Not CUI Compliant

4 NIST 800-171 gaps detected. Not FedRAMP authorized. Using this tool for CUI creates compliance violations under NIST 800-171 and DFARS 252.204-7012.

Video Conferencing

GoToMeeting

by GoTo

Not FedRAMP Authorized

FedRAMP Status

Not FedRAMP Authorized

Impact Level

N/A

Category

Video Conferencing

Overview

GoToMeeting is a commercial video conferencing service from GoTo (formerly LogMeIn). It is not FedRAMP authorized and should not be used for government meetings involving CUI.

CUI Risk Assessment

Not FedRAMP authorized. Using this tool for CUI creates compliance violations under NIST 800-171 and DFARS 252.204-7012.

Deployment & Architecture

Deployment Model: Cloud SaaS (vendor-hosted)

GoToMeeting has no FedRAMP authorization on record. DFARS 252.204-7012(b)(2)(ii)(D) requires an external cloud service provider to meet security requirements equivalent to the FedRAMP Moderate baseline — an authorization is the straightforward way to show that, but it is not the only one. Without one, the burden is on you to establish, document, and defend equivalency, and to meet the clause's incident-reporting and media-preservation obligations. Most contractors find an authorized alternative cheaper than carrying that burden.

Migration Checklist

  1. 1ISSO shall immediately audit all active GoToMeeting accounts and document CUI exposure incidents in the POA&M per NIST 800-171 requirement 3.13.8.
  2. 2Contracts officer must notify DCMA of non-compliant tool usage and provide remediation timeline per DFARS 252.204-7012 notification requirements.
  3. 3System administrator shall deploy FedRAMP-authorized alternative (Microsoft Teams Government or Adobe Connect FedRAMP) within the established authorization boundary.
  4. 4ISSO shall update the System Security Plan (SSP) to remove GoToMeeting from the authorization boundary diagram and add compliant replacement.
  5. 5System administrator must securely delete all meeting recordings and chat logs from GoToMeeting infrastructure and obtain vendor deletion certification.
  6. 6ISSO shall implement data loss prevention (DLP) policies blocking future GoToMeeting access from CUI processing systems per NIST 800-171 AC-4.
  7. 7Training officer must conduct mandatory security awareness training on CUI handling during virtual meetings for all affected personnel.
  8. 8ISSO shall configure audit logging on replacement platform to capture required events per NIST 800-171 AU family requirements.
  9. 9System administrator must establish encrypted communication channels and validate FIPS 140-2 compliance of replacement solution.
  10. 10ISSO shall document migration completion in authorization boundary diagram and submit updated documentation to authorizing official.

NIST 800-171 Violations

Using GoToMeeting for CUI without FedRAMP authorization may violate these NIST 800-171 controls:

Need a CUI-Compliant Alternative?

GoToMeeting has 4 NIST 800-171 gaps. Get real-time alerts when compliant alternatives launch, plus AI-matched contract opportunities.

Frequently Asked Questions

Is GoToMeeting FedRAMP authorized?

No. GoToMeeting does not hold FedRAMP authorization at any impact level.

Can I discuss CUI on GoToMeeting?

No. GoToMeeting is not authorized for CUI discussions. Use Zoom for Government or Webex for Government instead.

What is a compliant alternative to GoToMeeting?

Zoom for Government (FedRAMP Moderate) and Webex for Government (FedRAMP Moderate) are authorized video conferencing alternatives.

Run a Full Tech Stack Audit

Check all your enterprise tools at once with our free CUI Compliance Auditor.

Launch CUI Auditor

Get a defensible CUI architecture

This GoToMeeting CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures