By The Defense Compliance Report Editorial Team
Last reviewed: August 2026 Last verified: August 17, 2026 Evaluation depth: Official-source analysis — regulation, FedRAMP Marketplace, Salesforce's published documentation and pricing, and the Cyber AB assessment process. No hands-on testing of a customer Salesforce environment. Not affiliated with: Salesforce, the Cyber AB, NIST, DCMA DIBCAC, the Department of War/Department of Defense, GSA, FedRAMP, or any U.S. government agency.
Current program status (August 17, 2026): Under the original 32 CFR § 170.3 phase schedule, Phase 1 runs from November 10, 2025 through November 9, 2026, and Phase 2 was scheduled to begin November 10, 2026. The Department of War suspended Phase II on July 13, 2026 and directed requiring activities to use only Level 1 (Self) or Level 2 (Self) designations during the suspension. Active solicitations carrying Level 2 (C3PAO) or Level 3 requirements are to be amended, and existing contracts are to have those requirements removed by modification at the next option period or scheduled administrative modification. DFARS 252.204-7012 safeguarding duties remain unchanged. Nothing on this page depends on a Phase II countdown, and you should be skeptical of any Salesforce guide that still runs one.
Here's the short version of Salesforce CMMC compliance: Salesforce really did announce a CMMC Level 2 certification in January 2026 — for one internal enclave used by two of its own teams, not for your Salesforce org. For your own contractor-managed Controlled Unclassified Information (CUI), the Salesforce environment to evaluate is Government Cloud Plus, which the FedRAMP Marketplace lists as FedRAMP Certified, Class D (High), package FR2003061248 and Salesforce prices publicly at 15% applied to net spend. Your standard commercial Sales or Service Cloud org is not inside that FedRAMP package.
But the FedRAMP record answers only one half of the cloud-provider test. It does not, by itself, prove Salesforce will satisfy the separate incident-reporting, preservation, forensic-access, and damage-assessment commitments in DFARS 252.204-7012(c) through (g) for your contract. You need both halves in writing.
And keeping CUI out of the CRM entirely is a legitimate, cheaper answer — if you can prove it.
That last option is the one nobody sells you, and it's the one we'd look at first.
There's also a document Salesforce points defense contractors to on its public compliance site that a privately held defense contractor cannot self-serve from the page. The document is marked not available for download and tells readers to contact an account representative. We'll show you exactly what that means for your evidence plan and what to reference in your System Security Plan instead.
The Defense Compliance Report is an independent trade publication and decision resource for CMMC and Defense Industrial Base compliance. Read our methodology and editorial standards before you rely on our conclusions.
Which Salesforce CMMC path fits you — and which doesn't
| Your situation | Where this page sends you |
|---|---|
| Salesforce holds no Federal Contract Information (FCI), no CUI, and no Security Protection Data from your CUI systems | Keep it outside the assessment boundary only if it meets the actual out-of-scope test — inability, no security-protection role, and physical or logical separation |
| Salesforce holds FCI but no CUI | Level 1 scoping. The FedRAMP cloud-provider requirement in DFARS 252.204-7012 does not attach to FCI by itself |
| Salesforce holds contractor-managed CUI | Government Cloud Plus is the Salesforce offering to evaluate. Budget the 15% uplift, migration, product-boundary verification, and written DFARS (c)–(g) evidence |
| Salesforce holds logs or security configuration data from your CUI environment | It may be handling Security Protection Data and may therefore be assessed as a Security Protection Asset — "no CUI" is not automatically "no scope" |
| Your CUI is drawings, technical data packages, or export-controlled files | A CRM is probably the wrong home for that data. Skip to the disqualification section |
| You support a DoD mission owner with IL4 or IL5 data | Government Cloud Plus – Defense may apply in direct support of that mission owner; Salesforce says contractors cannot purchase it for internal use |
| You genuinely don't know what's in your org | Start with the data, not a sales call. The 30-day sequence at the end is written for you |
Not for you if: you're looking for a list of the best CMMC consultants, a GRC platform comparison, or a Microsoft GCC High walkthrough. We cover those elsewhere and we're not going to pad this page with them.
Is Salesforce CMMC compliant?
Answer capsule: No cloud platform is "CMMC compliant" on its own. Under 32 CFR Part 170, CMMC status is tied to a defined contractor information system and assessment scope, with a CMMC unique identifier recorded in SPRS — not transferred from a software vendor to every customer. Salesforce holds a CMMC Level 2 certificate for a defined internal enclave and Government Cloud Plus holds a FedRAMP High certification, but your result still depends on your environment, configuration, integrations, documentation, evidence, and required contract status.
Almost every argument about Salesforce and CMMC is really three different questions wearing one coat. Separate them and the confusion disappears in about ninety seconds.
Layer 1 — Salesforce the company. Did Salesforce itself get assessed and certified? Yes, in January 2026, for a specific internal enclave. Scope matters enormously here, and we break it down in the next section.
Layer 2 — Salesforce the cloud offering. Is the product you're buying inside a cloud authorization that addresses the baseline in the DFARS clause? For Government Cloud Plus, the FedRAMP Marketplace record answers the authorization-baseline question. It does not answer the separate DFARS 252.204-7012(c)–(g) contract question, and it does not cover products outside the package boundary.
Layer 3 — Your Salesforce org. Is your tenant, configured by your admins, connected to your other systems, used by your people, compliant? Nothing in Layer 1 or Layer 2 answers this. This is the layer your assessor or self-assessment actually reaches.
Vendor marketing blends Layer 1 and Layer 2 into Layer 3. Consultants selling migrations do it too. When someone tells you "Salesforce is CMMC certified, so you're covered," they've just skipped the only layer that determines whether you pass.
What buying Salesforce never does:
- It does not produce a CMMC status for your company.
- It does not make FedRAMP certify you. FedRAMP certifies cloud service offerings; it doesn't assess defense contractors.
- It does not transfer Salesforce's enclave certificate to your org.
- It does not put every Salesforce product, AgentExchange app, integration, or connected service inside one authorization boundary.
- It does not turn on the security features you'll be asked to evidence. Many relevant settings are configuration decisions, and several features cost extra.
What Salesforce's CMMC Level 2 certification actually covers
Answer capsule: On January 30, 2026, Salesforce announced that its Public Sector Enclave used by the Salesforce National Security and Public Sector Professional Services teams achieved CMMC Level 2. Salesforce identified DFARS 252.204-7021 and NIST SP 800-171 Revision 2 in the announcement and said the result provides assurance to customers who process, store, or transmit CUI to or with those two teams. It is not a certification of customer Salesforce environments.
We read the announcement rather than the headlines about it. Here is what it says, and what it carefully does not say.
The certified scope is the Public Sector Enclave used by the Salesforce National Security and Public Sector Professional Services teams. That scope language matters more than the logo.
The announcement says the result provides assurance to government customers, contractors, and subcontractors who exchange CUI with those two Salesforce teams. If your engagement is with one of those teams and Salesforce confirms the CUI work occurs inside that enclave, the certificate is directly relevant and genuinely useful — it addresses the enclave used for that work.
If you do not have that engagement, the certificate tells you Salesforce invested in a serious internal compliance program. It does not certify your tenant.
The context number, from Salesforce itself
Salesforce stated that, as of its January 30, 2026 announcement, fewer than 400 organizations had achieved a Final or Conditional CMMC Level 2 status following a C3PAO assessment, representing less than 0.3% of the DIB. Coalfire Federal's published case study repeats the early-certification context and identifies Coalfire Federal as the CMMC Third-Party Assessment Organization on the engagement.
Two things worth pulling out of that:
First, it is genuine evidence that Salesforce completed an official Level 2 assessment during the first implementation phase.
Second — and this is the overlooked point — neither Salesforce's announcement nor Coalfire Federal's case study states whether Salesforce's own status is Final or Conditional. Under 32 CFR § 170.17, those are different statuses. A Conditional status carries an open POA&M that must be closed to reach Final.
We're not implying anything is wrong. We're pointing it out because if you are relying on Salesforce's status in supply-chain due diligence, "Final or Conditional?" and "What is the CMMC UID?" are the questions to ask. That's a two-line email, and it's the difference between citing a certificate and citing a certificate you understand.
The case study, and what it can't tell you
Coalfire Federal's case study describes a mock assessment followed by an official assessment, internal stakeholder alignment, assessment-ready evidence, and boundary discipline. It is an assessor's commercial case study about a very large enterprise's own environment. It is not a typical-customer outcome, and nothing in it suggests a customer inherits the result.
The transferable lesson is procedural: define the boundary, make the evidence traceable, and find the gaps before the formal assessment.
Do not copy the provider structure from a case study without resolving independence. 32 CFR § 170.8 prohibits a CMMC Ecosystem member from participating in a Level 2 certification assessment when it served as a consultant to prepare that organization for any CMMC assessment within the prior three years. Whether a specific mock-assessment engagement crosses that line depends on what the provider actually did and how the engagement was structured. Get the separation in writing before you hire anyone.
Named-provider note. Coalfire Federal appears on this page as the C3PAO of record in a published case study — a factual attribution, not a recommendation. Provider category: C3PAO. Compensation relationship with The Defense Compliance Report: none. Evaluation depth: we read the publicly posted case study; we did not evaluate the firm. Last verified: August 17, 2026. What we could not verify: the assessment UID, the Final-versus-Conditional status, or any Salesforce customer outcome.
The right provider category depends on your situation
The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, a Salesforce implementation partner, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The solicitation and contract set the required status; a checklist does not.
Because a general answer can't resolve those variables for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, credentials, system diagrams, or sensitive contract details.
That routing runs on The CMMC Path Framework, our named logic for mapping required level, FCI versus CUI handling, assessment type, IT and cloud environment, and contract timeline to a provider category. It resolves the provider category first. Named provider options appear only after category fit and disclosure; the result is not a score, a ranking, or a compliance determination. See our provider categories and methodology for the rules behind it.
Which Salesforce environment can hold CUI?
Answer capsule: Salesforce's current comparison material points contractor-managed CUI to Government Cloud Plus, not standard commercial Salesforce and not Government Cloud Plus – Defense. Government Cloud Plus is listed on the FedRAMP Marketplace as FedRAMP Certified, Class D (High), package FR2003061248, and Salesforce publishes the price at 15% applied to net spend. Government Cloud Plus – Defense is the IL5 environment for direct support of a DoD mission owner; Salesforce says contractors cannot purchase it for internal use.
This is the table we wanted when we started researching this page and couldn't find anywhere. Every row below was checked against a current primary source on August 17, 2026.
| Salesforce environment | Current authorization and operating facts | Data fit shown by Salesforce's current comparison sheet | Published price | Contractor decision |
|---|---|---|---|---|
| Standard commercial Salesforce | Not part of FedRAMP package FR2003061248 | The current comparison sheet does not mark standard Salesforce for contractor-managed CUI; FCI may still place the org in a Level 1 scope | Standard product pricing | Use only when CUI is excluded and the boundary treatment is documented |
| Government Cloud Plus | FedRAMP Certified, Class D (High), FR2003061248; Rev5; JAB path; certified since May 27, 2020; 66 authorizations as checked August 17, 2026. Salesforce describes AWS GovCloud (US), CONUS residency, and screened and qualified U.S.-citizen operations and support | Contractor-managed CUI | 15% applied to net spend, billed annually | This is the Salesforce offering to evaluate for your own contractor-managed CUI |
| Government Cloud Plus – Defense | Salesforce markets it as IL5-authorized, physically isolated, with CAC login, salesforce.mil domains, BCAP, and NIPRNet support | DoD-managed CUI and unclassified national security systems in direct support of a mission owner | 25% applied to net spend, billed annually | Salesforce says contractors may use it in direct support of a DoD mission owner but cannot purchase it for internal use |
| Government Cloud Premium | Salesforce describes a Top Secret-authorized, air-gapped environment for classified national security systems | Classified mission use | Contact for pricing | Not the answer to a contractor's ordinary CMMC Level 2 problem |
Primary product sources: Salesforce's Government Cloud pricing page, Government Cloud page, and current How to Select the Right Government Cloud comparison sheet.
Our conclusion, not a regulatory designation: Government Cloud Plus is the realistic Salesforce product path for contractor-managed CUI because it is the current Salesforce offering tied to the relevant FedRAMP package and shown by Salesforce for that data type. That does not certify your tenant, prove every feature is in boundary, or complete the second DFARS 252.204-7012(c)–(g) half of the cloud-provider test.
The Impact Level question, and why it usually isn't the first question
Here's an original finding that will save you a meeting. Salesforce's current public sources still do not tell one clean story about the DoD Impact Level associated with Government Cloud Plus.
| Salesforce source | Checked | What it says about Government Cloud Plus |
|---|---|---|
| Government Cloud FAQ | August 17, 2026 | Supports up to FedRAMP High and IL2; Government Cloud Plus – Defense supports IL4 and IL5 |
| Government Cloud pricing FAQ | August 17, 2026 | Government Cloud Plus helps support IL4 controls; Government Cloud Plus – Defense helps support IL5 |
| Current comparison sheet | August 17, 2026 | Shows Government Cloud Plus at IL2 and Government Cloud Plus – Defense at IL4/IL5 |
The contradiction is real. Don't resolve it by picking the sentence you prefer.
For a contractor's own CUI in a system not operated on behalf of the Government, the baseline in DFARS 252.204-7012(b)(2)(ii)(D) is FedRAMP Moderate-equivalent security plus compliance with paragraphs (c) through (g). A contract, mission-owner architecture, or other clause can impose more. So stop shopping for an Impact Level until you have answered the threshold question: Is this your contractor system, or are you operating on behalf of a government mission owner?
Government Cloud Plus's FedRAMP High certification is the cleaner evidence for the first case. Government Cloud Plus – Defense is the mission-owner answer.
One more terminology trap
Salesforce's pages still describe Government Cloud Plus as holding a FedRAMP High JAB P-ATO. The current FedRAMP Marketplace describes the same offering as FedRAMP Certified, Class D (High), Path JAB.
Nothing in that difference suggests Salesforce lost standing. But when your assessor, prime, or contracting team asks for the current status, cite the live marketplace record and package ID instead of relying on a vendor page with older terminology.
If you have a headline in your inbox about IL5 AI agents
On August 5, 2026, Salesforce announced IL5-authorized Agentforce 360 capabilities under Missionforce National Security. Real news, but it does not change the product decision for a contractor's own CUI. That announcement concerns Salesforce's IL5 mission environment. It does not move a contractor's internal commercial org into the Government Cloud Plus authorization, and it does not change the DFARS test for your own CUI.
✅ Decision Resolution Point 1
You now know which environment to evaluate. The next question is whether your org actually has CUI or Security Protection Data in it — and that's a scoping question, not a shopping question.
Run the ten-path Salesforce CUI check below →
Mark each live path in your org before you call Salesforce or a consultant. No form, no email wall, and no data leaves your browser because the check is the table on this page.
Do not paste CUI, drawings, credentials, system diagrams, or contract text into any public web form.
What rule actually applies to a cloud CRM that holds CUI?
Answer capsule: DFARS 252.204-7012(b)(2)(ii)(D) creates a two-part test when an external cloud service provider stores, processes, or transmits covered defense information: the contractor must require and ensure that the provider meets security requirements equivalent to the FedRAMP Moderate baseline and complies with paragraphs (c) through (g) of the clause. 32 CFR § 170.19(c)(2) carries the cloud-provider requirement into CMMC scoping and requires the relationship, services, service description, and Customer Responsibility Matrix to be documented.
We keep the full regulatory treatment on our CMMC cloud service provider requirements page. Here it is applied to a CRM, in the order it actually bites.
Step one. Your contract establishes the obligation. DFARS 252.204-7012 tells you what happens when covered defense information is present. The CMMC solicitation provision and contract clause identify the CMMC status required for the systems that will process FCI or CUI. None of them names a product.
Step two. If an external cloud service stores, processes, or transmits covered defense information, subparagraph (b)(2)(ii)(D) attaches. The first half requires security equivalent to the FedRAMP Moderate baseline. Government Cloud Plus's Class D (High) certification is stronger in impact level than Moderate, but only for the cloud service offering, products, and features inside package FR2003061248.
Step three — the half of the clause nobody quotes. The same subparagraph requires the cloud service provider to comply with paragraphs (c) through (g). That is a separate obligation, not a benefit that automatically falls out of a FedRAMP listing.
| Clause paragraph | What the clause requires | Why a CRM makes this hard |
|---|---|---|
| (c) Cyber incident reporting | The contractor must rapidly report — defined as within 72 hours of discovery — a covered cyber incident to DoD | Your response clock depends on when you discover the incident, and platform notice timing is not entirely under your control |
| (d) Malicious software | When malicious software is discovered and isolated in connection with a reported incident, submit it to the DoD Cyber Crime Center | In SaaS, you may not be able to isolate or extract host-level code without provider support |
| (e) Media preservation | Preserve images of affected systems and relevant monitoring and packet-capture data for at least 90 days from report submission | You need to know what the provider retains, what applies in a multi-tenant service, and what it can make available |
| (f) Forensic access | Provide DoD access to additional information or equipment necessary for forensic analysis | Some of the evidence or equipment is controlled by the provider, not by your admins |
| (g) Damage assessment | Provide damage-assessment information if DoD elects to conduct one | The answer depends on whether the evidence required in (e) was preserved and can be produced |
We found no public Salesforce commitment that resolves paragraphs (c) through (g) for a specific contractor customer. That is not an accusation — commitments like this normally live in contract documents and restricted security packages, not marketing pages. It is a gap in your evidence, and it is question three in the letter further down this page.
Step four. Section 170.19(c)(2) requires the external service provider relationship and services to be documented in your SSP and described in the provider's service description and Customer Responsibility Matrix. The Cyber AB CMMC Assessment Process tells a C3PAO to confirm that the CRM will be available, that ESP personnel will participate when applicable, and that the organization can produce evidence of the provider's FedRAMP authorization, FedRAMP equivalency, or Level 2 status as appropriate.
Salesforce's CMMC FAQ says its NIST SP 800-171 Revision 2 attestation aligns with CMMC Level 2 and Level 3. That is too broad. 32 CFR § 170.14 makes Level 2 identical to the 110 requirements in NIST SP 800-171 Revision 2 across 14 families. Level 3 adds 24 selected enhanced requirements from the February 2021 edition of NIST SP 800-172. A Revision 2 attestation does not cover those additional Level 3 requirements.
And to close the common revision mix-up: CMMC Level 2 currently maps to NIST SP 800-171 Revision 2, not Revision 3. NIST has superseded Revision 2 in its publication catalog, but DoD has not amended 32 CFR Part 170 to replace the incorporated CMMC baseline. The same rule still incorporates the February 2021 edition of SP 800-172 for Level 3 even though NIST published SP 800-172 Revision 3 in May 2026.
Which DFARS clauses and SPRS records control the Salesforce decision?
Answer capsule: Five DFARS provisions and clauses answer five different questions. DFARS 252.204-7012 sets the safeguarding and cloud-provider duties. DFARS 252.204-7019 requires a current NIST SP 800-171 DoD assessment in SPRS before award when applicable. DFARS 252.204-7020 governs Government assessment access and score posting. DFARS 252.204-7025 states the exact CMMC status required by the solicitation. DFARS 252.204-7021 carries that status into the contract and requires annual affirmation in SPRS.
| Provision or clause | What it controls | What to verify for the Salesforce boundary |
|---|---|---|
| DFARS 252.204-7012 | Safeguarding covered defense information; external cloud rule; 72-hour reporting; preservation and forensic duties | Whether Salesforce stores, processes, or transmits covered defense information; FedRAMP evidence; written (c)–(g) support |
| DFARS 252.204-7019 | Award eligibility when NIST SP 800-171 applies; a current assessment normally not more than three years old; score present in SPRS | Whether the SSP and score cover the same information system boundary you are describing in the proposal |
| DFARS 252.204-7020 | Government Medium or High assessment access; summary scores in SPRS; subcontract flowdown | Whether you can give the Government access to the facilities, systems, personnel, provider evidence, and architecture needed to validate the score |
| DFARS 252.204-7025 | The exact CMMC status required by the solicitation; current status and affirmation in SPRS; CMMC UID in the proposal | The inserted status, each system UID, and whether a suspension-related solicitation amendment changed the original requirement |
| DFARS 252.204-7021 | Maintaining the required status during performance; processing FCI/CUI only on systems with that status; annual affirmation in SPRS | Whether the Salesforce boundary is inside the system associated with the UID and current affirmation |
The SPRS record is not just a number floating beside your CAGE code. For a Basic NIST SP 800-171 DoD Assessment, the required record includes the standard assessed, organization conducting the assessment, associated CAGE codes, a description of the SSP architecture when more than one plan exists, assessment date, summary score, and expected date to reach 110. The current SPRS site also provides separate tutorials for Level 2 self-assessment entry and the affirming official.
That creates a practical test nobody puts on a Salesforce slide:
Does the architecture described in SPRS, the SSP, the diagram, and the Salesforce evidence request all describe the same boundary?
If the answer is no, the problem is not Salesforce pricing. The problem is that your records disagree.
Can you keep Salesforce out of your CMMC Level 2 scope?
Answer capsule: Possibly — but 32 CFR § 170.19(c)(1) sets a real test. An Out-of-Scope Asset must be unable to process, store, or transmit CUI, must not provide security protection for CUI assets, and must be physically or logically separated. An asset that can hold CUI but is not intended to because of policy, procedure, and practice is a Contractor Risk Managed Asset, which must be inventoried, shown on the network diagram, and documented in the SSP. A written "no CUI in Salesforce" policy alone does not make the org out of scope.
This is the section that can save some readers an expensive migration, so we're going to be precise.
There are three doors, not two:
Door 1 — Move CUI into Government Cloud Plus. Cleanest Salesforce product story, biggest bill, longest implementation path, and still dependent on the product boundary, CRM, tenant configuration, integrations, and written DFARS (c)–(g) support.
Door 2 — Fence CUI out of Salesforce and document the fence. Cheapest, and defensible if the fence is real. If the org remains technically capable of processing CUI but is not intended to do so because of policy, procedure, and practice, this is Contractor Risk Managed Asset treatment, not Out-of-Scope. Out-of-Scope requires inability, no security-protection role, and physical or logical separation.
Contractor Risk Managed treatment is not a loophole. The rule requires the asset in the inventory, SSP, and network diagram. If the SSP is sufficiently documented, the assessor does not assess it against the other Level 2 requirements except as permitted. If the documentation or other findings raise questions, the assessor may conduct a limited check, and the regulation says that check cannot materially increase assessment duration or cost.
Door 3 — Put CUI in a purpose-built CUI enclave and leave the CRM commercial. This is the architecture to evaluate when the CUI is documents rather than CRM records. See CMMC managed enclave.
The whole thing turns on one question: can CUI actually get in?
The ten ways CUI gets into a Salesforce org
We built this from Salesforce's own feature set, and every row is a place we'd look first in a scoping walkthrough. Hand it to your admin.
| # | Path | Why it's the one that bites |
|---|---|---|
| 1 | Files and attachments on Opportunities, Accounts, and Cases | Drawings, specifications, and statements of work land here without anyone deciding they should |
| 2 | Notes, description fields, and free text | Program names, part numbers, and technical detail get typed in by hand |
| 3 | Email-to-Case and activity capture | Government and prime correspondence can be pulled into records automatically |
| 4 | Quotes, bills of material, and CPQ line detail | Controlled technical detail can hide inside a commercial-looking object |
| 5 | Experience Cloud and partner portals | External users, sometimes at other companies, can read or upload records |
| 6 | AppExchange and AgentExchange apps | Salesforce states AgentExchange apps are outside its authorization boundaries, and its current comparison sheet says AppExchange partner applications and products are not included in Salesforce authorization boundaries |
| 7 | Sandboxes and refreshes | Production data can be copied into an environment nobody documented |
| 8 | Reports, list exports, and Data Loader | CUI can leave for a laptop or shared drive in one click |
| 9 | Middleware and integrations | MuleSoft Government Cloud is a separate FedRAMP package, FR1818161169. Commercial middleware is not covered by the Government Cloud Plus package merely because Salesforce owns the brand |
| 10 | Agentforce and Einstein features | AI features may touch record data. Whether a specific feature and data path are inside the authorized boundary must be checked against the current authorized-products documentation, not assumed from a launch announcement |
The failure mode is never the architecture diagram. It's row 8 on a Tuesday afternoon.
Here is the failure pattern to test for: a company scopes Salesforce for FCI only, decides that's fine, and then a prime starts attaching CUI-marked documents to opportunity records. The architecture was right. The data classification moved. Nobody updated the boundary.
If your exclusion plan depends on every salesperson remembering a policy forever, it isn't an exclusion plan. It's a hope. Technical enforcement — attachment restrictions, disabled or constrained email sync, export permissions, portal controls, integration filters, monitoring, and response procedures — is what turns Door 2 into a boundary you can defend. The exact controls depend on your Salesforce edition and architecture; document what is actually configured, not what the platform can theoretically do.
If Salesforce only holds your logs
Don't skip this. 32 CFR § 170.4 defines Security Protection Data as security-relevant information used to protect the assessed environment, including configuration data, logs generated by or ingested by a Security Protection Asset, vulnerability-status data, and passwords that grant access to the environment.
If your CUI environment ships that kind of data into Salesforce or a Salesforce-connected service, § 170.19(c)(2) can place the service in scope as a Security Protection Asset even when it does not hold CUI. The classification turns on what the data is used for, not simply whether a field is labeled "log."
✅ Decision Resolution Point 2
If Door 2 looks like your answer, the work ahead is documentation and enforcement, not procurement — and you can start it today without hiring anyone.
Get the 32-point CMMC Readiness Checklist →
The printable checklist is delivered by email and covers scope and data classification, SSP and POA&M, SPRS, enclave and tooling, MSP/MSSP alignment, pre-assessment evidence, supply chain, and governance. Use it to find out whether your CRM is your actual gap or just your most visible one. The checklist may show that the CRM is not your first gap.
When Salesforce is the wrong place for your CUI — read this before you spend anything
Answer capsule: A CRM is designed for records and relationships, not controlled-document collaboration. When a contractor's CUI consists primarily of engineering drawings, technical data packages, or export-controlled files that people must open, edit, approve, and exchange, moving the CRM into a government cloud may leave the underlying workflow problem untouched while adding recurring cost.
We'd rather lose you here than sell you the wrong thing.
If your CUI is a marked PDF that three engineers and a supplier need to open every week, the question is not "which Salesforce edition." It's "where do controlled documents live, and how do people work on them." Government Cloud Plus will cost you 15% on top of the applicable Salesforce net spend and may still leave you buying a separate enclave or controlled collaboration environment.
Go read CMMC managed enclave and CMMC enclave cost instead, then come back to the CRM question once your documents have a home. If Microsoft's environment is the direction you're heading for that, start at GCC High for CMMC.
Same advice if you're a Level 1, FCI-only contractor with no CUI anywhere. Level 1 covers the 15 basic safeguarding requirements from FAR 52.204-21 with an annual self-assessment and affirmation under CMMC. The external-cloud requirement in DFARS 252.204-7012(b)(2)(ii)(D) attaches to covered defense information, not FCI by itself. A commercial Salesforce org can be an in-scope Level 1 asset without a government-cloud authorization. Don't buy the uplift to solve a problem you don't have — start at CMMC Level 1 vs. Level 2. See CMMC levels for the full status and assessment-type map.
What does Salesforce Government Cloud Plus actually cost for CMMC?
Answer capsule: Salesforce publishes Government Cloud Plus at 15% applied to net spend and Government Cloud Plus – Defense at 25%, both billed annually. Government Cloud Premium is priced on request. Salesforce defines net-spend pricing as a percentage of spend on applicable, technically compatible products hosted in the dedicated instance. The uplift does not include migration labor, integration rework, data cleansing, customer-side documentation, or security add-ons. Salesforce's general Shield page separately publishes Shield at 30% of net spend, but you must confirm the applicable product base and Government Cloud quote rather than assuming the percentages stack mechanically.
A cost range with no method behind it does not help you. We're going to give you published numbers and honest arithmetic, and then hand you a table for normalizing the quotes you collect.
The published numbers
| Item | Public price | What the percentage applies to | Verified |
|---|---|---|---|
| Government Cloud Plus | 15% of net spend, billed annually | Applicable, technically compatible Salesforce products hosted in the dedicated instance | August 17, 2026 |
| Government Cloud Plus – Defense | 25% of net spend, billed annually | Applicable, technically compatible Salesforce products hosted in the dedicated instance | August 17, 2026 |
| Government Cloud Premium | Contact for pricing | Quote-specific | August 17, 2026 |
| Salesforce Shield | 30% of net spend on Salesforce's general Shield pricing page | Other applicable Salesforce products; confirm Government Cloud compatibility and quote base | August 17, 2026 |
Sources: Salesforce Government Cloud pricing and Shield pricing. Both pages say pricing is informational, subject to change, and should be confirmed with sales.
What the 15% Government Cloud Plus uplift looks like in dollars
The spend figures below are illustrative inputs, not Salesforce prices. The only sourced number in the calculation is the 15%. Your base is your discounted net spend on applicable, technically compatible products.
| Annual applicable net Salesforce spend | Government Cloud Plus uplift at 15% | Three-year uplift before price changes |
|---|---|---|
| $50,000 | $7,500 per year | $22,500 |
| $150,000 | $22,500 per year | $67,500 |
| $300,000 | $45,000 per year | $135,000 |
| $500,000 | $75,000 per year | $225,000 |
That's the part that's knowable. Now the part vendors leave out of the first conversation.
The rest of the cost stack
| Cost line | What we can tell you |
|---|---|
| Salesforce Shield or individual components | Salesforce publishes general net-spend percentages, but the Government Cloud product base and compatibility must be confirmed in your quote |
| Migration labor | Moving an existing org is a project, not a setting. Salesforce publishes a Government Cloud Plus migrations program and separate org-migration guidance |
| Custom code and automation rework | Inventory Apex, flows, triggers, permission logic, and packaged customizations; make the implementation partner state what it tested and what it excluded |
| Integration re-platforming | Middleware, ETL jobs, identity connections, email capture, APIs, and downstream systems may need new endpoints or products |
| AppExchange package replacement | Some packages may not have an authorized or compatible Government Cloud version; the decision can affect functionality, not just licensing |
| Data cleansing before migration | Moving a contaminated dataset into a government environment does not make the history clean or the scope understood |
| Sandbox, backup, and export strategy | Every copy, refresh, backup, export, and restore path becomes part of the new evidence story |
| SSP, POA&M, diagram, and evidence work | Never inheritable in full, no matter which cloud you buy |
| Ongoing administration | Someone must own access reviews, configuration drift, release changes, evidence retention, and incident procedures after go-live |
| Provider document access | Your assessment plan must account for restricted documents, account-team access, provider participation, and review conditions |
We are deliberately not publishing a total migration range. We did not find a dataset that normalizes company size, user count, base spend, custom-object count, integration count, data volume, package inventory, migration condition, and starting maturity. A made-up range is worse than no range when you're about to negotiate. Program-level cost figures live on CMMC Level 2 cost and CMMC certification cost.
Use this to compare proposals
Vendors scope proposals differently. Force them into the same grid and the real price appears.
| Quote line | Vendor A | Vendor B | Vendor C |
|---|---|---|---|
| Users and licenses included | |||
| Government Cloud uplift — confirm percentage and base | |||
| Shield or individual security add-ons | |||
| Data migration and cleansing | |||
| Number of integrations included | |||
| Custom code and flow remediation | |||
| AppExchange package treatment | |||
| Security configuration and hardening | |||
| SSP, diagrams, asset inventory, and evidence documentation | |||
| Restricted-provider-document access and assessment participation | |||
| Assessment support | |||
| Named exclusions | |||
| Recurring annual cost, year 2 onward |
The "named exclusions" row is where the surprises are. Make them write it down.
What can you actually get in writing from Salesforce?
Answer capsule: Salesforce's CMMC FAQ points contractors to a NIST SP 800-171 attestation letter on its compliance site, but the document page says it is not available for download and tells readers to contact an account representative. The published access instructions show a self-service FedRAMP route for federal agencies with a .gov or .mil address and an account-executive route for state, local, quasi-governmental agencies, and implementation partners. They do not show a self-service lane for an ordinary privately held defense contractor. Salesforce's Government Cloud documentation guidance also treats the restricted material as proprietary and prohibits copying, pasting, or reproducing it.
This is the section that changes how you build the evidence plan.
Follow Salesforce's own trail. The CMMC FAQ on the Government Cloud page directs defense contractors to a NIST SP 800-171 attestation letter on the company's public compliance site.
Click through. The attestation-letter page says:
- Not available for download.
- Contact your account representative.
- Federal agencies use the FedRAMP Package Access Request Form and must have a
.govor.milemail address. - State, local, and quasi-governmental agencies and implementation partners go through an account executive.
A privately held defense contractor is not given a self-service download route on that page. The phrase "public-facing" should not be confused with "publicly downloadable."
Then the part that changes how you plan your evidence. Salesforce's Government Cloud compliance-documentation guidance says holders of the restricted documentation may not copy, paste, or reproduce its content. The safer SSP treatment is to reference the source artifact by title, version, date, and access location, then arrange controlled review for the assessor under the applicable agreement.
Your SSP can reference the Customer Responsibility Matrix. Do not assume you can paste it into an appendix.
| What you need | Can you self-serve it? | Route | What your SSP and evidence index should record |
|---|---|---|---|
| FedRAMP status and package identity | Yes | FedRAMP Marketplace, FR2003061248 | Package ID, Class D (High), Rev5, JAB path, certification date, current status, and check date |
| Current Salesforce product and feature boundary | Partly | Public authorized-products article plus account team | Exact environment, product, feature, and authoritative document version |
| Customer Responsibility Matrix and inheritance detail | Not from the public page | Account representative / Public Sector Document Portal | Artifact title, version, date, owner, access method, and assessment-review plan |
| NIST SP 800-171 attestation letter | Not from the public page | Account representative / Public Sector Document Portal | Artifact title, version, date, scope, assessor, and how it will be shown |
| CMVP validation certificate numbers for cryptographic modules | Not found in the public sources we reviewed | Written evidence request | Certificate number, module name/version, operational environment, and product mapping |
| Written position on DFARS 252.204-7012(c)–(g) | Not found in public Salesforce material we reviewed | Contract documents and written request | The exact contract document, obligation, notification timeline, retention, and access terms |
| Provider participation during an assessment | Not publicly resolved | Account team and contract | Named contact, participation scope, timing, and restrictions |
Practical instruction: the Cyber AB CAP expects the assessment team to confirm CRM availability, ESP participation where applicable, authorization evidence, and access to evidence before the substantive assessment phase. Get the portal path and provider participation plan resolved well before your assessment or self-assessment evidence review. Assuming the artifacts will appear on demand is the mistake, and it's a bad week to discover it.
Here's the part we can't do for you
We cannot tell you whether Salesforce will commit in writing to DFARS 252.204-7012 paragraphs (c) through (g) for your organization.
That commitment lives in contract documents and restricted materials we cannot read, and no public Salesforce page we reviewed on August 17, 2026 resolves it. Anyone who gives you a yes or no without showing you the governing contract language is guessing.
What we can do is remove the guesswork from everything that is publicly verifiable — package identity, class, certification date, product positioning, purchase restrictions, published pricing, document-access route — and hand you the exact questions that produce the rest in writing before you sign anything. That's a stronger position than arriving at assessment day without those answers.
The 17 questions to send your Salesforce account team
Copy this. Send it. Keep the reply.
- Which exact product and SKU are you quoting, and which Salesforce environment will our org sit in?
- Which FedRAMP package covers that environment — package ID, current status, certification profile, and authorization boundary?
- Will Salesforce commit in writing to DFARS 252.204-7012 paragraphs (c) through (g) for our org, and under which contract document?
- Salesforce's Government Cloud FAQ says Government Cloud Plus supports IL2 while the pricing FAQ says it supports IL4 controls. Which statement applies to our quoted environment, and does any Impact Level requirement apply to our contractor-managed CUI?
- How does a privately held defense contractor obtain the current Customer Responsibility Matrix, service description, System Security Plan inheritance material, and NIST SP 800-171 attestation letter?
- What is the current title, version, effective date, and scope of each document?
- What are the CMVP validation certificate numbers for the cryptographic modules protecting our data at rest and in transit, which product versions and operational environments do they cover, and what is the FIPS 140-3 transition plan?
- Which products and features are inside the authorization boundary for our org today, and which help article or package artifact is the authoritative list?
- Are the specific Agentforce and Einstein features in our quote inside the boundary? Does prompt, grounding, model, telemetry, search, or support data leave it?
- Which installed AppExchange or AgentExchange packages are compatible with the environment, and what independent authorization or CMMC evidence exists for each package that receives CUI or Security Protection Data?
- Who can access our org for operations and support, which personnel categories are restricted to U.S. citizens or U.S. persons, and what screening applies?
- What is the subprocessor, connected-service, and external-service inventory for this environment?
- How are sandboxes, refreshes, backups, exports, retention, and deletion handled?
- How long are relevant monitoring and packet-capture records retained, and what can Salesforce preserve or produce for at least 90 days after a DFARS cyber-incident report?
- What is Salesforce's incident-notification process and contractual notification timeline to us, measured from Salesforce's discovery?
- If Salesforce Professional Services will touch our CUI, will all of that work occur inside the CMMC Level 2-certified Public Sector Enclave, and what are the current CMMC status, scope, and UID for that enclave?
- What configuration baseline, hardening guidance, evidence guide, and Customer Responsibility Matrix do you publish for this exact environment and product set?
Answers that are not answers
Every one of these may be true and none of them resolves your scope:
- "Salesforce is FedRAMP."
- "Salesforce is CMMC certified."
- "It runs in AWS GovCloud."
- "Shield handles that."
- "It's on AppExchange, so it's fine."
- "Other defense contractors use it."
- "Our platform meets NIST."
- "The whole Salesforce stack is covered."
If you get one of these in response to questions one through five, ask for the Public Sector security specialist rather than escalating with the same question.
✅ Decision Resolution Point 3
You have the environment answer, the rule, the cost, and the evidence list. What's usually missing is a second opinion on which kind of help you need — because CRM migration, SSP and readiness work, and formal assessment are separate capabilities, and the readiness team must be kept appropriately separate from the formal assessor.
Get matched with source-checked CMMC provider options →
Tell us your required level, CUI scope, current Salesforce environment, and timeline. We'll map you to the provider category that fits the work — readiness and implementation help if you're documenting a CRM boundary, an enclave category if technical data needs a different home, a GRC platform if your gap is evidence workflow, or a C3PAO only when a certification assessment is actually required and permitted.
Category first, names second, and never a ranking. We may receive compensation if you accept an introduction; compensation does not change the category logic or the regulatory analysis. See our editorial and advertising policy.
Do not submit CUI, drawings, credentials, system diagrams, controlled files, or sensitive contract details.
How do integrations and AppExchange apps change your boundary?
Answer capsule: Salesforce states that AgentExchange apps are not included in its authorization boundaries, and its current Government Cloud comparison sheet says AppExchange partner applications and products are not included in Salesforce authorization boundaries. A connected cloud service or application that receives CUI or Security Protection Data must be classified and evidenced on its own under 32 CFR § 170.19. "Native to Salesforce" is not the same claim as "inside the FedRAMP package."
Salesforce is unusually direct about this. The Government Cloud pricing FAQ says AgentExchange apps are not included in Salesforce authorization boundaries even though many are native to the platform. The current comparison sheet carries the same boundary warning for AppExchange partner applications and products.
Read that in plain English: "Successfully tested with Government Cloud Plus" is not "inside the authorization boundary." Those are different claims, and only one of them answers the package-scope question.
| Connected system | The question to answer | Likely CMMC treatment |
|---|---|---|
| Email and calendar sync | Are messages, bodies, attachments, or meeting notes copied into Salesforce or back out? | CUI asset or connected cloud service if CUI crosses the boundary; otherwise classify the actual data |
| Document storage | Where do Salesforce files physically reside, and is an external repository used? | Cloud service provider handling CUI if controlled files are stored there |
| E-signature | Are controlled documents uploaded, rendered, signed, or retained? | Separate CSP/ESP question |
| ERP or accounting | Do contract, deliverable, technical, or invoice records cross the API? | FCI or CUI scope depending on content |
| Marketing automation | Are government contacts and opportunity fields synced? | Classify the actual fields; government-related is not automatically CUI |
| Middleware | Does it store payloads, logs, credentials, retries, or dead-letter queues? | ESP; potentially a CUI asset or Security Protection Asset |
| Data warehouse | Are Salesforce records replicated out? | A separate storage and analytics boundary |
| SIEM or MDR | Does it receive logs or configuration data used to protect the CUI environment? | Security Protection Asset |
| Mobile devices | Can users download, cache, screenshot, or forward records and files? | Endpoint and data-flow scope question |
| Custom API | Where do tokens, payloads, logs, errors, and retries live? | Evaluate every component and operator |
And one Salesforce-family caution: buying Government Cloud Plus does not cover every Salesforce-branded product. MuleSoft Government Cloud has its own FedRAMP package, FR1818161169, currently listed separately at Class C (Moderate). Slack and GovSlack are separate offerings with separate boundaries and authorization records. Same parent company, different evidence.
What does Salesforce cover, and what stays yours?
Answer capsule: Salesforce uses a shared-responsibility model. The authorized offering can supply platform, infrastructure, operations, and inheritance evidence, but the contractor still owns the tenant configuration, users, roles, connected systems, data classification, incident process, SSP, diagrams, asset inventory, evidence retention, and the customer responsibilities identified in the CRM. The Cyber AB CAP makes the operational consequence explicit: the CRM must be available, the provider may need to participate, and the assessment team must be able to see the authorization and implementation evidence.
| Decision area | What Salesforce can bring | What you still must produce or verify |
|---|---|---|
| Authorization boundary | FedRAMP package documentation for the certified cloud service offering | The exact products and features in your tenant, connected-service inventory, and how that scope appears in your SSP |
| Physical and environmental protection | Data-center and AWS GovCloud (US) controls inside the authorized boundary | Referenced inheritance evidence and proof that the services you use are actually inside that boundary |
| Platform maintenance | Patching and service operations for the platform | Change control and regression evidence for your customizations, releases, and integrations |
| Access control | MFA, SSO, CAC/PIV support where applicable, profiles, permission sets, sharing, and other platform capabilities | Users, roles, least privilege, guest access, administrative separation, periodic access reviews, and evidence |
| Audit and accountability | Event and field-history capabilities | Enabled settings, covered event types, alerting, review cadence, exports, retention, and response records |
| Encryption | Platform encryption capabilities and provider cryptographic modules | Data classification, field and file coverage, key decisions, module certificate mapping, and proof the configured path uses validated cryptography where required |
| Personnel | Salesforce-stated U.S.-citizen operating and support restrictions for Government Cloud Plus | Your own personnel security, training, access authorization, and offboarding |
| Incident response | Provider detection, service processes, contractual notices, and support | Your 72-hour DoD report, internal escalation, preservation, provider coordination, exercises, and evidence |
| Documentation | Service description, package artifacts, attestation material, and Customer Responsibility Matrix | SSP, POA&M where permitted, diagrams, inventory, policies, procedures, referenced artifacts, and implementation evidence |
The genuinely useful platform pieces, from Salesforce's current product pages:
- Event Monitoring — access to more than 50 event types, including logins, API calls, report exports, Apex execution, page loads, and user interactions. Transaction Security Policies can block risky actions or notify an administrator.
- Field Audit Trail — field-level change history with configurable retention policies. Salesforce's current page says data can be retained indefinitely and deleted when no longer required.
- Platform Encryption — policy-based encryption for fields, files, attachments, search indexes, and other supported data, with key lifecycle options including bring-your-own-key and rotation.
- Data Detect — discovery and classification tooling that can help locate sensitive patterns in fields, but it does not determine whether a record is CUI under your contract.
Those products sit inside Salesforce Shield or are sold separately. Salesforce's general pricing page publishes Shield at 30% of net spend, Platform Encryption at 20%, Data Detect at 15%, Event Monitoring at 10%, and Field Audit Trail at 10%, subject to product compatibility and quote terms.
No regulation makes Salesforce Shield mandatory. Anyone who tells you Shield is required for CMMC is describing a product, not a regulatory requirement. The requirement is the security outcome and the evidence. In some designs, Shield may be the cleanest way to produce them. In others, the same outcome may come from a different architecture.
One dated caution on FIPS validation
Salesforce materials describe FIPS-validated cryptography, but we did not locate public CMVP certificate numbers that map the exact modules, product versions, and operating environments to a contractor's Government Cloud Plus configuration.
That distinction matters. NIST says the correct term for a cryptographic module is validated, and purchasers should request the certificate number and verify the product/module/version/operating-environment mapping in the CMVP record.
FIPS 140-2 validations remain on the CMVP Active list through September 21, 2026. On September 22, 2026, only FIPS 140-3 validations remain Active and FIPS 140-2 validations move to the Historical list. Historical does not mean revoked, and NIST says existing systems may continue using those modules. It does mean a new procurement should ask for the module numbers and transition plan now, not after the quote is signed. See CMMC FIPS 140-2 requirements.
And one about the whitepaper your consultant is quoting
Salesforce's compliance portal lists a current US Department of Defense CMMC & Salesforce Whitepaper with an update date of March 19, 2026 and requires login to download it.
Public copies of an older 2021 Salesforce CMMC whitepaper still circulate. Do not use a 2021 document as the current authority for CMMC levels, rollout dates, DFARS clause structure, or today's Salesforce product boundary. Use the current portal edition, the live FedRAMP record, the current DFARS text, and the current 32 CFR rule.
The current whitepaper being gated is not evidence of a problem. It is evidence that a public PDF found in search is not automatically the version your assessor should rely on.
Who should you hire for Salesforce CMMC work?
Answer capsule: The work separates into two or three different capabilities, not one vendor. A Salesforce Government Cloud implementation partner handles CRM architecture and migration. A qualified readiness provider handles scope, SSP, diagrams, and remediation. An MSP or MSSP may operate ongoing security. A C3PAO performs a formal Level 2 certification assessment when one is required and permitted. The work must be separated so the assessment remains independent.
| What you need | The provider category that fits | What it is not a substitute for |
|---|---|---|
| Salesforce migration, configuration, custom code, and integration design | Salesforce Government Cloud implementation partner | CMMC scope interpretation or formal assessment |
| Scope decisions, SSP, POA&M, diagrams, and readiness work | RPO/RP or another qualified CMMC readiness advisor | Legal advice or certification |
| Logging, monitoring, identity, endpoints, and ongoing operations | CMMC-capable MSP or MSSP | Salesforce architecture unless separately qualified |
| Evidence workflow, mapping, and continuous compliance operations | GRC platform | The full CMMC program; software alone never satisfies CMMC |
| Documents and technical data that do not belong in a CRM | CUI enclave provider | Data classification or contract interpretation |
| Formal Level 2 certification assessment | C3PAO listed in good standing on the Cyber AB Marketplace | Implementation or remediation |
| Clause interpretation, export controls, False Claims Act questions, or disputed contractual scope | Qualified federal-contracts attorney | Technical implementation |
On independence, plainly: 32 CFR § 170.8 prohibits a CMMC Ecosystem member from participating in a Level 2 certification assessment when it served as a consultant to prepare that organization for any CMMC assessment within the previous three years. The Cyber AB CAP also prohibits a C3PAO from guaranteeing or promising an assessment result or tying incentive compensation to issuance of a Certificate of CMMC Status.
Plan the separation before procurement. Discovering it late can cost you either the readiness provider or the assessor.
For the full sequence, read Who to Hire First for CMMC and our CMMC provider categories. If you already know the category you need, use the request-a-quote form.
Why you won't find a "best Salesforce CMMC provider" list here. We publish provider categories, not rankings — and on a page where the honest answer for some readers is "don't buy anything yet," inserting a vendor list would undercut the only thing that makes this page worth reading. When we name a provider, the page carries the category, status basis, compensation relationship, evaluation depth, and last-verified date, or we don't name it.
Does the CMMC Phase II suspension change the Salesforce decision?
Answer capsule: No, not the underlying data and cloud decision. The Department of War suspended the transition to Phase II on July 13, 2026 and directed requiring activities to use Level 1 (Self) or Level 2 (Self) designations during the suspension. The implementing memo directs amendments to active solicitations and later modifications to existing contracts that carry Level 2 (C3PAO) or Level 3 requirements. But DFARS 252.204-7012 safeguarding and cloud-provider duties remain in force, and CUI still needs a defensible home.
What changed:
- The November 10, 2026 transition to Phase II is suspended.
- During the suspension, program managers and requiring activities may designate only Level 1 (Self) or Level 2 (Self) in procurement request and requirement documents.
- Active solicitations carrying Level 2 (C3PAO) or Level 3 requirements are to be amended as soon as practicable.
- Existing contracts with those requirements are to have them removed by modification before the next option period or during the next scheduled administrative modification.
- The Department announced a 60-day review and suspended pending and future implementation milestones.
What did not change:
- DFARS 252.204-7012 and the two-part cloud-provider requirement in (b)(2)(ii)(D).
- The 72-hour incident report and the malicious-software, preservation, forensic-access, and damage-assessment duties in paragraphs (c) through (g).
- The underlying 32 CFR Part 170 text, including the current Revision 2 and February 2021 SP 800-172 baselines.
- Level 1 and Level 2 self-assessment requirements during the suspension.
- DFARS 252.204-7019 and 252.204-7020 obligations where included and applicable.
- The fact that a CRM holding CUI or Security Protection Data still needs to be classified, documented, secured, and evidenced.
