A cloud platform can have strong security features and still fail the test for handling Controlled Unclassified Information (CUI). For DoD Contractors, Cybersecurity Maturity Model Certification and CMMC Level 2 FedRAMP verification require proof that each cloud service touching CUI meets the Department of Defense standard, not a vendor’s general security claim.
I have found that the hard part is rarely choosing a familiar cloud brand. The hard part is tracing where CUI travels, identifying the exact service offering, and collecting evidence that will stand up to a CMMC assessment.
Use this checklist to review your cloud environment before CUI reaches Microsoft 365, a hosted application, backup platform, managed endpoint tool, or support portal.
Key Takeaways
- A cloud service that stores, processes, or transmits CUI must be FedRAMP Moderate Authorized or meet the DoD’s FedRAMP Moderate equivalency requirements.
- FedRAMP authorization applies to a specific cloud offering, not every product a Cloud Service Provider sells.
- CMMC Level 2 covers your contractor environment and its implementation of NIST SP 800-171 requirements. Cloud authorization does not transfer those responsibilities to you.
- A complete evidence package should include the service’s authorization or equivalency proof, shared-responsibility details, data-flow records, and operational evidence.
- Requirements, assessment guidance, and cloud authorization status can change. Review them before making a contract, architecture, or scope decision.
CMMC Level 2 FedRAMP Requirements Start With CUI Scope
CMMC Level 2 aligns with the 110 Security Controls in NIST SP 800-171 Revision 2. Its purpose is to protect CUI in the Defense Industrial Base. For organizations across the DIB, your cloud verification effort starts with one practical question: does this service ever touch CUI?
The answer includes more than a file repository. CUI can appear in email attachments, Teams chats, SharePoint sites, help-desk tickets, engineering collaboration spaces, mobile-device backups, security logs, and remote-support sessions. A cloud service also comes into scope when it processes CUI metadata or protects a system that handles CUI.
The DoD’s Technical Application of CMMC Requirements states that a Cloud Service Offering that processes, stores, or transmits CUI must be FedRAMP Moderate Authorized or meet the DoD’s FedRAMP Moderate equivalency requirements. That rule applies to the particular offering, not a provider’s marketing category.
For example, a provider may offer a FedRAMP-authorized government cloud and a separate commercial environment. The commercial environment doesn’t inherit the government environment’s authorization. You must verify the precise tenant type, service name, region, support model, and subscription configuration your organization will use.

I recommend treating CUI scope as an architecture exercise, not a questionnaire. Map the people, devices, applications, integrations, and support channels around each CUI workflow. This step often exposes an overlooked risk, such as an unmanaged file-transfer tool or a backup copy stored outside the approved environment.
A FedRAMP Moderate cloud service can support a compliant CUI environment, but it does not make the contractor’s users, endpoints, configurations, or internal processes compliant by default.
FedRAMP Moderate Authorization and Equivalency Are Different
FedRAMP and CMMC address connected but different responsibilities. FedRAMP evaluates the security posture of a cloud service offering against a federal baseline built upon NIST SP 800-53 controls, which can lead to an official Authorization to Operate. CMMC evaluates the contractor’s practices and processes for protecting Federal Contract Information or CUI.
For CUI cloud use, the cleanest path is a current FedRAMP Moderate Authorization, or a higher authorization level, for the exact service offering. You can validate an offering’s status through the FedRAMP Marketplace and retain the verification date in your compliance records.
A service may also meet DoD FedRAMP Moderate equivalency without holding a formal FedRAMP Authorization. However, FedRAMP Equivalency is not a casual claim of similar security. It requires a documented, independently assessed body of evidence that meets the DoD’s current criteria.
Schellman’s explanation of FedRAMP Moderate equivalency describes the distinction well: equivalency does not grant a FedRAMP authorization. It gives a contractor a separate path to verify that the service meets the required baseline for CUI use.
| Verification path | What you need to confirm | What to retain |
|---|---|---|
| FedRAMP Moderate Authorized | The exact offering is currently listed at Moderate or higher | Marketplace record, service name, authorization status, verification date |
| DoD FedRAMP Moderate equivalent | The service meets the DoD’s full equivalency conditions | Body of evidence, 3PAO assessment records, control status, customer responsibility details |
| Commercial-only cloud service | It does not process, store, or transmit CUI | Data-flow evidence and documented scope boundary |
The key distinction is simple. Authorization is a formal FedRAMP status. Equivalency is a contractor’s evidence-based determination that a non-authorized service meets DoD requirements for CUI use.
Cloud providers sometimes use phrases such as “FedRAMP ready,” “FedRAMP aligned,” or “built on FedRAMP infrastructure.” None of those phrases alone proves that your selected service meets the CMMC cloud requirement. I advise clients to stop the review when the provider cannot identify the exact offering and produce current documentation.
Build a CUI Data Map Before Reviewing Vendors
A useful verification checklist begins with a complete service inventory. Most small business IT teams know their major platforms. They often miss browser-based software, outsourced support tools, workflow automation, managed detection portals, and employee-selected collaboration apps.
Start with the Controlled Unclassified Information lifecycle. Identify where CUI enters the organization, who accesses it, how it moves, where it is backed up, and how long it remains available. Include data in transit and at rest.
Your inventory should capture the following details:
- The service name, edition, tenant, hosting environment, and account owner.
- The CUI function, such as email, storage, engineering collaboration, accounting attachment, or remote support.
- The users, administrators, subcontractors, and service-provider personnel with access.
- Connected systems, APIs, synchronization tools, endpoint agents, and backup destinations.
- The verified authorization or equivalency path, evidence location, and next review date.
This mapping supports secure cloud architecture decisions because it separates systems that must meet the CUI cloud rule from systems that can remain outside the regulated boundary. It also prevents accidental CUI movement through convenience tools.
For instance, an Office 365 migration deserves a separate scope review if it includes legacy email or document libraries containing CUI. Moving data into Microsoft 365 without confirming the right government cloud environment, licensing, identity controls, and administrative boundaries can expand your assessment scope overnight.
Microsoft provides a CMMC overview for Azure services that is helpful when reviewing Microsoft-hosted workloads. Still, you must document your own configurations and control assignments. Provider documentation supports your evidence package, but it does not replace it.
Actionable Cloud Service Verification Checklist
Use the following checklist for every cloud service that may handle CUI. Assign an internal owner to each item and retain evidence in a controlled repository. A spreadsheet can work for a small environment, provided it has version control, access restrictions, and review dates.
Confirm the Exact Cloud Offering
Record the vendor’s legal name, product name, environment, edition, tenant type, and geographic hosting location. “Microsoft,” “AWS,” or “Google Cloud” is too broad for an assessor or a contract reviewer.
Ask the vendor to identify the service’s formal FedRAMP authorization status and provide a source you can validate. If the provider relies on equivalency, request written confirmation that its service is evaluated against the current DoD FedRAMP Moderate equivalency standard.
Evidence can include a Marketplace listing, authorization letter, attestation package, formal provider statement, contract language, or current assessment documentation. Capture the date because status and service boundaries can change.
Verify CUI Handling and Service Boundaries
Document whether the service stores, processes, or transmits CUI. Do not limit the answer to user-uploaded documents. Review logs, cache locations, mobile access, support tickets, email notifications, backups, and integrations.
A managed security platform might not store source CUI files. Yet it may receive filenames, user names, IP addresses, event details, or other information derived from a CUI system. Your System Security Plan should explain the boundary decision and its basis.
For cloud infrastructure, examine virtual machines, managed databases, object storage, virtual desktop services, containers, key-management services, and observability tools. Each one can have a distinct compliance position. A secure workload cannot compensate for an out-of-scope logging or backup service that receives CUI.
Obtain the Equivalency Evidence Package
When a provider is not FedRAMP Moderate Authorized, obtain its current body of evidence before approving CUI use. The evidence should show a Third-Party Assessment Organization, or 3PAO, assessed the service against the required FedRAMP Moderate baseline, a process that prepares the ground for eventual C3PAO engagement during defense audits.
Review the System Security Plan, Security Assessment Plan, Security Assessment Report, Plan of Action and Milestones status, Continuous Monitoring approach, and customer responsibility materials. Verify that the documents apply to the same service offering you plan to use.
The DoD’s current approach requires full implementation of the applicable FedRAMP Moderate baseline for equivalency. Do not accept open control-related POA&Ms as a substitute for completed controls. If you lack the expertise to evaluate the package, get focused technology consulting support from a qualified advisor who can interpret evidence without overstating a provider’s status.
Map Shared Responsibilities to CMMC Practices
Every cloud platform divides responsibilities between provider and customer. Your evidence must show who owns each control activity and how your organization performs its part.
For identity controls, the provider may secure its data centers while you enforce multifactor authentication, disable inactive accounts, review privileged roles, and protect administrator credentials. For encryption, the provider may protect the platform while you choose key-management options, manage access, and prevent unapproved exports.
A customer responsibility matrix should identify the responsible party for each relevant requirement, the implementation method, evidence source, review cycle, and accountable role. I consider this matrix indispensable for CMMC Level 2 FedRAMP reviews because it turns broad claims into assigned work.
Validate Incident Reporting and Contract Obligations
Cloud verification does not remove your DFARS 252.204-7012 responsibilities. Your incident response plan needs to address rapid reporting, preservation of relevant images and monitoring data, malware isolation, and coordination with the cloud provider.
Confirm the provider’s incident-notification process, log-retention period, support escalation route, and ability to preserve evidence. Contract terms should not prevent your organization from meeting its reporting and forensic obligations.
Also test access to evidence before an incident occurs. If security logs need a paid add-on, specialized administrator role, or vendor request, document that dependency. Business continuity and security depend on access to reliable records when systems are under pressure.
Review Access, Endpoints, and Administrative Tools
Cloud compliance weakens when endpoints and administrators are poorly controlled. Require MFA, role-based access, least privilege, protected administrator workstations where appropriate, and timely account removal.
Your endpoint security program should cover every device that accesses CUI. This includes encryption, supported operating systems, managed detection, patching, screen lock, remote-wipe capability where applicable, and documented device ownership. Strong device hardening reduces the chance that an authorized cloud service becomes a route for data loss.
Remote tools require added scrutiny. A provider offering restaurant POS support or kitchen technology solutions may use remote-management software that is appropriate for commercial operations but unsuitable for CUI systems. Segregate commercial support environments from defense work and block unauthorized remote-access paths.
Preserve Proof of Ongoing Review
A one-time vendor review is not enough. Maintain a cloud-service register with evidence links, contract dates, authorization checks, service changes, CUI scope, and internal owners.
Set review triggers for new integrations, mergers, major tenant changes, data migrations, contract renewals, security incidents, and provider notices. Also review recurring evidence such as access logs, privileged-account reviews, backup restoration results, vulnerability remediation, and incident-response tests.
Strike Graph’s comparison of CMMC and FedRAMP offers a useful reminder that the frameworks have different control structures and assessment purposes. Use that distinction when briefing leadership. A provider’s cloud posture and your organization’s CMMC evidence are connected, but neither replaces the other.
Keep Microsoft 365 and Managed Services in Scope
For many contractors, email and collaboration are the most active CUI channels. That makes Microsoft 365 configuration a major part of the evidence picture. Confirm the tenant environment, data locations, identity settings, retention, audit capabilities, external sharing rules, device access policies, and support boundaries.
A well-managed Office 365 migration can reduce risk when it removes scattered file shares and unmanaged mailboxes. However, the project must include CUI classification, migration scoping, permissions cleanup, and post-migration validation. Moving old data without those steps often preserves old access problems in a new location.
The same rule applies to managed providers. Managed IT for small business can bring needed expertise, but the provider becomes part of your security boundary when its technicians administer CUI systems. Review its personnel access, MFA, logging, toolset, support locations, incident process, and subcontractor arrangements.
A dependable business technology partner should make these responsibilities visible. The strongest tailored technology services include written system boundaries, documented escalation paths, and evidence that matches your System Security Plan. Broad promises of innovative IT solutions are not enough.
For leaders planning digital transformation, compliance review should happen before adopting a tool, not after business data has spread across it. An IT strategy for SMBs should set approved-cloud standards, purchasing controls, and a route for security review. That discipline supports infrastructure optimization without exposing CUI to unapproved services.
Turn Verification Into an Operating Practice
A verified service can still fall out of alignment after a product update, license change, new integration, or internal configuration change. Therefore, connect cloud checks to change management rather than treating them as a compliance project that ends.
Assign clear ownership. Your security lead can maintain the CUI inventory. The cloud administrator can validate tenant settings. Procurement can require evidence before renewal. Executive leadership can resolve risk acceptance decisions when a business need conflicts with the approved architecture.
For smaller organizations, cybersecurity services and fractional leadership can bring structure without building a large internal department. I advise documenting the decision process in plain language: what data is involved, which service is approved, what proof supports approval, who owns customer controls, and when the decision expires. You can use a structured compliance framework to guide these ongoing reviews, ensuring that every internal self-assessment aligns with your overall defense strategy before you update your official score in SPRS.
Data center technology may still have a place in a hybrid environment, especially where legacy systems or specialized workloads remain local. Apply the same scope discipline there. A local server connected to a cloud backup, remote-support platform, or identity provider creates a combined security boundary.
The goal is not paperwork for its own sake. It is evidence that your people, systems, and providers protect CUI according to the responsibilities assigned to each party.
Frequently Asked Questions
What makes a cloud service compliant with CMMC Level 2 FedRAMP requirements?
A cloud service must either hold a current FedRAMP Moderate Authorization or meet the DoD’s FedRAMP Moderate equivalency requirements for the exact service offering in use. Additionally, contractors must properly implement all applicable NIST SP 800-171 controls and manage their own shared-responsibility requirements.
Does using a FedRAMP-authorized cloud provider make my entire organization compliant?
No. Cloud authorization only covers the specific infrastructure and services provided by the vendor, leaving the contractor responsible for user access controls, device hardening, internal processes, and configuration management within that environment.
How should contractors handle cloud services that are not officially FedRAMP authorized?
If a cloud provider is not FedRAMP authorized, contractors must obtain and review a complete body of evidence demonstrating that an independent 3PAO assessed the service against the FedRAMP Moderate baseline to meet DoD equivalency standards. Without this documented proof, the service cannot be used to process, store, or transmit Controlled Unclassified Information.
Conclusion
CMMC Level 2 cloud verification comes down to proof. You need to know where CUI goes, which exact service handles it, and whether its authorization or equivalency evidence meets the current Department of Defense standard.
A current CMMC Level 2 FedRAMP verification record, paired with clear shared-responsibility evidence, gives your organization a defensible foundation for preparation. Keep reviewing the environment as services and requirements change, because yesterday’s approval may not cover tomorrow’s workflow.
Discover more from Guide to Technology
Subscribe to get the latest posts sent to your email.
