CUI Compliant
0 NIST 800-171 gaps detected. FedRAMP authorized at Moderate impact level. Approved for CUI handling in DoD environments.
Smartsheet Government
by Smartsheet
FedRAMP Status
FedRAMP Authorized
Impact Level
Moderate
Category
Project Management
Authorized: August 12, 2019
Overview
Smartsheet Government is a FedRAMP Moderate authorized work management and project tracking platform. It provides spreadsheet-style project management with government-grade security controls.
CUI Risk Assessment
FedRAMP authorized at Moderate impact level. Approved for CUI handling in DoD environments.
Deployment & Architecture
Deployment Model: Government Cloud (FedRAMP boundary)
Smartsheet Government operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.
Configuration Checklist
- 1ISSO shall update the authorization boundary diagram to include Smartsheet Government as an approved SaaS service within the cloud enclave boundary per NIST 800-171 SC-7 requirements.
- 2System administrator must configure Smartsheet Government conditional access policies integrated with enterprise identity provider to enforce multi-factor authentication per NIST 800-171 IA-2(1).
- 3ISSO shall modify the System Security Plan (SSP) to document Smartsheet Government's security controls inheritance from FedRAMP authorization and identify contractor-implemented controls per DFARS 252.204-7012.
- 4Contracts officer must establish CUI handling procedures specific to Smartsheet project templates and shared workspaces per DFARS 252.204-7021 requirements.
- 5System administrator shall implement role-based access controls within Smartsheet Government aligned with principle of least privilege per NIST 800-171 AC-6.
- 6ISSO must establish audit logging procedures for CUI modifications in Smartsheet projects per NIST 800-171 AU-2 requirements.
- 7Training coordinator shall conduct user training on CUI marking requirements within Smartsheet environments and proper data handling procedures.
- 8ISSO shall document compensating controls for shared workspace security in POA&M entries addressing NIST 800-171 AC-3 implementation gaps.
- 9System administrator must configure data loss prevention rules within Smartsheet Government to prevent unauthorized CUI exfiltration per NIST 800-171 SC-7(10).
- 10ISSO shall establish quarterly user access reviews for Smartsheet Government accounts to ensure continued authorization per NIST 800-171 AC-2(1) requirements.
Other FedRAMP Authorized Project Management Tools
Related Compliance Assessments
Frequently Asked Questions
Is Smartsheet Government FedRAMP authorized?
Yes. Smartsheet Government holds FedRAMP Moderate authorization for work management and project tracking.
Can I use Smartsheet Government with CUI?
Smartsheet Government is authorized at Moderate and can be used for project management involving CUI at that impact level.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This Smartsheet Government CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures