By The Defense Compliance Report Editorial Team
Last reviewed: August 2026 · Last verified: August 14, 2026
Editorial research — not formally reviewed by a CMMC Subject Matter Advisor. Verify scope and applicability with a CMMC Registered Practitioner or qualified federal-contracts attorney before acting.
Slack CMMC compliance is not a product badge. Slack is not itself CMMC certified, and buying it will not make your assessment scope compliant. CMMC status attaches to the contractor information systems inside a defined assessment scope — not to a chat app, not to a logo, and not automatically to an entire company.
The real question — the one that decides whether you have a problem — is whether Slack is an allowed place for the data your people are already putting in it. That answer splits hard at FCI versus CUI, and then it splits again at your plan tier.
Here is the part almost nobody tells you: Slack itself has published, in writing, that its FedRAMP Moderate support is limited to two commercial plans. We pulled the document. It is public, it names the plans, and it changes the answer.
The bottom line, before you scroll
Slack CMMC compliance depends on which Slack service you bought, what data reaches it, and how the service is configured and contracted. A commercial Slack service can be a CUI cloud path only when the exact offering is either confirmed inside a FedRAMP Moderate-or-higher authorization or supported by a complete DoD FedRAMP Moderate-equivalency body of evidence, then configured and contracted to satisfy DFARS 252.204-7012. Slack publicly limits its commercial FedRAMP Moderate support to Enterprise and Enterprise+. GovSlack has a separate FedRAMP High package, and Slack’s dedicated GovSlack pages state that it is DoD Impact Level 4 authorized. We found no primary-source basis for treating Free, Pro, or Business+ as a CUI cloud path.
Phase 1 began on November 10, 2025 and was scheduled to run through November 9, 2026. On July 13, 2026, the Department of War suspended the Phase 2 transition and later implementation milestones while leaving Phase 1 self-assessment requirements and DFARS 252.204-7012 in force. During the suspension, new procurement designations are limited to Level 1 (Self) and Level 2 (Self).
That is the verdict. Now the conditions that change it.
| Your situation | The first answer |
|---|---|
| Free, Pro, or Business+ and CUI can reach it | Do not use it as your CUI environment based on the public record. Slack’s own configuration guide excludes these plans from FedRAMP Moderate support, and we found no primary-source authorization or equivalency basis for them. |
| Enterprise or Enterprise+, service boundary confirmed in writing | Potentially viable for CUI — after you verify the exact service, contract terms, configuration, integrations, support path, endpoints, and evidence. |
| GovSlack | The strongest Slack-native CUI candidate. It has a separate FedRAMP High Marketplace package, and Slack’s dedicated pages state DoD IL4 authorization. It still does not finish your CMMC program. |
| Ordinary Slack with a written “no CUI” rule | Usually a Contractor Risk Managed Asset when it is not actually holding CUI but can receive it — not automatically out of scope. This is the mistake that costs people at assessment. |
| Ordinary Slack technically unable to receive CUI, and separated | May qualify as an Out-of-Scope Asset — but the bar is technical inability plus separation, not a policy memo. |
| You handle FCI only, no CUI | Different question entirely. CMMC Level 1 itself imposes no FedRAMP authorization requirement. Do not let anyone sell you GovSlack to solve an FCI-only CMMC problem. |
What we actually verified — and when
We do not ask you to take our word for it. Everything below was opened and checked on August 14, 2026.
| What we checked | Primary or current source | What we found |
|---|---|---|
| Slack’s FedRAMP record | FedRAMP Marketplace, Package FR1823447014 | FedRAMP Certified, Rev5, Agency path, Class C (Moderate), certified since May 20, 2020, with 13 total authorizations shown in the current record. |
| GovSlack’s FedRAMP record | FedRAMP Marketplace, Package FR2230252267 | FedRAMP Certified, Rev5, JAB path, Class D (High), certified since January 25, 2024, with 1 total authorization shown in the current record. |
| Slack’s plan restriction | Slack’s Secure Configuration Guide for FedRAMP Moderate, v0.02, finalized February 24, 2026 | FedRAMP Moderate support is limited to Enterprise or Enterprise+. Lower plans are excluded. |
| Salesforce’s own CMMC documentation | Salesforce Compliance — GovSlack and the CMMC whitepaper updated March 19, 2026 | The listed covered services include Slack (GovSlack). Commercial Slack is not named in that CMMC whitepaper’s covered-service list. |
| Four Slack-owned pages on FedRAMP and IL4 | Slack compliance, Slack features, GovSlack, and GovSlack developer documentation | The pages do not use consistent qualifiers, and the general compliance page conflicts with the dedicated GovSlack pages on IL4 status. Details below. |
| The Level 2 asset and ESP/CSP scoping rule | 32 CFR § 170.19 | Table 3 governs CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, and Out-of-Scope Assets. Table 4 governs ESP and CSP treatment. |
| The cloud and incident clause | DFARS 252.204-7012 | An external CSP handling covered defense information must meet FedRAMP Moderate-equivalent security and comply with paragraphs (c) through (g). |
| SPRS and CMMC contract mechanics | DFARS 252.204-7019, 252.204-7020, and 252.204-7021 | 7019 and 7020 address current NIST SP 800-171 DoD Assessment scores in SPRS and government assessment access. 7021 addresses current CMMC status, annual affirmation, CMMC UIDs, and contract performance on systems holding the required status. |
| Phase 1 and the July 2026 suspension | DoD CIO CMMC resources and Implementing Procedures 26-P-1023 | Phase 1 began November 10, 2025. The Phase 2 transition originally scheduled for November 10, 2026 is suspended; Level 1 and Level 2 self-assessment designations remain, and DFARS 7012 remains in effect. |
| The controlling NIST versions | 32 CFR Part 170 and NIST SP 800-171 Rev. 2 | CMMC Level 2 still uses 110 requirements across 14 families from Revision 2. Level 3 still adds 24 selected requirements from the February 2021 version of SP 800-172. Later NIST revisions do not silently amend the CMMC rule. |
| Slackbot web search | Slack Help — Manage Slackbot access and settings | Web search is off by default, and Slack warns that it may send data outside the FedRAMP authorization boundary. |
| Slack support-data declaration | Slack Help — Changes to FedRAMP for Slack support data | A Primary Owner must make the declaration by August 19, 2026 when support data must stay inside the FedRAMP boundary. The declaration is separate for each workspace or Enterprise organization. |
What we could not verify from public records: whether any specific customer’s commercial Slack tenant, order form, and enabled feature set sit inside the boundary of FedRAMP package FR1823447014. The Marketplace listing does not answer tenant-level eligibility. We tell you exactly how to get that answer in writing further down — and we are not going to pretend the public record resolves it.
Before you go further
The right CMMC provider is not the same for every contractor. The category you need — a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave — depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The contract clause sets your required path, not a checklist.
Start with the CMMC Levels guide if you are not certain whether the work is Level 1, Level 2, or Level 3. Use Find My CMMC Path before you request quotes if you know the data type but not the provider category. Do not submit CUI, drawings, network diagrams, credentials, vulnerabilities, or sensitive contract details through the form.
Definitions, once, so we can move fast after this. FCI (Federal Contract Information) is non-public information provided by or generated for the Government under a contract, excluding public and simple transactional information. CUI (Controlled Unclassified Information) is information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to safeguard or control. CMMC status is the result assigned to a defined assessment scope after the applicable assessment; it is not a certification badge for software. A C3PAO (CMMC Third-Party Assessment Organization) performs Level 2 certification assessments. DIBCAC performs government-led assessments. SPRS is the Supplier Performance Risk System. An ESP is an external service provider; a CSP is the cloud-service subset of ESPs.
CMMC Level 2 currently maps to NIST SP 800-171 Revision 2: 110 security requirements across 14 families. CMMC Level 3 adds 24 selected requirements from NIST SP 800-172, February 2021. NIST has since published SP 800-171 Revision 3 and SP 800-172 Revision 3, but those publications do not replace the versions incorporated into 32 CFR Part 170 unless DoD amends the rule.
Is Slack CMMC compliant?
No Slack product makes a contractor’s assessment scope compliant by itself. CMMC evaluates the contractor’s implementation inside a defined scope — users, endpoints, identity, configuration, procedures, logs, external services, incident response, and evidence. A cloud platform can sit underneath that program with the right authorization and contract terms, but it cannot run the program for you.
There is a reason this question produces so much bad content. “Slack” is not one thing. When someone asks whether Slack is CMMC compliant, they are usually asking one of four completely different questions, and the answers diverge sharply.
- We handle FCI only. Then CMMC Level 1 itself does not impose a FedRAMP authorization requirement, and anyone quoting you a government-cloud migration needs to show you the separate requirement they are solving.
- We handle CUI and we are on Enterprise or Enterprise+. Then you have a live, answerable question about the exact service boundary, configuration, contract terms, integrations, and evidence — and a real shot at keeping what you have.
- We handle CUI and we are on Free, Pro, or Business+. Then Slack has already told you the answer in its configuration guide, and it is not the one you wanted.
- We want to keep normal Slack for normal work and put CUI somewhere else. That is often the smartest play — and it has a specific name in the regulation that most people get wrong.
The rest of this page answers all four. In that order.
The distinction the marketing pages blur
Vendor pages talk about what the product has. Assessors ask what you implemented and can prove. Those are different columns on the same page, and confusing them is how companies fail assessments while holding a stack of vendor certificates.
| What the vendor provides | What you still have to do |
|---|---|
| FedRAMP certification for a named service offering | Confirm your purchased service, tenant, and features are inside that boundary |
| DoD Impact Level authorization | Determine whether your contract and data actually require it |
| Encryption at rest and in transit | Configure access, endpoints, keys, sharing, and evidence |
| Audit log APIs | Ingest, retain, review, protect, and produce those logs |
| DLP integration capability | Implement it and prove it detects or blocks the prohibited path |
| Enterprise Key Management | Operate key management and document who owns each responsibility |
Every row on the right is yours. None of it transfers.
Which Slack plans can hold FCI or CUI?
Slack publicly limits commercial FedRAMP Moderate support to Enterprise and Enterprise+ when properly configured under its Secure Configuration Guide. GovSlack is a separate environment with a FedRAMP High Marketplace package, and Slack’s dedicated GovSlack pages state DoD Impact Level 4 authorization. Free, Pro, and Business+ are outside Slack’s stated commercial FedRAMP Moderate support, though an FCI-only workspace raises a different and much lighter question.
We want to be precise here, because this is the single highest-consequence fact on the page.
Slack publishes a document called the Secure Configuration Guide for FedRAMP Moderate. Version 0.02 was finalized on February 24, 2026. Under “Required FedRAMP Moderate Settings,” it opens with this:
“FedRAMP Moderate is only supported on the Slack Enterprise or Enterprise+ plan.”
That is not our interpretation. That is the vendor, in writing.
So if your company is running CUI through a Free, Pro, or Business+ workspace, there is no policy memo or admin toggle that changes Slack’s published plan boundary. The plan itself is the first gate, and we found no public authorization or DoD-equivalency record that opens a second gate for those tiers.
The full environment and scope matrix
This is the table we wish had existed when we started researching this. It combines Slack’s plan limitation, both FedRAMP package records, the CMMC scoping rule, and the DFARS cloud clause into one decision.
| Your Slack scenario | Verified position on August 14, 2026 | FCI/CUI decision | Likely CMMC treatment | Evidence you will need | Our editorial verdict |
|---|---|---|---|---|---|
| Free, Pro, or Business+, ordinary business use | Slack’s public guide excludes these plans from FedRAMP Moderate support; no public authorization or DoD-equivalency basis was verified | No CUI. If it handles FCI, it is in the Level 1 assessment scope | Level 1 asset for FCI. At Level 2, likely a Contractor Risk Managed Asset if it can receive CUI but is not intended to | Approved-use policy, training, admin settings, scope record, monitoring or transfer-control evidence | Non-CUI use only unless Slack supplies written authorization-boundary or full DoD-equivalency evidence for your exact purchase |
| Enterprise or Enterprise+, authorization or equivalency confirmed in writing | Potentially inside package FR1823447014 when the exact service is confirmed and configured to the guide; otherwise the full DoD-equivalency burden applies | May support CUI if service, authorization/equivalency basis, terms, configuration, integrations, support path, and endpoints line up | CSP processing CUI; document the relationship, CRM, service boundary, and connecting infrastructure in the Level 2 scope | Order form, written package confirmation or equivalency body of evidence, current guide, CRM, SSP, data-flow and network diagrams, incident terms, app inventory, configuration evidence | A potentially viable Level 2 path. Do not call it compliant until the exact deployment is verified |
| GovSlack | Separate slack-gov.com environment; FedRAMP High package; Slack’s dedicated pages state DoD IL4 | Strongest Slack-native candidate for DoD CUI and IL4 workloads | CSP processing CUI; document the service, CRM, customer duties, support path, integrations, endpoints, and connecting infrastructure | GovSlack order record, current package documentation, CRM, SSP, app and Slack Connect inventory, endpoint controls, export-control procedures where applicable | Best Slack-native fit when the contract, data, or partner ecosystem justifies High or IL4. Still not automatic CMMC compliance |
| Ordinary Slack with a documented “no CUI” rule | FedRAMP is not the central question if no CUI is intended to enter, but users may still paste, upload, or forward it | CUI is prohibited, yet technically possible | Usually a Contractor Risk Managed Asset — it can, but is not intended to, process CUI | Asset inventory, SSP treatment, network diagram, policy, training, DLP or monitoring, access controls, exceptions, periodic tests | A defensible way to keep ordinary Slack. Do not casually label it out of scope |
| Ordinary Slack technically unable to receive CUI and separated | 32 CFR § 170.19 allows out-of-scope treatment only when the asset cannot handle CUI, provides no security protection for CUI assets, and is separated | No CUI and no Security Protection Data can enter | Potential Out-of-Scope Asset | Technical enforcement, identity and data-flow separation, blocked integrations, transfer tests, written justification of inability | Cleanest way to keep Slack outside the Level 2 boundary — but the burden is heavier than writing a policy |
| FCI-only Slack workspace | Level 1 maps to FAR 52.204-21, not the FedRAMP cloud rule in 7012 | FCI may be present; CUI may not | In the Level 1 assessment scope if it processes, stores, or transmits FCI | Evidence that the applicable 15 safeguards are met for the scoped environment | Use commercial Slack if it supports the Level 1 safeguards and no separate contract requirement says otherwise |
If you handle FCI only, stop worrying about the wrong problem
We see FCI-only shops get sold government-cloud migrations they do not need, and it makes us grouchy.
Under 32 CFR § 170.19(b), information systems that process, store, or transmit FCI are in scope for CMMC Level 1 and must be self-assessed against the applicable requirements. CMMC Level 1 itself contains no FedRAMP authorization requirement. DFARS 252.204-7012’s cloud language attaches to covered defense information, while FAR 52.204-21 supplies the 15 basic safeguarding requirements behind Level 1.
So commercial Slack is not prohibited for FCI by CMMC Level 1. If it processes, stores, or transmits FCI, it belongs in the Level 1 assessment scope and has to support the 15 safeguards. That is a very different afternoon than a GovSlack migration.
Use the CMMC Level 1 self-assessment checklist if this is your row.
Your contract clause decides which world you are in. Not a blog post, and not a salesperson.
The one thing we cannot answer for you
Here is our damaging admission, and we would rather say it out loud than let you discover it in an assessment.
We cannot tell you from public records whether your commercial Slack Enterprise or Enterprise+ tenant sits inside the boundary of FedRAMP package FR1823447014. The Marketplace listing does not describe tenant-level eligibility. Slack’s trust page says Enterprise or Enterprise+ can be used when properly configured. Salesforce’s CMMC whitepaper lists GovSlack, not commercial Slack, among its covered services. Those signals do not resolve your exact order form, org, features, or support path, and we are not going to close that gap with a guess dressed up as analysis.
Now the good news, and it is better than it sounds.
That question has an owner, and the owner is Slack or Salesforce. It is a normal thing to ask a vendor. Once you have the answer in writing, the decision collapses from “we do not know” into a two-branch choice you can actually make. Most companies never ask, which is precisely why they end up guessing in front of an assessor.
So ask. Here is exactly what to send.
The six questions to put to Slack or Salesforce in writing
Copy this. Send it to your account executive or customer success manager. Ask for the answers in email or contract documentation, not only on a call.
- Is the specific Slack service we purchased — plan name, order form, Enterprise organization, and enabled service — within the boundary of FedRAMP package FR1823447014? Please answer yes or no in writing. If no, does Slack claim DoD FedRAMP Moderate equivalency for this exact offering, and will it provide the complete body of evidence required by current DoD policy?
- Please provide the current Customer Responsibility Matrix for the service we purchased.
- Please provide the current Secure Configuration Guide applicable to our service.
- Do our service terms support DFARS 252.204-7012 paragraphs (c) through (g) — cyber-incident reporting, malicious-software handling, media preservation and protection, access for forensic analysis, and cyber-incident damage assessment? If not, what contractual vehicle supplies those duties?
- Which features are inside the authorization boundary and which are outside it — specifically Slack AI features, Slackbot web search, Slack Connect, Workflow Builder, support systems, exports, eDiscovery, and third-party marketplace apps?
- If IL4 applies to our program, confirm GovSlack’s current DoD Impact Level 4 status and provide the authorization documentation.
That is the whole letter. No consultant required to ask the question.
Map your Slack decision before you request quotes
Use Find My CMMC Path to map your level, FCI/CUI flow, assessment type, environment, and timeline to the provider category that fits.
Do not submit CUI, drawings, source code, network diagrams, credentials, vulnerabilities, or contract attachments. Non-sensitive routing information only.
What Slack’s own configuration guide actually requires
Slack’s Secure Configuration Guide contains one plan gate plus seven configuration topics in its “required” section — but Slack itself labels some substeps optional or recommended. Outdated-client handling appears in the separate optional section. The useful conclusion is not “eight mandatory settings.” It is that the customer owns the configuration and evidence, and the guide’s labels must be read item by item.
We read the entire five-page guide. The table below preserves its substance while separating what Slack calls critical, what Slack explicitly makes optional, and what we are mapping editorially to NIST SP 800-171 Revision 2.
The NIST-family column is our orientation, not a Slack or NIST control crosswalk. Your assessor evaluates the actual Rev. 2 requirement and assessment objectives, not this table.
| Guide item | Slack’s own status | Rev. 2 family orientation | Evidence to have ready |
|---|---|---|---|
| Enterprise or Enterprise+ plan | Plan gate in the required-settings section | Service-boundary prerequisite, not a NIST control by itself | Order form, exact service name, written package-boundary confirmation |
| SSO with MFA for privileged and non-privileged accounts; 2FA for guests | Critical/required topic | Identification & Authentication; Access Control | Identity-provider export, MFA policy, guest-account list, authentication test |
| Custom Terms of Service as a system-use banner; no sensitive data pre-authentication | Required topic | Access Control, including system-use notification | Screenshot of the banner as users see it |
| Enterprise Mobility Management and concurrent-session control | Required topic; blocking mobile downloads and copies is explicitly optional | Access Control; Media Protection; System & Communications Protection | EMM policy, managed-device inventory, session settings, mobile transfer test |
| Audit Log API ingested into the customer’s SIEM | Required topic; Slack says the customer is responsible for auditing actions in its instance | Audit & Accountability | SIEM ingest configuration, sample log pull, review records, alert test |
| Only FedRAMP-authorized apps approved | Required topic; Slack says directory apps are outside its boundary | Access Control; Security Assessment; System & Communications Protection | App approval register, each app’s service/authorization evidence, data-flow map |
| Locked display names and identifiers for contractors or foreign nationals | “If desired” inside the required-settings section | Access Control and personnel/export-control administration | Naming policy and sample profiles if used |
| TLS 1.2 or 1.3 browser configuration with downgrade protection | Slack recommendation inside the required-settings section | System & Communications Protection | Browser/endpoint policy and connection evidence |
| Outdated-client dashboard and upgrade follow-up | Optional-settings section | System & Information Integrity | Client-version dashboard, remediation record |
Read the ownership column that is hiding inside every row. Slack supplies capabilities. You configure them, operate them, test them, document them, and explain them.
That is what “properly configured” means, and it is why “Slack is FedRAMP Moderate” is a sentence that does almost no work for you on its own.
The optional control that is not optional in our design judgment
Here is the detail that stopped us cold.
Enterprise Key Management (EKM) appears under “Recommended Settings for Security (Optional).” Slack says EKM reduces the risk of data spills involving wrongly uploaded files or discussions of Covered Defense Information.
Slack used the exact DFARS term. In the optional section.
EKM adds object-level encryption using customer-controlled AWS KMS keys. Slack says administrators can revoke access at the organization, workspace, channel, one-hour message window, or individual-file level. When someone drops a drawing into #production at 2:47 on a Tuesday, that granularity can sharply narrow who can continue to reach it.
It does not erase the spill, decide whether a cyber incident occurred, satisfy evidence-preservation duties, or replace the response process. It gives your response team a containment lever.
Our editorial judgment, derived from the verified facts above: if you are seriously evaluating commercial Slack as a CUI environment, treat EKM as a design requirement unless your documented architecture provides an equivalent containment mechanism. Slack’s own description of its purpose tells you why.
Slack vs GovSlack for CMMC Level 2: what actually differs
Commercial Slack has a FedRAMP Moderate Marketplace package, while Slack says commercial FedRAMP Moderate support is limited to Enterprise and Enterprise+ when properly configured. GovSlack is a separate slack-gov.com environment with a FedRAMP High package, and Slack’s dedicated pages state DoD Impact Level 4 authorization. Salesforce says commercial Slack and GovSlack data are isolated.
| Decision factor | Commercial Slack path | GovSlack |
|---|---|---|
| Plan/service | Enterprise or Enterprise+, with exact service boundary confirmed | GovSlack, built on Enterprise+ capabilities |
| FedRAMP profile | Package FR1823447014, Class C (Moderate), Agency path | Package FR2230252267, Class D (High), JAB path |
| Certified since | May 20, 2020 | January 25, 2024 |
| Domain | slack.com | slack-gov.com — separate environment |
| DoD Impact Level | Not established by the commercial Moderate record | Slack’s dedicated pages state IL4; request documentation if IL4 is contractual |
| Infrastructure | Do not infer tenant infrastructure from the Slack brand | Slack states AWS GovCloud East and U.S. personnel |
| Encryption | EKM can use a FIPS 140-2-validated customer AWS KMS key | Slack states FIPS 140-2-validated encryption at rest and in transit |
| Slack Connect | Inventory every connection, external organization, and data flow | Slack says it is available only between organizations that also use GovSlack |
| App marketplace | Commercial directory; every app is a separate boundary decision | Separate GovSlack Marketplace and deployment process |
| ITAR | Do not infer ITAR suitability from FedRAMP Moderate | Slack says GovSlack controls can help customers maintain ITAR compliance; the customer remains responsible and must not send ITAR data in support requests |
| Published price | Not published for this CUI decision | Not published — contact sales |
| CMMC outcome | Your scoped implementation still gets assessed | Your scoped implementation still gets assessed |
When GovSlack is the right call
- Your contract or data genuinely requires DoD Impact Level 4.
- You handle export-controlled technical data and U.S.-person operations are part of the actual requirement.
- Your primes or government customers already collaborate in GovSlack — remember, GovSlack Slack Connect only reaches other GovSlack organizations.
- Your teams are so Slack-dependent that a different collaboration model would break how work gets done.
When GovSlack is being oversold to you
- You handle FCI only.
- CUI never enters Slack and you can defend that technically.
- Your CUI already lives in a separate enclave and commercial Slack sits outside that data flow.
- You are buying it for the logo rather than for a requirement you can point to.
- You cannot operate the remaining 800-171 controls anyway, in which case the platform is not your bottleneck.
The friction nobody mentions in the sales cycle
GovSlack runs on a separate domain with a separate app marketplace. Apps built for commercial Slack must meet GovSlack’s deployment requirements and be separately submitted before they work there. Slack’s developer documentation is explicit that commercial Slack and GovSlack data are isolated. Practically, that means integrations you rely on today may not exist there, and GovSlack Slack Connect does not bridge to a partner’s commercial Slack.
That is not a reason to avoid GovSlack. It is a reason to inventory your integrations and external collaborators before you sign, not after.
What Slack’s own pages say — and where they disagree
As of August 14, 2026, four Slack-owned pages describe Slack’s FedRAMP and Impact Level status with materially different precision, including a direct conflict over whether GovSlack’s DoD Impact Level 4 authorization is complete or still in progress. Contractors relying on a single vendor page can reach the wrong conclusion in either direction.
We did not go looking for this. We were cross-checking one claim and found four.
| Slack-owned page | What it says | Checked |
|---|---|---|
| slack.com/trust/compliance | Slack is FedRAMP Moderate authorized with an Enterprise or Enterprise+ plan when properly configured. The same page says GovSlack is “pursing” [sic] DoD CC SRG IL4 compliance. | August 14, 2026 |
| slack.com/features | “It is FedRAMP Moderate authorized.” No plan qualifier. No configuration condition. | August 14, 2026 |
| slack.com/solutions/govslack | GovSlack is FedRAMP High authorized and DoD SRG IL4 authorized. | August 14, 2026 |
| docs.slack.dev/govslack | GovSlack is “currently holding” DoD/DISA IL4 certification. | August 14, 2026 |
Two problems, both practical.
First, the IL4 conflict. The general compliance page says GovSlack is pursuing IL4. The dedicated GovSlack page and developer documentation say it has IL4. The specific GovSlack sources support the authorized position — but if IL4 is a contract requirement, do not rely on any marketing page. Ask your account team for the current authorization documentation. That is question six in the letter above.
Second, and more dangerous for a small contractor: the unqualified Moderate claim. A busy IT director who lands on the features page can read “It is FedRAMP Moderate authorized,” conclude a Business+ workspace is covered, and move on. The configuration guide says otherwise in the first line of its required-settings section. Same company, two very different impressions.
We are not accusing Slack of anything. Big vendors maintain a lot of pages and pages drift. But you are the one who eats the consequence, so verify at the package, service, order-form, and configuration-document level — not the marketing-headline level. That principle is the entire reason this publication exists.
Can we keep ordinary Slack if we ban CUI?
Possibly — but a written “no CUI in Slack” policy does not by itself put the workspace out of scope. If the workspace is not actually holding CUI but users can technically paste, upload, or forward CUI into it, the correct analysis under 32 CFR § 170.19 is usually Contractor Risk Managed Asset treatment, supported by documented policies, procedures, practices, monitoring, training, and enforcement.
This is the section we would most want a contractor to read, because it is where the money is and where the internet is most wrong.
Most “Slack and CMMC” content offers two boxes: compliant or rip it out. The regulation offers five Level 2 asset categories, and the middle one is where many real companies actually live.
Contractor Risk Managed Asset, in plain English
Table 3 to 32 CFR § 170.19(c)(1) defines a Contractor Risk Managed Asset as an asset that can, but is not intended to, process, store, or transmit CUI because of security policy, procedures, and practices in place. The rule adds that these assets do not have to be physically or logically separated from CUI assets.
Your obligations for one:
- Document it in the asset inventory.
- Document how you treat it in the System Security Plan.
- Show it on the network diagram of the assessment scope.
- Prepare to support the asset treatment during the assessment.
The assessment treatment is the part that saves the budget. The assessor reviews the SSP. If the treatment is sufficiently documented, the assessor does not assess the CRMA against the other CMMC security requirements, except as the rule notes. If the documentation or other findings raise questions, the assessor may conduct a limited check against relevant requirements — and the rule says those checks must not materially increase assessment duration or cost.
Good documentation on a CRMA is the difference between an SSP review and a preventable scope fight.
Out-of-Scope is a much higher bar
The same table defines Out-of-Scope Assets as assets that cannot process, store, or transmit CUI; do not provide security protections for CUI Assets; and are physically or logically separated from CUI Assets. The rule then closes the loophole directly: assets that fall into any in-scope category cannot be treated as out of scope.
So the test is inability, not intention. A policy expresses intention. A technical control creates inability. If your people can drag a CUI PDF into a channel right now, your Slack is not out of scope merely because the handbook says they should not.
And if Slack receives Security Protection Data — logs, configuration, or other data used to protect the CUI environment — the ESP/CSP table can pull the service into scope as a Security Protection Asset even when Slack does not receive CUI.
The evidence ladder
We built this to answer the question we kept hearing: “How much is enough?” This is our editorial evidence ladder, not a regulatory scoring scale. Each rung is stronger than the one below it. Where you stop determines how convincing a limited check will be.
- Written policy only (weakest — one interview can dismantle it)
- Policy plus annual training
- Policy plus an approved-use matrix naming what may and may not go in Slack
- Restricted integrations and restricted external sharing
- Data loss prevention or active monitoring on the workspace
- Managed identity and managed endpoint controls
- Periodic tests showing attempted CUI transfers are blocked or detected (this turns a claim into evidence)
- Formal exception and incident process, exercised and documented
Rungs 1 and 2 are where many companies sit and where many companies get hurt. Rung 7 is what “show me” looks like.
Our editorial judgment: for many small and mid-sized DIB suppliers, the CRMA path — CUI isolated in a proper enclave, ordinary Slack retained for everything else, documented honestly — is cheaper, faster, and more defensible than either a full GovSlack migration or a fragile out-of-scope argument. It preserves the tool the company actually runs on. It just requires you to do the paperwork and testing properly instead of hoping.
Build the documentation before an assessor is on the clock
Start with the CMMC Readiness Checklist to expose scope, SSP, SPRS, provider, and evidence gaps. Then use the CMMC Provider Categories guide if the Slack decision needs scoping, technical enforcement, an enclave, or managed operations.
How CMMC and DFARS actually apply when Slack processes CUI
The regulatory chain is short and direct. 32 CFR § 170.19 says a CSP that processes, stores, or transmits CUI must meet the FedRAMP requirements in DFARS 252.204-7012. That clause requires FedRAMP Moderate-equivalent security and paragraphs (c) through (g). The other DFARS clauses then govern SPRS assessment records, government access, current CMMC status, annual affirmations, and CMMC UIDs.
Step 1 — The contract decides, not a checklist
Identify whether the contract performance puts FCI or CUI on contractor systems, which clauses appear in the contract or flow-down, the required CMMC level, and whether the specified assessment path is self-assessment or C3PAO certification assessment. Nothing downstream is answerable until this is settled. Use our 32 CFR Part 170 guide if you need the full rule mapped before you classify Slack.
During the current suspension, new procurement designations are limited to Level 1 (Self) and Level 2 (Self). That current implementation posture does not rewrite the permanent assessment paths in 32 CFR Part 170, and it does not remove DFARS 252.204-7012 from contracts where the clause applies.
Step 2 — Find where the data actually goes
If Slack processes, stores, or transmits CUI, map users, Enterprise organizations, workspaces, channels, DMs, files, canvases, lists, message content, connected apps, endpoints, exports, support interactions, external organizations, and administrative paths.
Not where policy says CUI goes. Where it goes.
Step 3 — Apply the ESP and CSP rule
Table 4 to 32 CFR § 170.19(c)(2) resolves the external-provider treatment:
| What the provider handles | If it is a CSP | If it is not a CSP |
|---|---|---|
| CUI, with or without Security Protection Data | The CSP must meet the FedRAMP requirements in DFARS 252.204-7012 | The services are in your assessment scope and assessed as part of your assessment |
| Security Protection Data only | The services are in scope and assessed as Security Protection Assets | The services are in scope and assessed as Security Protection Assets |
| Neither CUI nor Security Protection Data | The provider does not meet the CMMC definition of an ESP for that service | The provider does not meet the CMMC definition of an ESP for that service |
The rule requires the ESP relationship, services, and responsibility split to be documented in your SSP, the provider’s service description, and a Customer Responsibility Matrix. An ESP may voluntarily undergo a CMMC assessment to reduce work during the customer’s assessment, but the rule does not generally require every ESP to obtain a separate CMMC status.
One more piece people miss: when you use a CSP for CUI at Level 2, 32 CFR § 170.16 and § 170.17 say the on-premises infrastructure connecting to the CSP offering is part of the assessment scope, and the CRM responsibilities must be documented or referenced in the SSP. Slack does not just bring a vendor record into the evidence package. It brings the systems connecting to and governing that service into the scope according to their role.
Step 4 — Understand what FedRAMP Moderate does and does not prove
DFARS 252.204-7012(b)(2)(ii)(D) requires a contractor using an external CSP for covered defense information to require and ensure security equivalent to the FedRAMP Moderate baseline and compliance with paragraphs (c) through (g): cyber-incident reporting, malicious-software handling, media preservation and protection, forensic access, and damage-assessment support.
That second half is a contract-and-operations question, not a Marketplace-logo question. A Marketplace listing does not deliver your incident workflow, support path, evidence preservation, or customer-side duties.
The Department’s December 2023 FedRAMP Moderate Equivalency memorandum applies to cloud offerings that are not FedRAMP Moderate authorized but claim equivalency. The memo says a FedRAMP-authorized Marketplace offering can be leveraged without a separate equivalency assessment. For a non-authorized provider, the contractor must validate the body of evidence and the provider’s compliance with the memo.
That distinction matters here. Slack has a FedRAMP-certified Marketplace offering. If Slack confirms that your exact purchased service is inside that package, a separate equivalency assessment is not the issue. If the service is outside the package, the burden shifts to the full DoD-equivalency body of evidence and the same 7012 contract duties. We found no public basis for that route on Free, Pro, or Business+.
What DFARS 7012, 7019, 7020, and 7021 each do
These four clauses get collapsed into “SPRS compliance” in bad sales decks. They do different jobs.
| Clause | What it does | What it means for your Slack decision |
|---|---|---|
| 252.204-7012 | Safeguarding, external-CSP FedRAMP Moderate-equivalent security, 72-hour cyber-incident reporting, malicious-software handling, media preservation, forensic access, and damage-assessment support | This is the cloud and incident clause you must solve when Slack holds covered defense information |
| 252.204-7019 | Requires a current NIST SP 800-171 DoD Assessment for each relevant covered contractor information system before award and requires the offeror to verify summary scores in SPRS | Your Slack-containing system boundary may be part of the SSP and score represented in SPRS |
| 252.204-7020 | Gives DoD access for Medium or High Assessments, governs score posting, and requires applicable subcontractors to have a current assessment | Your evidence must survive more than a self-entered number |
| 252.204-7021 | Requires the contract-specified current CMMC status for systems processing FCI or CUI, annual affirmations, flow-down, and submission of CMMC UIDs to the contracting officer | CMMC status belongs to the assessed information-system scope; it does not attach to Slack as a product |
Do not blur a 7019/7020 Basic NIST SP 800-171 DoD Assessment score with a CMMC status under 7021 and 32 CFR Part 170. Both can appear in SPRS, but they are not the same record, process, or contractual status.
For a Level 2 (Self) CMMC status, 32 CFR § 170.16 requires the self-assessment results in SPRS at least every three years. The minimum SPRS inputs are the CMMC level, CMMC Status Date, CMMC Assessment Scope, every industry CAGE code associated with the scoped systems, the overall score, and POA&M usage/compliance status when applicable. The affirmation is due at the assessment and annually afterward. Evidence artifacts used for the self-assessment must be retained for six years from the CMMC Status Date. If a conditional status uses a permitted POA&M, the closeout results must reach SPRS within 180 days or that conditional status expires.
For a Level 2 (C3PAO) certification assessment, the C3PAO posts the results into the CMMC instantiation of eMASS, which transmits them to SPRS. The contractor still owns the annual affirmation and the six-year retention of the hashed evidence artifacts.
Use the SPRS score guide for the separate 7019/7020 Basic Assessment record and the practical posting workflow.
Revision 2 still controls CMMC Level 2
NIST published SP 800-171 Revision 3 in May 2024 and SP 800-172 Revision 3 in May 2026. Those are current NIST publications. They are not the CMMC-controlling versions today.
Under 32 CFR Part 170, Level 2 still uses NIST SP 800-171 Revision 2 — 110 requirements across 14 families. Level 3 still adds 24 selected requirements from SP 800-172, February 2021. DoD must amend the rule before assessors can silently swap in the later revisions. NIST now marks that 2021 publication withdrawn and superseded by Revision 3, but Part 170 still incorporates the February 2021 edition for CMMC Level 3. A NIST publication-status change does not amend an incorporated federal rule.
That statement is about the CMMC assessment baseline. DFARS 252.204-7012(b)(2)(i) separately points to the NIST SP 800-171 version in effect when the solicitation is issued, or a version authorized by the Contracting Officer. Read the CMMC rule and the specific contract together; they present related version questions, not interchangeable ones.
If a vendor changes your Level 2 baseline to Revision 3 without explaining the contract and rule path, stop the meeting and make them reconcile the statement to Part 170.
The FedRAMP evidence is changing — the obligation is not
FedRAMP’s Consolidated Rules for 2026 timeline opened optional early adoption on July 4, 2026, makes adoption mandatory on January 1, 2027 subject to rule-specific applicability dates, and ends acceptance of new Rev5 certification applications on June 11, 2027.
Both Slack package records currently show Rev5.
What we are not going to tell you is that POA&Ms, SSPs, SAPs, or SARs have been “eliminated entirely.” FedRAMP’s 2026 rules change terminology, ownership, evidence, and certification paths in rule-specific ways; for example, FedRAMP still has guidance for agency-owned POA&Ms when an agency has an action or risk to manage.
What this means for you, practically: get the service boundary, CRM, configuration guide, support handling, and authorization evidence dated and in writing, and re-verify them as the FedRAMP transition reaches your provider. The security obligation does not disappear because the evidence vocabulary changes.
And no, the CMMC suspension did not change the cloud rule
Phase 1 began on November 10, 2025 and was scheduled to run through November 9, 2026. On July 13, 2026, the Department suspended the Phase 2 transition originally scheduled for November 10, 2026 and later milestones.
The implementing procedures state directly that:
- new procurement designations during the suspension are limited to Level 1 (Self) and Level 2 (Self);
- active solicitations and existing contracts carrying Level 2 (C3PAO) or Level 3 designations must be amended or modified as directed; and
- the cybersecurity requirements in DFARS 252.204-7012 remain in effect.
The cloud rule lives in 7012. Level 1 and Level 2 self-assessment requirements remain active. When 7021 applies, current status, annual affirmation, and CMMC UID duties still matter for the systems covered by the clause.
If someone tells you the suspension means you can leave CUI in Business+ Slack, they have not read the memo or Slack’s guide.
Which Slack features and integrations break the CUI boundary?
The authorization of Slack’s core service does not automatically extend to every app, workflow, external channel, AI feature, export destination, support system, or endpoint. Slack states directly that third-party applications in its directory are not inside its boundary. Every path that can receive Slack content has to be mapped and either approved, constrained, or blocked.
Most people scope “Slack” as one system. It is really a set of doors, and each one can move CUI somewhere the authorization does not reach.
| Data path | Why it changes the answer | The question to ask | Default action |
|---|---|---|---|
| Messages, files, canvases, and lists | Any content field or upload becomes a storage or transmission path | Which channels and users can create, upload, search, retain, or export CUI? | Restrict CUI to approved surfaces; document retention, access, marking, DLP, and export behavior |
| Direct messages | DMs are often less visibly governed than channels | Are DMs retained, searchable, exportable, and covered by the same controls? | Include DMs explicitly in policy, retention, monitoring, and tests |
| Slack Connect | An external organization adds another boundary and identity population | Is every connected organization approved, and where does shared content live? | Inventory every connection and owner. On GovSlack, remember Slack Connect only works with other GovSlack organizations |
| Apps, bots, webhooks, and Workflow Builder | Integrations can copy Slack data to a third-party environment that does not inherit Slack’s authorization | Does the integration touch CUI or Security Protection Data, and where does it send it? | Inventory each integration and run a separate ESP/CSP decision for every CUI-touching service |
| Slackbot web search | Slack warns that web search may send data outside the FedRAMP boundary | Is web search enabled, and can prompts or context include CUI? | Leave it disabled in any CUI environment and retain evidence that it is disabled |
| AI features generally | Enablement, context, connected records, retention, and processing boundary can differ by feature | Which feature is enabled, what data does it use, and where is that data processed? | Do not treat “Slack AI” as one yes-or-no. Enumerate features and verify each against the service boundary |
| Mobile downloads and copying | CUI can move into unmanaged storage, clipboards, screenshots, and backups | Are devices managed, and are downloads and copying restricted? | Apply EMM/MAM controls and test the actual transfer behavior |
| Exports, eDiscovery, DLP, and backups | Every export or replicated record creates another copy in another system | Where does it land, who can request it, and is the destination approved? | Show each destination in the data-flow diagram and assess it as its own service |
| Support requests | Pasted text, files, screenshots, and images create a separate disclosure path | Must support data stay in the FedRAMP boundary, and has the declaration been made? | Train users on prohibited support content and complete the support-data declaration when required |
| Commercial Slack and GovSlack together | Users can select the wrong tenant or workflow | Can users visually distinguish the environments, and are identities and devices separated? | Use visual labels, separated access groups, targeted training, and tested transfer controls |
A live deadline: August 19, 2026
While verifying Slackbot’s boundary warning, we opened Slack’s own help article, “FAQ: Changes to FedRAMP for your Slack support data.”
Slack says its commercial support infrastructure is outside the FedRAMP boundary unless the customer makes the required declaration. If support data must remain inside the authorization boundary, the Primary Owner must submit the declaration by August 19, 2026. The declaration is separate for each workspace or Enterprise organization. After the deadline, Slack directs customers to their account executive or support.
Support data includes text, messages, files, images, and screenshots provided through support tickets or chats. This is not a theoretical edge case. A well-meaning admin can paste exactly the wrong evidence into a support conversation while trying to fix a compliance problem.
If this applies to you, have the Primary Owner handle it now.
Separately, Slack’s Slackbot settings article says web search is off by default and warns that enabling it may send data outside the FedRAMP authorization boundary. Verify your own tenant and keep the screenshot. Defaults change; evidence lasts.
What a Level 2 assessor will ask to see for Slack
Expect an assessor to trace Slack from the contract and CUI data flow into your asset inventory, SSP, network diagram, service documentation, Customer Responsibility Matrix, configuration records, operating logs, user interviews, and technical tests. A dated FedRAMP Marketplace record is useful evidence of the service offering’s public status. It is the first link in a chain, not the chain.
| Evidence category | What to have ready |
|---|---|
| Applicability | Contract clause, CUI category, required level, assessment type |
| Scope | Data-flow diagram, network diagram, asset inventory, workspace/channel/DM inventory |
| Service boundary | Order form, exact service name, package ID, written confirmation from Slack or Salesforce |
| Shared responsibility | CRM, service description, current Secure Configuration Guide, responsibility-to-SSP mapping |
| Configuration | SSO/MFA settings, admin roles, retention, DLP, Slack Connect list, app approval register, AI settings |
| Endpoints | Device-management policy, managed-device inventory, download/copy restrictions, access tests |
| Operations | Access reviews, log reviews, alerts, account removals, app reviews, support records |
| Incident readiness | Incident plan, 72-hour decision workflow, preservation process, named contacts, tabletop evidence |
| Personnel | Training records and owners who can explain the system in an interview |
| External relationships | Connected organizations, apps, ESP/CSP treatment, agreements, support path |
| Testing | Screenshots, exports, sampled logs, transfer attempts, deprovisioning tests, alert results |
| Retention | Six-year retention plan for self-assessment evidence; for certification assessments, hashed artifact inventory and six-year retention from the CMMC Status Date |
The official CMMC Level 2 Assessment Guide uses examine, interview, and test. Examine the policy, configuration, contract, logs, and SSP. Interview the Slack admin, system owner, and ordinary users. Test whether removing an account removes access, whether a blocked download is blocked, whether restricted external sharing is restricted, and whether an alert fires.
The chain an assessor is really following is:
requirement → policy → technical setting → operating record → owner explanation → test result
Break any link and the whole thing reads as aspirational.
The Cyber AB’s CMMC Assessment Process (CAP) v2.0 is the official procedural guide that C3PAOs and CMMC Certified Assessors must follow for Level 2 certification assessments. The CAP’s own disclaimer says it does not supersede DoD or NIST authority, and the CMMC Final Rule says supplemental documents are not codified regulatory text. Use the CAP for assessment procedure; use 32 CFR Part 170 and incorporated sources for the controlling requirements.
Find the provider category that fits the evidence gap
Whether you need scoping help, a GovSlack or enclave implementation partner, managed security, evidence preparation, or an assessment path depends on your level, CUI scope, environment, and timeline.
Do not submit CUI, drawings, source code, contract attachments, network diagrams, credentials, vulnerabilities, or controlled technical information.
What if CUI is already in the wrong Slack workspace?
Stop further sharing, preserve the evidence, determine exactly what entered and who could reach it, and run your incident and contractual review process. Do not assume every misplaced file is automatically a reportable cyber incident — DFARS 252.204-7012 reporting turns on whether a cyber incident affecting a covered contractor information system or the covered defense information residing in it has occurred. That is a fact-specific determination.
We are correcting something here, deliberately. Some pages tell contractors that any CUI touching commercial Slack automatically triggers a 72-hour report to DIBNet. That overstates the clause and can produce bad decisions — including people deleting evidence to make a problem look smaller.
DFARS 252.204-7012 requires rapid reporting within 72 hours of discovery of a cyber incident. The clause defines the trigger around compromise or an actual or potentially adverse effect on a covered system or the information residing in it. Whether an internal placement into an unauthorized Slack workspace meets that definition depends on the facts: who could access it, whether it left your control, what the data was, what systems and integrations were involved, and what the contract says.
Make that call with your incident-response lead and contracts counsel. Not from a blog, including this one.
When the trigger is met, paragraph (c) directs the contractor to report through DIBNet within 72 hours and requires a DoD-approved medium-assurance certificate for submission. If malicious software is discovered and isolated in connection with a reported cyber incident, paragraph (d) directs submission to the DoD Cyber Crime Center (DC3) under DC3 or Contracting Officer instructions — not to the Contracting Officer.
The sequence:
- Stop further sharing and pause automated synchronization or forwarding.
- Preserve messages, files, logs, identities, timestamps, exports, support interactions, and integration records. Do not delete first.
- Identify the CUI category, source, recipients, external organizations, endpoints, and every path the data may have traveled.
- Determine whether the facts meet the clause’s cyber-incident conditions.
- Engage incident response, contracts, legal, and the system owner.
- Report or notify under DFARS, the contract, the prime, the insurer, and customer obligations as applicable.
- If a cyber-incident report is submitted, preserve and protect the required system images and relevant monitoring or packet-capture data for at least 90 days from submission, as paragraph (e) requires.
- Contain, revoke, delete, or migrate the data only after evidence-preservation and response duties are satisfied.
- Fix the cause — service boundary, configuration, integration, policy, or training.
- Update the SSP, risk treatment, and evidence.
- Test the corrected control and keep the result.
If you are in the middle of this right now: you are not the first company this has happened to, it is often more contained than it feels at hour one, and the worst move available to you is quietly deleting things. Preserve first.
How much does GovSlack cost?
Slack does not publish a GovSlack list price. Its official GovSlack page directs prospective buyers to contact sales. Any per-user figure you find in a comparison blog is an estimate, not a verified list price, and we are not going to add another one.
We looked. There is no official number to report, and we would rather say that than invent a range you take into a budget meeting.
What we can give you is the list of cost lines to force into any quote, so you compare the same thing across vendors:
| Cost component | What to ask for |
|---|---|
| Base licensing | Users, workspaces, minimums, term, renewal, legacy-plan transition |
| Enterprise Key Management | Included or separate; AWS KMS costs; who administers and can revoke keys |
| Identity | SSO, provisioning, MFA, privileged administration, dual commercial/GovSlack identity |
| Migration | Messages, files, channels, permissions, retention, and what does not transfer |
| Apps | GovSlack availability, redevelopment, hosting, approval effort |
| Slack Connect | External-organization requirements and onboarding |
| DLP and eDiscovery | License, implementation, storage, and export destination |
| Endpoints | MDM/MAM, desktop deployment, mobile controls, browser policy |
| Compliance documents | Access to the configuration guide, CRM, package materials, service description |
| Support-data handling | FedRAMP support declaration, support channels, escalation path, prohibited data |
| Implementation | Design, configuration, testing, migration, SSP and diagram updates |
| Ongoing operations | Log review, app review, access review, evidence retention, incident response |
| Exit | Export, deletion, migration assistance, key handling, termination terms |
One honest note on sequencing, because it saves real money: decide your asset treatment before you request quotes. A company that walks in knowing it needs a CUI enclave plus a CRMA-documented commercial workspace buys a much smaller thing than a company that walks in saying “we need to be CMMC compliant.” Ambiguity is expensive.
For the broader budget, use the CMMC Level 2 cost guide and the CMMC enclave cost guide.
If Slack is the wrong fit, what are the alternatives?
The alternative is rarely “replace Slack everywhere.” Most contractors have five viable architectures, and the right one depends on how much CUI they handle, how separable the workflow is, and how fast they need to move.
| Path | Best fit | Main tradeoff |
|---|---|---|
| Commercial Slack retained as a CRMA | You want Slack for general work while CUI lives elsewhere | Requires enforceable controls, monitoring, testing, and real documentation — not just a policy |
| Commercial Slack made genuinely out of scope | Strong technical separation is achievable | Harder than policy; users, integrations, and Security Protection Data must not bridge the boundary |
| Commercial Enterprise or Enterprise+ service, boundary confirmed | Moderate is sufficient and Slack confirms the exact purchased service | You still own contract terms, configuration, apps, support, endpoints, and evidence |
| GovSlack | Slack-dependent teams needing High/IL4 or GovSlack partner collaboration | Custom pricing, migration effort, smaller app ecosystem, no GovSlack Slack Connect to commercial |
| A dedicated CUI enclave, Slack outside it | Small CUI user population or narrow CUI workflow | Context switching and the need to hold the boundary |
Related reading on this site: the CMMC enclave cost guide, GCC High for CMMC, the CMMC external service provider assessment guide, and the CMMC software guide.
And if you are an FCI-only contractor who has read this far: you are in the wrong article, and we mean that helpfully. The FedRAMP/CUI analysis is not your problem. Go to the Level 1 self-assessment checklist and spend your budget on the requirements that actually apply.
What to do next about Slack CMMC compliance
Start with your data flow, not a product quote. Determine whether Slack receives FCI or CUI, identify the exact contracted service, map every integration and endpoint, classify the workspace under the scoping rule, close the evidence gaps, and only then approach the provider category that fits the remaining work.
Step 1 — Read the contract. FCI or CUI, applicable clauses, required level, assessment type, deadlines, flow-down obligations. Use the CMMC Levels guide if the contract language and data type are not yet reconciled.
Step 2 — Find the data. Messages, files, channels, DMs, canvases, workflows, apps, external organizations, endpoints, exports, backups, and support interactions.
Step 3 — Pin down the exact service. Plan, domain, order form, service name, package confirmation, support path, and included or excluded features. Send the six-question letter.
Step 4 — Choose the asset treatment and be able to defend it. Level 1 FCI asset, CUI Asset with a CSP relationship, Contractor Risk Managed Asset, Security Protection Asset, or Out-of-Scope Asset.
Step 5 — Build the evidence package. SSP, asset inventory, network and data-flow diagrams, CRM, configuration evidence, operating records, training, incident workflow, and test results.
Step 6 — Route to the right provider category.
- RPO/RP or readiness consultant — scoping, SSP, gap analysis, evidence, and interpretation support.
- MSP/MSSP or Slack/GovSlack implementation partner — configure and operate identity, endpoint, logging, integrations, DLP, and incident controls.
- GRC platform — track evidence, responsibilities, and control status. A supporting layer, never the whole solution.
- CUI enclave provider — isolate the workflow so ordinary Slack never sees CUI.
- C3PAO — when a valid contract requires Level 2 (C3PAO), the suspension posture has been reconciled, and you are assessment-ready.
One independence rule deserves exact language. Under 32 CFR § 170.8(b)(17)(ii)(G), a CMMC Ecosystem member cannot participate in a Level 2 certification assessment of an organization if that member served as a consultant preparing the organization for any CMMC assessment within the prior three years. Do not turn the rule into “no company may ever offer both services,” and do not ignore it either. Identify the actual people and entities involved, disclose conflicts, and keep readiness and formal assessment appropriately separated.
The Cyber AB’s CAP adds another bright line: a C3PAO cannot offer a guarantee or promise about the result of a Level 2 certification assessment or accept incentives tied to issuance of a Certificate of CMMC Status. “Guaranteed certification” is not strong sales copy. It is a reason to stop the sales call.
Use the Who to Hire First guide and CMMC Provider Categories before you sign a statement of work.
Frequently asked questions
Is Slack CMMC certified?
No. CMMC status applies to a contractor information-system assessment scope, not to software. Slack and GovSlack hold cloud authorization records for named service offerings. That is a different thing. Treat “CMMC-certified software” as a marketing phrase, not a status.
Is commercial Slack FedRAMP Moderate authorized?
Slack has a current FedRAMP Marketplace record, Package FR1823447014, at Class C (Moderate), certified since May 20, 2020. Slack states commercial FedRAMP Moderate support applies to Enterprise or Enterprise+ when properly configured under its Secure Configuration Guide. Confirm your exact purchased service, tenant, features, and support path in writing.
Is GovSlack FedRAMP High?
Yes. GovSlack’s Marketplace record, Package FR2230252267, is Class D (High), JAB path, certified since January 25, 2024.
Is GovSlack DoD Impact Level 4 authorized?
Slack’s dedicated GovSlack page and developer documentation state that GovSlack holds DoD SRG IL4 authorization. Slack’s general compliance page, checked August 14, 2026, still describes IL4 as being pursued. If IL4 matters to your program, request the current authorization documentation through your account team rather than relying on a web page.
Can Slack be used for CUI?
Potentially — through an appropriate, verified service offering with the required authorization basis, 7012 contract terms, configuration, documented shared responsibilities, controlled integrations, managed endpoints, support handling, policy, operations, and assessment evidence. Do not use Free, Pro, or Business+ as the CUI cloud path under Slack’s published guide.
Do I need GovSlack for CMMC Level 2?
Not automatically. A confirmed Moderate service can be a CUI path when Moderate is sufficient and all other conditions are met. Other contracts, data types, export-control needs, or partner ecosystems may require or strongly favor GovSlack’s High/IL4 environment. Your contract and data flow decide.
Can ordinary Slack be a Contractor Risk Managed Asset?
Potentially, yes. Under 32 CFR § 170.19, a CRMA can, but is not intended to, process, store, or transmit CUI because of security policy, procedures, and practices. It must appear in the asset inventory, SSP, and network diagram. If the SSP is sufficient, it is not assessed against the other Level 2 requirements; questions can trigger a limited check.
Does a no-CUI policy make Slack out of scope?
No. Out-of-scope treatment requires that the asset cannot process, store, or transmit CUI, provides no security protection to CUI Assets, and is physically or logically separated. Inability, not intention.
Do Slack apps inherit Slack’s FedRAMP authorization?
No. Slack’s configuration guide says third-party applications in its directory are not inside Slack’s boundary. Every app, bot, webhook, export destination, and connected service is its own data-flow and ESP/CSP decision.
Is Slackbot web search inside the FedRAMP boundary?
Slack warns that web search may send data outside the FedRAMP authorization boundary. Slack says the feature is off by default. Leave it disabled in any environment touching CUI and keep evidence that it is disabled.
What is the August 19, 2026 Slack support-data deadline?
Slack says the Primary Owner must declare whether support data must stay inside the FedRAMP boundary by August 19, 2026. The declaration is separate for each workspace or Enterprise organization. Support data can include ticket text, messages, files, images, and screenshots.
Is GovSlack ITAR compliant?
Do not use that sentence as a blanket product status. Slack says GovSlack has controls that can help customers maintain ITAR compliance, that customers remain responsible for compliance, and that customers must not provide ITAR-controlled data to Salesforce through support requests or other communications.
Does GovSlack Slack Connect work with our prime on commercial Slack?
No. Slack states that GovSlack Slack Connect is available only between organizations that also use GovSlack. Confirm partners’ environments before designing external collaboration around it.
How much does GovSlack cost?
Slack does not publish a GovSlack list price and directs buyers to contact sales. Get a written, scoped quote covering licensing, EKM, identity, migration, integrations, endpoints, support handling, implementation, operations, and exit.
Does the July 2026 Phase 2 suspension mean we can delay safeguarding CUI?
No. Phase 1 self-assessment requirements remain. The implementing procedures state that DFARS 252.204-7012 remains in effect. The suspension changes new procurement designations and later rollout milestones; it does not make an unsupported cloud service an acceptable CUI repository.
Does CMMC Level 2 use NIST SP 800-171 Revision 2 or Revision 3?
Revision 2. NIST published Revision 3 in May 2024, but 32 CFR Part 170 still maps Level 2 to Revision 2’s 110 requirements across 14 families. Revision 3 does not become the CMMC assessment baseline unless DoD amends the rule.
Is an SPRS NIST score the same as a CMMC status?
No. A NIST SP 800-171 DoD Assessment score under DFARS 7019/7020 and a CMMC status under DFARS 7021 and 32 CFR Part 170 are distinct records and processes, even though both use SPRS. Do not use one label for the other.
What does a Level 2 self-assessment post to SPRS?
At minimum: CMMC level, CMMC Status Date, CMMC Assessment Scope, every industry CAGE code associated with the scoped systems, the overall Level 2 score, and POA&M usage/compliance status if applicable. The assessment recurs every three years, the affirmation is due at the assessment and annually after it, and the supporting evidence must be retained for six years from the CMMC Status Date.
Who wrote this, how, and why
Who: The Defense Compliance Report Editorial Team. No named CMMC Subject Matter Advisor reviewed this article, and no “Reviewed by” attribution is claimed.
How: We read the controlling and current sources rather than treating vendor marketing or supplemental guidance as the rule. The source record includes:
- 32 CFR Part 170, including §§ 170.8, 170.16, 170.17, and 170.19;
- DFARS 252.204-7012, 252.204-7019, 252.204-7020, and 252.204-7021;
- NIST SP 800-171 Revision 2, NIST SP 800-172, February 2021, the CMMC Level 2 Assessment Guide, and the Cyber AB’s CAP v2.0;
- both Slack and GovSlack FedRAMP Marketplace records;
- Slack’s Secure Configuration Guide, compliance, features, GovSlack, developer, Slackbot, and support-data pages;
- the July 13, 2026 CMMC suspension procedures;
- the DoD FedRAMP Moderate Equivalency memorandum; and
- FedRAMP’s Consolidated Rules for 2026 timeline.
We then assembled the six-scenario environment matrix, the configuration-status crosswalk, the vendor-page contradiction register, the DFARS clause map, the CRMA evidence ladder, the data-path register, and the quote checklist above. Current-status claims were verified August 14, 2026.
Why: Because “is Slack compliant?” is the wrong question, and the right one — which service, for which data, under which clause, with what evidence — was not answered in one source we could find. Contractors are making expensive migration and scope decisions on marketing copy. They deserve the documents.
Read our Methodology, Editorial Standards, and Corrections Policy.
Disclosures
Independence. The Defense Compliance Report is an independent trade publication on CMMC and DIB compliance. We are not affiliated with, endorsed by, or sponsored by Slack, Salesforce, the Cyber AB, FedRAMP, NIST, DCMA DIBCAC, the Department of War, the Department of Defense, or any U.S. government agency.
Compensation. Provider-matching forms on this site may generate referral or lead-routing compensation. Sponsored, affiliate, partner, and referral relationships are labeled when they apply. Compensation does not control our regulatory analysis, provider-category recommendations, or status verification. See the Editorial & Advertising Policy.
Not advice. This article is educational research. It is not legal, contractual, cybersecurity, procurement, export-control, or compliance advice. CMMC requirements vary by contract, scope, system, data flow, and assessment type. The contract clause and actual handling set the path — not a checklist and not this page.
Corrections. Found an error, or has a status changed? We correct promptly and date material changes. See the Corrections Policy.
Need help deciding what type of CMMC provider you need? Tell us your level, scope, environment, and timeline, and we will route you to source-checked provider categories that fit the problem.
Find My CMMC Path → · Request a scoped quote →
Submit only non-sensitive routing information. Do not submit CUI, drawings, source code, contract attachments, network diagrams, credentials, vulnerabilities, incident evidence, or controlled technical information.