CUI Compliant

0 NIST 800-171 gaps detected. FedRAMP authorized at Moderate impact level. Approved for CUI handling in DoD environments.

File Sharing

Citrix ShareFile

by Citrix

FedRAMP AuthorizedModerate Impact

FedRAMP Status

FedRAMP Authorized

Impact Level

Moderate

Category

File Sharing

Authorized: April 18, 2022

Overview

Citrix ShareFile Government holds FedRAMP Moderate authorization and provides secure file sharing, sync, and storage with encryption and access controls for government contractors.

CUI Risk Assessment

FedRAMP authorized at Moderate impact level. Approved for CUI handling in DoD environments.

Deployment & Architecture

Deployment Model: Government Cloud (FedRAMP boundary)

Citrix ShareFile operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.

Configuration Checklist

  1. 1ISSO must update the System Security Plan to include Citrix ShareFile within the authorization boundary, documenting data flows and CUI handling procedures per NIST 800-171 requirements.
  2. 2System administrator shall configure SAML/OIDC integration with DoD-approved identity providers to ensure multi-factor authentication for all CUI access per DFARS 252.204-7012.
  3. 3ISSO must implement FIPS 140-2 Level 3 encryption key management for all CUI data at rest and in transit, documenting key lifecycle procedures in the SSP.
  4. 4System administrator shall configure audit logging to capture all file access, sharing, and modification events, forwarding logs to centralized SIEM per AU-2 requirements.
  5. 5ISSO must establish role-based access controls aligned with CUI categories and need-to-know principles, documenting user access matrices per AC-2 control requirements.
  6. 6Contracts officer shall review all ShareFile user agreements and data processing addendums to ensure DFARS 252.204-7021 flow-down requirements are met.
  7. 7System administrator must configure data loss prevention rules to prevent sharing of unmarked CUI and implement automated scanning for sensitive data patterns.
  8. 8ISSO shall create POA&M entries for any ShareFile configuration gaps identified during security control testing, with remediation timelines per organizational risk tolerance.
  9. 9Legal team must review data residency requirements and validate that all CUI data remains within CONUS boundaries per FedRAMP authorization scope.
  10. 10ISSO must establish quarterly user access reviews and annual penetration testing procedures specific to ShareFile CUI handling capabilities per CA-7 requirements.

Frequently Asked Questions

Is Citrix ShareFile FedRAMP authorized?

Yes. Citrix ShareFile holds FedRAMP Moderate authorization for secure file sharing and storage.

Can I use Citrix ShareFile with CUI?

Citrix ShareFile is authorized at Moderate and can be used for CUI file sharing with proper access controls configured.

Run a Full Tech Stack Audit

Check all your enterprise tools at once with our free CUI Compliance Auditor.

Launch CUI Auditor

Get a defensible CUI architecture

This Citrix ShareFile CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures