Platform is certified at the Low baseline; Copilot is not named on the record

GitHub Enterprise Cloud's FedRAMP record is Class B (Low), below the Moderate baseline DFARS 252.204-7012 asks of an external cloud service provider — and the word Copilot does not appear anywhere on that record.

Commercial multi-tenant SaaS

Is GitHub Copilot (Business and Enterprise) safe for CUI?

by GitHub

As of July 27, 2026. FedRAMP authorizations, DoD Impact Level approvals and vendor data-handling terms change. Every finding below links to the primary source it came from — open it and confirm the current status before you make a boundary decision.

What this verdict rests on

The 2 sources the finding above is drawn from, quoted so you can check the reading rather than take our word for it.

Primary source

GitHub Enterprise Cloud Package ID FR1812058188 ... Type Rev5 Path Agency Class Class B (Low)

FedRAMP MarketplaceGitHub Enterprise Cloud — GitHub (Package FR1812058188) · read 2026-07-27

Primary source

If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.

Acquisition.gov (DFARS, MAY 2024 revision)DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27

FedRAMP

Platform certified at Class B (Low)

DoD Impact Level

Not established

Deployment pattern

Commercial multi-tenant SaaS

Overview

GitHub Copilot sits in the developer workflow, which is exactly where controlled technical information tends to live in an engineering-heavy contractor. The authorization picture is unusually clear-cut on one point: the platform holds a Low-baseline FedRAMP certification, and Copilot is not itemised on that record.

Where does the data physically go?

The first question in any CUI boundary decision is not whether a product is secure — it is which system boundary the data lands in, and whose authorization covers that boundary.

Data location

Not established. We did not establish, from a primary source, where Copilot inference is processed for a given Business or Enterprise tenant. GitHub documents a data-residency capability for GitHub Enterprise Cloud; whether it binds Copilot inference for your tenant is a question for GitHub in writing.

Model training and retention

GitHub states it does not use Copilot Business or Enterprise data to train its models. As elsewhere, this speaks to data use and not to which authorization boundary the code and prompts sit in.

Primary source

GitHub does not use either Copilot Business or Enterprise data to train its models.

GitHubGitHub Copilot plans — data use · read 2026-07-27

What authorization exists?

A platform-level authorization does not automatically extend to every service running on it. What matters is whether this specific AI service is named in the authorization scope.

FedRAMP authorization

The FedRAMP record for GitHub Enterprise Cloud is a Rev5, Agency-path certification at Class B (Low). Two things follow. Low is below the FedRAMP Moderate baseline DFARS 252.204-7012 requires of an external cloud service provider handling covered defense information. And the record carries no mention of Copilot at all — a platform certification is not a certification of every service on the platform.

Primary source

GitHub Enterprise Cloud Package ID FR1812058188 ... Type Rev5 Path Agency Class Class B (Low)

FedRAMP MarketplaceGitHub Enterprise Cloud — GitHub (Package FR1812058188) · read 2026-07-27

DoD Impact Level

Not established. No DoD Impact Level authorization was established for GitHub or GitHub Copilot from any primary source we read. Verify with GitHub.

Vendor's own position on CUI

Not established. We found no GitHub statement establishing a position on CUI, DFARS 252.204-7012 or ITAR for Copilot. Absence of a statement is not a prohibition — it means the question is unanswered and you should put it to GitHub in writing.

What DFARS 252.204-7012 and NIST 800-171 require of this pattern

Quoted from the regulation itself, not paraphrased.

DFARS 252.204-7012(b)(2)(ii)(D) — the external cloud service provider test

This is the paragraph that decides most AI questions. The moment an external cloud service provider stores, processes or transmits covered defense information, the contractor must require and ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline — and that it complies with the clause's incident reporting, malicious software, media preservation, forensic access and damage assessment paragraphs. A commercial AI endpoint is an external cloud service provider. The obligation to ensure equivalency sits on the contractor, not the vendor.

Primary source

If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline ... and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.

Acquisition.gov (DFARS, MAY 2024 revision)DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27

NIST SP 800-171 — the control set itself

The security requirements DFARS 7012 imports. Rev. 3 (May 2024) is the current final publication; which revision binds a given contract is set by the solicitation, so check the clause in your award rather than assuming. For an AI deployment the load-bearing families are access control, audit and accountability, and system and communications protection — an assistant that reaches CUI must be inside the same access, logging and boundary-protection regime as any other system that touches it.

Primary source

This publication provides federal agencies with recommended security requirements for protecting the confidentiality of CUI when the information is resident in nonfederal systems and organizations.

NIST Computer Security Resource CenterNIST SP 800-171 Rev. 3, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations · read 2026-07-27

NIST 800-171 controls this decision turns on

These are the controls an assessor works through when CUI reaches an AI service. They are the controls at stake, not a finding against the vendor.

The compliant pattern

Source code is often the quiet CUI problem: controlled technical information and export-controlled designs end up in repositories that were never scoped as a CUI system. Decide first whether the repository itself is in your CUI boundary. If it is, a Low-baseline external platform is the wrong place for it regardless of Copilot, and the fix is repository placement, not an AI setting. If it is not, keep it that way with pre-commit scanning and repository-level controls, and keep the Copilot decision downstream of the repository decision.

Patterns with an authorized path for CUI

Sources for this page

Every finding above rests on one of these. Nothing on this page is asserted without one.

  1. FedRAMP MarketplaceGitHub Enterprise Cloud — GitHub (Package FR1812058188) · read 2026-07-27
  2. Acquisition.gov (DFARS, MAY 2024 revision)DFARS 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting · read 2026-07-27
  3. GitHubGitHub Copilot plans — data use · read 2026-07-27

Authorization records move and this page does not. Confirm the GitHub package record on the FedRAMP Marketplace before you rely on anything above.

Frequently Asked Questions

GitHub is FedRAMP authorized — does that cover Copilot?

The GitHub Enterprise Cloud record is a Class B (Low) certification, and the word Copilot appears nowhere on it. Platform-level authorization does not automatically extend to a service running on the platform, and Low does not meet the FedRAMP Moderate equivalency DFARS 252.204-7012 asks for.

Is source code CUI?

Sometimes — controlled technical information is a CUI category, and export-controlled designs and technical data packages routinely live in repositories. Whether a given repository is in your CUI boundary is a scoping decision to make deliberately rather than discover during an assessment.

Is there a government version of GitHub Copilot?

We did not establish one from a primary source. If you need AI assistance against CUI-bearing code, the patterns that do have an authorization story are a model running inside an authorized government cloud boundary, or a self-hosted model inside your own enclave.

Your AI tools are one row in the boundary

Audit the rest of the stack — storage, email, collaboration — against the same FedRAMP test.

Launch CUI Auditor

The tool-by-tool question does not end at one tool

This GitHub Copilot (Business and Enterprise) CUI review settles one boundary decision. AI Integration Assessment settles the whole question: a sequenced build plan with rough-order-of-magnitude costs and a route to a fixed price, plus the four things that decide whether it can start on time — who can get access and how long that takes, who is allowed to approve what, whether your records can carry an automated process, and where the system is allowed to run, boundary drawn against DFARS 252.204-7012(b)(2)(ii)(D). $12,500, fixed scope, fixed price, 4–6 weeks, exclusions published. Credits in full against an implementation engagement.

See the assessment

Related: how much CMMC certification costs — DoD’s own priced figures