CUI Compliant
0 NIST 800-171 gaps detected. FedRAMP Moderate authorized. Approved for handling CUI in e-signature workflows.
DocuSign Government
by DocuSign
FedRAMP Status
FedRAMP Authorized
Impact Level
Moderate
Category
E-Signature & Document Management
Authorized: August 24, 2017
Overview
DocuSign Government is FedRAMP Moderate authorized. It provides compliant e-signature, document management, and contract lifecycle management for defense contractors handling CUI in their contracting workflows.
CUI Risk Assessment
FedRAMP Moderate authorized. Approved for handling CUI in e-signature workflows.
Deployment & Architecture
Deployment Model: Government Cloud (FedRAMP boundary)
DocuSign Government operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.
Configuration Checklist
- 1ISSO must update the System Security Plan to document DocuSign Government as an external service provider within the authorization boundary, including data flow diagrams showing CUI movement.
- 2System administrator shall configure CAC/PIV authentication integration with existing Active Directory infrastructure to meet NIST 800-171 IA-2 requirements.
- 3Contracts officer must establish user roles and permissions based on principle of least privilege, documenting access decisions in security authorization documentation.
- 4ISSO shall implement audit logging configuration to capture all CUI document access events per NIST 800-171 AU-3 requirements.
- 5System administrator must configure data retention policies aligned with DFARS 252.204-7012 requirements for CUI retention and disposition.
- 6Legal counsel should review and execute Business Associate Agreement with DocuSign Government addressing CUI handling requirements.
- 7ISSO must update the authorization boundary diagram to reflect DocuSign Government connectivity and data flows for CMMC Level 2 assessment.
- 8Training coordinator shall conduct mandatory user training on CUI marking requirements before document upload to DocuSign Government platform.
- 9System administrator must implement network controls to ensure DocuSign Government access only occurs through approved network boundaries.
- 10ISSO shall document incident response procedures specific to DocuSign Government CUI breaches in the Incident Response Plan and POA&M entries.
Related Compliance Assessments
Frequently Asked Questions
Is DocuSign Government approved for CUI?
Yes. DocuSign Government holds FedRAMP Moderate authorization, which covers CUI in e-signature and document workflows within that boundary.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This DocuSign Government CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures