CUI Compliant

0 NIST 800-171 gaps detected. Certified under Palo Alto Networks, which acquired CyberArk: the marketplace record Idira Identity Security Government Services Platform (FR2001619337, Class D (High), certified since 2024-03-14, read 2026-07-27) links to cyberark.com/products/access-management/. Confirm the offering you are buying is the one that record covers.

Identity & Access Management

CyberArk

by CyberArk

FedRAMP AuthorizedHigh Impact

FedRAMP Status

FedRAMP Authorized

Impact Level

High

Category

Identity & Access Management

Authorized: March 14, 2024

Overview

CyberArk is covered by a certified FedRAMP Marketplace record. The FedRAMP Marketplace record behind this is Idira Identity Security Government Services Platform, held by Palo Alto Networks, Inc.: Class D (High), certified since 2024-03-14, read 2026-07-27 (https://www.fedramp.gov/marketplace/products/FR2001619337/). A certification covers that named offering, not the brand — confirm the plan, region and tenancy you are buying sit inside it before placing CUI there.

CUI Risk Assessment

Certified under Palo Alto Networks, which acquired CyberArk: the marketplace record Idira Identity Security Government Services Platform (FR2001619337, Class D (High), certified since 2024-03-14, read 2026-07-27) links to cyberark.com/products/access-management/. Confirm the offering you are buying is the one that record covers.

Deployment & Architecture

Deployment Model: Government Cloud (FedRAMP boundary)

CyberArk operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.

Configuration Checklist

  1. 1ISSO must update the System Security Plan (SSP) to include CyberArk components within the authorization boundary and document privileged access management controls (AC-2, AC-6, AU-2).
  2. 2Network administrator must configure network segmentation between CyberArk vault infrastructure and CUI processing systems per NIST 800-171 SC-7 requirements.
  3. 3System administrator must install and configure CyberArk Vault server within FedRAMP authorized cloud infrastructure ensuring encryption at rest and in transit.
  4. 4Database administrator must onboard privileged service accounts supporting CUI applications into CyberArk vault with automated password rotation enabled.
  5. 5ISSO must configure session recording policies for all privileged access to CUI systems ensuring 90-day retention minimum per AU-11 requirements.
  6. 6Security administrator must integrate CyberArk with existing SIEM platform for centralized monitoring and alerting of privileged access events.
  7. 7Training coordinator must conduct role-based CyberArk training for 16 hours (administrators) and 8 hours (end users) with CUI handling procedures.
  8. 8Compliance officer must update DFARS 252.204-7012 implementation documentation to reflect CyberArk privileged access controls and monitoring capabilities.
  9. 9ISSO must create POA&M entries for any privileged accounts not yet onboarded to CyberArk with target completion dates.
  10. 10Quality assurance lead must validate CyberArk session recording functionality captures all privileged commands executed on CUI systems for audit purposes.

Frequently Asked Questions

Do I need PAM for CMMC compliance?

NIST 800-171 requires controlling privileged access (3.1.5, 3.1.6, 3.1.7) and monitoring privileged sessions. A PAM solution like CyberArk provides centralized enforcement of these controls.

Run a Full Tech Stack Audit

Check all your enterprise tools at once with our free CUI Compliance Auditor.

Launch CUI Auditor

Get a defensible CUI architecture

This CyberArk CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures