CUI Vault has achieved FedRAMP Moderate equivalency.

Kratos, a FedRAMP-recognized 3PAO, independently assessed the CUI Vault platform against 100% of the FedRAMP Moderate baseline.

The CUI Vault platform implements 100% of the FedRAMP Moderate baseline, independently assessed by Kratos, a FedRAMP-recognized third-party assessment organization (3PAO).

For a defense contractor, this is the difference between a vendor that says it follows good practice and a vendor that has had every control in the baseline examined by an independent assessor and found to be implemented. You inherit that work rather than rebuilding it.

CUI Vault is not FedRAMP Authorized and NtelSec does not represent that it holds a FedRAMP authorization. FedRAMP Moderate equivalency is the standard described by DoD for cloud service offerings under DFARS 252.204-7012(b)(2)(ii)(D).

What "equivalency" actually means

DFARS 252.204-7012 requires that a cloud service provider handling covered defense information meet security requirements equivalent to the FedRAMP Moderate baseline. DoD guidance describes that as full implementation of the baseline, assessed by a FedRAMP-recognized 3PAO, with no open plan-of-action items — a body of evidence a contracting officer or assessor can review.

That is the bar CUI Vault was measured against. It is a separate thing from a FedRAMP authorization issued by a federal agency, and we do not describe it as one.

What was assessed

The assessment covered the CUI Vault authorization boundary — the managed environment in Microsoft Azure Government where customers process, store, and transmit CUI. Every control in the FedRAMP Moderate baseline was examined, including:

  • Identity and access control — enforced multi-factor authentication, conditional access, least-privilege role assignment, and separation of privileged administration from customer workloads.
  • Tenant isolation — each customer’s environment and data are segregated, with controls that prevent cross-customer access or discovery.
  • Data protection — FIPS 140-validated cryptographic modules for data at rest and in transit, plus controls restricting data egress from the environment.
  • Audit and accountability — centralized security logging with alerting, retention, and a documented incident response process.
  • Configuration, vulnerability, and supply-chain management — hardened baselines, flaw remediation timelines, and change control.
  • Contingency planning — backup, recovery, and tested restoration of the environment.

What is outside the boundary

We think a vendor that will not tell you where its boundary ends has not really told you anything, so: customer endpoint devices — the laptops and phones used to open a session — are outside the boundary and remain the customer’s responsibility. Email and file services are delivered through Microsoft 365 GCC High, which holds its own FedRAMP authorization, so those controls are inherited from Microsoft rather than assessed under ours.

Security of your enclave runs on a shared responsibility model. The controls we own and the controls you own are enumerated in the Customer Responsibility Matrix provided at onboarding.

What this changes for customers

  • Controls that CUI Vault implements on your behalf are inheritable, with a body of evidence behind them rather than an assertion.
  • Your Customer Responsibility Matrix distinguishes what we operate from what you must operate — the parts of NIST SP 800-171 that remain yours.
  • Diligence questions from a prime about your cloud environment have a documented answer.

Compliance is a shared effort, and the platform is only half of it. Your SPRS score, your affirmations, and the controls on your side of the matrix are still yours to implement and attest to — but you are not doing that alone. You inherit our platform controls with a body of evidence behind them, and our team supports you through the rest of your self-assessment.

From our CEO

The embedded post uses third-party cookies. Enable marketing cookies to view it here, or open it on LinkedIn.

View on LinkedIn
Talk to us about CUI Vault All news