Not CUI Compliant

5 NIST 800-171 gaps detected. Consumer VPNs are foreign-owned, have no FedRAMP authorization, no audit logging, and no centralized management. Absolutely not appropriate for CUI.

VPN & Network Security

NordVPN / ExpressVPN (Consumer)

by Various

Not FedRAMP Authorized

FedRAMP Status

Not FedRAMP Authorized

Impact Level

N/A

Category

VPN & Network Security

Overview

Consumer VPN services like NordVPN (Lithuanian) and ExpressVPN (acquired by Kape Technologies, Israeli) are absolutely inappropriate for defense contractor use. They are foreign-owned, have no FedRAMP authorization, no centralized management, no audit logging, and route traffic through infrastructure outside US government control.

CUI Risk Assessment

Consumer VPNs are foreign-owned, have no FedRAMP authorization, no audit logging, and no centralized management. Absolutely not appropriate for CUI.

Deployment & Architecture

Deployment Model: Cloud SaaS (vendor-hosted)

NordVPN / ExpressVPN (Consumer) has no FedRAMP authorization on record. DFARS 252.204-7012(b)(2)(ii)(D) requires an external cloud service provider to meet security requirements equivalent to the FedRAMP Moderate baseline — an authorization is the straightforward way to show that, but it is not the only one. Without one, the burden is on you to establish, document, and defend equivalency, and to meet the clause's incident-reporting and media-preservation obligations. Most contractors find an authorized alternative cheaper than carrying that burden.

Migration Checklist

  1. 1ISSO must immediately document consumer VPN usage as a critical finding in the POA&M with 30-day remediation timeline per DFARS 252.204-7012.
  2. 2Sysadmin must block all consumer VPN traffic at firewall level and implement DNS blocking for known VPN provider endpoints.
  3. 3ISSO must notify the Contracting Officer within 72 hours of consumer VPN discovery per DFARS 252.204-7019 incident reporting requirements.
  4. 4Legal counsel must review all contracts for potential breach notifications required due to unauthorized foreign technology usage.
  5. 5ISSO must update the System Security Plan Section 9.2 to document removal of unauthorized system interconnections and foreign technology.
  6. 6Procurement officer must initiate acquisition of FedRAMP Moderate approved VPN solution or government community cloud access.
  7. 7Sysadmin must configure replacement VPN with FIPS 140-2 Level 2 encryption, certificate-based authentication, and comprehensive audit logging per NIST 800-171 AU family.
  8. 8ISSO must conduct user training on new remote access procedures and foreign influence awareness per DFARS 252.204-7012.
  9. 9Sysadmin must implement network segmentation to isolate CUI systems from any remaining consumer VPN access points.
  10. 10ISSO must schedule independent verification testing to confirm complete removal of consumer VPN access to CUI environments.

NIST 800-171 Violations

Using NordVPN / ExpressVPN (Consumer) for CUI without FedRAMP authorization may violate these NIST 800-171 controls:

Need a CUI-Compliant Alternative?

NordVPN / ExpressVPN (Consumer) has 5 NIST 800-171 gaps. Get real-time alerts when compliant alternatives launch, plus AI-matched contract opportunities.

Frequently Asked Questions

Can I use NordVPN for remote access to CUI systems?

Absolutely not. Consumer VPNs are foreign-owned with no FedRAMP authorization, no audit logging, and no centralized management. Use enterprise solutions like Cisco AnyConnect, Palo Alto GlobalProtect, or Zscaler.

Run a Full Tech Stack Audit

Check all your enterprise tools at once with our free CUI Compliance Auditor.

Launch CUI Auditor

Get a defensible CUI architecture

This NordVPN / ExpressVPN (Consumer) CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures