FedRAMP Certified at Moderate — no DoD Impact Level established
The registry records this offering as FedRAMP Certified at Class C (Moderate), which is the baseline DFARS 252.204-7012 names. No DoD Impact Level authorization was established, and OpenAI's own documentation could not be retrieved to confirm data handling — so the remaining clause obligations have to be settled with OpenAI directly.
Is ChatGPT Enterprise and API Platform (OpenAI FedRAMP offering) safe for CUI?
by OpenAI
As of July 27, 2026. FedRAMP authorizations, DoD Impact Level approvals and vendor data-handling terms change. Every finding below links to the primary source it came from — open it and confirm the current status before you make a boundary decision.
What this verdict rests on
The 2 sources the finding above is drawn from, quoted so you can check the reading rather than take our word for it.
Primary source
“ChatGPT Enterprise and API Platform Package ID FR2533155773 ... FedRAMP Certified As of 1/9/2026 ... Type 20x Path Program Class Class C (Moderate)”
FedRAMP Marketplace — ChatGPT Enterprise and API Platform — OpenAI (Package FR2533155773) · read 2026-07-27
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
FedRAMP
Certified — Class C (Moderate), 1/9/2026
DoD Impact Level
Not established
Deployment pattern
Government cloud / sovereign variant
Overview
This is the OpenAI offering that carries an OpenAI-held FedRAMP certification, as distinct from the commercial tiers sold under similar names. For a defence contractor the distinction is the whole point: the authorization attaches to a specific named offering, and the name on your invoice is not evidence that you are inside it.
Where does the data physically go?
The first question in any CUI boundary decision is not whether a product is secure — it is which system boundary the data lands in, and whose authorization covers that boundary.
Data location
Not established. Not established. OpenAI's documentation, help centre and trust portal return HTTP 403 to automated retrieval, so we could not read them to verify this and will not restate a claim we have not seen. Verify directly with OpenAI, in writing, before routing CUI anywhere near this product.
Model training and retention
Not established. Not established. OpenAI's documentation, help centre and trust portal return HTTP 403 to automated retrieval, so we could not read them to verify this and will not restate a claim we have not seen. Verify directly with OpenAI, in writing, before routing CUI anywhere near this product.
What authorization exists?
A platform-level authorization does not automatically extend to every service running on it. What matters is whether this specific AI service is named in the authorization scope.
FedRAMP authorization
Recorded as FedRAMP Certified as of 1/9/2026, under the FedRAMP 20x program path, at Class C (Moderate), in the Ongoing Certification phase. Moderate is the baseline DFARS 252.204-7012(b)(2)(ii)(D) names, so on the authorization question this offering meets the level the clause asks for. The clause asks for more than a level, though — see the compliant pattern below.
Primary source
“ChatGPT Enterprise and API Platform Package ID FR2533155773 ... FedRAMP Certified As of 1/9/2026 ... Type 20x Path Program Class Class C (Moderate)”
FedRAMP Marketplace — ChatGPT Enterprise and API Platform — OpenAI (Package FR2533155773) · read 2026-07-27
DoD Impact Level
Not established. No DoD Impact Level authorization was established for this offering from a primary source we could read. If your contract or your customer requires IL4 or IL5, do not assume a FedRAMP Moderate certification satisfies it — they are different regimes with different authorizing bodies. Confirm the position with OpenAI in writing, and with your contracting officer.
Vendor's own position on CUI
Not established. Not established. OpenAI's documentation, help centre and trust portal return HTTP 403 to automated retrieval, so we could not read them to verify this and will not restate a claim we have not seen. Verify directly with OpenAI, in writing, before routing CUI anywhere near this product.
What DFARS 252.204-7012 and NIST 800-171 require of this pattern
Quoted from the regulation itself, not paraphrased.
DFARS 252.204-7012(b)(2)(ii)(D) — the external cloud service provider test
This is the paragraph that decides most AI questions. The moment an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — and that it complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. A commercial AI endpoint is an external cloud service provider. The obligation to ensure equivalency sits on the contractor, not the vendor.
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
NIST SP 800-171 — the control set itself
The security requirements DFARS 7012 imports. Rev. 3 (May 2024) is the current final publication; which revision binds a given contract is set by the solicitation, so check the clause in your award rather than assuming. For an AI deployment the load-bearing families are access control, audit and accountability, and system and communications protection — an assistant that reaches CUI must be inside the same access, logging and boundary-protection regime as any other system that touches it.
Primary source
“This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations.”
NIST Computer Security Resource Center — NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations · read 2026-07-27
NIST 800-171 controls this decision turns on
These are the controls an assessor works through when CUI reaches an AI service. They are the controls at stake, not a finding against the vendor.
The compliant pattern
A FedRAMP Moderate certification answers the first half of DFARS 252.204-7012(b)(2)(ii)(D) and not the second. The clause also requires you to ensure the provider complies with the cyber incident reporting, malicious software, media preservation and protection, forensic-access and cyber incident damage assessment paragraphs — those are contract terms you have to secure, not properties of a certification. Get them in the agreement, get confirmation in writing that the endpoint you are calling is inside the certified offering's boundary, pull the package artefacts through the registry, and record the whole thing in the SSP.
Patterns with an authorized path for CUI
Sources for this page
Every finding above rests on one of these. Nothing on this page is asserted without one.
- FedRAMP Marketplace — ChatGPT Enterprise and API Platform — OpenAI (Package FR2533155773) · read 2026-07-27
- Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
Authorization records move and this page does not. Confirm the OpenAI package record on the FedRAMP Marketplace before you rely on anything above.
Frequently Asked Questions
Does a FedRAMP Moderate certification satisfy DFARS 252.204-7012?
It satisfies the equivalency test — the clause names the FedRAMP Moderate baseline. It does not by itself satisfy the rest of the paragraph, which also requires you to ensure the cloud service provider complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment requirements. Those are things to negotiate into the agreement.
Does this offering carry a DoD Impact Level?
We did not establish one from any primary source we could read. FedRAMP and the DoD Cloud Computing SRG are separate regimes; if your contract requires IL4 or IL5, ask specifically about that and do not read it across from the FedRAMP record.
Why are the data-handling fields on this page empty?
Because OpenAI's own documentation returns HTTP 403 to automated retrieval, we could not read it, and this checker does not publish claims about a named vendor that it has not verified. Open the vendor's pages yourself, or ask OpenAI in writing.
Your AI tools are one row in the boundary
Audit the rest of the stack — storage, email, collaboration — against the same FedRAMP test.
Launch CUI AuditorGet a defensible CUI architecture
This ChatGPT Enterprise and API Platform (OpenAI FedRAMP offering) CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture review