# Qualys Secures FedRAMP High Authorization

Qualys announced that TotalAppSec is FedRAMP High authorized within the Qualys Government Platform, Class D package FR2231052341, giving federal agencies and contractors another application-security option for systems requiring a High-authorized boundary. CISA BOD 26-04 becomes operational on December 7, 2026, when FedRAMP vulnerability-detection requirements also become mandatory; offerings that do not meet the requirements risk losing authorization after March 7, 2027.

- Agencies and contractors should verify that TotalAppSec’s authorization boundary and capabilities cover their intended systems and application-security needs; the authorization alone does not establish fit for every deployment.
- Procurement and security teams evaluating FedRAMP offerings should account for the December 7, 2026 requirements milestone and the March 7, 2027 authorization risk for noncompliant offerings.
- Qualys advertised a webinar for October 7, 2026, which may provide an opportunity to review the offering and its authorization details.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** October 05, 2026

### Government Entities
- Cybersecurity and Infrastructure Security Agency (CISA)
- Federal Risk and Authorization Management Program (FedRAMP)

### Vendors
- Qualys (FedRAMP-authorized software provider)

### Sources
- [Qualys TotalAppSec Is Now FedRAMP High Authorized | Qualys](https://blog.qualys.com/product-tech/2026/10/05/totalappsec-fedramp-high-federal-application-security) - blog.qualys.com