CUI Compliant
0 NIST 800-171 gaps detected. FedRAMP authorized at Moderate impact level. Approved for CUI handling in DoD environments.
Jira Cloud for Government
by Atlassian
FedRAMP Status
FedRAMP Authorized
Impact Level
Moderate
Category
Project Management
Authorized: March 14, 2025
Overview
Jira Cloud for Government is the FedRAMP Moderate authorized version of Atlassian Jira, providing issue tracking, agile project management, and workflow automation for government teams.
CUI Risk Assessment
FedRAMP authorized at Moderate impact level. Approved for CUI handling in DoD environments.
Deployment & Architecture
Deployment Model: Government Cloud (FedRAMP boundary)
Jira Cloud for Government operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.
Configuration Checklist
- 1ISSO must update the System Security Plan to include Jira Cloud for Government within the collaboration systems boundary and document CUI data flows per NIST 800-171 SC-7 requirements.
- 2System administrator must configure Jira user groups and permissions to align with contract-based access requirements and implement role-based access controls per AC-2 and AC-3.
- 3ISSO must establish CUI marking procedures within Jira issue types and project templates to ensure compliance with DFARS 252.204-7012 marking requirements.
- 4System administrator must integrate Jira Cloud for Government with existing identity management systems and enable multi-factor authentication per IA-2(1) requirements.
- 5ISSO must configure audit logging for all CUI-related activities within Jira and establish log retention policies per AU-6 and AU-11 requirements.
- 6Contracts officer must review all project configurations to ensure alignment with specific contract CUI handling requirements and data rights provisions.
- 7System administrator must implement data backup and recovery procedures for CUI within Jira Cloud for Government per CP-9 and CP-10 requirements.
- 8ISSO must conduct user access reviews quarterly and document findings in POA&M entries per AC-2(7) requirements.
- 9Legal counsel must validate that Jira Cloud for Government's FedRAMP authorization meets specific contract security requirements and DFARS flow-down provisions.
- 10ISSO must update the authorization boundary diagram to reflect Jira's integration with other CUI systems and document security controls inheritance per CA-3 requirements.
Other FedRAMP Authorized Project Management Tools
Related Compliance Assessments
Frequently Asked Questions
Is Jira Cloud for Government FedRAMP authorized?
Yes. Atlassian Jira Cloud for Government holds FedRAMP Moderate authorization as part of the Atlassian Government Cloud offering.
Can I use Jira Cloud for Government with CUI?
Jira Cloud for Government is authorized at Moderate and can be used for project management involving CUI data at that impact level.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This Jira Cloud for Government CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures