CUI Compliant

0 NIST 800-171 gaps detected. AWS lists Wickr as in scope of its FedRAMP certification boundary on its own services-in-scope page (aws.amazon.com/compliance/services-in-scope/FedRAMP/, read 2026-07-27); the boundary itself is the AWS GovCloud package (F1603047866, High, certified since 2016-06-21). We could not read a DoD SRG record, so we make no impact-level claim beyond FedRAMP — check DISA's DoD CSP SRG services list for IL4/IL5 yourself.

Collaboration

AWS Wickr

by Amazon Web Services

FedRAMP AuthorizedHigh Impact

FedRAMP Status

FedRAMP Authorized

Impact Level

High

Category

Collaboration

Authorized: June 21, 2016

Overview

AWS Wickr provides end-to-end encrypted messaging, voice, video, and file sharing designed specifically for CUI-handling secure communications.

CUI Risk Assessment

AWS lists Wickr as in scope of its FedRAMP certification boundary on its own services-in-scope page (aws.amazon.com/compliance/services-in-scope/FedRAMP/, read 2026-07-27); the boundary itself is the AWS GovCloud package (F1603047866, High, certified since 2016-06-21). We could not read a DoD SRG record, so we make no impact-level claim beyond FedRAMP — check DISA's DoD CSP SRG services list for IL4/IL5 yourself.

Deployment & Architecture

Deployment Model: Government Cloud (FedRAMP boundary)

AWS Wickr operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.

Configuration Checklist

  1. 1ISSO must update the System Security Plan (SSP) to document AWS Wickr as an approved external service within the authorization boundary per NIST 800-171 SC.7 requirements.
  2. 2Contracts officer must verify Wickr subscription aligns with DFARS 252.204-7012 CUI requirements and document approval in contract compliance files.
  3. 3System administrator must configure Wickr Enterprise Console with organizational Active Directory integration and enforce multi-factor authentication for all CUI handlers.
  4. 4ISSO must establish message retention policies in Wickr console matching contract-specific CUI retention requirements (typically 3-7 years for technical data).
  5. 5System administrator must enable Wickr audit logging and integrate with existing SIEM solution to satisfy NIST 800-171 AU.2 audit event requirements.
  6. 6ISSO must create user training documentation specific to CUI marking protocols within Wickr messages and secure file sharing procedures.
  7. 7System administrator must configure Wickr network controls to prevent unauthorized external federation per NIST 800-171 SC.7 boundary protection.
  8. 8ISSO must update authorization boundary diagram to reflect encrypted communication flows through AWS GovCloud FedRAMP boundary.
  9. 9Legal counsel must review Wickr Enterprise Agreement for DFARS 252.204-7021 compliance and data location restrictions.
  10. 10ISSO must create POA&M entries for decommissioning any unauthorized messaging platforms (Signal, WhatsApp, Telegram) with 90-day remediation timeline.

Other FedRAMP Authorized Collaboration Tools

Frequently Asked Questions

Does AWS Wickr sit inside a FedRAMP-authorized boundary?

AWS lists Wickr as in scope of its FedRAMP certification boundary on its own services-in-scope page (aws.amazon.com/compliance/services-in-scope/FedRAMP/, read 2026-07-27); the boundary is the AWS GovCloud package (F1603047866, Class D (High)). Whether it carries a DoD Impact Level provisional authorization is a separate question this page does not answer — that record lives in the DISA cloud service catalog, which we could not read.

How does Wickr compare to Signal or WhatsApp?

Wickr is in scope of a certified FedRAMP boundary and offers retention and admin audit controls; neither Signal nor WhatsApp has a FedRAMP Marketplace record. Consumer messaging apps carry no FedRAMP Marketplace record.

Run a Full Tech Stack Audit

Check all your enterprise tools at once with our free CUI Compliance Auditor.

Launch CUI Auditor

Get a defensible CUI architecture

This AWS Wickr CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures