Overview
**Certification Classes We Support: **
-
Class A (20x): a lightweight, fast entry to the federal market for non-sensitive use cases. We map your existing credentials, such as a SOC 2 Type II, a GovRAMP certification, or a FedRAMP Rev5 designation (including FedRAMP Ready), to Class A requirements, close the gaps, build the mini FedRAMP Certification Package, and keep you listed with quarterly continuous-monitoring (ConMon) reporting. Class A provides a clear path to Class B/C/D after adoption.
-
Class B: low-impact and Li-SaaS workloads (the workloads previously certified under the Low and Li-SaaS baselines). We reuse existing frameworks and artifacts, run an expedited gap assessment, and coach your team through the Certification Package.
-
Class C: moderate-impact workloads, the most common federal target for SaaS. We leverage your existing evidence to reduce Independent Verification and Validation (IVV) effort, with senior Independent Assessors taking you from readiness through full Certification efficiently.
-
Class D: high-impact, most-sensitive workloads (Rev5 today; FedRAMP is developing the 20x path for 2027). Our senior teams deliver deep, technical Independent Verification and Validation (IVV) focused on the controls that matter, rigorous validation without wasting your engineers' time.
How We Accelerate Your Journey Wherever you start, SecureIT accelerates the process by reusing frameworks and evidence you already have, running expedited gap assessments, and building your FedRAMP Certification Package for submission. After Certification, we keep you compliant through continuous monitoring.
To protect assessment independence, SecureIT does not serve as both advisor and Independent Assessor (IA) on the same cloud service offering.
Optional: SecureIT Continuous Compliance (SCC) is SecureIT's subscription for staying compliant after you're Certified. Rather than scrambling each year, your program runs continuously: we perform ongoing security monitoring, vulnerability management, and incident-response support; keep your FedRAMP Certification Package current as your system changes; provide Significant Change Notice (SCN) support; and produce the periodic and quarterly reporting FedRAMP requires to keep your listing active on the Marketplace. One predictable subscription, senior SecureIT staff, and no lapse in your Certification.
**Associated AWS Products and Services
- SecureIT's FedRAMP Independent Verification and Validation (IVV) and continuous-compliance services are offered in direct relation to eligible AWS products and AWS services. We assess and support cloud service offerings that are built on and deployed in Amazon Web Services, including workloads running in AWS GovCloud (US) and AWS Commercial Regions, as well as cloud products listed and sold by independent software vendors on AWS Marketplace. Our Independent Assessors work hands-on with the core AWS services that commonly define a FedRAMP Minimum Assessment Scope (MAS), including Amazon EC2, Amazon S3, Amazon RDS, Amazon VPC, AWS Identity and Access Management (IAM), AWS Key Management Service (KMS), AWS CloudTrail, AWS Config, Amazon GuardDuty, AWS Security Hub, and Amazon CloudWatch. These professional services help AWS customers and AWS Marketplace sellers achieve and maintain FedRAMP Certification for their AWS-hosted cloud service offerings.
Highlights
- Acceleration by reuse: We map your existing SOC 2 Type II, GovRAMP, or FedRAMP documentation to Class A requirements, so you are not rebuilding what you already have.
- Certified faster: We build your Certification Package and drive the steps required to get you Certified.
- SecureIT Continuous Compliance (SCC): Our subscription keeps you certified: continuous monitoring, vulnerability management, incident response support, package upkeep, and the quarterly reporting and reviews required to stay on the Marketplace.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Support
Vendor support
**Support Contacts **
Email: info@secureit.com
**Level of Support **
Every engagement is staffed by senior SecureIT FedRAMP Independent Assessors and led by a named engagement manager who serves as your primary point of contact throughout the project. Customers receive direct email and phone access to the SecureIT team during business hours. We acknowledge support inquiries within one business day and provide a substantive response or action plan within two business days. During active engagements, SecureIT provides scheduled status reviews, coordination with the FedRAMP program and any agency stakeholders as needed, and guidance through every phase: readiness, Independent Verification and Validation (IVV), Certification, and post-Certification continuous monitoring.
Customers who subscribe to SecureIT Continuous Compliance (SCC) receive ongoing support for security monitoring, vulnerability management, incident-response coordination, Significant Change Notice (SCN) support, and the periodic and quarterly reporting required to keep a FedRAMP listing active.