CUI Compliant
0 NIST 800-171 gaps detected. Certified under Palo Alto Networks, which acquired CyberArk: the marketplace record Idira Identity Security Government Services Platform (FR2001619337, Class D (High), certified since 2024-03-14, read 2026-07-27) links to cyberark.com/products/access-management/. Confirm the offering you are buying is the one that record covers.
CyberArk
by CyberArk
FedRAMP Status
FedRAMP Authorized
Impact Level
High
Category
Identity & Access Management
Authorized: March 14, 2024
Overview
CyberArk is covered by a certified FedRAMP Marketplace record. The FedRAMP Marketplace record behind this is Idira Identity Security Government Services Platform, held by Palo Alto Networks, Inc.: Class D (High), certified since 2024-03-14, read 2026-07-27 (https://www.fedramp.gov/marketplace/products/FR2001619337/). A certification covers that named offering, not the brand — confirm the plan, region and tenancy you are buying sit inside it before placing CUI there.
CUI Risk Assessment
Certified under Palo Alto Networks, which acquired CyberArk: the marketplace record Idira Identity Security Government Services Platform (FR2001619337, Class D (High), certified since 2024-03-14, read 2026-07-27) links to cyberark.com/products/access-management/. Confirm the offering you are buying is the one that record covers.
Deployment & Architecture
Deployment Model: Government Cloud (FedRAMP boundary)
CyberArk operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.
Configuration Checklist
- 1ISSO must update the System Security Plan (SSP) to include CyberArk components within the authorization boundary and document privileged access management controls (AC-2, AC-6, AU-2).
- 2Network administrator must configure network segmentation between CyberArk vault infrastructure and CUI processing systems per NIST 800-171 SC-7 requirements.
- 3System administrator must install and configure CyberArk Vault server within FedRAMP authorized cloud infrastructure ensuring encryption at rest and in transit.
- 4Database administrator must onboard privileged service accounts supporting CUI applications into CyberArk vault with automated password rotation enabled.
- 5ISSO must configure session recording policies for all privileged access to CUI systems ensuring 90-day retention minimum per AU-11 requirements.
- 6Security administrator must integrate CyberArk with existing SIEM platform for centralized monitoring and alerting of privileged access events.
- 7Training coordinator must conduct role-based CyberArk training for 16 hours (administrators) and 8 hours (end users) with CUI handling procedures.
- 8Compliance officer must update DFARS 252.204-7012 implementation documentation to reflect CyberArk privileged access controls and monitoring capabilities.
- 9ISSO must create POA&M entries for any privileged accounts not yet onboarded to CyberArk with target completion dates.
- 10Quality assurance lead must validate CyberArk session recording functionality captures all privileged commands executed on CUI systems for audit purposes.
Other FedRAMP Authorized Identity & Access Management Tools
Related Compliance Assessments
Frequently Asked Questions
Do I need PAM for CMMC compliance?
NIST 800-171 requires controlling privileged access (3.1.5, 3.1.6, 3.1.7) and monitoring privileged sessions. A PAM solution like CyberArk provides centralized enforcement of these controls.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This CyberArk CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures