Moving CUI into a cloud service — a productivity suite, a file share, a SaaS app — is normal and fine. But DFARS clause 252.204-7012 adds a requirement to that move that many contractors discover late: the cloud service has to meet a FedRAMP Moderate baseline, or equivalent.

What the clause requires

When a cloud service provider stores, processes, or transmits your covered defense information, DFARS 252.204-7012 requires that provider to meet security requirements equivalent to the FedRAMP Moderate baseline and to comply with the clause’s incident-reporting and media-preservation terms. It is not enough that the cloud is ‘secure’ in a general sense; it has to meet that specific bar.

The commercial-vs-government-cloud trap

This is why you will hear about government-community cloud offerings (for example, the GCC High tier of a major productivity suite) for CUI workloads. A standard commercial tenant may not carry the FedRAMP Moderate authorization or the contractual terms the clause requires. Assuming your existing commercial subscription qualifies — without checking its authorization status — is a frequent and costly error.

What to verify

For each cloud service touching CUI, confirm its FedRAMP status (authorized or equivalent at Moderate) and confirm the DFARS 7012 flow-down terms are in your agreement. Then capture it in your shared-responsibility matrix. The goal is simple: no CUI lands in a cloud that cannot meet the bar it is contractually required to meet.

See how we vet your cloud stack for CUI.