GSA Ready Now
Two column diagram showing the shared responsibility split between a cloud provider and a contractor for protecting CUI
Back to Blog
Compliance Sep 23, 2026 8 min read

Cloud Services and CUI: The Questions to Ask Your Provider Before You Upload

Focus keyword: cloud services and CUI

If your company stores or processes Controlled Unclassified Information (CUI) in a commercial cloud, the cloud provider is part of how you protect it. You cannot hand that responsibility off entirely, so you need to ask specific questions and keep the answers on file.

This matters more this month because federal guidance to contractors on CUI is getting new attention. The rules for civilian agency work are still being settled, though, so it helps to be clear about what is required today and what is only proposed.

Two column diagram showing the shared responsibility split between a cloud provider and a contractor for protecting CUI
A two column comparison of shared responsibility: the cloud provider secures data centers, hardware, and platform, while the contractor controls accounts, access, sharing, CUI marking, and training.

Why Is CUI Guidance for Contractors Getting Attention Right Now?

According to a recent Mondaq article, new guidance from the Information Security Oversight Office (ISOO) tells federal agencies to give contractors more CUI guidance. ISOO, part of the National Archives, oversees the CUI program across the executive branch. The same article says the FAR Council released an updated draft of the FAR CUI rule earlier this summer.

For civilian contractors, the practical point is this: agencies are being told to be clearer about what CUI you will handle and how they expect you to protect it. That is a good moment to look at where CUI actually lives in your environment. For most small and mid-sized firms, the answer is a cloud service such as email, file storage, or a collaboration platform.

The FAR CUI rule is still proposed, not final. It is not a requirement in force, and its final contents, including anything specific to cloud services, are not settled.

What Rules Govern CUI in the Cloud for Civilian Contractors Today?

Today, your obligations come mainly from your contract and any agreements with the agency. The underlying framework is:

  • Executive Order 13556 created the CUI program.
  • 32 CFR Part 2002 is the implementing regulation. When agencies set requirements for protecting CUI on nonfederal systems, it directs them to use NIST SP 800-171.
  • NIST SP 800-171 is the security standard for CUI on nonfederal systems. Revision 3 was published in May 2024. Which revision applies to you depends on what your contract or agreement references.

There is currently no single government-wide FAR clause that imposes CUI safeguarding on all civilian contracts. The proposed FAR rule would create one. Until a final rule is issued, read your contract, any clauses or attachments on information handling, and any direction from your contracting officer.

Does My Cloud Provider Need to Be FedRAMP Authorized?

It depends on your contract. FedRAMP is the government program that authorizes cloud services for use by federal agencies. It is not a certification for contractors, and a provider’s FedRAMP authorization does not by itself make your use of that service compliant.

On the defense side, DFARS clause 252.204-7012 includes specific expectations for cloud providers. That clause applies to Department of War contracts. It does not apply to civilian agency work unless your contract says so. If a civilian agency contract names a cloud standard, follow the contract. If it does not, a FedRAMP-authorized service can still be a sensible choice, because it gives you documented, independently assessed security to point to. You can check a provider’s claimed status on the FedRAMP Marketplace.

What Questions Should I Ask My Cloud Provider About CUI?

Put these to your provider in writing and keep the responses:

  1. 1

    Is the specific service and tier we use FedRAMP authorized, and at what impact level?

    Authorization often covers a government-specific offering, not the commercial version you may be on.

  2. 2

    Where is our data stored and processed, and who can access it?

    Ask about data location, provider personnel access, and any support staff outside the United States.

  3. 3

    Which NIST SP 800-171 requirements do you meet for us, and which are ours?

    Ask for a customer responsibility matrix or equivalent document.

  4. 4

    How and when will you notify us of a security incident affecting our data?

    You may have your own reporting duties to an agency. Your provider’s timeline has to allow you to meet them.

  5. 5

    Is data encrypted at rest and in transit, and who controls the keys?

    Get a direct answer, not a marketing summary.

  6. 6

    What logs can we access, and for how long are they kept?

    If you ever need to investigate an incident, these logs are your evidence.

  7. 7

    What happens to our data when we leave?

    Ask about export, deletion, and confirmation of deletion.

A provider that cannot answer these clearly is telling you something useful.

What Does the Provider Handle, and What Stays With Me?

Cloud security works on a shared responsibility model. The provider usually secures the physical data centers, the hardware, and the core platform. You usually remain responsible for:

  • Who has accounts and what they can access
  • Multi-factor authentication and password settings
  • How files are shared, including external sharing links
  • Marking CUI and keeping it in the right locations
  • Training your people
  • Configuring the security settings the provider makes available

Many cloud problems come from customer-side settings, not provider failures. A well-secured platform can still expose CUI if a folder is shared with "anyone with the link."

Does CMMC Apply If I Only Sell to Civilian Agencies?

No. CMMC is a Department of War program for defense contracts. It does not apply to civilian agency contracts, and there is no equivalent certification on the civilian side. Be cautious of any vendor that offers a "civilian CUI certification." No such government credential exists.

The Department of War also recently issued Revision 3 of its class deviation on security requirements, as Inside Government Contracts reported. That too is defense-specific. If you hold both defense and civilian contracts, track the two sets of obligations separately.

Frequently Asked Questions

Is the FAR CUI rule in effect?

No. The FAR CUI rule is a proposed rule. It has not been finalized and is not a requirement in force. Civilian contractors should follow the CUI requirements in their current contracts and agency agreements, and watch for a final rule.

Is FedRAMP authorization required for cloud providers that store CUI on civilian contracts?

There is no government-wide requirement for civilian contracts today. Whether a FedRAMP-authorized service is required depends on your specific contract. Even where it is not required, a FedRAMP-authorized service gives you independently assessed security documentation to rely on.

Does using a FedRAMP-authorized cloud make my company compliant for CUI?

No. FedRAMP authorizes the cloud service for federal agency use, not your company. Under the shared responsibility model, you still control accounts, access, sharing settings, and how CUI is handled inside the service.

What security standard applies to CUI on contractor systems?

NIST SP 800-171 is the standard for protecting CUI on nonfederal systems, and 32 CFR Part 2002 directs agencies to use it when setting requirements for those systems. Which revision applies to you depends on your contract or agreement.

Does CMMC apply to civilian agency contractors?

No. CMMC is a Department of War program for defense contracts. There is no CMMC equivalent or certification for civilian agency work.

What is the most important document to request from a cloud provider?

Ask for a document that shows which security requirements the provider meets and which remain yours, often called a customer responsibility matrix. It shows you where your own work begins. Keep it on file with the provider’s written answers to your other questions.

Want help sorting out what your cloud provider actually owes you under your contract? We will walk through it with you.

Talk to a Compliance Specialist

Find Out If You're Ready for a GSA Contract

Take the free 19-question GSA readiness assessment and get a personalized score with a clear action plan — in minutes.

Start Free Assessment