FedRAMP High in AWS GovCloud; Anthropic states IL4/IL5 approval
AWS records Amazon Bedrock as a FedRAMP High authorized service in the AWS GovCloud (US-West) Region, and Anthropic states Claude in Amazon Bedrock is approved for use in FedRAMP High and DoD IL4/5 workloads. The authorization belongs to the hosting boundary, which is exactly why this pattern works.
Is Claude via Amazon Bedrock in AWS GovCloud (US) safe for CUI?
by Amazon Web Services
As of July 27, 2026. FedRAMP authorizations, DoD Impact Level approvals and vendor data-handling terms change. Every finding below links to the primary source it came from — open it and confirm the current status before you make a boundary decision.
What this verdict rests on
The 2 sources the finding above is drawn from, quoted so you can check the reading rather than take our word for it.
Primary source
“Amazon Bedrock is a FedRAMP High authorized service in the AWS GovCloud (US-West) Region.”
Amazon Web Services — Amazon Bedrock — security and compliance · read 2026-07-27
Primary source
“Available on AWS and Google Cloud with authorizations up to FedRAMP High and IL5 ... Claude in Amazon Bedrock: Approved for use in FedRAMP High and DoD IL4/5 workloads”
Anthropic — Claude for government — deployment options and authorizations · read 2026-07-27
FedRAMP
High (AWS GovCloud US-West)
DoD Impact Level
IL4 / IL5 per Anthropic
Deployment pattern
Government cloud / sovereign variant
Overview
Amazon Bedrock in AWS GovCloud (US) puts Claude and other foundation models behind an AWS-operated boundary that already holds a FedRAMP High authorization. It is the cleanest illustration of the rule this checker keeps returning to: the model is not what gets authorized — the boundary it runs in is.
Where does the data physically go?
The first question in any CUI boundary decision is not whether a product is secure — it is which system boundary the data lands in, and whose authorization covers that boundary.
Data location
Inference runs inside AWS GovCloud (US) rather than at the model vendor. AWS states that when you tune a foundation model it is based on a private copy, that your data is not shared with model providers, and that it is not used to improve the base models — so Anthropic is not in the data path for a Bedrock deployment.
Primary source
“When you tune a foundation model, we base it on a private copy of that model. This means your data is not shared with model providers, and is not used to improve the base models.”
Amazon Web Services — Amazon Bedrock — customer data handling · read 2026-07-27
Model training and retention
AWS states customer data is not shared with model providers and is not used to improve the base models. Anthropic separately states it does not use inputs or outputs from its commercial products to train its models by default. The two commitments come from different parties and are worth holding separately in your documentation.
Primary source
“When you tune a foundation model, we base it on a private copy of that model. This means your data is not shared with model providers, and is not used to improve the base models.”
Amazon Web Services — Amazon Bedrock — customer data handling · read 2026-07-27
What authorization exists?
A platform-level authorization does not automatically extend to every service running on it. What matters is whether this specific AI service is named in the authorization scope.
FedRAMP authorization
AWS states that Amazon Bedrock is a FedRAMP High authorized service in the AWS GovCloud (US-West) Region. High exceeds the FedRAMP Moderate baseline DFARS 252.204-7012 names. Note the region qualifier in that sentence — it is a per-region statement, not a per-service one, and the commercial AWS regions are a different scope.
Primary source
“Amazon Bedrock is a FedRAMP High authorized service in the AWS GovCloud (US-West) Region.”
Amazon Web Services — Amazon Bedrock — security and compliance · read 2026-07-27
DoD Impact Level
Anthropic states that Claude in Amazon Bedrock is approved for use in FedRAMP High and DoD IL4/5 workloads, and describes its availability on AWS and Google Cloud with authorizations up to FedRAMP High and IL5. This is a vendor statement about a hosting platform's authorization; confirm the current DoD scope against the AWS services-in-scope listing for the impact level you need.
Primary source
“Available on AWS and Google Cloud with authorizations up to FedRAMP High and IL5 ... Claude in Amazon Bedrock: Approved for use in FedRAMP High and DoD IL4/5 workloads”
Anthropic — Claude for government — deployment options and authorizations · read 2026-07-27
Vendor's own position on CUI
Not established. Neither the AWS Bedrock security page nor Anthropic's government page states a position on CUI or DFARS 252.204-7012 in terms — the words do not appear. The authorization levels are established; the explicit CUI statement is not. Verify with AWS for your agreement.
What DFARS 252.204-7012 and NIST 800-171 require of this pattern
Quoted from the regulation itself, not paraphrased.
DFARS 252.204-7012(b)(2)(ii)(D) — the external cloud service provider test
This is the paragraph that decides most AI questions. The moment an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — and that it complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. A commercial AI endpoint is an external cloud service provider. The obligation to ensure equivalency sits on the contractor, not the vendor.
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
DFARS 252.204-7012(b)(2)(i) — NIST SP 800-171 on your own systems
Any unclassified system owned or operated by or for the contractor that processes, stores or transmits covered defense information is a "covered contractor information system" and carries the full NIST SP 800-171 requirement set. An AI assistant does not sit outside this because it is new: if CUI reaches it, the system it runs on is in scope, and the revision that applies is the one in effect when the solicitation issued.
Primary source
“Except as provided in paragraph (b)(2)(ii) of this clause, the covered contractor information system shall be subject to the security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 ... in effect at the time the solicitation is issued or as authorized by the Contracting Officer.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
NIST SP 800-171 — the control set itself
The security requirements DFARS 7012 imports. Rev. 3 (May 2024) is the current final publication; which revision binds a given contract is set by the solicitation, so check the clause in your award rather than assuming. For an AI deployment the load-bearing families are access control, audit and accountability, and system and communications protection — an assistant that reaches CUI must be inside the same access, logging and boundary-protection regime as any other system that touches it.
Primary source
“This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations.”
NIST Computer Security Resource Center — NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations · read 2026-07-27
NIST 800-171 controls this decision turns on
These are the controls an assessor works through when CUI reaches an AI service. They are the controls at stake, not a finding against the vendor.
The compliant pattern
Deploy in AWS GovCloud (US), not a commercial AWS region — the AWS FedRAMP High statement for Bedrock is region-qualified, and the same service in a commercial region is a different scope. Confirm the specific foundation models you intend to call are in scope for GovCloud at your impact level, since the model list inside Bedrock is itself scoped. Then treat the deployment like any other CUI system: inside the documented enclave, with the same access control, logging and boundary protection, and with the clause's incident reporting and forensic-access obligations reflected in the agreement.
Patterns with an authorized path for CUI
Sources for this page
Every finding above rests on one of these. Nothing on this page is asserted without one.
- Amazon Web Services — Amazon Bedrock — security and compliance · read 2026-07-27
- Anthropic — Claude for government — deployment options and authorizations · read 2026-07-27
Authorization records move and this page does not. Search the FedRAMP Marketplace for the current AWS records before you rely on anything above.
Related Compliance Assessments
Frequently Asked Questions
Is Claude approved for CUI through Amazon Bedrock?
AWS records Amazon Bedrock as a FedRAMP High authorized service in the AWS GovCloud (US-West) Region, and Anthropic states Claude in Amazon Bedrock is approved for use in FedRAMP High and DoD IL4/5 workloads. Neither source uses the words CUI or DFARS 252.204-7012, so confirm the contractual position with AWS as well as the authorization position.
Does the commercial AWS region give me the same thing?
No. AWS's FedRAMP High statement for Bedrock is qualified to the AWS GovCloud (US-West) Region. Deploying the identical service in a commercial region puts you in a different authorization scope — this is the single most common way this pattern goes wrong.
Does Anthropic see my prompts in this pattern?
AWS states that your data is not shared with model providers and is not used to improve the base models, and that tuning is done against a private copy of the model. That is the property that makes the hosting boundary, rather than the model vendor, the thing your SSP describes.
Your AI tools are one row in the boundary
Audit the rest of the stack — storage, email, collaboration — against the same FedRAMP test.
Launch CUI AuditorGet a defensible CUI architecture
This Claude via Amazon Bedrock in AWS GovCloud (US) CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture review