CUI Compliant
0 NIST 800-171 gaps detected. AWS lists Wickr as in scope of its FedRAMP certification boundary on its own services-in-scope page (aws.amazon.com/compliance/services-in-scope/FedRAMP/, read 2026-07-27); the boundary itself is the AWS GovCloud package (F1603047866, High, certified since 2016-06-21). We could not read a DoD SRG record, so we make no impact-level claim beyond FedRAMP — check DISA's DoD CSP SRG services list for IL4/IL5 yourself.
AWS Wickr
by Amazon Web Services
FedRAMP Status
FedRAMP Authorized
Impact Level
High
Category
Collaboration
Authorized: June 21, 2016
Overview
AWS Wickr provides end-to-end encrypted messaging, voice, video, and file sharing designed specifically for CUI-handling secure communications.
CUI Risk Assessment
AWS lists Wickr as in scope of its FedRAMP certification boundary on its own services-in-scope page (aws.amazon.com/compliance/services-in-scope/FedRAMP/, read 2026-07-27); the boundary itself is the AWS GovCloud package (F1603047866, High, certified since 2016-06-21). We could not read a DoD SRG record, so we make no impact-level claim beyond FedRAMP — check DISA's DoD CSP SRG services list for IL4/IL5 yourself.
Deployment & Architecture
Deployment Model: Government Cloud (FedRAMP boundary)
AWS Wickr operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.
Configuration Checklist
- 1ISSO must update the System Security Plan (SSP) to document AWS Wickr as an approved external service within the authorization boundary per NIST 800-171 SC.7 requirements.
- 2Contracts officer must verify Wickr subscription aligns with DFARS 252.204-7012 CUI requirements and document approval in contract compliance files.
- 3System administrator must configure Wickr Enterprise Console with organizational Active Directory integration and enforce multi-factor authentication for all CUI handlers.
- 4ISSO must establish message retention policies in Wickr console matching contract-specific CUI retention requirements (typically 3-7 years for technical data).
- 5System administrator must enable Wickr audit logging and integrate with existing SIEM solution to satisfy NIST 800-171 AU.2 audit event requirements.
- 6ISSO must create user training documentation specific to CUI marking protocols within Wickr messages and secure file sharing procedures.
- 7System administrator must configure Wickr network controls to prevent unauthorized external federation per NIST 800-171 SC.7 boundary protection.
- 8ISSO must update authorization boundary diagram to reflect encrypted communication flows through AWS GovCloud FedRAMP boundary.
- 9Legal counsel must review Wickr Enterprise Agreement for DFARS 252.204-7021 compliance and data location restrictions.
- 10ISSO must create POA&M entries for decommissioning any unauthorized messaging platforms (Signal, WhatsApp, Telegram) with 90-day remediation timeline.
Other FedRAMP Authorized Collaboration Tools
Related Compliance Assessments
Frequently Asked Questions
Does AWS Wickr sit inside a FedRAMP-authorized boundary?
AWS lists Wickr as in scope of its FedRAMP certification boundary on its own services-in-scope page (aws.amazon.com/compliance/services-in-scope/FedRAMP/, read 2026-07-27); the boundary is the AWS GovCloud package (F1603047866, Class D (High)). Whether it carries a DoD Impact Level provisional authorization is a separate question this page does not answer — that record lives in the DISA cloud service catalog, which we could not read.
How does Wickr compare to Signal or WhatsApp?
Wickr is in scope of a certified FedRAMP boundary and offers retention and admin audit controls; neither Signal nor WhatsApp has a FedRAMP Marketplace record. Consumer messaging apps carry no FedRAMP Marketplace record.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This AWS Wickr CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures