Certified at Class B (Low) — below the Moderate baseline the clause names
The FedRAMP record for Gemini for Government is a 20x certification at Class B (Low). DFARS 252.204-7012 names the FedRAMP Moderate baseline, so the certification as recorded sits below it — and Google separately publishes an Assured Workloads deployment path for the same product at FedRAMP High and DoD IL4. Which path you are on decides the answer.
Is Gemini for Government safe for CUI?
by Google
As of July 27, 2026. FedRAMP authorizations, DoD Impact Level approvals and vendor data-handling terms change. Every finding below links to the primary source it came from — open it and confirm the current status before you make a boundary decision.
What this verdict rests on
The 3 sources the finding above is drawn from, quoted so you can check the reading rather than take our word for it.
Primary source
“Gemini for Government Package ID FR2604952026 ... FedRAMP Certified As of 1/21/2026 ... Type 20x Path Program Class Class B (Low)”
FedRAMP Marketplace — Gemini for Government — Google (Package FR2604952026) · read 2026-07-27
Primary source
“This document provides technical guidance for US Federal agencies and DoD departments on deploying and using Gemini for Government in compliance with FedRAMP High and DoD Impact Level 4 (IL4) requirements. ... You must deploy all Gemini for Government resources within an Assured Workloads folder that's configured for your specific compliance regime (FedRAMP High or IL4).”
Google Cloud documentation — Deployment guidance for Gemini for Government · read 2026-07-27
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
FedRAMP
Certified — Class B (Low); High via Assured Workloads
DoD Impact Level
IL4 via the Assured Workloads path
Deployment pattern
Government cloud / sovereign variant
Overview
Gemini for Government is Google's packaged government AI offering, and it is the clearest example in this checker of why "is it FedRAMP certified" is the wrong question. It is certified — at the Low baseline — and it also has a documented path to FedRAMP High and DoD IL4. Those are different deployments of the same name.
Where does the data physically go?
The first question in any CUI boundary decision is not whether a product is secure — it is which system boundary the data lands in, and whose authorization covers that boundary.
Data location
Google requires Gemini for Government resources to be deployed inside an Assured Workloads folder configured for the compliance regime you need. The boundary is the folder configuration, which means data location follows the regime you selected — and a deployment outside that folder is outside the boundary you are claiming.
Primary source
“This document provides technical guidance for US Federal agencies and DoD departments on deploying and using Gemini for Government in compliance with FedRAMP High and DoD Impact Level 4 (IL4) requirements. ... You must deploy all Gemini for Government resources within an Assured Workloads folder that's configured for your specific compliance regime (FedRAMP High or IL4).”
Google Cloud documentation — Deployment guidance for Gemini for Government · read 2026-07-27
Model training and retention
Not established. We did not establish a Gemini-for-Government-specific training and retention statement from a primary source in preparing this entry. Google publishes data-governance terms for its generative-AI services; read them for the exact product and regime you deploy, and verify with Google.
What authorization exists?
A platform-level authorization does not automatically extend to every service running on it. What matters is whether this specific AI service is named in the authorization scope.
FedRAMP authorization
Two distinct authorization stories exist for the same product name, and conflating them is the trap. The Marketplace record is FedRAMP Certified as of 1/21/2026 under the 20x path at Class B (Low). Separately, Google publishes deployment guidance for running Gemini for Government in compliance with FedRAMP High and DoD IL4 via Assured Workloads. Low does not meet the Moderate baseline the DFARS clause names; the Assured Workloads path does.
Primary source
“Gemini for Government Package ID FR2604952026 ... FedRAMP Certified As of 1/21/2026 ... Type 20x Path Program Class Class B (Low)”
FedRAMP Marketplace — Gemini for Government — Google (Package FR2604952026) · read 2026-07-27
DoD Impact Level
Google's deployment guide is explicitly written for FedRAMP High and DoD Impact Level 4, and requires the resources to sit in an Assured Workloads folder configured for that regime. It also shows the granularity that matters: dependencies not yet authorized at IL4 make their dependent Gemini features unauthorized at IL4 too.
Primary source
“This document provides technical guidance for US Federal agencies and DoD departments on deploying and using Gemini for Government in compliance with FedRAMP High and DoD Impact Level 4 (IL4) requirements. ... You must deploy all Gemini for Government resources within an Assured Workloads folder that's configured for your specific compliance regime (FedRAMP High or IL4).”
Google Cloud documentation — Deployment guidance for Gemini for Government · read 2026-07-27
Vendor's own position on CUI
Google states that DoD contractors and DIB customers can use Google Cloud and Google Workspace to meet the requirements of DFARS 252.204-7012 by enabling Assured Workloads or Assured Controls to create compliant boundaries — and that customers must select the FedRAMP Moderate or FedRAMP High regulatory control package for deployment within that boundary.
Primary source
“DoD contractors and DIB customers can use Google Cloud and Google Workspace to meet the requirements of DFARS 252.204-7012. By enabling Assured Workloads or Assured Controls, these organizations can facilitate the creation of compliant boundaries or system enclaves within their Google Cloud environments. ... Customers must select the FedRAMP Moderate or FedRAMP High regulatory control package for deployment within the software-defined boundary.”
Google Cloud — Google Cloud compliance — Defense Federal Acquisition Regulation Supplement (DFARS) · read 2026-07-27
What DFARS 252.204-7012 and NIST 800-171 require of this pattern
Quoted from the regulation itself, not paraphrased.
DFARS 252.204-7012(b)(2)(ii)(D) — the external cloud service provider test
This is the paragraph that decides most AI questions. The moment an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — and that it complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. A commercial AI endpoint is an external cloud service provider. The obligation to ensure equivalency sits on the contractor, not the vendor.
Primary source
“If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.”
Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
NIST SP 800-171 — the control set itself
The security requirements DFARS 7012 imports. Rev. 3 (May 2024) is the current final publication; which revision binds a given contract is set by the solicitation, so check the clause in your award rather than assuming. For an AI deployment the load-bearing families are access control, audit and accountability, and system and communications protection — an assistant that reaches CUI must be inside the same access, logging and boundary-protection regime as any other system that touches it.
Primary source
“This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations.”
NIST Computer Security Resource Center — NIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations · read 2026-07-27
NIST 800-171 controls this decision turns on
These are the controls an assessor works through when CUI reaches an AI service. They are the controls at stake, not a finding against the vendor.
The compliant pattern
Establish which of the two paths you are actually on, in writing, before anything else — the product name is identical and the assurance level is not. For CUI, take the Assured Workloads path: create the folder with the FedRAMP High or IL4 control package, deploy every Gemini for Government resource inside it, and then walk the per-dependency authorization table, because a dependency that is not authorized at your level makes the features that rely on it unauthorized too. Record the folder and its control package in the SSP as the boundary.
Patterns with an authorized path for CUI
Sources for this page
Every finding above rests on one of these. Nothing on this page is asserted without one.
- FedRAMP Marketplace — Gemini for Government — Google (Package FR2604952026) · read 2026-07-27
- Google Cloud documentation — Deployment guidance for Gemini for Government · read 2026-07-27
- Acquisition.gov (DFARS, MAY 2024 revision) — DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
- Google Cloud — Google Cloud compliance — Defense Federal Acquisition Regulation Supplement (DFARS) · read 2026-07-27
Authorization records move and this page does not. Confirm the Gemini for Government record on the FedRAMP Marketplace before you rely on anything above.
Related Compliance Assessments
Frequently Asked Questions
Gemini for Government is FedRAMP Certified — is that enough for CUI?
Read the class, not just the status. The record is Class B (Low). DFARS 252.204-7012 names the FedRAMP Moderate baseline as the equivalency standard for an external cloud service provider handling covered defense information, so a Low certification does not by itself meet what the clause asks. Google publishes a separate Assured Workloads path at FedRAMP High and DoD IL4 for the same product.
What is the Assured Workloads path?
Google's deployment guidance requires all Gemini for Government resources to be deployed within an Assured Workloads folder configured for your specific compliance regime — FedRAMP High or IL4. The folder configuration is the boundary; a resource outside it is outside the authorization you are claiming.
Are all Gemini features authorized at IL4?
No, and Google publishes the exceptions. Its guidance notes that where a dependency isn't yet IL4 authorized, the Gemini features that depend on it aren't authorized at IL4 either. Walk the dependency table for the features you plan to use.
Your AI tools are one row in the boundary
Audit the rest of the stack — storage, email, collaboration — against the same FedRAMP test.
Launch CUI AuditorGet a defensible CUI architecture
This Gemini for Government CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture review