FedRAMP Authorized — Moderate Impact

Cisco Webex for Government by Cisco. 6 compliance features verified.

Collaboration

Cisco Webex for Government

by Cisco

Moderate ImpactAuthorized

Impact Level

Moderate

Status

Authorized

Pricing

enterprise

Authorization Date: September 20, 2019 | Sponsoring Agency: DHS

Overview

Cisco Webex for Government provides FedRAMP Moderate authorized video conferencing, messaging, and calling for government organizations. It features end-to-end encryption, data residency controls, and integration with Cisco networking and security products. Webex Government runs on dedicated infrastructure.

Key Features

FedRAMP Moderate baseline controls
End-to-end encryption for meetings
U.S. data residency
Pro Pack compliance and analytics
Webex Calling integration
AI-powered meeting transcription

Certifications & Authorizations

FedRAMP Moderate (3PAO assessed by A-LIGN)DoD SRG Impact Level 2 (IL2)SOC 2 Type IIISO 27001:2013FIPS 140-2 Level 1 (cryptographic modules)NIST 800-53 Rev 4 (moderate baseline)Section 508/WCAG 2.1 AA compliance

Deployment Options

Cisco Cloud (FedRAMP Moderate) — Webex for Government dedicated tenant with US-based data residency
AWS GovCloud (US-East/US-West) — Hybrid cloud deployment with Webex Video Mesh Node integration
On-premises Webex Room devices — Connected to FedRAMP authorized cloud services via encrypted channels
Webex Edge for Devices — Government-specific edge computing nodes for low-latency deployment
Hybrid deployment — On-premises Unified CM integration with Webex for Government cloud services
Webex Video Mesh — Customer-controlled video routing with FedRAMP boundary protection

NIST 800-171 Compliance Coverage

87% of controls covered

How to Procure Cisco Webex for Government for Defense Contracts

Cisco Webex for Government is available through GSA MAS (Multiple Award Schedule) under SIN 518210C and SEWP V contracts. Government pricing includes volume discounts and educational rates not available commercially. The FedRAMP authorization boundary covers Webex Meetings, Teams, and Calling services but excludes third-party integrations requiring separate assessment. Contracting officers must verify the specific Webex services align with the FedRAMP authorization scope and approve any hybrid deployments connecting to existing telephony infrastructure. Standard procurement timeline is 60-90 days including security review and ATO documentation. For organizations requiring CMMC Level 2 compliance, include Webex for Government within your assessment boundary as a cloud service provider, documenting data flow mappings and ensuring contractor personnel accessing CUI through Webex maintain appropriate clearance levels. The SSP must address boundary controls between FedRAMP moderate services and any higher classification data, implementing appropriate network segmentation. Consider bandwidth requirements for video conferencing and ensure your COMSEC boundary properly accounts for encrypted communications through Cisco's government cloud infrastructure.

Compliance Cross-References

Cisco Webex for Government directly supports DFARS 252.204-7012 requirements by providing FedRAMP Moderate authorized cloud services with adequate security controls for CUI processing. The platform addresses DFARS 252.239-7010 cloud computing security requirements through documented data residency controls and encryption standards. NIST 800-171 control family compliance includes Access Control (AC) through multi-factor authentication and role-based permissions, System and Communications Protection (SC) via end-to-end encryption and secure protocols, and Audit and Accountability (AU) through comprehensive logging and monitoring capabilities. For CMMC Level 2, Webex for Government satisfies Access Control (AC), System and Information Integrity (SI), and System and Communications Protection (SC) domains. The DoD Cloud Computing SRG Impact Level 2 authorization ensures appropriate data handling for controlled unclassified information, with documented security controls mapping to DoD risk management framework requirements and continuous monitoring processes.

Defense Contractor Use Case

Defense contractors use Cisco Webex Government for video conferencing and virtual meetings, particularly when they have existing Cisco networking infrastructure and need integrated collaboration.

Frequently Asked Questions

What is the FedRAMP authorization level for Cisco Webex for Government?

Cisco Webex for Government is authorized at the FedRAMP Moderate impact level, with authorization granted on 2019-09-20 sponsored by DHS. The FedRAMP Moderate baseline includes approximately 325 security controls covering confidentiality, integrity, and availability.

Can defense contractors use Cisco Webex for Government for CUI?

Cisco Webex for Government is authorized at the FedRAMP Moderate baseline. While FedRAMP Moderate covers a broad range of government data, defense contractors handling CUI should carefully evaluate whether Moderate controls meet their specific DFARS 252.204-7012 and NIST 800-171 requirements. Some CUI categories may require FedRAMP High authorization depending on the sensitivity of the data and contract requirements.

How does Cisco Webex for Government pricing compare to commercial?

Cisco Webex for Government government pricing is typically negotiated on an enterprise basis and may differ from commercial list prices. Government and defense contractor pricing often includes compliance overhead that can make it 15-30% higher than commercial equivalents. However, volume discounts, GSA Schedule pricing, and multi-year commitments can help offset these costs. Contact Cisco directly or check GSA Advantage for current government pricing.

Browse All FedRAMP Authorized Tools

Search and filter 80+ FedRAMP authorized products for your defense contracting needs.

Open FedRAMP Finder

Get a defensible CUI architecture

This Cisco Webex for Government FedRAMP profile flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures