Not CUI Compliant
4 NIST 800-171 gaps detected. Not FedRAMP authorized despite marketing claims. Has suffered multiple data breaches. Cannot be used for credential management in CUI environments.
LastPass
by LastPass (GoTo)
FedRAMP Status
Not FedRAMP Authorized
Impact Level
N/A
Category
Identity & Access Management
Overview
LastPass is a widely used password manager that has suffered multiple significant data breaches. It is not FedRAMP authorized despite marketing language suggesting government trust. Defense contractors should not store credentials for CUI systems in LastPass.
CUI Risk Assessment
Not FedRAMP authorized despite marketing claims. Has suffered multiple data breaches. Cannot be used for credential management in CUI environments.
Deployment & Architecture
Deployment Model: Cloud SaaS (vendor-hosted)
LastPass has no FedRAMP authorization on record. DFARS 252.204-7012(b)(2)(ii)(D) requires an external cloud service provider to meet security requirements equivalent to the FedRAMP Moderate baseline — an authorization is the straightforward way to show that, but it is not the only one. Without one, the burden is on you to establish, document, and defend equivalency, and to meet the clause's incident-reporting and media-preservation obligations. Most contractors find an authorized alternative cheaper than carrying that burden.
Migration Checklist
- 1ISSO must immediately add LastPass removal to the POA&M with 90-day completion target per DFARS 252.204-7012 requirements.
- 2Contracts officer should review all DoD contracts to identify CUI handling requirements triggering NIST 800-171 compliance.
- 3ISSO must export all credential data from LastPass using encrypted CSV export while maintaining CUI data protection protocols.
- 4System administrator should implement FedRAMP-authorized alternative (CyberArk, Azure AD) or deploy on-premises KeePass infrastructure.
- 5ISSO must update the System Security Plan to remove LastPass from the authorization boundary diagram and control implementations.
- 6System administrator should establish new password policies aligned with NIST 800-63B authenticator requirements for replacement system.
- 7ISSO must conduct user training on new password management system with emphasis on CUI handling procedures.
- 8System administrator should migrate all CUI system credentials to compliant password manager using secure transfer protocols.
- 9ISSO must validate complete removal of LastPass access to CUI systems and document compliance restoration in assessment report.
- 10Legal counsel should review cyber insurance policies for potential coverage gaps related to data breach exposure from LastPass usage.
NIST 800-171 Violations
Using LastPass for CUI without FedRAMP authorization may violate these NIST 800-171 controls:
Need a CUI-Compliant Alternative?
LastPass has 4 NIST 800-171 gaps. Get real-time alerts when compliant alternatives launch, plus AI-matched contract opportunities.
FedRAMP Compliant Alternatives
Frequently Asked Questions
Is LastPass FedRAMP authorized?
No. Despite marketing that uses terms like "trusted," LastPass does not hold FedRAMP authorization. Its multiple data breaches further undermine its suitability for defense environments.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This LastPass CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures