Not CUI Compliant

1 NIST 800-171 gaps detected. No certified FedRAMP Marketplace record for VMware Workspace ONE as of 2026-07-27 — searched the live registry at fedramp.gov/marketplace. Get any authorization or equivalency claim in writing from the vendor and assess it yourself under DFARS 252.204-7012(b)(2)(ii)(D).

Endpoint Management

VMware Workspace ONE

by Broadcom

Not FedRAMP Authorized

FedRAMP Status

Not FedRAMP Authorized

Impact Level

N/A

Category

Endpoint Management

Overview

VMware Workspace ONE holds no FedRAMP authorization we can source. There is no FedRAMP Marketplace record for VMware Workspace ONE in the live registry at fedramp.gov/marketplace, read 2026-07-27. Treat any authorization or equivalency claim as something to obtain in writing from the vendor and to assess yourself under DFARS 252.204-7012(b)(2)(ii)(D).

CUI Risk Assessment

No certified FedRAMP Marketplace record for VMware Workspace ONE as of 2026-07-27 — searched the live registry at fedramp.gov/marketplace. Get any authorization or equivalency claim in writing from the vendor and assess it yourself under DFARS 252.204-7012(b)(2)(ii)(D).

Deployment & Architecture

Deployment Model: Hybrid (cloud + on-prem)

VMware Workspace ONE has no FedRAMP authorization on record. DFARS 252.204-7012(b)(2)(ii)(D) requires an external cloud service provider to meet security requirements equivalent to the FedRAMP Moderate baseline — an authorization is the straightforward way to show that, but it is not the only one. Without one, the burden is on you to establish, document, and defend equivalency, and to meet the clause's incident-reporting and media-preservation obligations. Most contractors find an authorized alternative cheaper than carrying that burden.

Migration Checklist

  1. 1ISSO must conduct immediate assessment of all Workspace ONE components within the authorization boundary and document CUI data flows in SSP Section 13.1.
  2. 2Sysadmin shall configure custom session timeout policies to enforce automatic lock after 15 minutes of inactivity per NIST 800-171 3.13.8 requirements.
  3. 3ISSO must disable all cloud-based analytics and reporting features that transmit device data outside the authorization boundary.
  4. 4Sysadmin shall implement network segmentation between Workspace ONE management servers and CUI-handling endpoints using VLANs or microsegmentation.
  5. 5ISSO must update authorization boundary diagram to clearly delineate on-premises Workspace ONE components from cloud services.
  6. 6Sysadmin shall configure TLS 1.2+ encryption for all Workspace ONE communications and disable legacy protocols.
  7. 7ISSO must create POA&M entry tracking session lock compliance with 90-day remediation timeline per DFARS 252.204-7012.
  8. 8Contracts officer shall evaluate migration to FedRAMP Moderate alternatives like Microsoft Intune within 6 months if remediation fails.
  9. 9Sysadmin must implement compensating controls including DLP policies and endpoint encryption for all managed devices.
  10. 10ISSO shall conduct monthly compliance testing of session timeout functionality and document results in continuous monitoring reports.

NIST 800-171 Violations

Using VMware Workspace ONE for CUI without FedRAMP authorization may violate these NIST 800-171 controls:

Need a CUI-Compliant Alternative?

VMware Workspace ONE has 1 NIST 800-171 gaps. Get real-time alerts when compliant alternatives launch, plus AI-matched contract opportunities.

Frequently Asked Questions

Is Workspace ONE suitable for CMMC compliance?

There is no FedRAMP Marketplace record for VMware Workspace ONE in the live registry at fedramp.gov/marketplace, read 2026-07-27. Treat any authorization or equivalency claim as something to obtain in writing from the vendor and to assess yourself under DFARS 252.204-7012(b)(2)(ii)(D).

Run a Full Tech Stack Audit

Check all your enterprise tools at once with our free CUI Compliance Auditor.

Launch CUI Auditor

Get a defensible CUI architecture

This VMware Workspace ONE CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures