CUI Compliant
0 NIST 800-171 gaps detected. FedRAMP Moderate authorized. Supports 27 of 110 CMMC Level 2 controls. Adds end-to-end encryption as an overlay to Gmail and Outlook.
Virtru Email Encryption
by Virtru
FedRAMP Status
FedRAMP Authorized
Impact Level
Moderate
Category
Authorized: May 10, 2023
Overview
Virtru is a FedRAMP Moderate authorized email encryption plugin for Gmail and Outlook. It adds end-to-end encryption, access controls, and audit logging to existing email platforms. More affordable than full GCC High migration but covers fewer controls than PreVeil.
CUI Risk Assessment
FedRAMP Moderate authorized. Supports 27 of 110 CMMC Level 2 controls. Adds end-to-end encryption as an overlay to Gmail and Outlook.
Deployment & Architecture
Deployment Model: Cloud SaaS (vendor-hosted)
Virtru Email Encryption operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.
Configuration Checklist
- 1ISSO: Define Virtru within CMMC authorization boundary and update SSP to reflect encrypted email processing (Week 1)
- 2IT Admin: Configure Virtru policy engine to automatically encrypt emails containing CUI markings and technical specifications (Week 2)
- 3Security Admin: Implement DLP rules preventing transmission of unencrypted CUI and establish audit log collection for SIEM integration (Week 2)
- 4ISSO: Develop key management procedures including emergency escrow and departing employee key revocation processes (Week 3)
- 5Training Coordinator: Conduct user training on CUI marking requirements before encryption and Virtru access control features (Week 3-4)
- 6IT Admin: Test integration with existing email retention systems and verify encrypted email backup procedures (Week 4)
- 7ISSO: Update incident response procedures for encrypted email compromise scenarios and establish forensics procedures (Week 4)
- 8Compliance Officer: Document Virtru configuration in CMMC assessment evidence packages and prepare assessor demonstrations (Week 5-6)
Other FedRAMP Authorized Email Tools
Related Compliance Assessments
Frequently Asked Questions
Does Virtru make Gmail compliant for CUI?
Virtru adds encryption and access controls that address some NIST 800-171 requirements, but the underlying Gmail infrastructure remains non-FedRAMP. Virtru is a partial compliance solution best combined with other controls.
How does Virtru compare to PreVeil?
Virtru covers 27 CMMC controls vs PreVeil 102 controls. Virtru is simpler to deploy but provides less comprehensive compliance coverage. Both are FedRAMP authorized.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This Virtru Email Encryption CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures