CUI Compliant
0 NIST 800-171 gaps detected. Class D (High) on the FedRAMP Marketplace: record GovSlack (Slack Technologies), certified since 2024-01-25, read 2026-07-27. Confirm the plan and region you are buying sit inside that offering before placing CUI there.
Slack GovSlack
by Salesforce
FedRAMP Status
FedRAMP Authorized
Impact Level
High
Category
Collaboration
Authorized: January 25, 2024
Overview
Slack GovSlack is covered by a certified FedRAMP Marketplace record. The FedRAMP Marketplace record behind this is GovSlack, held by Slack Technologies: Class D (High), certified since 2024-01-25, read 2026-07-27 (https://www.fedramp.gov/marketplace/products/FR2230252267/). A certification covers that named offering, not the brand — confirm the plan, region and tenancy you are buying sit inside it before placing CUI there.
CUI Risk Assessment
Class D (High) on the FedRAMP Marketplace: record GovSlack (Slack Technologies), certified since 2024-01-25, read 2026-07-27. Confirm the plan and region you are buying sit inside that offering before placing CUI there.
Deployment & Architecture
Deployment Model: Government Cloud (FedRAMP boundary)
Slack GovSlack operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.
Configuration Checklist
- 1ISSO must update the System Security Plan to include GovSlack within the authorization boundary and document all data flows with other FedRAMP systems.
- 2System administrator should configure enterprise SSO integration with existing Active Directory to enforce MFA requirements per NIST 800-171 IA-2.
- 3ISSO must implement data loss prevention policies to automatically detect and prevent unauthorized CUI sharing outside approved channels.
- 4System administrator should establish channel governance procedures requiring CUI marking in channel names and mandatory encryption for all external communications.
- 5ISSO must configure audit logging to capture all user activities, message retention, and file sharing events to satisfy NIST 800-171 AU control family.
- 6Legal team should review and approve data processing addendum with Salesforce to ensure DFARS 252.204-7012 compliance requirements are met.
- 7System administrator must disable all third-party app integrations and establish approval workflow for future integration requests per SC-7 boundary protection.
- 8ISSO should establish incident response procedures specific to potential CUI spillage events and integrate with existing security incident workflows.
- 9Contracts officer must verify GovSlack inclusion in existing DFARS 252.204-7021 contractor compliance certifications.
- 10System administrator should implement automated backup procedures for CUI data retention requirements and establish recovery testing schedule.
Other FedRAMP Authorized Collaboration Tools
Related Compliance Assessments
Frequently Asked Questions
Is GovSlack FedRAMP authorized?
The FedRAMP Marketplace record behind this is GovSlack, held by Slack Technologies: Class D (High), certified since 2024-01-25, read 2026-07-27 (https://www.fedramp.gov/marketplace/products/FR2230252267/). A certification covers that named offering, not the brand — confirm the plan, region and tenancy you are buying sit inside it before placing CUI there.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This Slack GovSlack CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures