Not CUI Compliant
4 NIST 800-171 gaps detected. Not FedRAMP authorized. Using this tool for CUI creates compliance violations under NIST 800-171 and DFARS 252.204-7012.
WPS Office
by Kingsoft
FedRAMP Status
Not FedRAMP Authorized
Impact Level
N/A
Category
Office Suite
Overview
WPS Office is a commercial office suite developed by Kingsoft, a Chinese software company. It is not FedRAMP authorized and its foreign ownership raises additional security concerns for defense contractors.
CUI Risk Assessment
Not FedRAMP authorized. Using this tool for CUI creates compliance violations under NIST 800-171 and DFARS 252.204-7012.
Deployment & Architecture
Deployment Model: Hybrid (cloud + on-prem)
WPS Office has no FedRAMP authorization on record. DFARS 252.204-7012(b)(2)(ii)(D) requires an external cloud service provider to meet security requirements equivalent to the FedRAMP Moderate baseline — an authorization is the straightforward way to show that, but it is not the only one. Without one, the burden is on you to establish, document, and defend equivalency, and to meet the clause's incident-reporting and media-preservation obligations. Most contractors find an authorized alternative cheaper than carrying that burden.
Migration Checklist
- 1ISSO shall immediately inventory all CUI documents stored in or created with WPS Office to establish migration scope per NIST 800-171 3.1.1 requirements.
- 2Data owners must classify and export all CUI documents from WPS Office using native export functions while maintaining NIST 800-171 3.8.2 media protection requirements.
- 3System administrator shall deploy Microsoft 365 GCC High or equivalent FedRAMP-authorized office suite within the established CMMC Level 2 authorization boundary.
- 4ISSO shall update the System Security Plan (SSP) to remove WPS Office from software inventory and boundary diagrams per DFARS 252.204-7012 requirements.
- 5Contracts officer must verify all proposal development and contract modification processes no longer utilize WPS Office for CUI handling.
- 6System administrator shall configure new office suite with appropriate DLP policies and CUI marking requirements per NIST 800-171 3.1.3.
- 7ISSO shall create POA&M entries documenting WPS Office removal timeline and residual risk mitigation per CMMC Level 2 assessment requirements.
- 8Legal counsel shall review all existing contracts to ensure WPS Office removal doesn't affect deliverable formatting requirements or intellectual property protections.
- 9ISSO shall conduct user training on new office suite focusing on CUI handling procedures and collaboration restrictions per NIST 800-171 3.2.1.
- 10System administrator shall implement network monitoring to prevent future WPS Office installations and cloud synchronization attempts per NIST 800-171 3.13.1.
NIST 800-171 Violations
Using WPS Office for CUI without FedRAMP authorization may violate these NIST 800-171 controls:
Need a CUI-Compliant Alternative?
WPS Office has 4 NIST 800-171 gaps. Get real-time alerts when compliant alternatives launch, plus AI-matched contract opportunities.
FedRAMP Compliant Alternatives
Frequently Asked Questions
Is WPS Office FedRAMP authorized?
No. WPS Office is not FedRAMP authorized. Its development by a Chinese company raises supply chain risk concerns under NIST 800-171.
Can I use WPS Office with CUI?
No. WPS Office is not authorized for CUI and its foreign-developed software may pose additional supply chain risks under DFARS requirements.
What is a compliant alternative to WPS Office?
Microsoft 365 GCC High is the recommended FedRAMP High authorized office suite for defense contractors handling CUI.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This WPS Office CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures