CMMC ANSWER ENGINE

Can a hosted SaaS application process or store CUI, and what does it need?

JWJil Wright, Lead CMMC Certified Assessor · Last verified 2026-05-14

This is one of the most common questions in CMMC because the CUI workflow increasingly runs through SaaS — file sharing, project tracking, ticketing, customer-facing portals. The legal foundation is DFARS 252.204-7012(b)(2)(ii)(D) and the operational guidance is in the DoW CIO's FedRAMP Authorization and Equivalency brief (Feb 2025).

What DFARS 252.204-7012 requires

"Contractors that use external cloud service providers that store, process, or transmit any covered defense information shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the FedRAMP Moderate baseline."

The clause sets a floor: FedRAMP Moderate baseline. Two paths satisfy the floor.

Path 1 — FedRAMP Authorized (Moderate or higher)

The Cloud Service Offering holds an Authority to Operate from the FedRAMP program at Moderate or High. Listed on the FedRAMP Marketplace. The contractor's burden:

  • Verify the CSO's authorization on marketplace.fedramp.gov.
  • Confirm the authorization covers the specific tier and service you intend to use.
  • Obtain and document the CSO's Customer Responsibility Matrix.
  • Reference the CSO and CRM in your SSP per the CMMC L2 Scoping Guide ESP Considerations section.

Path 2 — FedRAMP Moderate Equivalent

For CSOs that don't have an ATO, DoW provides an Equivalency path. Per the FedRAMP Authorization and Equivalency brief:

  • The CSO must achieve 100% compliance with the latest FedRAMP Moderate Baseline at the conclusion of an assessment conducted by a FedRAMP-recognized Third Party Assessment Organization (3PAO).
  • The 3PAO produces a Body of Evidence (BoE) including: System Security Plan, Information System Contingency Plan, Incident Response Plan, Configuration Management Plan, FIPS 199 categorization, Security Assessment Plan, Security Assessment Report (with risk exposure table, infrastructure scan results, web scan results, penetration test reports), Plan of Action and Milestones, and Continuous Monitoring Strategy.
  • The BoE is reviewed by DCMA DIBCAC and, for CMMC assessments, by the C3PAO.
  • Continuing operational POA&Ms after assessment are expected and acceptable.
  • Complete risk avoidance is required — there is no government sponsor and therefore no Authorizing Official who can officially accept risk on behalf of the CSO.
  • FedRAMP Moderate Equivalency does not confer FedRAMP Moderate Authorization. They are distinct.

Roles and responsibilities

PartyResponsibility
DIB Contractor (you)Ensures the CSO meets requirements; validates the BoE; provides the CRM to DIBCAC and C3PAO assessors; acts as the approver for using the CSO; confirms the CSP has an Incident Response Plan; ensures the CSP follows it; reports incidents per contract terms.
3PAOAssesses the CSO and produces the FedRAMP Moderate Equivalency package (BoE) for the contractor.
DCMA DIBCACReviews the CSP's BoE asserting to FedRAMP Moderate Equivalency; validates compliance with DFARS 252.204-7012 and 252.204-7020.
C3PAOFor CMMC assessments, reviews the CSP's BoE asserting to FedRAMP Moderate Equivalency; validates compliance with DFARS 252.204-7012 and 252.204-7020.

How to actually evaluate a SaaS for CUI handling

  1. Look up the CSO on the FedRAMP Marketplace. If it's authorized at Moderate or higher and the authorization covers the tier you intend to use, you're on Path 1.
  2. If not authorized, ask the vendor for their FedRAMP Moderate Equivalency documentation. The full BoE — not a summary, not a SOC 2 report. If the vendor doesn't have a BoE, the SaaS cannot lawfully hold your CUI under DFARS 7012.
  3. Obtain the Customer Responsibility Matrix. The CRM tells you which controls are the CSP's responsibility and which are yours.
  4. Confirm the on-premise infrastructure connecting to the CSP is in your CMMC scope. Per the L2 Scoping Guide, the OSA's on-premise infrastructure connecting to the CSO is assessed at Level 2 or Level 3 as applicable.
  5. Document the relationship in your SSP. Reference the CRM, the agreements, and the OSA-side responsibilities.

Common errors

  • Trusting vendor marketing claims about FedRAMP without verification. The FedRAMP Marketplace is the only authoritative source for authorization status.
  • Treating FedRAMP Equivalent as if it were FedRAMP Authorized. Both can satisfy DFARS 7012, but they are different paths with different documentation.
  • Accepting a FedRAMP Equivalency claim without the BoE. The BoE is the deliverable that DIBCAC and the C3PAO will review at your assessment.
  • Forgetting that on-premise infrastructure connecting to the CSP is in your scope. The CSP's authorization doesn't cover your endpoints, your network boundary, or your identity provider.
  • Assuming SOC 2 satisfies the requirement. SOC 2 and FedRAMP are different programs; SOC 2 does not satisfy DFARS 7012 for CUI in cloud services.

Sources

  • DoW CIO FedRAMP Authorization and Equivalency Brief (Feb 2025) — link
  • FedRAMP Moderate Equivalency Memo — link
  • DFARS 252.204-7012 — (b)(2)(ii)(D) — Cloud computing services for CDI — link
  • FedRAMP Marketplace — link
  • CMMC Assessment Scope — Level 2 (v2.13) — External Service Provider Considerations — link
Rulebook version: DFARS 252.204-7012; DoW FedRAMP Authorization & Equivalency Brief (Feb 2025); CMMC L2 Scoping Guide v2.13

Track every CUI-touching SaaS against your contract requirements.

The CMMC Compliance Engine includes the VRQ-01_Vendor_Risk_Register for tracking each SaaS vendor's FedRAMP authorization status, equivalency package, CRM availability, and the CUI categories the vendor processes under your contract.

Get the CMMC Compliance Engine
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.