One operational nuance matters: the implementing memo directs the Government to amend or modify the document. It does not tell contractors to pretend the written solicitation or contract changed before the amendment or modification arrives. Read the current document, watch for the promised change, and get any ambiguity resolved in writing through the contracting channel.
The dangerous conclusion is "CMMC is paused, so the CRM is fine." The certification ramp changed. The data did not.
We'll say the honest thing about urgency: we're not going to tell you assessor capacity is running out. We will tell you that data classification, migration, integration redesign, evidence access, and operating procedures cannot be created retroactively when a solicitation lands. Current status belongs on the official CMMC page and our CMMC phases and deadlines page, not in a recycled countdown graphic.
Your next 30 days
Answer capsule: The correct sequence starts with the contract and the data, not with a Salesforce quote. Determine the written requirements, classify what actually enters the CRM, reconcile the SSP and SPRS boundary, map every data flow, choose an inclusion or exclusion architecture, obtain the exact provider evidence, document the customer side, and then engage the provider category that fits the remaining work.
Week 1 — Read the solicitation, contract, and flowdowns. Find all five moving parts:
- DFARS 252.204-7012 tells you whether covered defense information and the cloud-provider duties are in play.
- DFARS 252.204-7019 tells you whether a current NIST SP 800-171 DoD assessment must be in SPRS for award.
- DFARS 252.204-7020 gives the Government assessment access and score-posting framework.
- DFARS 252.204-7025 states the CMMC status inserted in the solicitation and requires current SPRS status, affirmation, and CMMC UIDs.
- DFARS 252.204-7021 carries the status into the contract and requires annual affirmation.
If the document still says Level 2 (C3PAO) or Level 3 during the suspension, ask the contracting officer or prime for the amendment or modification in writing. Do not rewrite the contract in your own head.
Week 1 — Reconcile SPRS with the architecture. Pull the current NIST score, assessment date, CAGE codes, SSP architecture description, expected 110 date, CMMC status, affirmation, and UID. Make sure those records describe the same boundary you are about to describe for Salesforce.
Week 1 — Classify what's in the org. Public, ordinary commercial, FCI, CUI, Security Protection Data, or unknown. The "unknown" pile is the real project.
Week 2 — Map the flows. Use the ten-path table above as your walkthrough script. Include email, files, middleware, endpoints, mobile, analytics, backups, sandboxes, exports, logs, packages, and AI features. Print the installed-package and connected-app inventory.
Week 2 — Send the 17 questions. Nothing improves by waiting for the account team. Start the evidence clock early.
Week 3 — Choose one architecture. Keep Salesforce outside the CUI boundary, run it as FCI-only under Level 1, move the CUI workload into Government Cloud Plus, or put controlled documents in an enclave and leave the CRM alone. Pick one and write the reason down. That paragraph becomes the opening of your SSP treatment.
Week 3 — Price it honestly. Use 15% of actual applicable net spend as the sourced Government Cloud Plus starting point, then add migration, add-ons, integrations, documentation, provider evidence access, and named exclusions. Use the quote-normalization table.
Week 4 — Document the customer side. SSP treatment, boundary diagram, asset inventory, connected-services list, policy, technical enforcement, configuration evidence, data-flow evidence, incident procedure, and referenced provider artifacts by title and version.
Week 4 — Engage the right category. One partner for the platform, one for readiness and documentation where needed, ongoing operations where needed, and a separate assessor only when the acquisition requirement calls for it and the program permits it.
What we actually verified
| Fact | Primary source | Date checked |
|---|---|---|
| Salesforce's CMMC Level 2 announcement and the exact Public Sector Enclave/team scope | Salesforce announcement, January 30, 2026 | August 17, 2026 |
| Coalfire Federal as the C3PAO; mock and official assessment sequence | Coalfire Federal Salesforce case study | August 17, 2026 |
| Salesforce's dated "fewer than 400" and "less than 0.3%" statements | Salesforce announcement; repeated in the Coalfire case study | August 17, 2026 |
| Government Cloud Plus FedRAMP status, Class D (High), package ID, Rev5, JAB path, 66 authorizations, and May 27, 2020 certification date | FedRAMP Marketplace FR2003061248 | August 17, 2026 |
| Standard Salesforce versus Government Cloud Plus versus Government Cloud Plus – Defense data positioning | Salesforce Government Cloud comparison sheet | August 17, 2026 |
| Government Cloud Plus 15%, Government Cloud Plus – Defense 25%, Premium contact pricing, and net-spend definition | Salesforce Government Cloud pricing | August 17, 2026 |
| General Shield 30%, Platform Encryption 20%, Data Detect 15%, Event Monitoring 10%, and Field Audit Trail 10% public pricing | Salesforce Shield pricing | August 17, 2026 |
| Government Cloud Plus – Defense purchase restriction for contractors | Salesforce Government Cloud and pricing FAQs | August 17, 2026 |
| Conflicting IL2/IL4 statements for Government Cloud Plus | Salesforce Government Cloud FAQ, pricing FAQ, and comparison sheet | August 17, 2026 |
NIST attestation letter not downloadable from the public page; account-representative instruction and .gov/.mil access route | Salesforce attestation-letter page | August 17, 2026 |
| Restricted Government Cloud documentation cannot be copied, pasted, or reproduced | Salesforce documentation-access guidance | August 17, 2026 |
| AgentExchange apps outside Salesforce authorization boundaries; AppExchange partner products excluded in the comparison sheet | Salesforce pricing FAQ and current comparison sheet | August 17, 2026 |
| MuleSoft Government Cloud is a separate package, FR1818161169, currently Class C (Moderate) | FedRAMP Marketplace FR1818161169 | August 17, 2026 |
| FedRAMP-equivalent baseline and paragraphs (c)–(g) cloud-provider test | DFARS 252.204-7012 | August 17, 2026 |
| Current NIST assessment in SPRS, Government assessment access, solicitation status, contract maintenance, annual affirmation, and CMMC UID requirements | DFARS 252.204-7019, -7020, -7025, and -7021; SPRS | August 17, 2026 |
| Level 1 = 15 FAR safeguards; Level 2 = 110 NIST SP 800-171 Revision 2 requirements across 14 families; Level 3 adds 24 selected February 2021 SP 800-172 requirements | 32 CFR §§ 170.4 and 170.14 | August 17, 2026 |
| CUI Asset, Security Protection Asset, Contractor Risk Managed Asset, Out-of-Scope Asset, and ESP/CSP treatment | 32 CFR § 170.19 | August 17, 2026 |
| Three-year consultant-to-assessor restriction | 32 CFR § 170.8 | August 17, 2026 |
| C3PAO Marketplace check, CRM/ESP/evidence expectations, and ban on guarantees or contingent outcome incentives | Cyber AB CMMC Assessment Process v2.0 | August 17, 2026 |
| Phase II suspension and the instructions for current solicitations and contracts | DoW CMMC page and implementing memo | August 17, 2026 |
| FIPS 140-2 active through September 21, 2026 and Historical on September 22, 2026 | NIST CMVP FAQ | August 17, 2026 |
| Current Salesforce CMMC whitepaper portal edition dated March 19, 2026 | Salesforce compliance portal | August 17, 2026 |
What we could not verify, and are therefore not claiming:
- Whether Salesforce commits contractually to DFARS 252.204-7012(c)–(g) for a given customer.
- Whether Salesforce's own Level 2 status is Final or Conditional, or the assessment UID.
- The CMVP certificate numbers and exact product/module/operating-environment mapping for a customer's Government Cloud Plus configuration.
- That the general 30% Shield price applies unchanged to every Government Cloud Plus quote or to the same net-spend base.
- The contents of any restricted FedRAMP, DoD, Salesforce SSP, CRM, attestation, or security package we could not access.
- A defensible total Salesforce migration-cost range.
- Whether any specific record in your org is FCI, CUI, or Security Protection Data. That is a contract, marking, use, and data-flow question.
- Whether any named implementation or readiness provider is right for your organization. This page evaluates the decision and provider category, not vendor performance.
Salesforce CMMC compliance FAQ
Answer capsule: These are the questions most likely to change your product, scope, evidence, or hiring decision. Each answer stands alone and points back to the primary-source rule applied above.
Is Salesforce CMMC certified?
Salesforce announced a CMMC Level 2 certificate in January 2026 for its Public Sector Enclave used by the Salesforce National Security and Public Sector Professional Services teams. That is not the same as every Salesforce product, environment, or customer org being certified.
Does Salesforce's certification cover my company?
No. CMMC status is tied to a defined contractor information system and assessment scope. Salesforce's announcement is meaningful when those Salesforce teams process, store, or transmit CUI to or with you. It does not transfer to your tenant.
Is Salesforce FedRAMP authorized?
Government Cloud Plus is listed on the FedRAMP Marketplace as FedRAMP Certified, Class D (High), package FR2003061248, Rev5, JAB path, certified since May 27, 2020, with 66 authorizations as checked August 17, 2026. MuleSoft Government Cloud is a separate package, FR1818161169. Standard commercial Salesforce orgs are not inside the Government Cloud Plus package.
Can I store CUI in a regular commercial Salesforce org?
Not on the evidence presently available for the standard commercial offering. DFARS 252.204-7012(b)(2)(ii)(D) requires an external CSP handling covered defense information to meet the FedRAMP Moderate-equivalent baseline and comply with paragraphs (c) through (g). Salesforce's current comparison sheet points contractor-managed CUI to Government Cloud Plus, not standard Salesforce.
Which Salesforce environment do I need for CMMC Level 2?
For your own contractor-managed CUI, Government Cloud Plus is the Salesforce environment to evaluate. The alternative is keeping CUI out of Salesforce and documenting the boundary treatment under 32 CFR § 170.19. Neither answer eliminates the need to classify integrations, products, features, and Security Protection Data.
Can a defense contractor buy Government Cloud Plus – Defense?
Salesforce says contractors directly supporting a DoD mission owner with IL4 or IL5 data can use it on behalf of or in direct support of that mission owner, but cannot purchase it for internal use.
Does Government Cloud Plus meet DoD IL4?
Salesforce's current public sources disagree. The Government Cloud FAQ and comparison sheet say IL2; the pricing FAQ says Government Cloud Plus helps support IL4 controls. Get a written answer for the quoted environment. For your own contractor-managed CUI, start with the DFARS 252.204-7012 test unless the contract or mission-owner architecture imposes an Impact Level.
What does Salesforce Government Cloud Plus cost?
Salesforce publishes Government Cloud Plus at 15% applied to applicable net spend, billed annually. Government Cloud Plus – Defense is 25%. Shield is listed separately on Salesforce's general pricing page at 30% of net spend. Confirm the applicable product base, compatibility, and stacking in the quote.
Can I upgrade my existing org to Government Cloud Plus?
Salesforce publishes a Government Cloud Plus migrations program and org-migration guidance. Treat this as a staffed migration project, not a toggle. Price data cleansing, code and flow remediation, packages, integrations, sandboxes, backups, exports, endpoint changes, and evidence work.
Do AppExchange or AgentExchange apps inherit Salesforce's FedRAMP authorization?
No. Salesforce says AgentExchange apps are outside its authorization boundaries, and its current comparison sheet excludes AppExchange partner products from Salesforce authorization boundaries. Each connected app that receives CUI or Security Protection Data needs its own classification and evidence.
Is Salesforce Shield required for CMMC?
No regulation names or mandates Salesforce Shield. Its components may be useful for encryption, event monitoring, transaction controls, field history, and data discovery. The requirement is the implemented security outcome and the evidence, not the product name.
Is Salesforce Government Cloud the same as Microsoft GCC High?
No. They are different vendors, products, authorization packages, operating models, and boundaries. Salesforce Government Cloud Plus should not be abbreviated "GCC High."
Do I need Government Cloud if I only handle FCI?
Not because of the FedRAMP cloud-provider requirement in DFARS 252.204-7012, which attaches to covered defense information. Level 1 applies the 15 FAR 52.204-21 safeguards to systems handling FCI. A commercial Salesforce org can be part of that Level 1 scope.
Are Agentforce and Einstein features inside the boundary?
That must be checked per product, feature, and data path against the current authorized-products documentation and your quote. Ask whether prompt, grounding, model, telemetry, search, and support data stay inside the authorized boundary.
Does Slack count as Salesforce for CMMC purposes?
No. Common ownership does not merge authorization boundaries. Commercial Slack and GovSlack are separate offerings, and buying Government Cloud Plus does not automatically cover them.
Will Salesforce report a cyber incident to DIBNet for me?
The contractor's DFARS 252.204-7012(c) obligation is to report a covered cyber incident to DoD within 72 hours of discovery. You need provider notice, preservation, evidence, and forensic cooperation quickly enough to perform that duty. Get the provider's contractual role in writing.
Does Government Cloud Plus replace a C3PAO assessment?
No. A FedRAMP certification addresses a cloud service offering. A CMMC assessment addresses your defined contractor information system and implementation. During the current Phase II suspension, requiring activities are directed to use Level 1 (Self) or Level 2 (Self), but the distinction between platform evidence and contractor assessment remains.
Should I hire a C3PAO first?
Not while the unresolved problem is CRM architecture, scope, migration, or documentation. Start with the work that makes the boundary and evidence coherent. Engage a C3PAO when a formal Level 2 assessment is required and permitted, and keep readiness work separated from the assessor under the three-year independence rule.
The bottom line
Salesforce brought real credentials to this problem: a FedRAMP High-certified Government Cloud Plus offering on AWS GovCloud (US), a current product path positioned for contractor-managed CUI, and its own CMMC Level 2 certificate for the Public Sector Enclave used by two professional-services teams. Those are real credentials.
None of it certifies your org.
Your result comes from your contract, data classification, assessment boundary, environment choice, product and feature scope, configuration, integrations, provider commitments, SPRS records, and evidence. The expensive mistake is buying the uplift before answering the scoping question.
So answer the scoping question first.
If CUI genuinely belongs in your CRM, Government Cloud Plus is the Salesforce product path to evaluate, 15% is the published starting uplift, and the 17 questions are the evidence gate before signature.
If CUI does not have to live there, prove it, enforce it, document it, and spend the money on the boundary that actually holds your technical data.
Need help deciding what type of CMMC provider you need? Tell us your level, scope, environment, and timeline, and we'll match you with source-checked CMMC provider options.
We may receive compensation if you accept an introduction. Category routing is not a ranking or a compliance determination.
Do not submit CUI, drawings, credentials, system diagrams, controlled files, or sensitive contract details.
Compliance notice
This article is educational research, not legal, contractual, or compliance advice. Confirm contract interpretation, scope, and applicability with a qualified CMMC professional or federal-contracts attorney. Your solicitation, contract, flowdowns, data, and system use determine the obligations that apply. Regulatory and product facts on this page are dated because rules, program policy, authorizations, products, and pricing change.
Disclosure
The Defense Compliance Report is an independent trade publication on CMMC and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category logic, Cyber AB status verification, or editorial conclusions.
We have no compensation relationship with Salesforce, and no compensation relationship influenced this analysis. Coalfire Federal is named solely as the C3PAO identified in a published Salesforce case study; we have no compensation relationship with Coalfire Federal.
Read our methodology, editorial standards, editorial and advertising policy, and corrections policy.
Primary sources cited on this page
- Cybersecurity Maturity Model Certification Program Final Rule, 89 FR 83092
- 32 CFR Part 170 — CMMC Program
- DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS 252.204-7019 — Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS 252.204-7020 — NIST SP 800-171 DoD Assessment Requirements
- DFARS 252.204-7021 — Contractor Compliance With CMMC Level Requirements
- DFARS 252.204-7025 — Notice of CMMC Level Requirements
- SPRS
- FAR 52.204-21 — Basic Safeguarding of Covered Contractor Information Systems
- NIST SP 800-171 Revision 2
- NIST SP 800-172, February 2021
- NIST SP 800-172 Revision 3, May 2026
- NIST Cryptographic Module Validation Program
- Cyber AB CMMC Assessment Process v2.0
- Department of War CMMC status page
- Implementing Suspension of CMMC Phase II memo
- FedRAMP Marketplace — Salesforce Government Cloud Plus, FR2003061248
- FedRAMP Marketplace — MuleSoft Government Cloud, FR1818161169
- Salesforce Earns CMMC Level 2 Certification
- Salesforce Government Cloud
- Salesforce Government Cloud pricing
- Salesforce Government Cloud comparison sheet
- Salesforce Government Cloud Plus compliance page
- Salesforce NIST SP 800-171 attestation-letter page
- Salesforce Government Cloud documentation-access guidance
- Salesforce CMMC whitepaper portal record
- Salesforce Shield
- Salesforce Shield pricing
- Coalfire Federal Salesforce case study
- Salesforce Missionforce National Security IL5 announcement
Found an error? Our corrections policy is public, and we date every fix.