FedRAMP Authorized — Moderate Impact

Smartsheet Government by Smartsheet. 6 compliance features verified.

Productivity

Smartsheet Government

by Smartsheet

Moderate ImpactAuthorized

Impact Level

Moderate

Status

Authorized

Pricing

mid market

Authorization Date: July 20, 2021 | Sponsoring Agency: GSA

Overview

Smartsheet Government provides FedRAMP Moderate authorized work management and collaboration for government organizations. It offers project tracking, automated workflows, and reporting dashboards within a compliant environment. The platform enables no-code workflow automation and cross-organizational collaboration.

Key Features

FedRAMP Moderate baseline controls
Project and work management
Automated workflows
Resource management
Dynamic reporting dashboards
Content collaboration

Certifications & Authorizations

FedRAMP Moderate Authorization (3PAO assessed)SOC 2 Type IIISO 27001:2013FIPS 140-2 Level 1 (cryptographic modules)NIST 800-171 compliant controls implementationAWS GovCloud infrastructure inheritance

Deployment Options

AWS GovCloud (US-West) — FedRAMP Moderate boundary
AWS GovCloud (US-East) — FedRAMP Moderate boundary
Multi-tenant SaaS deployment within FedRAMP authorized infrastructure
Government-dedicated tenant isolation within AWS GovCloud
API integration deployment for hybrid workflows
Single sign-on integration via SAML 2.0/PIV authentication

NIST 800-171 Compliance Coverage

87% of controls covered

How to Procure Smartsheet Government for Defense Contracts

Smartsheet Government is available through GSA Multiple Award Schedule (MAS) under SIN 518210C (IT Services) and SEWP V contracts. Government pricing includes volume discounts and differs from commercial rates through negotiated federal pricing schedules. The FedRAMP Moderate authorization boundary encompasses the core Smartsheet application, AWS GovCloud infrastructure, and integrated authentication services - contracting officers must ensure their System Security Plan (SSP) accurately reflects this boundary and includes proper data flow diagrams. Required approvals include ATO from your agency's Authorizing Official, ISSO review of the FedRAMP P-ATO package, and validation that CUI handling requirements align with organizational data classification policies. Typical procurement timeline spans 45-90 days including security review, contract negotiation, and technical configuration. For CMMC compliance, include Smartsheet Government within your assessment boundary as a cloud service provider, ensuring proper documentation of data flows, encryption in transit/at rest, and access controls. Verify the service's role in protecting CUI and document compensating controls for any gaps between FedRAMP Moderate and CMMC Level 2 requirements.

Compliance Cross-References

Smartsheet Government's FedRAMP Moderate authorization directly satisfies DFARS 252.204-7012 requirements for adequate security when processing CUI, providing required encryption, access controls, and incident response capabilities. Under DFARS 252.239-7010 cloud computing requirements, the service meets government data location restrictions through AWS GovCloud deployment and provides required cloud security documentation. The authorization implements key NIST 800-171 control families: Access Control (AC) through role-based permissions and MFA, System and Communications Protection (SC) via encryption and boundary protection, and Audit and Accountability (AU) through comprehensive logging. For CMMC Level 2 compliance, Smartsheet Government addresses Asset Management (AM), Access Control (AC), System Security (SS), and Data Protection (DP) domains. The DoD Cloud Computing SRG Impact Level 2 requirements are satisfied through the FedRAMP Moderate baseline, providing appropriate controls for CUI processing and storage within the authorized cloud environment.

Defense Contractor Use Case

Defense contractors use Smartsheet Government for program management, tracking deliverables, automating status reporting, and collaborating with government clients on project timelines.

Frequently Asked Questions

What is the FedRAMP authorization level for Smartsheet Government?

Smartsheet Government is authorized at the FedRAMP Moderate impact level, with authorization granted on 2021-07-20 sponsored by GSA. The FedRAMP Moderate baseline includes approximately 325 security controls covering confidentiality, integrity, and availability.

Can defense contractors use Smartsheet Government for CUI?

Smartsheet Government is authorized at the FedRAMP Moderate baseline. While FedRAMP Moderate covers a broad range of government data, defense contractors handling CUI should carefully evaluate whether Moderate controls meet their specific DFARS 252.204-7012 and NIST 800-171 requirements. Some CUI categories may require FedRAMP High authorization depending on the sensitivity of the data and contract requirements.

How does Smartsheet Government pricing compare to commercial?

Smartsheet Government government pricing is generally competitive with commercial pricing, though the government edition may carry a premium of 10-20% to cover FedRAMP compliance and dedicated infrastructure costs. Mid-market organizations can often access government pricing through GSA Schedule contracts or reseller partners. Contact Smartsheet for a quote tailored to your organization size and requirements.

Browse All FedRAMP Authorized Tools

Search and filter 80+ FedRAMP authorized products for your defense contracting needs.

Open FedRAMP Finder

Get a defensible CUI architecture

This Smartsheet Government FedRAMP profile flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures