What does FedRAMP Moderate or equivalent mean for my CUI cloud?

The product itself needs a FedRAMP Moderate listing, or a 3PAO assessment showing 100% of the baseline. "Hosted on GovCloud" is neither. The email to send the vendor.

Evaluate the service you buy. Underlying infrastructure. Offered application. Customer responsibilities. Working guide.
In this guide

Updated September 29, 2026

A file-sharing vendor tells you it's "FedRAMP compliant because we run on AWS GovCloud." Your engineers like the tool. Can you put your defense customers' drawings in it?

Not on that answer. The drawings, specs, and technical data the government marks as sensitive are called CUI (controlled unclassified information). Your defense contracts carry a clause, DFARS 252.204-7012, that says any outside cloud service holding that information must meet the security level of FedRAMP Moderate. FedRAMP is the government's security approval program for cloud services; Moderate is the middle of its three tiers. The same clause requires the service to report cyber incidents to DoD, hand over any malware it finds, keep copies of affected systems, and let DoD investigate. (DFARS 252.204-7012, paragraph (b)(2)(ii)(D), which points to paragraphs (c) through (g).)

Put CUI in a tool that doesn't qualify and you're out of step with a clause you already signed. An assessor will find it on the first question about where files live, and you'll have to move everything anyway.

The approval has to belong to the product you're buying, not to whatever it runs on. GovCloud, Amazon's government data-center region, has its own authorization. That covers Amazon's buildings and servers. It says nothing about the vendor's software, its admins, its support staff, or where it sends your files for virus scanning.

Two ways a product qualifies

The simple one is its own FedRAMP Moderate (or High) authorization, listed on the FedRAMP Marketplace, the government's public list of approved services. Search the product name. "In process" on the Marketplace means not yet authorized. Check the exact offering, too: CrowdStrike's government Falcon platform is listed, its commercial cloud isn't.

The other is "equivalent," and DoD's December 21, 2023 memo sets a hard bar for it. An independent assessment firm recognized by FedRAMP (called a 3PAO, third-party assessment organization) tests the product against the full Moderate requirement list, and the product must meet 100% of it. Problems that assessment finds can't be parked on a to-do list; they have to be fixed before the vendor claims equivalency. The vendor then owes you the paperwork behind it: its system security plan, the assessment plan, and the assessor's report. DoD equivalency memo

A SOC 2 report, an ISO certificate, or a "FedRAMP-ready" badge is none of those things. They're real security reports; they're just not this one.

The email to send

Copy this as written. The technical phrasing is on purpose: a vendor with a real answer will recognize every item.

Subject: FedRAMP basis for [product]

We're evaluating [product] for data covered by DFARS 252.204-7012. Please send:

  1. The FedRAMP Marketplace link for [product] at Moderate or higher, or, if you claim equivalency under the DoD memo of December 21, 2023, the name of your 3PAO, the assessment date, and confirmation that all Moderate controls were met with no open assessment POA&Ms.
  2. Your customer responsibility matrix for that offering.
  3. The contract language in which you agree to DFARS 7012 paragraphs (c) through (g).
  4. A list of subprocessors and services that receive customer data: backups, logs, support tools, malware scanning.

If you can't provide items 1 or 3, please tell us so we can plan accordingly.

A vendor with a real answer replies in a day or two with links. A vendor without one sends a two-page letter about its commitment to security. You'll know which you got.

When the answer is no

Keep the tool out of CUI work, and make that true in practice. A "no CUI" rule falls apart the first time an engineer pastes a part number and tolerance into a notes field or attaches a drawing to a support request. Either block uploads in the tool or give people an approved place for that work.

When the answer is yes, save the email thread, the Marketplace link or equivalency letter, and the customer responsibility matrix in one folder named for the product. That matrix is the vendor's chart of which security jobs it handles and which stay with you. Work through it: every row marked "customer" is yours to do and prove. How to read one

For Microsoft 365 specifically, the question becomes which of Microsoft's government versions to buy (Commercial, GCC, or GCC High), and how much each one carries for you. For Google Workspace, it's the edition and the requirements Google handles.

Mock assessment

Know which of your cloud tools can hold CUI.

Garde1 records each service's FedRAMP basis in your scope, flags stale or missing evidence, and carries it into your SSP and mock assessment.

Or start a 14-day trial

HOSTED ON FEDRAMP MODERATE AWS · ITAR-AWARE