Certification exists, but it names a different offering
OpenAI does hold a FedRAMP certification — recorded against the offering "ChatGPT Enterprise and API Platform" at Class C (Moderate). The registry record does not establish that an ordinary consumer, Plus, Business or Enterprise workspace sits inside that certified boundary, and OpenAI's own documentation could not be retrieved to settle it.
Is ChatGPT (consumer, Plus, Business and standard Enterprise) safe for CUI?
by OpenAI
As of July 27, 2026. FedRAMP authorizations, DoD Impact Level approvals and vendor data-handling terms change. Every finding below links to the primary source it came from — open it and confirm the current status before you make a boundary decision.
What this verdict rests on
The 2 sources the finding above is drawn from, quoted so you can check the reading rather than take our word for it.
Primary source
“ChatGPT Enterprise and API Platform Package ID FR2533155773 ... FedRAMP Certified As of 1/9/2026 ... Type 20x Path Program Class Class C (Moderate)”
FedRAMP Marketplace — ChatGPT Enterprise and API Platform — OpenAI (Package FR2533155773) · read 2026-07-27
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
FedRAMP
Certified — but for a named separate offering
DoD Impact Level
Not established
Deployment pattern
Commercial multi-tenant SaaS
Overview
The consumer, Plus, Business and Enterprise tiers of ChatGPT are the ones most employees already have open in a browser tab, which is what makes this the most common shadow-CUI path in a defence contractor. OpenAI does hold a FedRAMP certification, but it is recorded against a specifically named offering — so the question is not "is OpenAI FedRAMP certified" but "is the thing I am actually using the thing that was certified".
Where does the data physically go?
The first question in any CUI boundary decision is not whether a product is secure — it is which system boundary the data lands in, and whose authorization covers that boundary.
Data location
Not established. Not established. OpenAI's documentation, help centre and trust portal return HTTP 403 to automated retrieval, so we could not read them to verify this and will not restate a claim we have not seen. Verify directly with OpenAI, in writing, before routing CUI anywhere near this product.
Model training and retention
Not established. Not established. OpenAI's documentation, help centre and trust portal return HTTP 403 to automated retrieval, so we could not read them to verify this and will not restate a claim we have not seen. Verify directly with OpenAI, in writing, before routing CUI anywhere near this product.
What authorization exists?
A platform-level authorization does not automatically extend to every service running on it. What matters is whether this specific AI service is named in the authorization scope.
FedRAMP authorization
The FedRAMP registry records one OpenAI offering: "ChatGPT Enterprise and API Platform", FedRAMP Certified as of 1/9/2026 under the 20x program path at Class C (Moderate). Which of OpenAI's commercially sold tiers are inside that certified boundary is not something the registry record states — get it in writing from OpenAI for the exact workspace or API endpoint you intend to use.
Primary source
“ChatGPT Enterprise and API Platform Package ID FR2533155773 ... FedRAMP Certified As of 1/9/2026 ... Type 20x Path Program Class Class C (Moderate)”
FedRAMP Marketplace — ChatGPT Enterprise and API Platform — OpenAI (Package FR2533155773) · read 2026-07-27
DoD Impact Level
Not established. No DoD Impact Level authorization was established for any OpenAI-operated offering from a primary source we could read. Verify with OpenAI and with your DoD customer.
Vendor's own position on CUI
Not established. Not established. OpenAI's documentation, help centre and trust portal return HTTP 403 to automated retrieval, so we could not read them to verify this and will not restate a claim we have not seen. Verify directly with OpenAI, in writing, before routing CUI anywhere near this product.
What DFARS 252.204-7012 and NIST 800-171 require of this pattern
Quoted from the regulation itself, not paraphrased.
DFARS 252.204-7012(b)(2)(ii)(D) — the external cloud service provider test
This is the paragraph that decides most AI questions. The moment an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — and that it complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. A commercial AI endpoint is an external cloud service provider. The obligation to ensure equivalency sits on the contractor, not the vendor.
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
NIST SP 800-171 — the control set itself
The security requirements DFARS 7012 imports. Rev. 3 (May 2024) is the current final publication; which revision binds a given contract is set by the solicitation, so check the clause in your award rather than assuming. For an AI deployment the load-bearing families are access control, audit and accountability, and system and communications protection — an assistant that reaches CUI must be inside the same access, logging and boundary-protection regime as any other system that touches it.
Primary source
“This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations.”
NIST Computer Security Resource Center — NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations · read 2026-07-27
NIST 800-171 controls this decision turns on
These are the controls an assessor works through when CUI reaches an AI service. They are the controls at stake, not a finding against the vendor.
The compliant pattern
Do not resolve this by reading a marketing page. Ask OpenAI, in writing, whether the specific workspace or API endpoint you are buying is inside the boundary of the FedRAMP-certified "ChatGPT Enterprise and API Platform" offering, and get the FedRAMP package artefacts through the registry. Until that is answered in writing, treat an ordinary ChatGPT workspace as outside your CUI boundary and use technical controls — DLP, egress restriction, browser policy — to keep CUI out of it. The alternative that needs no such letter is running the model inside a boundary you already have authorized.
Patterns with an authorized path for CUI
FedRAMP Certified at Moderate — no DoD Impact Level established
In scope of the Azure Government authorizations, up to IL5
No external cloud service provider — a different test applies
Sources for this page
Every finding above rests on one of these. Nothing on this page is asserted without one.
- FedRAMP Marketplace — ChatGPT Enterprise and API Platform — OpenAI (Package FR2533155773) · read 2026-07-27
- Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
Authorization records move and this page does not. Confirm the OpenAI package record on the FedRAMP Marketplace before you rely on anything above.
Frequently Asked Questions
OpenAI is FedRAMP certified — does that cover my ChatGPT Enterprise workspace?
The registry records the certification against the offering named "ChatGPT Enterprise and API Platform" and does not itself establish which commercially sold workspaces sit inside that boundary. Because brand names are reused across authorized and unauthorized environments across this whole market, treat the offering name on the FedRAMP record — not the product name on the invoice — as the thing that was certified, and get the mapping confirmed in writing.
Why do you not state OpenAI's data retention and training policy here?
Because we could not read it. OpenAI's documentation, help centre and trust portal all return HTTP 403 to automated retrieval, and this checker does not restate claims about a named vendor from memory or from someone else's summary. The gap is the honest answer; verify with OpenAI directly.
What does DFARS 252.204-7012 require here?
If an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline, and that it complies with the clause's cyber incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. That obligation is on you, not on the vendor.
Your AI tools are one row in the boundary
Audit the rest of the stack — storage, email, collaboration — against the same FedRAMP test.
Launch CUI AuditorGet a defensible CUI architecture
This ChatGPT (consumer, Plus, Business and standard Enterprise) CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture review