Partial CUI Compliance
4 NIST 800-171 gaps detected. Certified at the lowest class: the marketplace record Trello Enterprise Cloud (FR2028534270) is Class B (Low), certified since 2020-09-23, read 2026-07-27. A Low-class authorization is not a Moderate one and does not by itself cover CUI.
Trello
by Atlassian
FedRAMP Status
FedRAMP Authorized
Impact Level
Low
Category
Project Management
Authorized: September 23, 2020
Overview
Trello is covered by a certified FedRAMP Marketplace record. The FedRAMP Marketplace record behind this is Trello Enterprise Cloud, held by Trello: Class B (Low), certified since 2020-09-23, read 2026-07-27 (https://www.fedramp.gov/marketplace/products/FR2028534270/). A certification covers that named offering, not the brand — confirm the plan, region and tenancy you are buying sit inside it before placing CUI there.
CUI Risk Assessment
Certified at the lowest class: the marketplace record Trello Enterprise Cloud (FR2028534270) is Class B (Low), certified since 2020-09-23, read 2026-07-27. A Low-class authorization is not a Moderate one and does not by itself cover CUI.
Deployment & Architecture
Deployment Model: Cloud SaaS (vendor-hosted)
Trello operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.
Migration Checklist
- 1ISSO must immediately inventory all Trello instances and boards containing potential CUI, documenting findings in a POA&M entry referencing NIST 800-171 3.1.1 violation.
- 2Contracts officer must review all DoD contracts to identify DFARS 252.204-7012 applicability and determine CUI exposure scope across Trello usage.
- 3Sysadmin must implement immediate access restrictions to prevent new CUI uploads to existing Trello boards until migration completion.
- 4ISSO must update the authorization boundary diagram to remove Trello from the CUI environment and document the compliance gap.
- 5Legal team must coordinate with Atlassian to ensure proper data deletion procedures align with DFARS 252.204-7012 requirements.
- 6ISSO must procure FedRAMP authorized alternative (Jira Cloud Government or equivalent) and validate its authorization status through GSA marketplace.
- 7Sysadmin must execute controlled CUI data export from Trello using encrypted transfer methods and approved temporary storage.
- 8ISSO must configure new platform with appropriate NIST 800-171 controls including multi-factor authentication, audit logging, and access controls.
- 9Training coordinator must conduct user education sessions on new platform and CUI handling procedures within the replacement system.
- 10ISSO must update SSP sections 2.3 (system inventory) and 10.2 (information system architecture) to reflect Trello removal and new platform integration.
NIST 800-171 Violations
Using Trello for CUI without FedRAMP authorization may violate these NIST 800-171 controls:
Need a CUI-Compliant Alternative?
Trello has 4 NIST 800-171 gaps. Get real-time alerts when compliant alternatives launch, plus AI-matched contract opportunities.
FedRAMP Compliant Alternatives
Related Compliance Assessments
Frequently Asked Questions
Is Trello FedRAMP authorized?
The FedRAMP Marketplace record behind this is Trello Enterprise Cloud, held by Trello: Class B (Low), certified since 2020-09-23, read 2026-07-27 (https://www.fedramp.gov/marketplace/products/FR2028534270/). A certification covers that named offering, not the brand — confirm the plan, region and tenancy you are buying sit inside it before placing CUI there.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This Trello CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures