Not CUI Compliant

4 NIST 800-171 gaps detected. Not FedRAMP authorized. Using this tool for CUI creates compliance violations under NIST 800-171 and DFARS 252.204-7012.

File Sharing

Hightail

by OpenText

Not FedRAMP Authorized

FedRAMP Status

Not FedRAMP Authorized

Impact Level

N/A

Category

File Sharing

Overview

Hightail (formerly YouSendIt) is a commercial file sharing and creative collaboration tool owned by OpenText. It is not FedRAMP authorized and should not be used for CUI file transfers.

CUI Risk Assessment

Not FedRAMP authorized. Using this tool for CUI creates compliance violations under NIST 800-171 and DFARS 252.204-7012.

Deployment & Architecture

Deployment Model: Cloud SaaS (vendor-hosted)

Hightail has no FedRAMP authorization on record. DFARS 252.204-7012(b)(2)(ii)(D) requires an external cloud service provider to meet security requirements equivalent to the FedRAMP Moderate baseline — an authorization is the straightforward way to show that, but it is not the only one. Without one, the burden is on you to establish, document, and defend equivalency, and to meet the clause's incident-reporting and media-preservation obligations. Most contractors find an authorized alternative cheaper than carrying that burden.

Migration Checklist

  1. 1ISSO must immediately audit all Hightail accounts to identify CUI data and document findings in incident response tracking system per NIST 800-171 requirement 3.6.1.
  2. 2Contracts officer shall review all active contracts to determine CUI processing requirements and notify customers of file sharing tool changes per DFARS 252.204-7012 compliance.
  3. 3System administrator must disable all Hightail integrations and API connections to prevent automated CUI uploads while maintaining audit logs per NIST 800-171 control AU-2.
  4. 4ISSO shall update the authorization boundary diagram to remove Hightail and document the change in SSP Section 8 (System Boundary).
  5. 5Legal team must coordinate with OpenText/Hightail to execute data destruction certificates for any CUI previously stored in their systems.
  6. 6System administrator shall implement FedRAMP authorized replacement solution (Box for Government, SharePoint, or DoD Safe) within the existing authorization boundary.
  7. 7ISSO must create POA&M entry documenting migration timeline and interim risk mitigation measures per NIST 800-171 control CA-5.
  8. 8Training officer shall conduct mandatory briefings for all users on new file sharing procedures and CUI handling requirements per DFARS 252.204-7012.
  9. 9ISSO shall update incident response procedures to include file sharing tool compliance verification and unauthorized cloud service detection.
  10. 10Compliance officer must schedule follow-up assessment within 90 days to verify complete Hightail elimination and proper implementation of authorized alternatives.

NIST 800-171 Violations

Using Hightail for CUI without FedRAMP authorization may violate these NIST 800-171 controls:

Need a CUI-Compliant Alternative?

Hightail has 4 NIST 800-171 gaps. Get real-time alerts when compliant alternatives launch, plus AI-matched contract opportunities.

Frequently Asked Questions

Is Hightail FedRAMP authorized?

No. Hightail does not hold FedRAMP authorization at any impact level.

Can I use Hightail with CUI?

No. Hightail lacks the FedRAMP authorization and security controls required for CUI file sharing.

What is a compliant alternative to Hightail?

SharePoint GCC High and Citrix ShareFile are FedRAMP authorized file sharing platforms for government contractors.

Run a Full Tech Stack Audit

Check all your enterprise tools at once with our free CUI Compliance Auditor.

Launch CUI Auditor

Get a defensible CUI architecture

This Hightail CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures