Certified at Class B (Low) — below the Moderate baseline the clause names

The FedRAMP record for Gemini for Government is a 20x certification at Class B (Low). DFARS 252.204-7012 names the FedRAMP Moderate baseline, so the certification as recorded sits below it — and Google separately publishes an Assured Workloads deployment path for the same product at FedRAMP High and DoD IL4. Which path you are on decides the answer.

Government cloud / sovereign variant

Is Gemini for Government safe for CUI?

by Google

As of July 27, 2026. FedRAMP authorizations, DoD Impact Level approvals and vendor data-handling terms change. Every finding below links to the primary source it came from — open it and confirm the current status before you make a boundary decision.

What this verdict rests on

The 3 sources the finding above is drawn from, quoted so you can check the reading rather than take our word for it.

Primary source

Gemini for Government Package ID FR2604952026 ... FedRAMP Certified As of 1/21/2026 ... Type 20x Path Program Class Class B (Low)

FedRAMP MarketplaceGemini for Government — Google (Package FR2604952026) · read 2026-07-27

Primary source

This document provides technical guidance for US Federal agencies and DoD departments on deploying and using Gemini for Government in compliance with FedRAMP High and DoD Impact Level 4 (IL4) requirements. ... You must deploy all Gemini for Government resources within an Assured Workloads folder that's configured for your specific compliance regime (FedRAMP High or IL4).

Google Cloud documentationDeployment guidance for Gemini for Government · read 2026-07-27

Primary source

If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.

Acquisition.gov (DFARS, MAY 2024 revision)DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27

FedRAMP

Certified — Class B (Low); High via Assured Workloads

DoD Impact Level

IL4 via the Assured Workloads path

Deployment pattern

Government cloud / sovereign variant

Overview

Gemini for Government is Google's packaged government AI offering, and it is the clearest example in this checker of why "is it FedRAMP certified" is the wrong question. It is certified — at the Low baseline — and it also has a documented path to FedRAMP High and DoD IL4. Those are different deployments of the same name.

Where does the data physically go?

The first question in any CUI boundary decision is not whether a product is secure — it is which system boundary the data lands in, and whose authorization covers that boundary.

Data location

Google requires Gemini for Government resources to be deployed inside an Assured Workloads folder configured for the compliance regime you need. The boundary is the folder configuration, which means data location follows the regime you selected — and a deployment outside that folder is outside the boundary you are claiming.

Primary source

This document provides technical guidance for US Federal agencies and DoD departments on deploying and using Gemini for Government in compliance with FedRAMP High and DoD Impact Level 4 (IL4) requirements. ... You must deploy all Gemini for Government resources within an Assured Workloads folder that's configured for your specific compliance regime (FedRAMP High or IL4).

Google Cloud documentationDeployment guidance for Gemini for Government · read 2026-07-27

Model training and retention

Not established. We did not establish a Gemini-for-Government-specific training and retention statement from a primary source in preparing this entry. Google publishes data-governance terms for its generative-AI services; read them for the exact product and regime you deploy, and verify with Google.

What authorization exists?

A platform-level authorization does not automatically extend to every service running on it. What matters is whether this specific AI service is named in the authorization scope.

FedRAMP authorization

Two distinct authorization stories exist for the same product name, and conflating them is the trap. The Marketplace record is FedRAMP Certified as of 1/21/2026 under the 20x path at Class B (Low). Separately, Google publishes deployment guidance for running Gemini for Government in compliance with FedRAMP High and DoD IL4 via Assured Workloads. Low does not meet the Moderate baseline the DFARS clause names; the Assured Workloads path does.

Primary source

Gemini for Government Package ID FR2604952026 ... FedRAMP Certified As of 1/21/2026 ... Type 20x Path Program Class Class B (Low)

FedRAMP MarketplaceGemini for Government — Google (Package FR2604952026) · read 2026-07-27

DoD Impact Level

Google's deployment guide is explicitly written for FedRAMP High and DoD Impact Level 4, and requires the resources to sit in an Assured Workloads folder configured for that regime. It also shows the granularity that matters: dependencies not yet authorized at IL4 make their dependent Gemini features unauthorized at IL4 too.

Primary source

This document provides technical guidance for US Federal agencies and DoD departments on deploying and using Gemini for Government in compliance with FedRAMP High and DoD Impact Level 4 (IL4) requirements. ... You must deploy all Gemini for Government resources within an Assured Workloads folder that's configured for your specific compliance regime (FedRAMP High or IL4).

Google Cloud documentationDeployment guidance for Gemini for Government · read 2026-07-27

Vendor's own position on CUI

Google states that DoD contractors and DIB customers can use Google Cloud and Google Workspace to meet the requirements of DFARS 252.204-7012 by enabling Assured Workloads or Assured Controls to create compliant boundaries — and that customers must select the FedRAMP Moderate or FedRAMP High regulatory control package for deployment within that boundary.

Primary source

DoD contractors and DIB customers can use Google Cloud and Google Workspace to meet the requirements of DFARS 252.204-7012. By enabling Assured Workloads or Assured Controls, these organizations can facilitate the creation of compliant boundaries or system enclaves within their Google Cloud environments. ... Customers must select the FedRAMP Moderate or FedRAMP High regulatory control package for deployment within the software-defined boundary.

Google CloudGoogle Cloud compliance — Defense Federal Acquisition Regulation Supplement (DFARS) · read 2026-07-27

What DFARS 252.204-7012 and NIST 800-171 require of this pattern

Quoted from the regulation itself, not paraphrased.

DFARS 252.204-7012(b)(2)(ii)(D) — the external cloud service provider test

This is the paragraph that decides most AI questions. The moment an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — and that it complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. A commercial AI endpoint is an external cloud service provider. The obligation to ensure equivalency sits on the contractor, not the vendor.

Primary source

If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.

Acquisition.gov (DFARS, MAY 2024 revision)DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27

NIST SP 800-171 — the control set itself

The security requirements DFARS 7012 imports. Rev. 3 (May 2024) is the current final publication; which revision binds a given contract is set by the solicitation, so check the clause in your award rather than assuming. For an AI deployment the load-bearing families are access control, audit and accountability, and system and communications protection — an assistant that reaches CUI must be inside the same access, logging and boundary-protection regime as any other system that touches it.

Primary source

This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations.

NIST Computer Security Resource CenterNIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations · read 2026-07-27

NIST 800-171 controls this decision turns on

These are the controls an assessor works through when CUI reaches an AI service. They are the controls at stake, not a finding against the vendor.

The compliant pattern

Establish which of the two paths you are actually on, in writing, before anything else — the product name is identical and the assurance level is not. For CUI, take the Assured Workloads path: create the folder with the FedRAMP High or IL4 control package, deploy every Gemini for Government resource inside it, and then walk the per-dependency authorization table, because a dependency that is not authorized at your level makes the features that rely on it unauthorized too. Record the folder and its control package in the SSP as the boundary.

Patterns with an authorized path for CUI

Sources for this page

Every finding above rests on one of these. Nothing on this page is asserted without one.

  1. FedRAMP MarketplaceGemini for Government — Google (Package FR2604952026) · read 2026-07-27
  2. Google Cloud documentationDeployment guidance for Gemini for Government · read 2026-07-27
  3. Acquisition.gov (DFARS, MAY 2024 revision)DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
  4. Google CloudGoogle Cloud compliance — Defense Federal Acquisition Regulation Supplement (DFARS) · read 2026-07-27

Authorization records move and this page does not. Confirm the Gemini for Government record on the FedRAMP Marketplace before you rely on anything above.

Frequently Asked Questions

Gemini for Government is FedRAMP Certified — is that enough for CUI?

Read the class, not just the status. The record is Class B (Low). DFARS 252.204-7012 names the FedRAMP Moderate baseline as the equivalency standard for an external cloud service provider handling covered defense information, so a Low certification does not by itself meet what the clause asks. Google publishes a separate Assured Workloads path at FedRAMP High and DoD IL4 for the same product.

What is the Assured Workloads path?

Google's deployment guidance requires all Gemini for Government resources to be deployed within an Assured Workloads folder configured for your specific compliance regime — FedRAMP High or IL4. The folder configuration is the boundary; a resource outside it is outside the authorization you are claiming.

Are all Gemini features authorized at IL4?

No, and Google publishes the exceptions. Its guidance notes that where a dependency isn't yet IL4 authorized, the Gemini features that depend on it aren't authorized at IL4 either. Walk the dependency table for the features you plan to use.

Your AI tools are one row in the boundary

Audit the rest of the stack — storage, email, collaboration — against the same FedRAMP test.

Launch CUI Auditor

The tool-by-tool question does not end at one tool

This Gemini for Government CUI review settles one boundary decision. AI Integration Assessment settles the whole question: a sequenced build plan with rough-order-of-magnitude costs and a route to a fixed price, plus the four things that decide whether it can start on time — who can get access and how long that takes, who is allowed to approve what, whether your records can carry an automated process, and where the system is allowed to run, boundary drawn against DFARS 252.204-7012(b)(2)(ii)(D). $12,500, fixed scope, fixed price, 4–6 weeks, exclusions published. Credits in full against an implementation engagement.

See the assessment

Related: how much CMMC certification costs — DoD’s own priced figures