Partial CUI Compliance

4 NIST 800-171 gaps detected. Certified at the lowest class: the marketplace record Trello Enterprise Cloud (FR2028534270) is Class B (Low), certified since 2020-09-23, read 2026-07-27. A Low-class authorization is not a Moderate one and does not by itself cover CUI.

Project Management

Trello

by Atlassian

FedRAMP AuthorizedLow Impact

FedRAMP Status

FedRAMP Authorized

Impact Level

Low

Category

Project Management

Authorized: September 23, 2020

Overview

Trello is covered by a certified FedRAMP Marketplace record. The FedRAMP Marketplace record behind this is Trello Enterprise Cloud, held by Trello: Class B (Low), certified since 2020-09-23, read 2026-07-27 (https://www.fedramp.gov/marketplace/products/FR2028534270/). A certification covers that named offering, not the brand — confirm the plan, region and tenancy you are buying sit inside it before placing CUI there.

CUI Risk Assessment

Certified at the lowest class: the marketplace record Trello Enterprise Cloud (FR2028534270) is Class B (Low), certified since 2020-09-23, read 2026-07-27. A Low-class authorization is not a Moderate one and does not by itself cover CUI.

Deployment & Architecture

Deployment Model: Cloud SaaS (vendor-hosted)

Trello operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.

Migration Checklist

  1. 1ISSO must immediately inventory all Trello instances and boards containing potential CUI, documenting findings in a POA&M entry referencing NIST 800-171 3.1.1 violation.
  2. 2Contracts officer must review all DoD contracts to identify DFARS 252.204-7012 applicability and determine CUI exposure scope across Trello usage.
  3. 3Sysadmin must implement immediate access restrictions to prevent new CUI uploads to existing Trello boards until migration completion.
  4. 4ISSO must update the authorization boundary diagram to remove Trello from the CUI environment and document the compliance gap.
  5. 5Legal team must coordinate with Atlassian to ensure proper data deletion procedures align with DFARS 252.204-7012 requirements.
  6. 6ISSO must procure FedRAMP authorized alternative (Jira Cloud Government or equivalent) and validate its authorization status through GSA marketplace.
  7. 7Sysadmin must execute controlled CUI data export from Trello using encrypted transfer methods and approved temporary storage.
  8. 8ISSO must configure new platform with appropriate NIST 800-171 controls including multi-factor authentication, audit logging, and access controls.
  9. 9Training coordinator must conduct user education sessions on new platform and CUI handling procedures within the replacement system.
  10. 10ISSO must update SSP sections 2.3 (system inventory) and 10.2 (information system architecture) to reflect Trello removal and new platform integration.

NIST 800-171 Violations

Using Trello for CUI without FedRAMP authorization may violate these NIST 800-171 controls:

Need a CUI-Compliant Alternative?

Trello has 4 NIST 800-171 gaps. Get real-time alerts when compliant alternatives launch, plus AI-matched contract opportunities.

Frequently Asked Questions

Is Trello FedRAMP authorized?

The FedRAMP Marketplace record behind this is Trello Enterprise Cloud, held by Trello: Class B (Low), certified since 2020-09-23, read 2026-07-27 (https://www.fedramp.gov/marketplace/products/FR2028534270/). A certification covers that named offering, not the brand — confirm the plan, region and tenancy you are buying sit inside it before placing CUI there.

Run a Full Tech Stack Audit

Check all your enterprise tools at once with our free CUI Compliance Auditor.

Launch CUI Auditor

Get a defensible CUI architecture

This Trello CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures