- FedRAMP High authorization requires adherence to over 400 security controls (nearly 100 more than Moderate level).
- Only 16% of services listed on the FedRAMP Marketplace have achieved the High designation.
Experts would likely conclude that New Relic's pursuit of FedRAMP High and DoD IL4 authorizations is a high-stakes, resource-intensive strategic move to position itself as an indispensable tool for federal agencies handling highly sensitive data.
New Relic's High-Stakes Bet on Securing the Nation's Sensitive Data
SAN FRANCISCO, CA – June 23, 2026
New Relic, a prominent player in the intelligent observability space, has formally announced its commitment to achieving the federal government's most stringent cloud security authorizations: FedRAMP High and the Department of Defense (DoD) Impact Level 4 (IL4). The move, which builds on its existing FedRAMP Moderate status, signals a deliberate and resource-intensive strategy to embed its platform within the nation's most sensitive, unclassified data ecosystems.
This isn't merely a compliance upgrade; it's a strategic gambit to become an indispensable tool for federal agencies navigating the complexities of cloud migration, cybersecurity, and the burgeoning era of artificial intelligence. By pursuing these top-tier authorizations on AWS GovCloud, the San Francisco-based company is positioning itself to monitor the digital infrastructure that underpins everything from law enforcement and healthcare to critical defense operations.
The High Bar for Federal Compliance
Understanding the gravity of New Relic's commitment requires looking beyond the acronyms. The Federal Risk and Authorization Management Program (FedRAMP) is the standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by the U.S. government. While the company achieved the FedRAMP Moderate baseline in 2020, the leap to the High baseline is a monumental undertaking.
FedRAMP High is reserved for systems housing the government's most sensitive, unclassified data, where a breach could lead to severe or catastrophic consequences, including threats to public safety or national security. It mandates adherence to over 400 security controls derived from the National Institute of Standards and Technology (NIST) SP 800-53 framework—nearly 100 more controls than the Moderate level. These controls govern everything from advanced encryption and multi-layered physical security to stringent personnel screening and real-time threat intelligence.
Simultaneously, the pursuit of DoD Impact Level 4 (IL4) authorization targets the specific needs of the Department of Defense. IL4 is designed to protect Controlled Unclassified Information (CUI), a broad category that includes everything from export-controlled technical data and critical infrastructure information to sensitive law enforcement and defense contract details. Achieving IL4 requires not only meeting a rigorous set of controls often aligned with FedRAMP High but also ensuring data is stored exclusively within the U.S. and handled only by vetted U.S. persons.
This dual pursuit places the observability firm in an exclusive category. According to industry analysis, only about 16% of the services listed on the FedRAMP Marketplace have achieved the High designation, a testament to the significant technical, financial, and operational investment required.
A Strategic Play for a High-Stakes Market
New Relic’s push for elevated compliance is a clear-eyed business strategy aimed at capturing a larger share of the lucrative and expanding public sector cloud market. With the FedRAMP Authorization Act codifying the program into law and recent White House directives pushing agencies to prioritize authorized services, holding a FedRAMP High authorization is becoming a non-negotiable entry ticket for high-value government contracts.
By meeting this high bar, the company can differentiate itself in a competitive observability landscape that includes heavyweights like Datadog, Splunk, and Dynatrace, many of whom are also navigating their own federal compliance journeys. Offering an IL4-compliant solution on AWS GovCloud directly addresses the needs of the sprawling defense industrial base and DoD agencies, a market segment with uniquely stringent security demands and deep budgets.
“As the public sector transitions from legacy data centers to dynamic, cloud-native architectures, the complexity of their digital environments has reached an inflection point,” said New Relic CTO Michael Frendo in the announcement. “To support the government’s most sensitive and mission-essential workloads, agencies need more than just visibility—they need a secure, intelligent orchestration layer.”
This commitment reinforces the company's long-term focus on public sector clients. To navigate the arduous authorization process, New Relic has re-enlisted proven partners. Coalfire Systems, a premier FedRAMP advisory firm that assisted with its initial Moderate authorization, will provide strategic guidance. Schellman Compliance, a leading FedRAMP Third-Party Assessment Organization (3PAO), will conduct the rigorous independent audit required for approval.
De-Risking the Future of Government AI
The timing of this initiative aligns perfectly with another major government imperative: the responsible adoption of artificial intelligence. As agencies begin to experiment with and deploy AI and Large Language Models (LLMs) for mission-critical tasks, the need for secure and comprehensive monitoring has become paramount. An observability platform that is itself compliant with FedRAMP High and DoD IL4 provides the trusted foundation necessary for this adoption.
For government CIOs and security officers, the risks associated with AI are substantial. They include the potential for LLMs to leak sensitive CUI, the threat of adversarial attacks that could manipulate model behavior, and the challenge of ensuring AI systems perform reliably and ethically. This is where a highly compliant observability solution becomes critical.
With its AI Observability tools, New Relic aims to provide agencies with end-to-end visibility across the entire AI stack. This enables them to monitor LLM inputs and outputs for potential data spillage, track model performance against benchmarks, identify unapproved or rogue AI instances operating on their networks, and optimize the significant cloud resources that AI workloads consume. Providing these capabilities within an IL4-compliant environment means that even the most security-conscious defense and intelligence agencies can innovate with AI without compromising their security posture.
By committing to the government's highest security standards, New Relic is not just selling a software tool; it is offering a foundational layer of trust. This enables public sector customers to accelerate their modernization efforts, from cloud migrations to AI deployments, with the confidence that their most vital digital operations are visible, secure, and under control.
