CUI Compliant
0 NIST 800-171 gaps detected. FedRAMP authorized at Moderate impact level. Approved for CUI handling in DoD environments.
Zoom for Government
by Zoom
FedRAMP Status
FedRAMP Authorized
Impact Level
Moderate
Category
Video Conferencing
Authorized: July 28, 2023
Overview
Zoom for Government is a FedRAMP Moderate authorized video conferencing platform hosted on AWS GovCloud. It provides compliant video meetings for government agencies and defense contractors.
CUI Risk Assessment
FedRAMP authorized at Moderate impact level. Approved for CUI handling in DoD environments.
Deployment & Architecture
Deployment Model: Government Cloud (FedRAMP boundary)
Zoom for Government operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.
Configuration Checklist
- 1ISSO shall update the System Security Plan to include Zoom for Government within the CUI processing boundary and document its FedRAMP Moderate authorization inheritance per NIST 800-171 requirement 3.12.1.
- 2System administrator must configure identity federation between Zoom for Government and the organization's CAC/PIV authentication system to meet NIST 800-171 IA-2 requirements.
- 3ISSO shall implement mandatory end-to-end encryption for all meetings containing CUI per NIST 800-171 control SC-13 and document configuration in security control assessment procedures.
- 4System administrator must establish session recording policies that align with CUI retention requirements under DFARS 252.204-7012 and configure automated retention schedules.
- 5Security team shall configure network monitoring to track Zoom for Government traffic flows and implement boundary protection controls per NIST 800-171 SC-7.
- 6ISSO must create incident response procedures specific to video conferencing CUI spillage events and train users on immediate containment actions per NIST 800-171 IR-6.
- 7Contracts officer shall verify Zoom for Government licensing includes required government terms and FedRAMP authorization documentation for DCMA assessment preparation.
- 8System administrator must disable external participant features and configure meeting admission controls to prevent unauthorized CUI access per NIST 800-171 AC-3.
- 9ISSO shall update authorization boundary diagrams to reflect Zoom for Government data flows and document interconnection security agreements with AWS GovCloud.
- 10Training coordinator must deliver CUI-specific video conferencing training covering proper meeting classification, screen sharing restrictions, and recording handling procedures per DFARS 252.204-7012 requirements.
Other FedRAMP Authorized Video Conferencing Tools
Related Compliance Assessments
Frequently Asked Questions
Is Zoom for Government FedRAMP authorized?
Yes. Zoom for Government holds FedRAMP Moderate authorization and runs on AWS GovCloud infrastructure.
Can I discuss CUI on Zoom for Government?
Zoom for Government is authorized at Moderate. For High-impact CUI discussions, verify the authorization level meets your requirements or use Teams GCC High.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This Zoom for Government CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures