Public Sector Solutions

Secure Government Networks. Zero Infrastructure.

Meet federal compliance requirements without deploying on-premise RADIUS servers. SOC 2 Type II attested cloud authentication with NIST 800-171 alignment, CJIS-ready controls, and US data residency.

SOC 2 Type II Attested · SAM.gov Active · 6 Global Data Center Regions

Government WiFi authentication requires meeting strict compliance frameworks including NIST 800-171, CJIS Security Policy, and FedRAMP. IronWiFi provides cloud-based RADIUS authentication with a SOC 2 Type II attestation, certificate-based 802.1X, MFA integration, comprehensive audit logging, and US data residency options for federal, state, and local government agencies.

How Does IronWiFi Map to Government Frameworks?

Built on SOC 2 Type II foundations with alignment to the frameworks your agency requires

SOC 2 Type II

Attested

Independent audit verification of security controls covering availability, confidentiality, and processing integrity across our entire platform.

NIST 800-171

Controls Mapped

Access control (3.1), audit and accountability (3.3), identification and authentication (3.5), and system protection (3.13) requirements addressed.

CJIS Security Policy

Policy Ready

Advanced authentication, encryption in transit and at rest, audit logging, and access control enforcement meeting CJIS requirements for criminal justice networks.

FedRAMP 20x

Marketplace Listed

Listed on the FedRAMP Marketplace since 12 August 2026 (FedRAMP ID FR2631154499, Initial Implementation Phase) and working toward a FedRAMP 20x Class A Certification, application targeted September 2026. Not FedRAMP Authorized or Certified today. Public certification data.

StateRAMP

Aligned

Meeting StateRAMP security requirements for state and local government cloud adoption with continuous monitoring and standardized security assessments.

FISMA

Controls Mapped

Security controls aligned with FISMA requirements and NIST SP 800-53 control families for federal information systems protection.

Which Government Agencies Use Cloud RADIUS?

Secure network authentication for every level of government

Federal Offices

Centralized authentication across multiple federal buildings and campuses with unified policy management

State & Local Agencies

Scalable authentication for city halls, DMVs, and county offices with StateRAMP-aligned security controls

Military Facilities

FIPS 140-2 compatible encryption and certificate-based authentication for defense installations

Courts & Justice

CJIS-compliant network access for courthouses and justice departments handling sensitive case data

Public Libraries

Secure patron WiFi with captive portal authentication, usage policies, and content filtering support

Government Contractors

NIST 800-171 compliant network authentication for contractors handling Controlled Unclassified Information

Why Cloud RADIUS for Government?

Eliminate the cost and complexity of on-premise authentication infrastructure

Eliminate On-Premise Servers

No RADIUS hardware to deploy, patch, or maintain. Reduce your IT footprint and operational overhead.

Reduce Attack Surface

Cloud-managed authentication means fewer exposed endpoints in your network perimeter.

Automated Compliance Reporting

Generate audit trails and compliance reports on demand for your security assessors and inspectors general.

Multi-Site Management

Manage authentication policies across all agency locations from a single console with role-based access.

Security Features Built for Government

Cloud security controls that meet the demands of public sector security

Certificate-Based Authentication

802.1X with EAP-TLS certificate authentication eliminates password-based vulnerabilities. Managed PKI with automated certificate lifecycle.

Multi-Factor Authentication

Integrate with your existing MFA provider. Support for TOTP, push notifications, and PIV/CAC smart card authentication.

Role-Based Access Control

Granular RBAC aligned with government organizational structures. Separate admin roles for network, security, and audit functions.

Comprehensive Audit Logging

Every authentication event logged with timestamp, source, result, and policy applied. Tamper-evident logs exportable to your SIEM.

Data Residency Options

Choose from 6 global data center regions. US government clients can enforce US-only data residency for all authentication data.

FIPS 140-2 Compatible Encryption

TLS 1.2/1.3 encryption in transit, AES-256 encryption at rest. All cryptographic operations use FIPS-validated modules.

How Does the Security Architecture Work?

End-to-end encrypted authentication with isolated tenant environments

Agency Devices

Laptops, phones, IoT

Access Points

802.1X / RADIUS

IronWiFi Cloud

Encrypted RADIUS

Identity Provider

AD / Microsoft Entra ID / Okta

Encryption Everywhere

TLS 1.2/1.3 in transit, AES-256 at rest. No plaintext credentials ever traverse the network.

Isolated Tenant Environments

Each agency gets a logically isolated environment. No cross-tenant data access is possible.

Redundant Infrastructure

Multi-region failover with high-availability SLA. Authentication continues even during maintenance windows.

SIEM Integration

Export authentication logs to Splunk, Elastic, or your agency SIEM via webhooks and syslog.

Simplified Government Procurement

We understand government buying cycles and can work with your contracting office

Marketplaces & Contract Vehicles

SAM.gov Active (UEI TB1XW4HNNUG9, CAGE issued). Listed on the AWS, Cisco, and Oracle marketplaces. SEWP and OMNIA available through an approved federal reseller on named opportunities. Section 889 compliant service.

Government Pricing

Billed annually for US federal, state, and local agencies: $15 per user per month for employee and device 802.1X; $30 per access point per month for guest WiFi (10-AP minimum); WiFi ITDR $18,000, $54,000, or $180,000 per year for 1,000, 5,000, or 25,000 monitored identities. Base year plus option years at a held rate. Volume pricing for multi-site or multi-agency rollouts on a named opportunity.

Dedicated Government Support

Priority support with US-based engineers. Dedicated account management for agency deployments with SLA-backed response times.

Federal Pilot, Under the Micro-Purchase Threshold

$14,400 fixed for 12 months, one site: up to 80 users on 802.1X, or up to 40 access points on guest WiFi. Includes EAP-TLS / 802.1X and RADIUS device-admin login, Entra ID, Okta or Google Workspace integration, certificate enrollment, onboarding, standard support, and a 120-day WiFi ITDR evaluation for up to 1,000 identities. Below the $15,000 federal micro-purchase threshold (FAR 2.101). Ships with the SOC 2 Type II report and our FedRAMP public certification data for your ISSO review. One pilot per agency. Expansion and any production ITDR subscription are priced at the Government rates above and acquired under your agency's procurement procedures.

Request the pilot · Download the capability statement (PDF)

Government-Specific Questions

Common questions from public sector IT teams

Is IronWiFi FedRAMP authorized?

Not yet. IronWiFi is listed on the FedRAMP Marketplace (FedRAMP ID FR2631154499, Initial Implementation Phase since 12 August 2026) and is working toward a FedRAMP 20x Class A Certification, application targeted September 2026. Our SOC 2 Type II report (unqualified opinion, May 2026) is the qualifying framework for Class A. We are not FedRAMP Authorized or Certified today.

Where is government data stored?

We operate across 6 global data center regions. US government clients can select US-only data residency to ensure authentication logs and user data never leave US jurisdiction.

Does IronWiFi meet CJIS requirements?

Yes. We support the authentication, encryption, audit logging, and access control requirements of the CJIS Security Policy for criminal justice information access.

What procurement vehicles are available?

SAM.gov Active (UEI TB1XW4HNNUG9, CAGE issued). Listed on the AWS, Cisco, and Oracle marketplaces. On a named opportunity we transact through an approved federal reseller for SEWP or OMNIA. Standard purchase orders and micro-purchase thresholds supported. A fixed-price Federal Pilot at $14,400 for 12 months (up to 80 users, or up to 40 guest access points, one site) sits under the $15,000 micro-purchase threshold.

Do we need security clearances?

No clearances required. IronWiFi is a commercial cloud service. Your agency maintains full control of access policies, and our support staff undergoes background checks.

Can you integrate with our identity provider?

Yes. We integrate with Active Directory, Microsoft Entra ID, Okta, and other SAML/LDAP providers commonly used in government, enabling SSO and centralized identity management.

Getting Started

From Signup to Live: Your Onboarding Path

A clear, step-by-step path — no surprises, no consultants, no complexity.

Time to value: Pilot in 1 week; full ATO process timeline varies by agency
1

Sales call: compliance framework (NIST 800-53, FedRAMP, CJIS), user categories

Sales / Compliance 30 min
2

Create account, select compliant data region

IT 5 min
3

Configure SSID 1: Staff — WPA-Enterprise, PIV/CAC card auth or Microsoft Entra ID GovCloud

IT 20 min
4

Configure SSID 2: Citizen/Public — captive portal with terms acceptance

IT 20 min
5

Configure SSID 3: Guest — isolated, time-limited access

IT 10 min
6

Enable comprehensive audit logs (all auth events)

IT / Compliance 10 min
7

Configure OpenRoaming for inter-agency roaming (if applicable)

IT 15 min
8

Network segmentation review and sign-off

Security Officer 20 min
9

Pilot in one facility

IT 1 day
10

ATO/IATO documentation (SOC 2 cert, architecture docs)

IronWiFi + Agency 15 min
11

Full deployment

IT 1 week

Key Integrations

Microsoft Entra ID GovCloud Active Directory PIV/CAC smartcard infrastructure

Ready to get started?

Let's walk through it together

Our onboarding team will guide you through each step — most customers are live within a day.

Setup in minutes  ·  Cancel anytime

Talk to a WiFi Identity Specialist

  • Walk through a deployment for your industry
  • See how similar organizations use IronWiFi
  • Get a custom setup plan

Set up in under 30 minutes