Not CUI Compliant
4 NIST 800-171 gaps detected. Not FedRAMP authorized. Using this tool for CUI creates compliance violations under NIST 800-171 and DFARS 252.204-7012.
LibreOffice
by The Document Foundation
FedRAMP Status
Not FedRAMP Authorized
Impact Level
N/A
Category
Office Suite
Overview
LibreOffice is a free, open-source desktop office suite. While it can be self-hosted, the cloud version is not FedRAMP authorized. Local installations may be acceptable if the underlying infrastructure meets NIST 800-171 requirements.
CUI Risk Assessment
Not FedRAMP authorized. Using this tool for CUI creates compliance violations under NIST 800-171 and DFARS 252.204-7012.
Deployment & Architecture
Deployment Model: Self-hosted (open-source)
LibreOffice has no FedRAMP authorization on record. DFARS 252.204-7012(b)(2)(ii)(D) requires an external cloud service provider to meet security requirements equivalent to the FedRAMP Moderate baseline — an authorization is the straightforward way to show that, but it is not the only one. Without one, the burden is on you to establish, document, and defend equivalency, and to meet the clause's incident-reporting and media-preservation obligations. Most contractors find an authorized alternative cheaper than carrying that burden.
Migration Checklist
- 1ISSO must remove LibreOffice from the authorization boundary diagram and update SSP Section 10.2 to reflect compliant office suite deployment.
- 2Contracts officer must review all active contracts to identify CUI requirements triggering DFARS 252.204-7012 and validate alternative office suite meets government requirements.
- 3System administrator must inventory all workstations with LibreOffice installations and document CUI exposure risk in POA&M entry CO-1.
- 4ISSO must procure FedRAMP-authorized office suite (Microsoft 365 GCC High or Google Workspace for Government) and validate authorization package currency.
- 5Legal team must review data residency requirements in contracts to ensure selected FedRAMP service meets geographic restrictions for CUI processing.
- 6System administrator must implement file-level encryption on all existing LibreOffice documents containing CUI using FIPS 140-2 validated cryptographic modules per SC-28.
- 7ISSO must establish document migration procedures maintaining CUI markings and audit trails in compliance with NIST 800-171 control AU-3.
- 8Training coordinator must deliver 8-hour CUI handling certification for all users transitioning to new office suite platform.
- 9System administrator must uninstall LibreOffice from all CUI processing systems and validate removal through vulnerability scanning per SI-2.
- 10ISSO must conduct post-migration assessment and update continuous monitoring plan to include new office suite security controls per CA-7.
NIST 800-171 Violations
Using LibreOffice for CUI without FedRAMP authorization may violate these NIST 800-171 controls:
Need a CUI-Compliant Alternative?
LibreOffice has 4 NIST 800-171 gaps. Get real-time alerts when compliant alternatives launch, plus AI-matched contract opportunities.
FedRAMP Compliant Alternatives
Frequently Asked Questions
Is LibreOffice FedRAMP authorized?
No. LibreOffice does not hold FedRAMP authorization. As a desktop application, it can be used on compliant endpoints, but the cloud version is not authorized.
Can I use LibreOffice with CUI?
LibreOffice installed locally on a NIST 800-171 compliant workstation may be acceptable for editing CUI documents. However, any cloud-based deployment requires FedRAMP authorization.
What is a compliant alternative to LibreOffice?
Microsoft 365 GCC High and Google Docs Government provide FedRAMP authorized cloud office suites for defense contractors.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This LibreOffice CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures