStatus changed from FedRAMP Ready to FedRAMP In Process
November 4, 2021Status ChangeStatus set to Legacy FedRAMP Ready

Section C. Cost context

What reaching High costs

Our own published ranges for a provider going through this level. Nothing here is a figure this provider has disclosed.

Cost context

Budget for a High authorization

Initial authorization$2,500,000 to $5,000,000+
Continuous monitoring$300,000 to $600,000+ a year
Typical timeline18 to 24 months
Control baseline421+ controls
Annual assessment$180,000 to $450,000 a year

Our published planning range for a provider pursuing High. It is not a figure any listed provider has disclosed.

Read the FedRAMP High cost guide / annual assessment cost / continuous monitoring cost

Path

The marketplace lists 53 offerings against the JAB path. Our JAB vs Agency page records that the JAB P-ATO path was retired in 2024 and that Agency Authorization is now the single traditional route, at $800,000 to $2,000,000 over 12 to 18 months. JAB vs Agency ATO cost

Assessment and monitoring

An annual assessment date of June 23, 2011 is on the record, and that assessment recurs for as long as the package stays listed. Annual assessment cost / continuous monitoring cost

Section E. Agencies on the record

13 agencies listed against this package

As published on the marketplace. An agency named here has issued its own authorization to operate; FedRAMP does not issue ATOs itself.

  • Centers for Disease Control and Prevention
  • Cybersecurity & Infrastructure Security Agency
  • Department of State
  • Drug Enforcement Administration
  • Federal Aviation Administration
  • Federal Emergency Management Agency
  • Food and Drug Administration
  • HHS Office of the Inspector General
  • HUD Office of Inspector General
  • Immigration and Customs Enforcement
  • Internal Revenue Service
  • Southwestern Power Administration
  • Tennessee Valley Authority

Section F. Dependent offerings

1 listed offering builds on this package

From the marketplace's dependent products view. A provider that inherits controls from a package below it carries a narrower assessment boundary of its own, which is one of the larger levers on authorization cost.

Inheritance is why boundary scope moves a budget more than headcount does. The hidden costs page sets out where scope creeps back in.

Section G. Nearest entries on the register

Comparable offerings

Scored on impact level, path, status, shared business categories and how close the two entries sit in the register's own timeline.

Section H. Description

As published on the marketplace

The provider's own description of the service, reproduced from the FedRAMP feed without edits.

Zscaler Internet Access Gov, part of the Zscaler Zero Trust Exchange, defines safe, fast internet and SaaS access with the industry's most comprehensive cloud native security service edge (SSE) platform. Zscaler's Zero Trust Exchange helps agencies achieve the target goals of the Executive Order 14028 and resulting OMB mandates, CISA guidance and directives. ZIA Gov security products are currently utilized by over 100 federal agencies and federal systems integrators today in Zscaler's US-based FedRAMP Moderate and FedRAMP JAB High approved boundaries in support of the Cybersecurity and Infrastructure Security Agency (CISA) Trusted Internet Connection (TIC) 3.0 use case model for FedRAMP approved Policy Enforcement Point (PEP) capabilities. Delivered as a scalable SaaS platform from the world's largest security cloud, ZIA eliminates legacy network security solutions to stop advanced attacks and prevent data loss with a comprehensive zero trust TIC 3.0 compliant approach, fully supporting the CISA approved Branch Office, Remote Users, and Cloud use cases with: Best-in-class, consistent security for today's hybrid workforce: When you move security to the cloud, all users, apps, devices, and locations get always-on threat protection based on identity and context. Your security policy goes everywhere your users go. Secure cloud-based telework solution: Migrate to a cloud-first, cloud-secure Trusted Internet Connections (TIC) 3.0 zero-trust architecture that can accelerate cloud migration, enhance user productivity, and improve support for cloud applications. Lightning-fast access with zero infrastructure: Direct-to-cloud architecture ensures a fast, seamless user experience. This eliminates backhauling, improves performance and user experience, and simplifies network administration - with no physical infrastructure, ever. AI-powered protection from the world's largest security cloud: Inline inspection of all internet and SaaS traffic, including SSL decryption, with a suite of AI-powered cloud security services to stop ransomware, phishing, zero-day malware, and advanced attacks based on threat intelligence from 300 trillion daily signals. Simplified management: Using a cloud native security solution infused with AI, streamlined workflows, and business focused policy creation frees up valuable time for your team to focus on strategic goals. Zscaler Internet Access includes a comprehensive suite of AI-powered security and data protection services to help you stop cyberattacks and data loss. As a fully cloud-delivered SaaS solution, you can add new capabilities without any additional hardware or lengthy deployment cycles. The modules available as part of Zscaler Internet Access are: - Cloud Secure Web Gateway (SWG) - Cloud Access Security Broker (CASB) - Cloud Data Loss Prevention (DLP) - Cloud Firewall & IPS - Cloud Sandbox - Digital Experience Monitoring (ZDX) Zscaler will also provide our Zero Trust Exchange services at the FedRAMP Moderate level not only for federal agencies and service integrators, but state, local, education, and critical infrastructure as a fully authorized StateRAMP solution. All Zscaler's FedRAMP platforms are fully managed and supported by US Citizens and meet the ITAR, CJIS, and DFARS requirements and attestations. Zscaler, a Leader in the Gartner Magic Quadrant for Security Service Edge.

Next step

What the same authorization would cost you

The worksheet turns an impact level, an existing security posture and an organization size into a line-by-line budget, with the 3PAO fee split out.

Provenance and independence

Source: the FedRAMP Marketplace product feed, produced by the General Services Administration. The feed's own last-change stamp is September 3, 2026; this copy was taken on September 5, 2026.

GSA's disclaimers page states that FedRAMP content about a specific commercial product or service is provided for the information and convenience of the public and “does not constitute endorsement, recommendation, or favoring by the General Services Administration”. A listing here is a record of a certification status, not a judgment about the product.

FedRAMPCost.com is an independent cost reference. We are not affiliated with FedRAMP, the GSA, any provider listed on this page, or any assessment organization, and no provider pays to appear in this register.

DOC-REF: FRC-2026-04-28 / Updated 2026-04-28