Guide

Acceptable Methods for Sending and Receiving CUI

Last updated: 2026-06-16

SC AC MP
The Governing Requirement Method-by-Method Breakdown What Is Not Acceptable Assessor Evidence Expectations How 1TEN Helps FAQ

The Governing Requirement

NIST SP 800-171 requirement 3.13.8 states that organizations must implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards. This is the anchor requirement for every question about how CUI moves.

The requirement lives in the System and Communications Protection (SC) domain, but it pulls in controls from Access Control (AC) and Media Protection (MP) as well. Remote access configurations, cloud platform choices, and portable media policies all feed into a single compliance question: is CUI protected at every point it moves from one system, person, or location to another?

Three factors determine whether a transmission method is acceptable:

Factor What Assessors Look For
Encryption in transit FIPS 140-2 or 140-3 validated cryptography; TLS 1.2 minimum, TLS 1.3 preferred; no deprecated protocols (SSL, TLS 1.0, TLS 1.1)
Platform authorization Cloud-based services must hold FedRAMP Moderate authorization at minimum; commercial-tier SaaS does not qualify regardless of encryption claims
Access controls and logging Only authorized users may send or receive CUI; transmission events must be logged; MFA required for remote access to CUI systems

Meeting only one or two of these three factors does not produce a compliant transmission. All three must be satisfied simultaneously. A platform may encrypt traffic using TLS 1.3 and still fail if it lacks FedRAMP Moderate authorization.

Method-by-Method Breakdown

Defense contractors use a range of channels to move data between team members, between facilities, and between organizations. The table below summarizes the compliance status and requirements for each common method.

Transmission Method Acceptable? Requirements
Email via Microsoft 365 GCC Yes FedRAMP Moderate authorized; TLS encryption in transit; MFA on accounts with CUI access
Email via Google Workspace for Government Yes FedRAMP Moderate authorized; TLS required; confirm your tenant is on the Government tier, not standard Workspace
Email via standard Microsoft 365 / Gmail No Does not meet FedRAMP Moderate baseline; commercial-tier licensing is not compliant regardless of TLS configuration
SFTP (SSH File Transfer Protocol) Yes Encrypted channel using SSH; server must be hardened and access-controlled; transmission events must be logged
HTTPS file transfer (TLS 1.2+) Yes TLS 1.2 minimum; FIPS-validated cryptography; hosted on a compliant or on-premises platform; no consumer file-sharing services
FedRAMP Moderate-authorized file sharing Yes Platform must appear on the FedRAMP Marketplace at the Moderate authorization level; confirm authorization status before use
VPN remote access to CUI systems Yes FIPS-validated encryption; strong authentication with MFA; remote sessions must be logged; personal devices must be prohibited or brought into scope
Encrypted USB drive (FIPS 140-2 validated) Yes Hardware encryption required; drive must be organization-issued and inventoried; access must be logged; NIST SP 800-88 sanitization required before reuse or disposal
Unencrypted USB drive No No encryption in place; loss or theft results in direct CUI exposure; not acceptable under any circumstances
Encrypted laptop (full-disk encryption, FIPS-validated) Yes Full-disk encryption using FIPS 140-2 validated modules (BitLocker with TPM in FIPS mode, or equivalent); access controls and logging required
Dropbox / WeTransfer / Box personal No Consumer-tier services without FedRAMP Moderate authorization; not acceptable regardless of stated encryption capabilities
Physical mail (U.S. Postal Service, courier) Conditionally Physical transport can substitute for encryption as an "alternative physical safeguard" under 3.13.8; documents must be in sealed, opaque packaging; chain of custody must be documented; courier tracking recommended
FedRAMP Marketplace Verification
A vendor claiming FedRAMP authorization is not the same as a vendor holding it. Before relying on any cloud service for CUI transmission or storage, verify its authorization status directly at marketplace.fedramp.gov. Look for "Authorized" status at the Moderate impact level. "In Process" does not qualify. Authorization must be current, not expired.

What Is Not Acceptable

Assessors consistently flag the same categories of non-compliant transmission during C3PAO assessments. These are not edge cases. They reflect tools that defense contractor teams use every day without recognizing their compliance status.

Non-Compliant Practice Why It Fails Compliant Replacement
Emailing CUI via standard Microsoft 365 or Gmail Commercial-tier platforms do not meet FedRAMP Moderate baseline; MORSECORP was partly penalized for this exact practice Microsoft 365 GCC or Google Workspace for Government
Sharing files via Dropbox, Google Drive personal, or WeTransfer No FedRAMP Moderate authorization; consumer platforms have no obligation to protect government-controlled data SFTP, HTTPS transfer via compliant platform, or FedRAMP Moderate-authorized file sharing
FTP (unencrypted) Transmits data in plaintext; any network observer can capture the transfer; explicitly non-compliant with 3.13.8 SFTP or HTTPS with TLS 1.2 or higher
RDP without MFA or encryption Unprotected remote desktop sessions expose CUI systems to credential attacks; AC domain requires MFA for remote access Encrypted RDP with MFA, or VPN-gated remote access with session logging
Texting or messaging apps (consumer) SMS is not encrypted; consumer messaging apps (iMessage, WhatsApp, Signal personal) are not FedRAMP authorized for CUI Transmission must move to a compliant channel; no consumer messaging platform is acceptable for CUI
Unencrypted portable drives Physical loss results in immediate CUI exposure with no recovery option; MP domain requires encryption on all CUI media FIPS 140-2 validated hardware-encrypted drives only
The MORSECORP Precedent
In 2023, MORSECORP settled a False Claims Act case for $4.6 million. The DoJ cited, among other findings, the company's use of a non-compliant cloud email platform for CUI. The settlement established that misrepresenting compliance in SPRS self-assessments while using prohibited tools carries real liability, not just assessment findings. The email platform issue alone was sufficient to support the enforcement action.

One pattern surfaces repeatedly in assessment findings: organizations that have invested in compliant infrastructure for their primary CUI workflows but have not addressed secondary channels. The engineering team uses M365 GCC for email. But the business development team sends contract deliverables via personal Gmail. Or a project manager shares a drawing through a personal Dropbox link. A single non-compliant transmission can constitute a reportable incident if CUI is exposed.

Assessor Evidence Expectations

During a C3PAO assessment, evaluators do not accept policy statements as evidence that compliant transmission methods are in use. They will request documentation and, where possible, verify configurations directly. Knowing what they look for lets you prepare your evidence package before the assessment begins.

Requirement Evidence Assessors Will Request
SC.L2-3.13.8 (Encryption in transit) TLS configuration screenshots; FIPS module validation certificates; email platform FedRAMP authorization letter or marketplace listing; network diagrams showing encrypted paths for CUI flows
SC.L2-3.13.1 (Boundary monitoring) Firewall rules showing default-deny posture; network monitoring logs; documentation of data flows crossing the CUI boundary
AC.L2-3.1.12 (Remote access control) VPN configuration; MFA enrollment records for remote users; session logging evidence; documented prohibition on personal device use for CUI access or evidence that personal devices are in scope
MP.L2-3.8.6 (Portable media) Inventory of authorized portable media; encryption validation for USB drives; policy governing media use on CUI systems; sanitization records for decommissioned media

The System Security Plan (SSP) must document each transmission method your organization uses for CUI and explain how each one satisfies the applicable controls. Assessors will compare your SSP descriptions against what they observe in the environment. Gaps between documentation and practice are among the most common sources of findings.

Data Flow Diagrams in the SSP
Your SSP should include a data flow diagram showing every path by which CUI enters, moves within, and exits your environment. Assessors use this diagram as a checklist: each path must correspond to a control. Transmission methods not shown on the diagram but observed in practice represent undocumented CUI flows, which is itself a finding under SC.L2-3.13.1.

How 1TEN Helps

Documenting CUI transmission methods across an entire organization requires tracking every data flow, every platform, and every user group that touches CUI. 1TEN provides an air-gapped compliance platform that maps your CUI flows, generates SSP documentation for each transmission control, and produces the evidence package assessors request for SC and MP domain requirements. Because the platform runs entirely on-premises, the act of using 1TEN to document your CUI transmission controls does not itself create a CUI transmission compliance issue.

Frequently Asked Questions

No. Standard commercial email services, including Microsoft 365 Business, Gmail, and Google Workspace, do not meet the FedRAMP Moderate baseline required for CUI transmission. You must use a FedRAMP Moderate-authorized variant such as Microsoft 365 GCC or Google Workspace for Government. This is a hard requirement under NIST SP 800-171 requirement 3.13.8 and has been the basis for enforcement action, including the MORSECORP False Claims Act settlement.

No. Consumer-grade file sharing services including Dropbox, standard Google Drive, Box personal, OneDrive personal, and WeTransfer do not meet the FedRAMP Moderate authorization required for CUI storage and transmission. For file sharing with subcontractors, you must use a FedRAMP Moderate-authorized platform. The subcontractor receiving CUI also inherits the same NIST SP 800-171 obligations under the DFARS 252.204-7012 flow-down requirement.

NIST SP 800-171 requirement 3.13.8 requires encryption of CUI on open networks. The cryptographic modules used must be FIPS 140-2 or FIPS 140-3 validated. For TLS-based transmission, TLS 1.2 is the minimum acceptable version; TLS 1.3 is preferred. Older protocols including TLS 1.0, TLS 1.1, SSL 3.0, and any version of SSL are not acceptable for CUI transmission and will generate findings in a C3PAO assessment.

A USB drive can be an acceptable transport method for CUI only if it is encrypted using FIPS 140-2 validated encryption, access to the drive is controlled and logged on systems where it is used, and the drive is sanitized using NIST SP 800-88 methods before disposal or reuse. Unencrypted USB drives are never acceptable for CUI. Many organizations prohibit personal USB drives entirely and permit only organization-issued, hardware-encrypted drives for CUI use.

Remote access to systems that contain CUI must use encrypted connections with FIPS-validated cryptography and must require multi-factor authentication. VPN with strong authentication is the standard approach. Remote desktop sessions must be encrypted and MFA-protected. Personal devices used to access CUI remotely are in scope for your CMMC assessment unless explicitly prohibited by technical controls. Any remote access capability must be documented in your System Security Plan.

Transmitting CUI via a non-compliant channel is a violation of DFARS 252.204-7012 and, if willfully misrepresented in a SPRS self-assessment, can trigger False Claims Act liability. An unauthorized disclosure resulting from a non-compliant transmission method is a reportable cyber incident: you must notify the DoD within 72 hours via the DIBNet portal and preserve system images for at least 90 days. The MORSECORP settlement demonstrates that enforcement actions follow from documented use of non-compliant platforms.

Know your posture.

1TEN is the GRC platform built specifically for small defense manufacturers navigating CMMC Level 2.

Request a Demo