Updated September 29, 2026
A file-sharing vendor tells you it's "FedRAMP compliant because we run on AWS GovCloud." Your engineers like the tool. Can you put your defense customers' drawings in it?
Not on that answer. The drawings, specs, and technical data the government marks as sensitive are called CUI (controlled unclassified information). Your defense contracts carry a clause, DFARS 252.204-7012, that says any outside cloud service holding that information must meet the security level of FedRAMP Moderate. FedRAMP is the government's security approval program for cloud services; Moderate is the middle of its three tiers. The same clause requires the service to report cyber incidents to DoD, hand over any malware it finds, keep copies of affected systems, and let DoD investigate. (DFARS 252.204-7012, paragraph (b)(2)(ii)(D), which points to paragraphs (c) through (g).)
Put CUI in a tool that doesn't qualify and you're out of step with a clause you already signed. An assessor will find it on the first question about where files live, and you'll have to move everything anyway.
The approval has to belong to the product you're buying, not to whatever it runs on. GovCloud, Amazon's government data-center region, has its own authorization. That covers Amazon's buildings and servers. It says nothing about the vendor's software, its admins, its support staff, or where it sends your files for virus scanning.
Two ways a product qualifies
The simple one is its own FedRAMP Moderate (or High) authorization, listed on the FedRAMP Marketplace, the government's public list of approved services. Search the product name. "In process" on the Marketplace means not yet authorized. Check the exact offering, too: CrowdStrike's government Falcon platform is listed, its commercial cloud isn't.
The other is "equivalent," and DoD's December 21, 2023 memo sets a hard bar for it. An independent assessment firm recognized by FedRAMP (called a 3PAO, third-party assessment organization) tests the product against the full Moderate requirement list, and the product must meet 100% of it. Problems that assessment finds can't be parked on a to-do list; they have to be fixed before the vendor claims equivalency. The vendor then owes you the paperwork behind it: its system security plan, the assessment plan, and the assessor's report. DoD equivalency memo
A SOC 2 report, an ISO certificate, or a "FedRAMP-ready" badge is none of those things. They're real security reports; they're just not this one.
The email to send
Copy this as written. The technical phrasing is on purpose: a vendor with a real answer will recognize every item.
Subject: FedRAMP basis for [product]
We're evaluating [product] for data covered by DFARS 252.204-7012. Please send:
- The FedRAMP Marketplace link for [product] at Moderate or higher, or, if you claim equivalency under the DoD memo of December 21, 2023, the name of your 3PAO, the assessment date, and confirmation that all Moderate controls were met with no open assessment POA&Ms.
- Your customer responsibility matrix for that offering.
- The contract language in which you agree to DFARS 7012 paragraphs (c) through (g).
- A list of subprocessors and services that receive customer data: backups, logs, support tools, malware scanning.
If you can't provide items 1 or 3, please tell us so we can plan accordingly.
A vendor with a real answer replies in a day or two with links. A vendor without one sends a two-page letter about its commitment to security. You'll know which you got.
When the answer is no
Keep the tool out of CUI work, and make that true in practice. A "no CUI" rule falls apart the first time an engineer pastes a part number and tolerance into a notes field or attaches a drawing to a support request. Either block uploads in the tool or give people an approved place for that work.
When the answer is yes, save the email thread, the Marketplace link or equivalency letter, and the customer responsibility matrix in one folder named for the product. That matrix is the vendor's chart of which security jobs it handles and which stay with you. Work through it: every row marked "customer" is yours to do and prove. How to read one
For Microsoft 365 specifically, the question becomes which of Microsoft's government versions to buy (Commercial, GCC, or GCC High), and how much each one carries for you. For Google Workspace, it's the edition and the requirements Google handles.
