CUI Compliant
0 NIST 800-171 gaps detected. Class D (High) on the FedRAMP Marketplace: record Box Enterprise Cloud Content Collaboration Platform (Box Inc.), certified since 2025-03-25, read 2026-07-27. Confirm the plan and region you are buying sit inside that offering before placing CUI there.
Box for Government
by Box
FedRAMP Status
FedRAMP Authorized
Impact Level
High
Category
File Sharing
Authorized: March 25, 2025
Overview
Box for Government is covered by a certified FedRAMP Marketplace record. The FedRAMP Marketplace record behind this is Box Enterprise Cloud Content Collaboration Platform, held by Box Inc.: Class D (High), certified since 2025-03-25, read 2026-07-27 (https://www.fedramp.gov/marketplace/products/F1212191840A/). A certification covers that named offering, not the brand — confirm the plan, region and tenancy you are buying sit inside it before placing CUI there.
CUI Risk Assessment
Class D (High) on the FedRAMP Marketplace: record Box Enterprise Cloud Content Collaboration Platform (Box Inc.), certified since 2025-03-25, read 2026-07-27. Confirm the plan and region you are buying sit inside that offering before placing CUI there.
Deployment & Architecture
Deployment Model: Government Cloud (FedRAMP boundary)
Box for Government operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.
Configuration Checklist
- 1ISSO shall verify Box for Government tenant is provisioned within FedRAMP boundary and obtain ATO documentation for inclusion in organizational authorization package.
- 2System administrator must configure SAML SSO integration with organizational identity provider ensuring PIV/CAC authentication compatibility per NIST 800-63 requirements.
- 3ISSO shall establish data governance policies defining CUI marking requirements and approved sharing protocols within Box for Government tenant.
- 4System administrator must enable comprehensive audit logging with 90-day retention minimum and configure automated log forwarding to organizational SIEM system.
- 5ISSO shall update System Security Plan section 10 to document Box for Government as external service provider with appropriate security control inheritance mappings.
- 6Contracts officer must verify Box for Government usage aligns with DFARS 252.204-7012 cloud computing requirements and adequate security provisions.
- 7ISSO shall create user access matrix defining role-based permissions aligned with organizational CUI access authorization procedures.
- 8System administrator must configure data loss prevention policies preventing unauthorized CUI exfiltration and enforcing organizational data classification requirements.
- 9Training officer shall deliver Box for Government security awareness training covering CUI handling procedures and incident reporting requirements.
- 10ISSO shall document Box for Government implementation in POA&M tracking compliance milestones and outstanding configuration items requiring remediation.
Other FedRAMP Authorized File Sharing Tools
Related Compliance Assessments
Frequently Asked Questions
Is Box for Government FedRAMP authorized?
The FedRAMP Marketplace record behind this is Box Enterprise Cloud Content Collaboration Platform, held by Box Inc.: Class D (High), certified since 2025-03-25, read 2026-07-27 (https://www.fedramp.gov/marketplace/products/F1212191840A/). A certification covers that named offering, not the brand — confirm the plan, region and tenancy you are buying sit inside it before placing CUI there.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This Box for Government CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures