Blog

ThreatModeler Achieves FedRAMP Moderate Authorization

Bringing continuous, automated threat modeling to federal agencies without slowing down the mission.

Reading Time

September 14, 2026

ThreatModeler Achieves FedRAMP Moderate Authorization

Author

ThreatModeler
The Threat Modeling Experts

We're excited to announce that ThreatModeler Nexus has achieved FedRAMP® Moderate authorization, sponsored by Knox. This milestone means federal agencies can now bring ThreatModeler's Secure Design Graph and threat modeling automations into environments handling controlled unclassified information (CUI) and other moderate-impact federal data with the same continuous, evolving threat modeling capability our commercial customers already rely on.

For agencies under pressure to build secure software faster, without static documentation piling up behind every release, this is the milestone that makes that possible inside an authorized boundary.

Meeting a Rigorous Federal Security Bar

FedRAMP exists to give agencies a standardized, trusted way to evaluate the security of cloud solutions before they touch government data. Reaching the Moderate baseline meant demonstrating compliance with the roughly 325 controls defined in NIST SP 800-53 Revision 5 for systems handling moderate-impact information validated through formal review by Knox.

"Achieving FedRAMP Moderate reflects our commitment to helping federal teams automate continuous threat modeling, without slowing down development. Agencies can now bring the Secure Design Graph and NexusAI into their most sensitive environments and know threat modeling intelligence is built into their security process, not bolted on.
Kevin Gallagher, CEO at ThreatModeler"

Why This Matters Now

Software development inside the government has changed as much as it has everywhere else. AI-assisted engineering is accelerating how federal systems are designed and shipped, and initiatives like CISA’s Secure by Design, CMMC, NIST800-53 Rev5 and the federal push toward continuous authorization are raising the bar on what "secure" has to mean from day one  not just at the point of an ATO package.

Most agencies still rely on static architecture reviews and point-in-time threat models that are outdated the moment the system changes again. That approach wasn't built for software that evolves every sprint, and it forces security and compliance teams to keep re-explaining the same architecture instead of building on what they already know.

ThreatModeler Nexus: A Living System of Record for Federal Security

ThreatModeler Nexus is built on two capabilities that make this authorization especially meaningful for government customers:

  • The Secure Design Graph captures architecture, security decisions, mitigations, and governance approvals as a shared knowledge layer so every new threat model, ATO package, or system change builds on what came before instead of starting over.
  • NexusAI puts that knowledge to work, automating threat modeling, system mapping, and reporting, and bringing recommendations directly into the tools agency teams already use.

Inside a FedRAMP Moderate boundary, that means agencies aren't just generating documentation for compliance they're building organizational security intelligence that compounds across every system, every review, and every re-architecture, and that stays current as missions and applications evolve.

What This Means for Federal Customers

  • Available now via FedRAMP Marketplace
  • No migration or re-architecture required for agencies already engaging with ThreatModeler
  • Supports agencies and contractors subject to FISMA moderate-impact requirements
  • Strengthens governance and compliance reporting inside an authorized environment
  • Reduces manual security effort for architecture and design review without slowing developers

Learn More

To see how ThreatModeler Nexus fits into your agency's ATO process and existing AppSec stack, request a demo or visit FedRAMP Marketplace.

Bringing continuous, automated threat modeling to federal agencies without slowing down the mission.

Show more

Blogs

Show more Resources
Start Left At Design: Lessons From a CISO Panel

Blog

Start Left At Design: Lessons From a CISO Panel

A CISO panel reveals why most "shift left" efforts still fail — and why real progress starts with design review, not later-stage scanning.

Read More
STRIDE Threat Modeling Methodology Explained (2026)

Blog

STRIDE Threat Modeling Methodology Explained (2026)

What is STRIDE threat modeling? Learn the six threat categories, real benefits and limitations, and how to apply STRIDE in 2026.

Read More
Secure by Design: Proactive Resilience in the era of AI Supply Chain Risk and MCP

Blog

Secure by Design: Proactive Resilience in the era of AI Supply Chain Risk and MCP

After an MCP vulnerability reportedly impacting over 150 million downloads, see why AI supply chain risk demands architectural threat modeling, not just reactive scanning.

Featured

Read More