Not CUI Compliant
4 NIST 800-171 gaps detected. Not FedRAMP authorized. Using this tool for CUI creates compliance violations under NIST 800-171 and DFARS 252.204-7012.
Wrike
by Citrix
FedRAMP Status
Not FedRAMP Authorized
Impact Level
N/A
Category
Project Management
Overview
Wrike is a commercial project management and work collaboration platform. Despite being owned by Citrix, Wrike itself does not hold FedRAMP authorization and is not approved for CUI.
CUI Risk Assessment
Not FedRAMP authorized. Using this tool for CUI creates compliance violations under NIST 800-171 and DFARS 252.204-7012.
Deployment & Architecture
Deployment Model: Cloud SaaS (vendor-hosted)
Wrike has no FedRAMP authorization on record. DFARS 252.204-7012(b)(2)(ii)(D) requires an external cloud service provider to meet security requirements equivalent to the FedRAMP Moderate baseline — an authorization is the straightforward way to show that, but it is not the only one. Without one, the burden is on you to establish, document, and defend equivalency, and to meet the clause's incident-reporting and media-preservation obligations. Most contractors find an authorized alternative cheaper than carrying that burden.
Migration Checklist
- 1ISSO must immediately audit all Wrike projects to identify CUI content and document findings in POA&M entry referencing DFARS 252.204-7012 violation.
- 2Contracts officer shall review all active contracts to determine CUI requirements and notify customers of migration timeline per FAR 52.204-21 requirements.
- 3System administrator must export all project data from Wrike using native export tools while maintaining chain of custody documentation for CUI materials.
- 4ISSO shall update System Security Plan to remove Wrike from authorization boundary diagram and document security control gaps created by unauthorized cloud service usage.
- 5Legal counsel must assess potential DFARS 252.204-7012 breach notification requirements and coordinate with contracting officers on customer communications.
- 6System administrator must provision FedRAMP-authorized alternative such as Microsoft Project GCC High or Smartsheet Government Cloud with appropriate security configurations.
- 7ISSO shall implement NIST 800-171 security controls (AC-2, AC-3, SC-7, AU-2) on replacement platform and document configuration in SSP appendices.
- 8Training coordinator must conduct mandatory CUI awareness training for all users covering new platform and proper identification of controlled unclassified information.
- 9ISSO must validate complete CUI data migration to compliant platform and document secure destruction of any remaining Wrike data per NIST 800-88 guidelines.
- 10Compliance officer shall update POA&M to close Wrike-related findings and schedule follow-up assessment to verify sustained compliance with CMMC Level 2 requirements.
NIST 800-171 Violations
Using Wrike for CUI without FedRAMP authorization may violate these NIST 800-171 controls:
Need a CUI-Compliant Alternative?
Wrike has 4 NIST 800-171 gaps. Get real-time alerts when compliant alternatives launch, plus AI-matched contract opportunities.
FedRAMP Compliant Alternatives
Related Compliance Assessments
Frequently Asked Questions
Is Wrike FedRAMP authorized?
No. Wrike does not hold FedRAMP authorization, even though its parent company Citrix has other FedRAMP authorized products.
Can I use Wrike with CUI?
No. Wrike is not authorized for CUI project management. Use Jira Cloud for Government or Smartsheet Government instead.
What is a compliant alternative to Wrike?
Jira Cloud for Government (FedRAMP Moderate) and Smartsheet Government (FedRAMP Moderate) are compliant alternatives.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This Wrike CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures