Public information for the IronWiFi cloud service offering, per FedRAMP rule CDS-CSO-PUB under the Consolidated Rules for 2026.
| Provider | IronWiFi, LLC |
|---|---|
| Cloud Service Offering | IronWiFi Cloud RADIUS and Wi-Fi Authentication Platform |
| FedRAMP ID | FR2631154499 |
| Marketplace Status | Initial Implementation Phase, approved 12 August 2026 |
| Certification Type | FedRAMP 20x |
| Service Model | SaaS |
| Deployment Model | Public Cloud |
| Business Category | Cybersecurity & Risk Management; Network Management |
| UEI Number | TB1XW4HNNUG9 |
| Sales Contact | IronWiFi Sales, [email protected], 800-963-6221 |
| Security Contact | IronWiFi Security Team, [email protected] |
| Product Website | www.ironwifi.com |
| Next Ongoing Certification Report | Not yet applicable. The target date for the first Ongoing Certification Report is published here on initial certification, per CCM-OCR-NRD. |
| Independent Assessment Service | No FedRAMP Recognized independent assessment service is currently engaged for this offering. Independent verification today is the annual SOC 2 Type II audit; the report is available in the Trust Center. |
IronWiFi is a cloud-native SaaS providing RADIUS authentication (802.1X / EAP-TLS), captive portals, cloud PKI with SCEP certificate enrollment, and Wi-Fi identity threat detection (ITDR). It authenticates users and devices against enterprise identity providers including Microsoft Entra ID (commercial and GCC High), Google Workspace, Okta, and LDAP/Active Directory, across wireless hardware from any vendor whose access points and controllers support RADIUS and 802.1X. The service is vendor-neutral: agencies keep their existing access points and switches while IronWiFi provides the authentication, policy, and monitoring layer.
IronWiFi is in the Initial Implementation Phase: listed in the FedRAMP Marketplace and working toward a FedRAMP 20x Certification. The offering is not FedRAMP Authorized or FedRAMP Certified today, and nothing on this page should be read as a claim that it is.
Agency use case. Both apply. Direct Use: agencies run IronWiFi as the authentication, policy and monitoring layer for their own wireless and wired networks, inside a federal information system that receives an agency Authorization to Operate. Indirect Use: integrators and managed service providers include IronWiFi as a third-party information resource in offerings they deliver to federal customers.
| Done · 7 May 2026 | SOC 2 Type II report issued by Johanson Group LLP, unqualified opinion. This is the qualifying alternative security framework for a FedRAMP 20x Class A Certification, and it is renewed annually. |
|---|---|
| Done · 12 Aug 2026 | FedRAMP Marketplace listing approved for the Initial Implementation Phase. FedRAMP ID FR2631154499 assigned. |
| Done · 12 Aug 2026 | Public certification data published in human-readable and machine-readable form, validated against the FedRAMP Certification Package Overview schema. |
| In progress | Key Security Indicator evidence: control automation, monitoring coverage and platform hardening to the standard the certification package will attest to. |
| In progress · target September 2026 | FedRAMP Certification Package: Certification Package Overview, Security Decision Record covering every applicable rule, and the first Ongoing Certification Report. |
| Planned · target September 2026 | Submit the FedRAMP 20x Class A Certification application, as soon as the package is complete and self-verified. |
| Planned · decision by Q3 2027 | Select and schedule a FedRAMP Recognized independent assessment service for a higher certification class, which FedRAMP requires to be scheduled within two years of the Initial Implementation listing. |
Progress is measured against the milestones above and this section is updated at least quarterly, per FedRAMP rule MKT-IIP-DCP. Targets are goals rather than commitments and are reviewed at each update. Last updated 12 August 2026; next update by 12 November 2026. Questions from agencies: [email protected].
Every service below is part of the single multi-tenant IronWiFi platform that constitutes this cloud service offering (CDS-CSO-SVC). Names match those used in public marketing materials; each links to its product page.
Security categories: the FIPS 199 security categorization for this offering, approved 24 August 2026, is Confidentiality Moderate, Integrity Moderate, Availability Low - overall Moderate. It applies identically to every service listed above: all services share the same tenancy, data stores and credential material, so no service carries a different category. Scope and control detail are available from [email protected].
FedRAMP Certification Data, audit reports, control listings, and subprocessor listings are published in the IronWiFi Trust Center. The landing page and its Controls and Subprocessors sections are open, with no account required. Under Resources, the SOC 3 report, Data Processing Agreement, Terms of Service, and this FedRAMP Public Information package open directly via View. The SOC 2 Type II report is gated: select Request access on that resource; requests are reviewed and access is granted to the requesting email address under a non-disclosure agreement. Questions about a request, or federal agency requests that need a different route, go to [email protected].
All public FedRAMP Certification Data for this offering is retrievable without authentication, at stable URLs, by any HTTP client:
https://www.ironwifi.com/fedramp/ironwifi-fedramp-public.jsonhttps://www.ironwifi.com/fedramp/https://trust.ironwifi.com/doc/trust-zip?r=8a9wpl33zl9c7j1645r56https://www.ironwifi.com/dpaThe SOC 2 Type II report is released per person under a non-disclosure agreement and is deliberately not available programmatically; request access through the Trust Center resource or [email protected]. The inventory and history of federal agency users granted Trust Center access (CDS-TRC-AAI), and any party's log of its own Trust Center activity (CDS-TRC-ACL), are maintained in the Trust Center platform's access-request and viewer-activity records and are available to FedRAMP and to the party concerned on request to [email protected].
A dedicated Secure Configuration Guide for federal deployments is in preparation and will be linked here when published.
Machine-readable JSON (CDS-CSO-PUB)The JSON document is valid against the FedRAMP Certification Package Overview schema (2026-06-24) and is kept consistent with this page by an automated check in the site build.