Not CUI Compliant
4 NIST 800-171 gaps detected. Not FedRAMP authorized. Consumer-grade backup with no CUI protections. Cannot be used for backing up CUI data.
Carbonite / CrashPlan
by OpenText / CrashPlan
FedRAMP Status
Not FedRAMP Authorized
Impact Level
N/A
Category
Backup & Recovery
Overview
Carbonite and CrashPlan are consumer-grade cloud backup solutions commonly used by small businesses. They lack FedRAMP authorization, government-grade encryption, and the audit controls required for CUI protection. CUI data must not be backed up to these platforms.
CUI Risk Assessment
Not FedRAMP authorized. Consumer-grade backup with no CUI protections. Cannot be used for backing up CUI data.
Deployment & Architecture
Deployment Model: Cloud SaaS (vendor-hosted)
Carbonite / CrashPlan has no FedRAMP authorization on record. DFARS 252.204-7012(b)(2)(ii)(D) requires an external cloud service provider to meet security requirements equivalent to the FedRAMP Moderate baseline — an authorization is the straightforward way to show that, but it is not the only one. Without one, the burden is on you to establish, document, and defend equivalency, and to meet the clause's incident-reporting and media-preservation obligations. Most contractors find an authorized alternative cheaper than carrying that burden.
Migration Checklist
- 1ISSO must immediately audit all endpoints to identify Carbonite/CrashPlan installations and create inventory with system owners responsible for each deployment.
- 2Legal team must review data processing agreements to determine if CUI was backed up and assess breach notification requirements under DFARS 252.204-7012.
- 3Sysadmin must disable all Carbonite/CrashPlan backup agents and block network access to prevent further CUI transmission until compliant solution is deployed.
- 4ISSO must update SSP Section 10.2 to remove unauthorized cloud backup services from the authorization boundary diagram and data flow documentation.
- 5Contracts officer must procure FedRAMP Moderate authorized backup solution (Druva inSync Gov, Carbonite Safe for Government, or equivalent) within 30 days.
- 6Sysadmin must export non-CUI data using vendor export tools and document complete data deletion from Carbonite/CrashPlan systems with destruction certificates.
- 7ISSO must create POA&M entries documenting the unauthorized cloud backup usage and remediation timeline per NIST 800-171 requirements.
- 8System administrator must deploy replacement backup solution with proper CUI marking and encryption controls per NIST 800-171 SC-28 requirements.
- 9ISSO must conduct user training on backup policy compliance and CUI identification procedures to prevent future violations.
- 10ISSO must update SPRS score in SAM.gov to reflect remediation of backup security controls and prepare documentation for next DCMA assessment.
NIST 800-171 Violations
Using Carbonite / CrashPlan for CUI without FedRAMP authorization may violate these NIST 800-171 controls:
Need a CUI-Compliant Alternative?
Carbonite / CrashPlan has 4 NIST 800-171 gaps. Get real-time alerts when compliant alternatives launch, plus AI-matched contract opportunities.
FedRAMP Compliant Alternatives
Frequently Asked Questions
Can I use CrashPlan to back up CUI data?
No. CrashPlan and Carbonite are not FedRAMP authorized and lack the security controls required for CUI. Use Veeam Government or Commvault Government for compliant backup.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This Carbonite / CrashPlan CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures