Not CUI Compliant

4 NIST 800-171 gaps detected. Not FedRAMP authorized. Using this tool for CUI creates compliance violations under NIST 800-171 and DFARS 252.204-7012.

Email

HEY Email

by Basecamp

Not FedRAMP Authorized

FedRAMP Status

Not FedRAMP Authorized

Impact Level

N/A

Category

Email

Overview

HEY is a consumer-focused email service from Basecamp that reimagines inbox management. It is not FedRAMP authorized and lacks the security controls required for government CUI handling.

CUI Risk Assessment

Not FedRAMP authorized. Using this tool for CUI creates compliance violations under NIST 800-171 and DFARS 252.204-7012.

Deployment & Architecture

Deployment Model: Cloud SaaS (vendor-hosted)

HEY Email has no FedRAMP authorization on record. DFARS 252.204-7012(b)(2)(ii)(D) requires an external cloud service provider to meet security requirements equivalent to the FedRAMP Moderate baseline — an authorization is the straightforward way to show that, but it is not the only one. Without one, the burden is on you to establish, document, and defend equivalency, and to meet the clause's incident-reporting and media-preservation obligations. Most contractors find an authorized alternative cheaper than carrying that burden.

Migration Checklist

  1. 1ISSO: Conduct immediate CUI data inventory across all HEY Email accounts within 5 business days
  2. 2Contracts team: Review all active contracts for CUI email transmission requirements and notify COR of service change within 1 week
  3. 3IT Admin: Procure FedRAMP-authorized email solution (Office 365 GCC High/Google Gov) - 2-3 weeks procurement cycle
  4. 4ISSO: Export all business-critical emails while segregating any CUI for secure transfer via approved methods within 2 weeks
  5. 5IT Admin: Configure new compliant email system with required NIST 800-171 controls (MFA, encryption, audit logging) - 1 week
  6. 6ISSO: Update System Security Plan and authorization boundary diagrams to reflect new email architecture within 2 weeks
  7. 7Training team: Conduct CUI handling refresher training for all users focusing on approved email usage - 1 week
  8. 8ISSO: Document migration completion in POAM and schedule follow-up CMMC readiness assessment within 30 days

NIST 800-171 Violations

Using HEY Email for CUI without FedRAMP authorization may violate these NIST 800-171 controls:

Need a CUI-Compliant Alternative?

HEY Email has 4 NIST 800-171 gaps. Get real-time alerts when compliant alternatives launch, plus AI-matched contract opportunities.

Frequently Asked Questions

Is HEY Email FedRAMP authorized?

No. HEY Email is not FedRAMP authorized and is designed for consumer and small business use, not government compliance.

Can I use HEY Email with CUI?

No. HEY Email does not meet FedRAMP or NIST 800-171 requirements for CUI.

What is a compliant alternative to HEY Email?

Microsoft 365 GCC High (FedRAMP High) is the recommended email platform for defense contractors handling CUI.

Run a Full Tech Stack Audit

Check all your enterprise tools at once with our free CUI Compliance Auditor.

Launch CUI Auditor

Get a defensible CUI architecture

This HEY Email CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures