FedRAMP In Process — Moderate Impact

Nutanix Government Cloud by Nutanix. 6 compliance features verified.

Infrastructure as a Service

Nutanix Government Cloud

by Nutanix

Moderate ImpactIn Process

Impact Level

Moderate

Status

In Process

Pricing

enterprise

Overview

Nutanix Government Cloud provides hyperconverged infrastructure as a service designed for government and defense organizations. It offers a software-defined approach that simplifies datacenter operations while maintaining strict compliance requirements. The platform supports hybrid and multi-cloud deployments.

Key Features

Hyperconverged infrastructure
FedRAMP Moderate in-process
Software-defined networking
One-click operations
Built-in disaster recovery
Multi-cloud management

Certifications & Authorizations

FedRAMP Moderate Authorization (in-process)SOC 2 Type IIISO 27001:2013FIPS 140-2 Level 1 (cryptographic modules)Common Criteria EAL4+ (hypervisor components)DoD SRG Impact Level 2 (IL2) compliant architectureNIST Cybersecurity Framework alignment

Deployment Options

Nutanix Government Cloud — FedRAMP Moderate hosted infrastructure
On-premises deployment via Nutanix AHV hypervisor with government-hardened configurations
Hybrid cloud model connecting on-premises Nutanix clusters to Government Cloud
Air-gapped deployment for classified workloads using Nutanix software stack
Edge computing deployment via Nutanix Edge platform for tactical environments
Multi-cluster federation across government facilities using Nutanix Prism Central

NIST 800-171 Compliance Coverage

85% of controls covered

How to Procure Nutanix Government Cloud for Defense Contracts

Nutanix Government Cloud is available through GSA MAS (Multiple Award Schedule) under IT Schedule 70 and SEWP VI (Solutions for Enterprise-Wide Procurement) contracts. The product offers government-specific pricing models including subscription-based consumption pricing and enterprise licensing agreements with educational discounts for federal training environments. Authorization boundary documentation requires defining the infrastructure components within the Nutanix stack including AHV hypervisor, Prism management plane, and data services layer. Contracting officers must approve the cloud service agreement, data processing addendum, and incident response procedures specific to government requirements. The System Security Plan (SSP) should clearly delineate between Nutanix-managed infrastructure controls and customer-managed application controls. Typical procurement timeline spans 6-9 months including technical evaluation, security assessment review, and contract negotiation. For CMMC compliance, organizations must include Nutanix Government Cloud in their assessment boundary when processing Controlled Unclassified Information (CUI), ensuring proper data flow mapping and control inheritance documentation. The assessment boundary should encompass the hyperconverged infrastructure layer, network segmentation controls, and data encryption mechanisms provided by the platform.

Compliance Cross-References

Nutanix Government Cloud directly supports DFARS 252.204-7012 compliance through its FedRAMP Moderate authorization, providing adequate security controls for CUI processing. The platform addresses DFARS 252.239-7010 cloud computing requirements via government-dedicated infrastructure with controlled access and data residency within CONUS. For NIST 800-171 compliance, the service inherits Access Control (AC) family controls through role-based access management and multi-factor authentication, System and Communications Protection (SC) controls via encryption in transit and at rest, and Audit and Accountability (AU) controls through comprehensive logging and monitoring capabilities. The hyperconverged infrastructure supports CMMC Level 2 domains including Asset Management through automated inventory discovery, Configuration Management via infrastructure-as-code templates, and Incident Response through integrated SIEM capabilities. DoD Cloud Computing SRG requirements are satisfied through the government cloud deployment model, ensuring data sovereignty, personnel security clearances for support staff, and adherence to government-specific operational procedures for incident handling and system maintenance.

Defense Contractor Use Case

Defense contractors evaluate Nutanix Government Cloud for simplifying on-premises infrastructure management while preparing for hybrid cloud deployments that require FedRAMP authorization.

Frequently Asked Questions

What is the FedRAMP authorization level for Nutanix Government Cloud?

Nutanix Government Cloud is in process at the FedRAMP Moderate impact level. The FedRAMP Moderate baseline includes approximately 325 security controls covering confidentiality, integrity, and availability.

Can defense contractors use Nutanix Government Cloud for CUI?

Nutanix Government Cloud is authorized at the FedRAMP Moderate baseline. While FedRAMP Moderate covers a broad range of government data, defense contractors handling CUI should carefully evaluate whether Moderate controls meet their specific DFARS 252.204-7012 and NIST 800-171 requirements. Some CUI categories may require FedRAMP High authorization depending on the sensitivity of the data and contract requirements.

How does Nutanix Government Cloud pricing compare to commercial?

Nutanix Government Cloud government pricing is typically negotiated on an enterprise basis and may differ from commercial list prices. Government and defense contractor pricing often includes compliance overhead that can make it 15-30% higher than commercial equivalents. However, volume discounts, GSA Schedule pricing, and multi-year commitments can help offset these costs. Contact Nutanix directly or check GSA Advantage for current government pricing.

Browse All FedRAMP Authorized Tools

Search and filter 80+ FedRAMP authorized products for your defense contracting needs.

Open FedRAMP Finder

Get a defensible CUI architecture

This Nutanix Government Cloud FedRAMP profile flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures