CUI Compliant
0 NIST 800-171 gaps detected. FedRAMP authorized at Moderate impact level. Approved for CUI handling in DoD environments.
Webex for Government
by Cisco
FedRAMP Status
FedRAMP Authorized
Impact Level
Moderate
Category
Video Conferencing
Authorized: February 2, 2016
Overview
Cisco Webex for Government is a FedRAMP Moderate authorized video conferencing and collaboration platform. It provides encrypted meetings, messaging, and calling for government users.
CUI Risk Assessment
FedRAMP authorized at Moderate impact level. Approved for CUI handling in DoD environments.
Deployment & Architecture
Deployment Model: Government Cloud (FedRAMP boundary)
Webex for Government operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.
Configuration Checklist
- 1ISSO must coordinate with Cisco Government Cloud support to provision tenant within FedRAMP Moderate boundary and configure FIPS 140-2 encryption settings.
- 2System administrator shall implement single sign-on integration with contractor's Active Directory to ensure user provisioning aligns with contract personnel access lists per DFARS 252.204-7012.
- 3ISSO shall configure audit logging retention policies to meet 1-year minimum requirement and establish automated log forwarding to contractor's SIEM solution.
- 4System administrator must disable public meeting creation capabilities and implement guest access controls requiring approval workflow for external participants.
- 5ISSO shall update System Security Plan Section 10.2 to document Webex integration points and data flow diagrams showing encrypted communication paths.
- 6Training coordinator must develop CUI-specific user training covering screen sharing protocols, meeting recording policies, and incident reporting procedures.
- 7ISSO shall create POA&M entries for quarterly configuration reviews and monthly user access audits to maintain CMMC Level 2 compliance.
- 8System administrator must implement endpoint compliance checking to ensure only managed devices can access CUI-enabled Webex sessions.
- 9ISSO shall establish meeting recording classification procedures aligned with contract CUI categories and retention schedules.
- 10Contracts officer must review current DoD contracts to ensure Webex for Government usage aligns with approved collaboration tool listings in contract clauses.
Other FedRAMP Authorized Video Conferencing Tools
Related Compliance Assessments
Frequently Asked Questions
Is Webex for Government FedRAMP authorized?
Yes. Cisco Webex for Government holds FedRAMP Moderate authorization for video conferencing and collaboration.
Can I discuss CUI on Webex for Government?
Webex for Government is authorized at Moderate and can be used for CUI discussions at that impact level.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This Webex for Government CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures