The Governing Requirement
NIST SP 800-171 requirement 3.13.8 states that organizations must implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards. This is the anchor requirement for every question about how CUI moves.
The requirement lives in the System and Communications Protection (SC) domain, but it pulls in controls from Access Control (AC) and Media Protection (MP) as well. Remote access configurations, cloud platform choices, and portable media policies all feed into a single compliance question: is CUI protected at every point it moves from one system, person, or location to another?
Three factors determine whether a transmission method is acceptable:
| Factor | What Assessors Look For |
|---|---|
| Encryption in transit | FIPS 140-2 or 140-3 validated cryptography; TLS 1.2 minimum, TLS 1.3 preferred; no deprecated protocols (SSL, TLS 1.0, TLS 1.1) |
| Platform authorization | Cloud-based services must hold FedRAMP Moderate authorization at minimum; commercial-tier SaaS does not qualify regardless of encryption claims |
| Access controls and logging | Only authorized users may send or receive CUI; transmission events must be logged; MFA required for remote access to CUI systems |
Meeting only one or two of these three factors does not produce a compliant transmission. All three must be satisfied simultaneously. A platform may encrypt traffic using TLS 1.3 and still fail if it lacks FedRAMP Moderate authorization.
Method-by-Method Breakdown
Defense contractors use a range of channels to move data between team members, between facilities, and between organizations. The table below summarizes the compliance status and requirements for each common method.
| Transmission Method | Acceptable? | Requirements |
|---|---|---|
| Email via Microsoft 365 GCC | Yes | FedRAMP Moderate authorized; TLS encryption in transit; MFA on accounts with CUI access |
| Email via Google Workspace for Government | Yes | FedRAMP Moderate authorized; TLS required; confirm your tenant is on the Government tier, not standard Workspace |
| Email via standard Microsoft 365 / Gmail | No | Does not meet FedRAMP Moderate baseline; commercial-tier licensing is not compliant regardless of TLS configuration |
| SFTP (SSH File Transfer Protocol) | Yes | Encrypted channel using SSH; server must be hardened and access-controlled; transmission events must be logged |
| HTTPS file transfer (TLS 1.2+) | Yes | TLS 1.2 minimum; FIPS-validated cryptography; hosted on a compliant or on-premises platform; no consumer file-sharing services |
| FedRAMP Moderate-authorized file sharing | Yes | Platform must appear on the FedRAMP Marketplace at the Moderate authorization level; confirm authorization status before use |
| VPN remote access to CUI systems | Yes | FIPS-validated encryption; strong authentication with MFA; remote sessions must be logged; personal devices must be prohibited or brought into scope |
| Encrypted USB drive (FIPS 140-2 validated) | Yes | Hardware encryption required; drive must be organization-issued and inventoried; access must be logged; NIST SP 800-88 sanitization required before reuse or disposal |
| Unencrypted USB drive | No | No encryption in place; loss or theft results in direct CUI exposure; not acceptable under any circumstances |
| Encrypted laptop (full-disk encryption, FIPS-validated) | Yes | Full-disk encryption using FIPS 140-2 validated modules (BitLocker with TPM in FIPS mode, or equivalent); access controls and logging required |
| Dropbox / WeTransfer / Box personal | No | Consumer-tier services without FedRAMP Moderate authorization; not acceptable regardless of stated encryption capabilities |
| Physical mail (U.S. Postal Service, courier) | Conditionally | Physical transport can substitute for encryption as an "alternative physical safeguard" under 3.13.8; documents must be in sealed, opaque packaging; chain of custody must be documented; courier tracking recommended |
What Is Not Acceptable
Assessors consistently flag the same categories of non-compliant transmission during C3PAO assessments. These are not edge cases. They reflect tools that defense contractor teams use every day without recognizing their compliance status.
| Non-Compliant Practice | Why It Fails | Compliant Replacement |
|---|---|---|
| Emailing CUI via standard Microsoft 365 or Gmail | Commercial-tier platforms do not meet FedRAMP Moderate baseline; MORSECORP was partly penalized for this exact practice | Microsoft 365 GCC or Google Workspace for Government |
| Sharing files via Dropbox, Google Drive personal, or WeTransfer | No FedRAMP Moderate authorization; consumer platforms have no obligation to protect government-controlled data | SFTP, HTTPS transfer via compliant platform, or FedRAMP Moderate-authorized file sharing |
| FTP (unencrypted) | Transmits data in plaintext; any network observer can capture the transfer; explicitly non-compliant with 3.13.8 | SFTP or HTTPS with TLS 1.2 or higher |
| RDP without MFA or encryption | Unprotected remote desktop sessions expose CUI systems to credential attacks; AC domain requires MFA for remote access | Encrypted RDP with MFA, or VPN-gated remote access with session logging |
| Texting or messaging apps (consumer) | SMS is not encrypted; consumer messaging apps (iMessage, WhatsApp, Signal personal) are not FedRAMP authorized for CUI | Transmission must move to a compliant channel; no consumer messaging platform is acceptable for CUI |
| Unencrypted portable drives | Physical loss results in immediate CUI exposure with no recovery option; MP domain requires encryption on all CUI media | FIPS 140-2 validated hardware-encrypted drives only |
One pattern surfaces repeatedly in assessment findings: organizations that have invested in compliant infrastructure for their primary CUI workflows but have not addressed secondary channels. The engineering team uses M365 GCC for email. But the business development team sends contract deliverables via personal Gmail. Or a project manager shares a drawing through a personal Dropbox link. A single non-compliant transmission can constitute a reportable incident if CUI is exposed.
Assessor Evidence Expectations
During a C3PAO assessment, evaluators do not accept policy statements as evidence that compliant transmission methods are in use. They will request documentation and, where possible, verify configurations directly. Knowing what they look for lets you prepare your evidence package before the assessment begins.
| Requirement | Evidence Assessors Will Request |
|---|---|
| SC.L2-3.13.8 (Encryption in transit) | TLS configuration screenshots; FIPS module validation certificates; email platform FedRAMP authorization letter or marketplace listing; network diagrams showing encrypted paths for CUI flows |
| SC.L2-3.13.1 (Boundary monitoring) | Firewall rules showing default-deny posture; network monitoring logs; documentation of data flows crossing the CUI boundary |
| AC.L2-3.1.12 (Remote access control) | VPN configuration; MFA enrollment records for remote users; session logging evidence; documented prohibition on personal device use for CUI access or evidence that personal devices are in scope |
| MP.L2-3.8.6 (Portable media) | Inventory of authorized portable media; encryption validation for USB drives; policy governing media use on CUI systems; sanitization records for decommissioned media |
The System Security Plan (SSP) must document each transmission method your organization uses for CUI and explain how each one satisfies the applicable controls. Assessors will compare your SSP descriptions against what they observe in the environment. Gaps between documentation and practice are among the most common sources of findings.
How 1TEN Helps
Documenting CUI transmission methods across an entire organization requires tracking every data flow, every platform, and every user group that touches CUI. 1TEN provides an air-gapped compliance platform that maps your CUI flows, generates SSP documentation for each transmission control, and produces the evidence package assessors request for SC and MP domain requirements. Because the platform runs entirely on-premises, the act of using 1TEN to document your CUI transmission controls does not itself create a CUI transmission compliance issue.
Frequently Asked Questions
No. Standard commercial email services, including Microsoft 365 Business, Gmail, and Google Workspace, do not meet the FedRAMP Moderate baseline required for CUI transmission. You must use a FedRAMP Moderate-authorized variant such as Microsoft 365 GCC or Google Workspace for Government. This is a hard requirement under NIST SP 800-171 requirement 3.13.8 and has been the basis for enforcement action, including the MORSECORP False Claims Act settlement.
No. Consumer-grade file sharing services including Dropbox, standard Google Drive, Box personal, OneDrive personal, and WeTransfer do not meet the FedRAMP Moderate authorization required for CUI storage and transmission. For file sharing with subcontractors, you must use a FedRAMP Moderate-authorized platform. The subcontractor receiving CUI also inherits the same NIST SP 800-171 obligations under the DFARS 252.204-7012 flow-down requirement.
NIST SP 800-171 requirement 3.13.8 requires encryption of CUI on open networks. The cryptographic modules used must be FIPS 140-2 or FIPS 140-3 validated. For TLS-based transmission, TLS 1.2 is the minimum acceptable version; TLS 1.3 is preferred. Older protocols including TLS 1.0, TLS 1.1, SSL 3.0, and any version of SSL are not acceptable for CUI transmission and will generate findings in a C3PAO assessment.
A USB drive can be an acceptable transport method for CUI only if it is encrypted using FIPS 140-2 validated encryption, access to the drive is controlled and logged on systems where it is used, and the drive is sanitized using NIST SP 800-88 methods before disposal or reuse. Unencrypted USB drives are never acceptable for CUI. Many organizations prohibit personal USB drives entirely and permit only organization-issued, hardware-encrypted drives for CUI use.
Remote access to systems that contain CUI must use encrypted connections with FIPS-validated cryptography and must require multi-factor authentication. VPN with strong authentication is the standard approach. Remote desktop sessions must be encrypted and MFA-protected. Personal devices used to access CUI remotely are in scope for your CMMC assessment unless explicitly prohibited by technical controls. Any remote access capability must be documented in your System Security Plan.
Transmitting CUI via a non-compliant channel is a violation of DFARS 252.204-7012 and, if willfully misrepresented in a SPRS self-assessment, can trigger False Claims Act liability. An unauthorized disclosure resulting from a non-compliant transmission method is a reportable cyber incident: you must notify the DoD within 72 hours via the DIBNet portal and preserve system images for at least 90 days. The MORSECORP settlement demonstrates that enforcement actions follow from documented use of non-compliant platforms.