Partial CUI Compliance

0 NIST 800-171 gaps detected. FedRAMP authorizes cloud service offerings, not endpoint client software, so there is no AnyConnect / Secure Client record to cite. The nearest Cisco record is Cisco Security Cloud for Government (FR2304757473, Moderate); confirm with Cisco whether the service side of your deployment sits inside it before routing CUI over it.

VPN & Network Security

Cisco AnyConnect / Secure Client

by Cisco

Not FedRAMP Authorized

FedRAMP Status

Not FedRAMP Authorized

Impact Level

N/A

Category

VPN & Network Security

Overview

Cisco AnyConnect / Secure Client holds no FedRAMP authorization we can source. There is no FedRAMP Marketplace record for Cisco AnyConnect / Secure Client in the live registry at fedramp.gov/marketplace, read 2026-07-27. Treat any authorization or equivalency claim as something to obtain in writing from the vendor and to assess yourself under DFARS 252.204-7012(b)(2)(ii)(D).

CUI Risk Assessment

FedRAMP authorizes cloud service offerings, not endpoint client software, so there is no AnyConnect / Secure Client record to cite. The nearest Cisco record is Cisco Security Cloud for Government (FR2304757473, Moderate); confirm with Cisco whether the service side of your deployment sits inside it before routing CUI over it.

Deployment & Architecture

Deployment Model: Hybrid (cloud + on-prem)

Cisco AnyConnect / Secure Client has no FedRAMP authorization on record. DFARS 252.204-7012(b)(2)(ii)(D) requires an external cloud service provider to meet security requirements equivalent to the FedRAMP Moderate baseline — an authorization is the straightforward way to show that, but it is not the only one. Without one, the burden is on you to establish, document, and defend equivalency, and to meet the clause's incident-reporting and media-preservation obligations. Most contractors find an authorized alternative cheaper than carrying that burden.

Migration Checklist

  1. 1ISSO must update the System Security Plan to include AnyConnect within the authorization boundary as a boundary protection system per NIST 800-171 3.13.1.
  2. 2System administrator shall configure AnyConnect to disable split-tunneling for all CUI-accessing users to ensure NIST 800-171 3.13.2 compliance.
  3. 3ISSO must integrate AnyConnect with the organization's certificate authority to enforce multi-factor authentication per NIST 800-171 3.5.3.
  4. 4System administrator shall configure endpoint posture assessment to verify antivirus and patch compliance before VPN access per NIST 800-171 3.14.1.
  5. 5ISSO must configure AnyConnect logging to capture all connection events and forward to the organizational SIEM per NIST 800-171 3.3.1.
  6. 6System administrator shall implement geofencing restrictions to block connections from prohibited countries per DFARS 252.204-7012.
  7. 7ISSO must create POA&M entries for any legacy VPN solutions being replaced with target remediation dates.
  8. 8Contracts officer must verify AnyConnect licensing includes required security modules for CUI protection before contract execution.
  9. 9System administrator shall configure AnyConnect integration with mobile device management (MDM) for BYOD policy enforcement per NIST 800-171 3.1.18.
  10. 10ISSO must conduct tabletop exercises testing incident response procedures for compromised VPN credentials per NIST 800-171 3.6.1.

Need a CUI-Compliant Alternative?

Cisco AnyConnect / Secure Client has 0 NIST 800-171 gaps. Get real-time alerts when compliant alternatives launch, plus AI-matched contract opportunities.

Other FedRAMP Authorized VPN & Network Security Tools

Frequently Asked Questions

Is Cisco AnyConnect required for CMMC?

A VPN or zero-trust remote access solution is required by NIST 800-171 3.1.12. Cisco AnyConnect is the most common choice in the defense sector but Palo Alto GlobalProtect and Zscaler are also compliant alternatives.

Run a Full Tech Stack Audit

Check all your enterprise tools at once with our free CUI Compliance Auditor.

Launch CUI Auditor

Get a defensible CUI architecture

This Cisco AnyConnect / Secure Client CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures