# DoD Requires FedRAMP-Equivalent CUI Cloud Security

Under DFARS 252.204-7012, defense contractors using cloud services to handle controlled unclassified information (CUI) must ensure those services meet the FedRAMP Moderate baseline or a documented equivalent. Contractors remain responsible for verifying security controls, configuring the services, and documenting the controls in their system security plans (SSPs). The article also notes potential False Claims Act exposure for misrepresenting cybersecurity compliance, citing more than $14 million in recoveries during FY2024.

- Contractors should inventory each cloud service that handles CUI and identify authorization, configuration, or documentation gaps; the requirement applies to the services used, not just the provider’s general security claims.
- Procurement and security teams should coordinate on control verification and SSP documentation, and plan migrations early where current services cannot demonstrate the required baseline or an equivalent.
- The cited False Claims Act recoveries underscore the financial and legal risks of inaccurate compliance representations, making substantiated security evidence important in contractor certifications and government-facing work.

**Jurisdictions:** federal
**Industries:** Defense & Military, Information Technology
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** September 29, 2026

### Government Entities
- U.S. Department of Defense (DoD)
- U.S. Department of Justice (DOJ)
- Defense Industrial Base Cybersecurity Assessment Center (DIBCAC)

### Vendors
- Microsoft (Cloud service provider)

### Sources
- [Could Security and CMMC: FedRamp Equivalency | Smithers](https://www.smithers.com/resources/2026/september/cloud-security-and-cmmc) - Smithers