CMMC Ready Now
Compliance Guide

FedRAMP Equivalency for CUI in the Cloud: What Qualifies and What Does Not

If a cloud service stores, processes or transmits your CUI, it has to be FedRAMP Moderate authorized or meet the DoD's definition of FedRAMP Moderate equivalency. That definition is narrower than many vendor sales pages suggest, and if your CSP does not meet it, you cannot close the gap with your own controls.

This week DLA's Small Business Resource Center published a CMMC FAQ that starts with the basic question of FCI versus CUI. It is the right place to start, because the cloud rule only applies once CUI is in the picture. This post covers what comes next: once you know you hold CUI, which cloud services can hold it?

Where Does the FedRAMP Requirement for CUI Actually Come From?

It comes from two sources that point to the same standard.

The first is DFARS 252.204-7012, paragraph (b)(2)(ii)(D). When a contractor uses an external cloud service provider to store, process or transmit covered defense information, the contractor must require and ensure that the CSP meets security requirements equivalent to the FedRAMP Moderate baseline. The CSP must also comply with paragraphs (c) through (g) of the clause: cyber incident reporting, malicious software submission, media preservation, access for forensic analysis and cooperation with damage assessment.

The second is the CMMC Program rule at 32 CFR Part 170. The Level 2 assessment requirements say that if an organization uses an external CSP to process, store or transmit CUI, the offering must be FedRAMP Moderate authorized or meet FedRAMP Moderate equivalency under DoD policy. So the cloud question comes up in your Level 2 assessment no matter whether you are on a self-assessment or a C3PAO certification path.

In practice the obligation belongs to you. The clause says the contractor “shall require and ensure.” Your assessor will judge your evidence, not the vendor's marketing claims.

What Does "FedRAMP Moderate Equivalent" Mean After the 2023 DoD CIO Memo?

On December 21, 2023, the DoD CIO issued a memo titled “Federal Risk and Authorization Management Program Moderate Equivalency for Cloud Service Provider's Cloud Service Offerings.” It replaced the older, looser readings of “equivalent.” The main points:

  • 100 percent of the FedRAMP Moderate baseline. The cloud service offering must fully implement the current FedRAMP Moderate baseline controls. A partial implementation does not count, and neither does “substantially similar.”
  • Assessed by a FedRAMP-recognized 3PAO. A self-attestation does not qualify. An assessment by a firm outside the FedRAMP 3PAO program does not qualify either.
  • A full body of evidence. The CSP should be able to give the contractor its System Security Plan, Security Assessment Plan, Security Assessment Report, Plan of Action and Milestones, and a Customer Responsibility Matrix.
  • No open baseline deficiencies. Because full implementation is required, a 3PAO report that still shows open POA&M items against baseline controls does not establish equivalency.
  • Evidence available on request. The contractor must be able to produce the body of evidence for the DoD, which includes the assessment that evaluates your CMMC status.

Read the memo itself rather than a summary. Parts of it are open to interpretation, and some of how assessors apply it in edge cases is still developing through practice rather than written guidance.

Which Cloud Services Qualify, and Which Do Not?

These generally qualify:

  • An offering listed as FedRAMP Moderate Authorized on the FedRAMP Marketplace.
  • An offering listed as FedRAMP High Authorized. The High baseline includes everything in the Moderate baseline.
  • An offering that meets all the equivalency criteria in the 2023 DoD CIO memo, backed by a complete body of evidence.

In every case, the CSP also has to be contractually bound to the 7012 requirements in paragraphs (c) through (g). An authorization does not create that obligation. Your contract with the CSP does.

These do not qualify on their own:

  • FedRAMP Ready. This status means a readiness assessment was done. It is not an authorization.
  • FedRAMP In Process. The offering is working toward authorization and has not received it.
  • SOC 2 reports, ISO/IEC 27001 certification, or a vendor's statement of alignment with NIST SP 800-171. These may be useful due-diligence documents. None of them is FedRAMP Moderate equivalency.
  • A different tier of the same vendor's product. Authorizations apply to a specific offering and its authorization boundary. Vendors often sell a commercial tier and a government tier as separate offerings. Look up the exact offering you are using, not just the vendor name.

This is not settled: FedRAMP is changing its authorization process, including the FedRAMP 20x initiative. How new authorization paths will map to the DoD's equivalency expectations over time is not fully resolved in published DoD guidance. Until DoD says otherwise, a Moderate or High authorization listed on the Marketplace is the lowest-risk path.

Does Every External Provider in My Environment Need FedRAMP?

No. The FedRAMP requirement is triggered by a cloud service provider that processes, stores or transmits CUI. It does not apply to every vendor that touches your environment.

The CMMC rule separates CSPs from the wider category of External Service Providers. For example, a managed service provider that administers your systems but does not host CUI in its own cloud offering is not held to FedRAMP. Its services instead fall within the scope of your assessment, and your SSP must document them. The final rule also narrowed the FedRAMP requirement so that it depends on CUI. An ESP that handles only Security Protection Data, such as logs or configuration data, is assessed as part of your environment and is not held to FedRAMP for that data. Scoping edge cases still come up, so document your reasoning in your SSP.

If you handle only FCI and are at Level 1 under FAR 52.204-21, the DFARS 7012 cloud equivalency requirement does not apply to that FCI. That is why the FCI versus CUI determination in this week's DLA FAQ matters so much. It sets the scope of everything that follows.

If My CSP Qualifies, Am I Done With the Cloud Controls?

No. A FedRAMP authorization covers the provider's side of the shared responsibility model. You still own your side, and your assessor will check it. The Customer Responsibility Matrix tells you which controls you inherit, which you share and which are entirely yours. Common areas where contractors fall short:

  • AC.L2-3.1.1 (Authorized Access Control): You still define and enforce who and what can reach CUI in the tenant.
  • IA.L2-3.5.3 (Multifactor Authentication): MFA settings in your tenant are usually your responsibility, not the provider's.
  • SC.L2-3.13.11 (CUI Encryption): If encryption protects the confidentiality of CUI, it must use FIPS-validated cryptography. Confirm the validated modules are in use in your configuration.
  • AU.L2-3.3.1 (System Auditing): The provider may produce logs, but retaining and reviewing them is often on you.
  • IR.L2-3.6.2 (Incident Reporting): Your incident process needs to account for events inside the CSP's environment and for DFARS 7012 reporting.
  • CA.L2-3.12.4 (System Security Plan): Your SSP should name the CSP, the specific offering, its authorization status or equivalency basis, and how inherited controls map to your environment.

Assessors will not accept “the cloud handles it.” They will ask you to show the CRM, point to the specific inherited control and show your own implementation for the customer-owned portion.

Will the CMMC Reforms in the News Change the Cloud Requirement?

Nothing reported this week changes the cloud standard. Federal News Network's interview with Cyber AB CEO Matthew Travis on CMMC reform discusses assessment logistics, such as allowing some assessments to be run by two-person teams, as a way to lower assessment costs. That affects how assessments are carried out. It does not affect the FedRAMP Moderate equivalency requirement, which comes from DFARS 252.204-7012 and 32 CFR Part 170.

Program timelines and phasing are still in flux, so do not plan your cloud decisions around an expected enforcement date. The 7012 cloud requirement already applies to contracts that include the clause, whatever the status of the CMMC rollout.

Not Sure Whether Your Cloud Provider Meets the Bar?

Before your next assessment, get the Customer Responsibility Matrix for every cloud offering that touches CUI and map it line by line in your SSP. Book a free 30-minute call with Rick and CMMC Ready Now can walk you through that mapping.

Book a Free Call with Rick

Frequently Asked Questions

Does my cloud provider need to be FedRAMP authorized to store CUI?

Your cloud provider must be FedRAMP Moderate authorized or meet FedRAMP Moderate equivalency as defined by the DoD CIO's December 2023 memo. This comes from DFARS 252.204-7012(b)(2)(ii)(D) and is enforced in CMMC Level 2 assessments under 32 CFR Part 170. The provider must also be contractually bound to the clause's incident reporting and forensic cooperation requirements.

Does FedRAMP Ready or FedRAMP In Process satisfy CMMC Level 2?

No. FedRAMP Ready means only that a readiness assessment was completed, and In Process means authorization has not been granted. Neither status meets the FedRAMP Moderate authorized or equivalent standard for storing, processing or transmitting CUI.

What does FedRAMP Moderate equivalency require?

Under the 2023 DoD CIO memo, the cloud offering must implement 100 percent of the current FedRAMP Moderate baseline, verified by a FedRAMP-recognized 3PAO. The provider must be able to supply a body of evidence that includes the SSP, assessment plan, assessment report, POA&M and a Customer Responsibility Matrix. Open deficiencies against baseline controls prevent a finding of equivalency.

Is a SOC 2 report or ISO 27001 certificate enough for CUI in the cloud?

No. SOC 2 and ISO/IEC 27001 are useful for vendor due diligence, but neither is FedRAMP Moderate authorization or DoD-defined equivalency. A C3PAO will look for FedRAMP authorization or a body of evidence that meets the equivalency memo.

Does my managed service provider need FedRAMP?

Not if it does not store, process or transmit CUI in its own cloud offering. Under the CMMC rule, an external service provider that is not a CUI-handling CSP is assessed as part of your environment and documented in your SSP (CA.L2-3.12.4). The FedRAMP requirement applies to cloud service providers that handle CUI.

If my cloud provider is FedRAMP Moderate authorized, am I compliant?

Not automatically. The authorization covers the provider's responsibilities, and you still own the customer-side controls listed in the Customer Responsibility Matrix. These often include access control (AC.L2-3.1.1), multifactor authentication (IA.L2-3.5.3), FIPS-validated encryption (SC.L2-3.13.11) and audit log review.

Sources

  • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting (acquisition.gov)
  • DoD CIO memorandum, “Federal Risk and Authorization Management Program Moderate Equivalency for Cloud Service Provider's Cloud Service Offerings,” December 21, 2023 (dodcio.defense.gov)
  • 32 CFR Part 170, Cybersecurity Maturity Model Certification (CMMC) Program (ecfr.gov)
  • NIST SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations (csrc.nist.gov)
  • FedRAMP Marketplace (marketplace.fedramp.gov)
  • Defense Logistics Agency, “CMMC Frequently Asked Questions and Answers” (dla.mil)
  • Federal News Network, “Cyber AB's Matt Travis on CMMC reform” (federalnewsnetwork.com)