Partial CUI Compliance
1 NIST 800-171 gaps detected. No FedRAMP Marketplace record for Rapid7 InsightVM as of 2026-07-27. Rapid7 holds a separate certified offering, InsightGovCloud (FR2422240916, Moderate, certified since 2025-07-11) — confirm which of the two your tenant is on.
Rapid7 InsightVM
by Rapid7
FedRAMP Status
Not FedRAMP Authorized
Impact Level
N/A
Category
Cybersecurity
Overview
Rapid7 InsightVM is not FedRAMP certified. The FedRAMP Marketplace record for InsightGovCloud (Rapid7) shows status FedRAMP Certified, read 2026-07-27 (https://www.fedramp.gov/marketplace/products/FR2422240916/). FedRAMP Ready is a readiness assessment by a recognised assessor, not an authorization, and does not put CUI inside an authorized boundary.
CUI Risk Assessment
No FedRAMP Marketplace record for Rapid7 InsightVM as of 2026-07-27. Rapid7 holds a separate certified offering, InsightGovCloud (FR2422240916, Moderate, certified since 2025-07-11) — confirm which of the two your tenant is on.
Deployment & Architecture
Deployment Model: Hybrid (cloud + on-prem)
Rapid7 InsightVM has no FedRAMP authorization on record. DFARS 252.204-7012(b)(2)(ii)(D) requires an external cloud service provider to meet security requirements equivalent to the FedRAMP Moderate baseline — an authorization is the straightforward way to show that, but it is not the only one. Without one, the burden is on you to establish, document, and defend equivalency, and to meet the clause's incident-reporting and media-preservation obligations. Most contractors find an authorized alternative cheaper than carrying that burden.
Migration Checklist
- 1ISSO must document current InsightVM deployment architecture and identify all CUI data flows within vulnerability scanning processes in the System Security Plan.
- 2System administrator must implement network segmentation to isolate InsightVM scan engines from systems processing CUI per NIST 800-171 SC-7 requirements.
- 3ISSO must configure encrypted communication channels for all scan data transmission using FIPS 140-2 validated cryptographic modules per SC-8 requirements.
- 4System administrator must deploy on-premises vulnerability databases to store scan results containing technical system information that could constitute CUI.
- 5ISSO must implement comprehensive audit logging for all InsightVM activities including user access, scan initiation, and report generation per AU-2 requirements.
- 6Contracts officer must create POA&M entry tracking FedRAMP authorization progress with monthly status updates and estimated completion timeline.
- 7System administrator must configure role-based access controls limiting vulnerability report access to personnel with appropriate CUI handling authorization per AC-2.
- 8ISSO must update authorization boundary diagram to clearly delineate InsightVM components and their relationship to CUI processing systems.
- 9Legal counsel must review vulnerability scanning policies to ensure compliance with DFARS 252.204-7012 adequate security requirements.
- 10ISSO must establish incident response procedures for vulnerability scan data breaches that may expose protected technical information per IR-4 requirements.
NIST 800-171 Violations
Using Rapid7 InsightVM for CUI without FedRAMP authorization may violate these NIST 800-171 controls:
Need a CUI-Compliant Alternative?
Rapid7 InsightVM has 1 NIST 800-171 gaps. Get real-time alerts when compliant alternatives launch, plus AI-matched contract opportunities.
FedRAMP Compliant Alternatives
Related Compliance Assessments
Frequently Asked Questions
Is Rapid7 InsightVM FedRAMP authorized?
The FedRAMP Marketplace record for InsightGovCloud (Rapid7) shows status FedRAMP Certified, read 2026-07-27 (https://www.fedramp.gov/marketplace/products/FR2422240916/). FedRAMP Ready is a readiness assessment by a recognised assessor, not an authorization, and does not put CUI inside an authorized boundary.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This Rapid7 InsightVM CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures