CUI Compliant
0 NIST 800-171 gaps detected. FedRAMP Moderate authorized. Handles secure file sharing, MFT, SFTP, and email.
Kiteworks
by Kiteworks
FedRAMP Status
FedRAMP Authorized
Impact Level
Moderate
Category
File Sharing
Authorized: June 1, 2017
Overview
Kiteworks provides secure file sharing, SFTP, MFT, and email all in one FedRAMP authorized platform. Widely used by mid-size contractors for CMMC compliance.
CUI Risk Assessment
FedRAMP Moderate authorized. Handles secure file sharing, MFT, SFTP, and email.
Deployment & Architecture
Deployment Model: Government Cloud (FedRAMP boundary)
Kiteworks operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.
Configuration Checklist
- 1ISSO must update the System Security Plan (SSP) to include Kiteworks within the authorization boundary and document its role in CUI data flows per NIST 800-171 requirements.
- 2Systems administrator shall configure Kiteworks encryption settings to meet FIPS 140-2 requirements for data at rest and TLS 1.2+ for data in transit per DFARS 252.204-7012.
- 3ISSO must establish user access controls within Kiteworks aligned with need-to-know principles and document role-based permissions in the access control matrix.
- 4Systems administrator shall integrate Kiteworks with existing Active Directory infrastructure and configure multi-factor authentication for all CUI access.
- 5ISSO must configure audit logging within Kiteworks to capture all CUI access events and establish log retention policies meeting NIST 800-171 AU controls.
- 6Contracts officer shall validate that Kiteworks usage aligns with contract requirements and notify customers of the secure file sharing mechanism.
- 7Systems administrator must establish data loss prevention (DLP) policies within Kiteworks to prevent unauthorized CUI disclosure and configure automated scanning.
- 8ISSO shall conduct user training on CUI handling procedures within Kiteworks including proper marking, sharing protocols, and incident reporting requirements.
- 9Systems administrator must implement backup and disaster recovery procedures for Kiteworks data ensuring CUI protection during recovery operations.
- 10ISSO must update the authorization boundary diagram to reflect Kiteworks data flows and establish continuous monitoring procedures for configuration compliance.
Other FedRAMP Authorized File Sharing Tools
Frequently Asked Questions
Is Kiteworks FedRAMP authorized?
Yes. Kiteworks holds FedRAMP Moderate authorization and supports CMMC Level 2, DFARS 7012, and ITAR compliance.
What makes Kiteworks different from Box or SharePoint?
Kiteworks combines file sharing, managed file transfer, SFTP, and secure email in a single FedRAMP authorized platform. It provides comprehensive audit logging and DLP specifically designed for CUI compliance.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This Kiteworks CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures