Zoom CMMC compliance depends on the exact platform, service boundary, contract terms, and CUI workflow—not on a vendor badge.
By The Defense Compliance Report Editorial Team Last updated: August 2026 · Last verified: August 14, 2026 Evaluation depth: public-source and primary-source verification. No hands-on tenant test.
The Defense Compliance Report is not affiliated with the Cyber AB, the U.S. Department of War or Department of Defense, DCMA DIBCAC, NIST, FedRAMP, DISA, Zoom, or any U.S. government agency. This is educational research, not legal, contractual, cybersecurity, or compliance advice. Confirm scope and applicability with a qualified CMMC advisor, a Cyber AB Registered Practitioner when appropriate, or a federal-contracts attorney.
The short answer
Zoom CMMC compliance is not a product badge. CMMC status is tied to a defined contractor information system and CMMC Assessment Scope—not granted to a Zoom license. Commercial Zoom has no public FedRAMP certification package, and we found no public evidence package establishing FedRAMP Moderate equivalency for that commercial service. That makes Commercial Zoom the wrong default for Controlled Unclassified Information (CUI). Zoom for Government is FedRAMP Certified under package FR1825941347A, with a current profile of Rev5, JAB, Class C (Moderate). Zoom states that Zoom for Defense holds DISA Impact Level 4 authorization for specified capabilities on NIPRNet. Which one you need depends on the data path, the service, and the written requirement—not the logo or the budget.
Here's the part almost nobody tells you, and it's the reason this page exists: DFARS 252.204-7012 has two joined cloud requirements. The cloud service must meet security requirements equivalent to the FedRAMP Moderate baseline, and the provider must comply with the clause's incident-response obligations in paragraphs (c) through (g). A valid Zoom for Government package can support the first half for services actually inside its boundary. It does not write the second half into your contract.
We'll show you where that second half lives, what it obligates, and the evidence to collect before an assessor or contracting team asks—including the Customer Responsibility Matrix that may sit behind an access gate you do not control.
Which fits, which doesn't
| Your situation | Where to start |
|---|---|
| No FCI or CUI will ever enter the meeting | CMMC does not drive the platform decision. Apply normal company and contract policy. Stop reading. |
| Federal Contract Information (FCI) only, no CUI | Do not jump to a CUI architecture. Apply your Level 1 and contract safeguards first. |
| CUI will be spoken, shown, typed, uploaded, or recorded | Evaluate Zoom for Government and the rest of your boundary. Both, not either. |
| Your solicitation, contract, flowdown, or customer instruction names IL4 or NIPRNet | Evaluate Zoom for Defense and confirm the exact capability is authorized today. |
| Unmanaged guests, meeting bots, unknown apps, or personal devices will receive CUI | Stop. Fix the data path before you buy anything. |
The three-platform verdict
There are three distinct Zoom service environments in the public record as of August 2026, not two. A lot of compliance advice written before December 2025 is missing Zoom for Defense entirely.
| Decision point | Commercial Zoom (zoom.us) | Zoom for Government (zoomgov.com) | Zoom for Defense (zoomgov.mil) |
|---|---|---|---|
| Public FedRAMP record | No public FedRAMP certification package located for the commercial service | FedRAMP Certified; package FR1825941347A; Rev5; JAB; Class C (Moderate); certified since July 28, 2023; 44 ATO/ATU letters shown in the Marketplace | Zoom describes it as part of its dedicated U.S. government platform lineage; verify the specific authorization evidence supplied for your order |
| DoD authorization claim | None located | Zoom tenant pages describe Moderate with IL2 reciprocity and an Air Force ATO with conditions at IL4 for Zoom Meetings | Zoom states DISA granted IL4 authorization for communications on NIPRNet behind BCAP. Zoom expands BCAP as "Boundary Connection Access Point"; DoD budget documents use "Boundary Cloud Access Point." |
| Publicly named IL4 capabilities | None | Do not infer a tenant-wide IL4 status from a Meetings-specific statement | Zoom's December 1, 2025 announcement names Meetings, Chat, Webinars, Events, and Rooms; Phone and Contact Center were marked “coming soon” |
| Public infrastructure description | Commercial service environment | AWS GovCloud plus U.S.-based co-located data centers; customer-generated data described as remaining in CONUS | U.S.-based GovCloud environment on the zoomgov.mil domain; Zoom states customer content remains in CONUS |
| Public operations description | Commercial operating model | Managed by U.S. persons, with a separate government release schedule | Managed by U.S. persons, with a separate government release schedule |
| Public eligibility description | Generally available | Government agencies and approved businesses, contractors, integrators, and institutions supporting government customers | Zoom describes DoD organizations, supporting agencies, and mission partners; a July 2026 Carahsoft briefing describes authorized U.S.-based contractors as eligible |
| FCI-only use | Potentially workable if configured and governed | Workable, often more than an FCI-only workflow needs | Almost certainly more than an FCI-only workflow needs |
| CUI use | Stop by default. No public FedRAMP package or public equivalency body of evidence was located. A theoretical equivalency route would still require complete evidence and the DFARS (c)–(g) commitments. | Conditional. Exact service must be in the certified boundary; contract terms, CRM, configuration, endpoints, guests, apps, and evidence still matter. | Conditional. Exact service must be within the current IL4 authorization, your organization must be eligible, and the DFARS contract half still remains. |
| Export-controlled CUI or a named IL4/NIPRNet requirement | No defensible public basis located | Get the written data-category, export-control, and authorization answer for your tenant; CMMC Level 2 alone does not settle every export-control requirement | The purpose-built starting point when the written requirement is IL4/NIPRNet, but exact capability and dissemination restrictions still have to be confirmed |
| Confers CMMC status on your company | No | No | No |
Primary records checked August 14, 2026: FedRAMP Marketplace package FR1825941347A, Zoom for Government, Zoom's December 1, 2025 Zoom for Defense announcement, and the July 24, 2026 Carahsoft briefing.
One caution before you cite that table in an SSP. Zoom's public pages describe several different authorization facts: IL2 reciprocity for Zoom for Government, an Air Force ATO with conditions at IL4 for Meetings, and a later DISA IL4 authorization for Zoom for Defense. Those statements do not create one universal “Zoom is IL4” conclusion. Get the answer in writing for your platform, tenant, service, and SKU—not from a logo, a reseller slide, or a sentence about a different Zoom environment.
The admission we'd rather you hear from us
Zoom for Government will not make you compliant. And for a large share of small defense suppliers, it is not even the right first purchase.
Video is rarely where most of your CUI lives. If your drawings, specs, quality records, and technical data packages are moving through email and a file share, buying a government meeting platform is like installing a deadbolt on the back door while the front door stands open. You'll spend real money and move your assessment position almost not at all.
If that's you, go fix the bigger leak first—start with CUI email encryption for CMMC or the GCC High decision, then come back here.
Now the other side. If Zoom is genuinely where your program conversations happen—if your engineers walk customers through drawings on screen share, if your prime runs technical interchange meetings on Zoom, if your whole company runs on it—then the Zoom for Government path can be legitimate, defensible, and far smaller than rebuilding your entire productivity tenant. The rest of this page is how to do it so the decision survives an assessment.
Before you request a single quote
The right CMMC provider is not the same for every contractor. The category you need—a C3PAO, readiness consultant or RPO, MSP/MSSP, GRC platform, or CUI enclave provider—depends on the CMMC level and assessment type identified in your solicitation, contract, or flowdown, whether you handle FCI or CUI, your cloud and IT environment, and your contract timeline. The written acquisition requirement identifies the required status. Your data flow and system architecture determine the scope needed to meet it.
Because a general article cannot resolve those facts for you, use The Defense Compliance Report's Find My CMMC Path tool before you request quotes. It maps your situation to a provider category, not a guaranteed outcome or a named-provider ranking. Do not submit CUI, drawings, system diagrams, contract documents, customer names, or incident details.
Before you spend, compare the provider categories, read Who to Hire First, and anchor the budget with the CMMC Level 2 cost guide.
Is Zoom CMMC compliant?
No Zoom product is CMMC compliant on its own. Under 32 CFR Part 170, CMMC evaluates contractor information systems inside a defined CMMC Assessment Scope. The defensible question is whether a specific Zoom environment, service set, configuration, contract, and workflow fit inside that scoped system.
Read Zoom's own language carefully, because Zoom is more precise than many pages summarizing it. Zoom's September 2022 comparison white paper says Zoom for Government's controls “help support” a list that includes CMMC compliance. That is a support claim. It is not a CMMC certificate, level, status, or assessment result.
That distinction matters more than it sounds. CMMC Level 2 remains tied to NIST SP 800-171 Revision 2: 110 security requirements across 14 families, evaluated through 320 assessment objectives in the June 2018 SP 800-171A procedures. The CMMC Level 2 Assessment Guide still directs assessors to that Rev. 2 model. A meeting platform can help implement part of that system. It cannot implement the 110 requirements on your behalf, and no assessor will accept a vendor badge as your evidence.
The version drift is real, but it does not change the controlling CMMC standard today. NIST now labels SP 800-171 Rev. 2 withdrawn and superseded by Rev. 3. The CMMC Final Rule still incorporates Rev. 2, so Rev. 3 does not replace the Level 2 assessment standard unless the Department amends the rule or another contract requirement separately invokes it. The same warning applies at Level 3: NIST now labels the February 2021 SP 800-172 superseded, but 32 CFR Part 170 still incorporates 24 selected requirements from the February 2021 publication. See our full Rev. 2 vs. Rev. 3 guide and SP 800-171 vs. SP 800-172 comparison.
What “CMMC ready” scores are actually worth
You'll find pages assigning Zoom a compliance percentage—“83% NIST coverage,” that sort of thing—with two named control gaps and a green badge. Ignore them. CMMC does not score products. It scores an organization's implementation under the CMMC Scoring Methodology in 32 CFR § 170.24, against the assets and assessment objectives in that organization's scope.
A number with no reproducible method is not evidence. It's decoration.
Which Zoom can actually hold CUI?
Commercial Zoom has no public FedRAMP certification package and should not be the default location for CUI. Zoom for Government has a current FedRAMP Certified record at Class C (Moderate), package FR1825941347A. Zoom states that Zoom for Defense operates at IL4 on NIPRNet—but that statement must be narrowed to the exact platform and capabilities covered.
Commercial Zoom
We found no FedRAMP Marketplace package for the ordinary commercial Zoom environment. DFARS 252.204-7012(b)(2)(ii)(D) allows a cloud provider to meet security requirements equivalent to the FedRAMP Moderate baseline, so the legally accurate sentence is not “FedRAMP listing or nothing.” It is this:
Do not put CUI in Commercial Zoom unless the provider supplies a complete, current equivalency body of evidence for that exact service and accepts the separate DFARS paragraphs (c) through (g) obligations. We found neither in the public record reviewed for this article.
Turning off cloud recording does not change that. Neither does enabling end-to-end encryption. Those are useful controls; they are not an authorization or equivalency basis.
We're being careful with our wording here, and you should be too. The defensible statement is not “commercial Zoom is illegal.” It's this: the public evidence a contractor needs for a CUI cloud decision—the certification or equivalency basis, applicable boundary, Customer Responsibility Matrix, service description, and DFARS contract terms—was not available for the standard commercial environment in the sources we reviewed.
Zoom for Government
This is the workhorse answer for many DIB contractors, and the public FedRAMP record is unusually specific.
We pulled the FedRAMP Marketplace listing on August 14, 2026. Package FR1825941347A, listed to Zoom Video Communications, LLC. Phase: Ongoing Certification. Status: FedRAMP Certified as of July 28, 2023. Certification profile: Type Rev5, Path JAB, Class C (Moderate). The Marketplace shows 44 ATO and/or ATU letters, including initial and reuse authorizations.
A naming note that will confuse your consultant. The DFARS clause still says “FedRAMP Moderate baseline.” The current Marketplace profile says Class C (Moderate). Do not rely on a shorthand label alone. Put the package ID, current profile, exact service, and date checked in your documentation. FedRAMP's 2026 transition timeline makes the Consolidated Rules mandatory January 1, 2027 and ends applications for new Rev5 certifications June 11, 2027; existing Rev5 offerings are moving through a broader transition, not disappearing overnight.
Zoom for Defense—and the capability gap worth catching
Zoom for Defense launched effective December 1, 2025. In its launch announcement, Zoom states that DISA authorized IL4 communications on NIPRNet behind BCAP. Zoom expands that acronym as "Boundary Connection Access Point"; DoD budget documents use "Boundary Cloud Access Point." We could not locate a DISA-published authorization record that reconciles the wording, so use the current authorization artifact—not the acronym expansion on a marketing page—in your evidence file.
Now the detail that matters if you're buying voice.
That same announcement lists the IL4-authorized capabilities as Zoom Meetings, Zoom Chat, Zoom Webinars, Zoom Events, and Zoom Rooms. It marks Zoom Phone and Zoom Contact Center as “coming soon.”
A Carahsoft briefing published July 24, 2026, authored by the same Zoom federal-sales executive, presents Zoom for Defense as delivering Meetings, AI Companion, Zoom Phone, Webinars, and Hybrid Survivability. It does not restate the authorization status of each capability.
We are not accusing anyone of anything. Products ship. Authorizations advance. Marketing pages answer different questions. But availability is not proof of authorization. If you intend to put CUI into Zoom Phone voice, voicemail, SMS, AI output, or Contact Center under an IL4 requirement, ask for the current authorization status of that exact service, in writing, before you sign.
That question takes ninety seconds to ask and can save you a finding.
What DFARS 252.204-7012 actually requires from Zoom
The cloud sentence in DFARS 252.204-7012 contains two requirements joined by “and.” The provider must meet security requirements equivalent to the FedRAMP Moderate baseline, and the provider must comply with paragraphs (c) through (g). FedRAMP evidence addresses the baseline side. Only enforceable terms and an operating incident process address the rest.
The exact hinge in paragraph (b)(2)(ii)(D) is short: “and that the cloud service provider complies with requirements in paragraphs (c) through (g) of this clause.”
We've read a lot of vendor pages on this topic. Nearly all of them stop at FedRAMP. That is the easy half because somebody else already issued the status. The second half is a negotiation and operating procedure you have to own.
The second half, mapped
| Clause paragraph | What the contractor must be able to do | Question to put to Zoom or the reseller in writing | Public DFARS-specific commitment located as of Aug. 14, 2026 |
|---|---|---|---|
| (c) Cyber incident reporting | Rapidly report a covered cyber incident to DoD; “rapidly report” is defined as within 72 hours of discovery | Will you notify us fast enough, through a defined channel, for us to investigate and file within our 72-hour clock? Where is that commitment enforceable? | None located |
| (d) Malicious software | Submit malicious software discovered and isolated in connection with a reported incident to the DoD Cyber Crime Center | If malware is isolated in your environment in connection with our incident, what evidence or sample will you preserve and provide so we can meet this duty? | None located |
| (e) Media preservation | Preserve and protect images of affected systems and relevant monitoring or packet-capture data for at least 90 days from the report | What tenant evidence can you preserve, for how long, and how do we invoke preservation immediately? | None located |
| (f) Forensic access | Provide DoD access to additional information or equipment necessary for forensic analysis when requested | What is your process when the Department requests additional tenant information or access for analysis? | None located |
| (g) Damage assessment | Support DoD damage-assessment activities, including submission of media when requested | What media, logs, exports, and personnel support will you provide, and through whom? | None located |
Read that last column precisely. “None located” does not mean Zoom refuses. It means we did not locate a public DFARS-specific commitment in the sources reviewed. The commitment may appear in a private order form, government addendum, reseller agreement, service description, or negotiated rider. That is not a scandal. It is the work item.
If you're buying through Carahsoft or another reseller, this gets sharper: a reseller's paper is not automatically Zoom's paper. Ask what the reseller commits to, what Zoom commits to, and which obligations flow through.
And here is the regulatory twist almost every page misses: the CMMC Final Rule preamble says explicitly that the CMMC Program does not assess DFARS 252.204-7012 paragraphs (c) through (g). Those obligations remain contractual even if your Level 2 assessment focuses on the 110 NIST requirements. A clean CMMC result is not a substitute for an incident clause that works.
Before deployment, collect four things:
- The exact authorization or equivalency evidence for every Zoom service and SKU that will touch CUI.
- The current Customer Responsibility Matrix showing Zoom, reseller, and customer responsibilities.
- The service description and boundary/data-flow evidence for recordings, chat, files, AI output, Phone, Contact Center, and integrations.
- Enforceable incident terms covering notification, preservation, malware support, forensic access, and damage-assessment cooperation.
Get the CMMC evidence checklist
The 32-point CMMC readiness checklist covers scope, SSP, SPRS, external-service-provider evidence, incident workflow, and pre-assessment artifacts. Use it to build the evidence folder around this Zoom decision.
No contract uploads and no CUI. Do not submit drawings, export-controlled content, system diagrams, vulnerabilities, incident details, or sensitive customer information.
Is Zoom a CSP or an ESP—and what has to be in your SSP?
Zoom is a cloud service provider. It becomes an External Service Provider for your CMMC scope when the facts satisfy the CMMC ESP definition—most importantly, when CUI or Security Protection Data resides on the provider's assets or the service provides security protection for CUI assets. Under 32 CFR § 170.19, a CSP that processes, stores, or transmits CUI must meet the FedRAMP requirements in DFARS 252.204-7012, and the in-scope relationship must be documented in the SSP, service description, and CRM.
The scoping rule resolves four situations:
| What the external provider handles | If the provider is a CSP | If the provider is not a CSP |
|---|---|---|
| CUI, with or without Security Protection Data | The CSP must meet the FedRAMP requirements in DFARS 252.204-7012 | The service is in your assessment scope and is assessed as part of your assessment |
| Security Protection Data only | The service is in scope and assessed as a Security Protection Asset | The service is in scope and assessed as a Security Protection Asset |
| Neither CUI nor Security Protection Data, and it protects no CUI asset | It generally does not meet the CMMC ESP definition | It generally does not meet the CMMC ESP definition |
Two consequences people miss.
First, your own infrastructure does not leave scope just because the cloud has a certification. For a Level 2 certification assessment, the rule includes the organization's on-premises infrastructure that connects to the CSP offering. Your managed endpoints, identity provider, conference rooms, administrators, and data paths remain your responsibility.
Second, the paperwork requirement is specific. Section 170.19(c)(2)(ii) requires the ESP relationship and services to be documented in your SSP and described in the ESP's service description and Customer Responsibility Matrix. The current Cyber AB CMMC Assessment Process tells the assessment team to confirm that a CRM will be available and that the appropriate ESP personnel will participate when needed.
The rule also says an ESP may voluntarily undergo a CMMC certification assessment to reduce effort during the organization's assessment. That means a vendor's organizational CMMC claim is not automatically nonsense. It is simply not a substitute for checking the exact status, scope, UID, validity, and services that claim covers. Zoom does not make that claim in the public materials we reviewed.
The document you need may sit behind someone else's gate
Here is the practical trap.
The CRM and other sensitive package materials ordinarily live in the provider's FedRAMP certification package or trust center. The current Zoom for Government Marketplace listing shows a Package Request Form, not an open package download.
FedRAMP's 2026 package-access guidance now distinguishes two paths:
- Provider-hosted trust centers: the Marketplace links to the trust center or contact, and the provider controls access under FedRAMP's data-sharing rules.
- Legacy FedRAMP-hosted repositories: access requires a
.govor.miladdress, an OMB MAX account, and the package-access process described by FedRAMP.
That means the old statement “a small contractor can never get the package” is too broad. The accurate statement is less comfortable: your access depends on the path shown in the Marketplace and on the provider's release process. You may not be able to retrieve the CRM directly from FedRAMP with a normal .com address.
So ask Zoom or your reseller for the current CRM and service description under NDA on day one of the readiness project, not the week before an assessment. If they point you to a federal approver, start that process immediately. If they use a trust center, document who granted access, what version you reviewed, and the date.
What's actually inside the Zoom for Government boundary
Zoom publishes a current list of products it describes as FedRAMP authorized for Zoom for Government. That list is broader than the product set in Zoom's still-available September 2022 comparison white paper. Your SSP needs the current answer for your tenant, not a blended list assembled from pages written four years apart.
Zoom's current FedRAMP page lists these Zoom for Government products:
- Cloud Video Conferencing
- Zoom Events
- Zoom Rooms
- Zoom Whiteboard
- Workspace Reservation
- Zoom Meeting Connector
- Zoom Mesh
- Zoom Continuous Meeting Chat
- Zoom Chat
- Zoom Phone
- Zoom Contact Center
- Zoom API
- Zoom Meeting SDK
- Zoom Client
- Zoom for Chrome PWA
- QSS
- AI Companion for Zoom for Government
Zoom's September 2022 “What's The Difference?” white paper lists five government-platform solutions: Meetings, Webinars, Chat, Phone, and Rooms.
And zoomgov.com carries the practical caveat: not every product may be available on every government platform, so customers should confirm details with sales.
Three public surfaces. Different dates. Different purposes. Your SSP needs one current, tenant-specific answer.
Whichever list you use, save the URL, date, tenant, SKU list, and a dated screenshot or export in your evidence folder. An assessor can open a different Zoom page and find a different level of detail. A dated artifact is worth more than a confident sentence.
Not on the current public list
The following commercial product names do not appear on the current public Zoom for Government FedRAMP product list we checked:
Zoom Mail and Calendar · Zoom Scheduler · Zoom Clips · the AI Productivity Suite names Canvas, Sheets, Slides, and Paper · ZoomMate · Zoom Revenue Accelerator · Zoom Compliance Manager · Customer Managed Key · third-party Marketplace apps.
Absence from that public list is not proof that every underlying feature is outside every tenant boundary. It is proof that you should not assume coverage. Treat each as unverified for your use until Zoom maps it to the applicable service, package, data flow, and contract in writing.
Stanford's ZoomGov service page puts the practical version plainly: because of security restrictions, some advanced features may not be available in ZoomGov. Feature parity is not the design goal. Authorization boundaries are.
There's an operational consequence too, straight from Zoom: Zoom for Government and Zoom for Defense share a codebase with commercial Zoom, but government updates run on a separate schedule that Zoom says can be up to several weeks behind the commercial platform. Put the release difference, patch evidence, and exception process in your risk and change-management records.
Third-party apps: Zoom's own terms name CMMC
This is the single sharpest contract language Zoom has published on this subject, and it sits in the Zoom App Marketplace Terms of Use.
Section 15 says Zoom has not independently evaluated third-party Marketplace software or content for FedRAMP or other cybersecurity standards, and it names the Cybersecurity Maturity Model Certification. The customer is responsible for verification.
Section 16 says using Zoom for Government Marketplace content may transfer customer data outside the Zoom for Government FedRAMP boundary, after which the customer accepts responsibility for securing that data.
Read that with your notetaker bot in mind. Your transcription app, CRM connector, calendar integration, scheduling assistant, AI meeting recorder, and sales bot do not inherit Zoom's authorization. Zoom's own terms tell you that.
If one app installed by one enthusiastic salesperson is pulling transcripts to a third party, your carefully documented boundary has a hole in it that no admin-console screenshot will cover.
Action item: export the Zoom app inventory today. Block installs or establish an account-level allowlist. Map every approved app's data path, authorization basis, retention, subprocessors, and contract. Put the resulting inventory in your SSP evidence set.
The Zoom CUI workflow matrix
CMMC scope follows CUI and the assets that protect it, not the logo. Zoom enters the decision when it or connected assets process, store, or transmit CUI—or provide security protection for CUI assets—through speech, screen sharing, chat, files, screenshots, recordings, transcripts, AI summaries, endpoints, rooms, or integrations. The platform decision and the workflow decision are separate. The workflow decision is the one that usually breaks.
This is our editorial framework, built from 32 CFR Part 170, DFARS 252.204-7012, Zoom's current product and legal documents, and federal agencies' published ZoomGov practices. It is a decision aid, not a regulatory status determination, assessment result, or guarantee.
Three dispositions:
- GO — the described use keeps CUI out of the Zoom workflow. Proceed under normal policy.
- CONDITIONAL — the workflow can be supportable only after the listed conditions are verified, implemented, and documented.
- STOP — do not put CUI into this workflow until the failed condition is closed or a different architecture is chosen.
| Workflow | What it does to the boundary | Editorial disposition | What must be true first |
|---|---|---|---|
| Public or internal meeting, no FCI or CUI | No protected contract data enters the workflow | GO | Normal meeting hygiene and company policy |
| FCI-only meeting | FCI is processed and transmitted | CONDITIONAL | Level 1 and contract safeguards documented; a real control keeps CUI out |
| CUI spoken aloud | Audio transmits CUI | STOP in Commercial Zoom by default · CONDITIONAL in a verified government environment | Exact environment and service verified; participants, endpoints, contract terms, and incident path controlled |
| CUI shown through screen share | The service transmits CUI and each participant endpoint displays it | CONDITIONAL | Approved presenters and viewers; managed endpoints; share procedure; capture risk documented |
| CUI typed into in-meeting chat | CUI enters a separate channel that may persist | CONDITIONAL | Chat, private chat, saving, retention, notifications, and external-user rules configured |
| CUI in persistent Team Chat | CUI becomes a durable cloud record | CONDITIONAL | Exact service in boundary; external contacts, retention, export, search, and screenshot behavior governed |
| CUI file transfer in a meeting or chat | A durable CUI object lands in the cloud and on recipient endpoints | STOP by default | Use only with a documented need, approved recipients, approved storage, retention, and endpoint controls. Many small contractors disable it and move files elsewhere. |
| Screenshot containing CUI | Creates a new CUI artifact outside the original file workflow | CONDITIONAL | Policy, training, endpoint controls, and handling rules address OS-level capture; disabling file transfer does not stop screenshots |
| Whiteboard containing CUI | Creates a persistent, shareable, exportable collaboration object | CONDITIONAL | Exact service verified; sharing, export, guest access, retention, and connected apps controlled |
| Local recording or transcript | The recording endpoint becomes a CUI storage asset | CONDITIONAL | Endpoint is in scope, encrypted, access-controlled, inventoried, and covered by retention and destruction procedures |
| Cloud recording or saved chat | The CSP stores additional CUI artifacts | CONDITIONAL | Service is in boundary; links, downloads, notifications, retention, legal holds, and deletion are controlled |
| AI-generated meeting summary | Meeting content is processed and a new derived artifact is created | CONDITIONAL—default off | Exact feature, model/data path, recipients, retention, admin controls, and authorization mapping verified in writing |
| Managed external guest | CUI reaches another person and another system | CONDITIONAL | Authorization, need-to-know, receiving environment, endpoint, applicable subcontract/flowdown, and retention rules resolved |
| Guest on an unmanaged or unknown device | CUI reaches an uncontrolled endpoint | STOP | Use an approved access architecture or remove CUI from the meeting |
| Third-party app, bot, or connector | Data may leave the FedRAMP boundary under Zoom's own Marketplace terms | STOP until separately verified | Independent authorization/equivalency basis, data flow, agreement, retention, subprocessors, and incident obligations documented |
| Zoom Phone, voicemail, SMS, or Contact Center carrying CUI | Voice or message content enters additional services and storage | CONDITIONAL | Confirm that exact service's current authorization for your platform. Do not infer Zoom for Defense Phone status from a Zoom for Government fact. |
| Zoom Room or shared conference hardware | Room computer, controller, displays, microphones, cameras, and physical space may enter scope | CONDITIONAL | Managed room assets, authentication, patching, physical controls, logs, and evidence documented |
| “We don't intend to discuss CUI,” but users still can | Intent alone does not prevent the data flow | CONDITIONAL | Technically prevent the workflow or classify, control, and document the assets and users that can receive CUI |
The line that should stick with you: Zoom is not your compliance boundary. Your meeting workflow is.
You now know the workflow. Do you know the provider category?
Most contractors reading this discover the same thing: the Zoom question was never really about Zoom. It's about scope, environment, contracts, and evidence—and those map to a specific kind of help.
Use Find My CMMC Path to map your level, CUI scope, environment, and timeline to readiness help, secure-environment work, evidence tooling, or a formal assessment category before you take a sales call.
Do not submit CUI, drawings, system diagrams, contracts, customer names, or incident details. Categories and yes/no answers only.
Recordings, transcripts, chat, and AI notes: where the leaks actually happen
Every enabled Zoom feature can create another CUI artifact, recipient, or storage location. Audio, recording files, transcripts, saved chat, screenshots, whiteboards, AI summaries, notification emails, and downloaded copies are separate data flows. Each one has to remain inside the approved boundary or be excluded from the workflow.
Federal agencies have documented the multiplication problem in their own privacy assessments. Those agency settings are not CMMC mandates, but their observations are useful operational evidence.
The Federal Trade Commission's ZoomGov Privacy Impact Assessment, reviewed in November 2025, says authorized hosts can record video, audio, and public chat; content may be stored locally or in the ZoomGov cloud; shared files may be downloaded; and chat may be logged or transcribed.
The IRS ZoomGov privacy assessment is blunter about the limit of admin controls: participants may use screen-capture and third-party recording tools, and the IRS disabled selected features—including file transfer and forms of screen sharing—for its own risk posture.
That's the sentence to bring to your next policy meeting. Your admin console governs what happens inside the managed service. It does not govern a phone camera pointed at the monitor, the operating system's capture tool, or a personal recorder. A share of CUI protection here is policy, training, participant selection, and endpoint control—not a checkbox.
The four artifact rules we'd put in any Zoom CUI policy
- Recording defaults to off, and turning it on requires prior approval. This is not exotic. The Federal Reserve's Zoom for Government tenant publicly documents recording with prior approval.
- Local recording endpoints are in-scope CUI assets the moment a CUI recording lands there. Inventory them, encrypt them, control access, define retention, and document destruction—or prohibit local recording.
- AI meeting summaries stay off until the data path is documented in writing. AI Companion for Zoom for Government appears on Zoom's current in-boundary product list, which matters. But “listed in the boundary” and “approved for this feature, tenant, data type, retention setting, and recipient set” are different sentences. Get the second one.
- File transfer is usually the easiest feature to turn off. The Federal Reserve's published tenant page says file sharing is disabled. If your organization can move CUI through a better-controlled file path, do it. Just remember screenshots survive the setting.
Can external guests join a CUI meeting?
An external participant is not automatically prohibited. But identity, authorization, need-to-know, endpoint, receiving environment, applicable contract or subcontract terms, retention, and redistribution all have to be resolved first. Zoom admitting someone to the meeting is not the same as that person being authorized to receive the CUI.
Run these six questions in order. If any answer is “I don't know,” the answer for that meeting is no.
- Is this person authorized and has a need-to-know for this specific CUI?
- Is the person's organization permitted to receive it under the applicable prime contract, subcontract, flowdown, security classification guidance, or DD Form 254 where one applies?
- Is the endpoint part of an approved environment, or is it a personal laptop on hotel Wi-Fi?
- Can the participant record, save chat, screenshot, download files, or route audio through another service?
- Does the meeting expose more than this person needs to see?
- Can you evidence six months from now who attended, who approved them, and what controls applied?
The practical pattern that works: a standing “external CUI meeting” profile with authentication required, screen sharing limited to approved presenters, chat restricted, file transfer off, recording off, and a named approver. Everything else is an exception with a paper trail.
Does encryption make commercial Zoom acceptable? And the FIPS date on your calendar
No. Encryption protects CUI; it does not decontrol it. Encrypted CUI is still CUI, and the CSP decision still has to meet DFARS 252.204-7012. Separately, NIST SP 800-171 Rev. 2 requirement 3.13.11 requires FIPS-validated cryptography when cryptography protects CUI confidentiality. That means a validated module in the right version and configuration—not merely a strong algorithm.
Enabling end-to-end encryption in Commercial Zoom does not create a FedRAMP certification, a Moderate-equivalency body of evidence, a CRM, or DFARS incident terms. It also does not remove participant endpoints, recordings, screenshots, and connected apps from the data flow.
Requirement 3.13.11 is short: “employ FIPS-validated cryptography when used to protect the confidentiality of CUI.” The module must be validated through NIST's Cryptographic Module Validation Program. “AES-256,” “FIPS capable,” or “FIPS compliant” is not the evidence by itself.
The September 21, 2026 date
Zoom customer tenant pages say Zoom for Government uses FIPS 140-2 validated cryptographic solutions and 256-bit AES-GCM. That is useful vendor evidence. It is not the certificate number or validated configuration you need to tie the claim to your service.
NIST's FIPS 140-3 transition page says FIPS 140-2 validations remain active until September 21, 2026, then move to the Historical list; its transition schedule lists September 22, 2026 as the date all 140-2 certificates are placed there. September 21 is thirty-eight days after this article's verification date.
Say what that means precisely:
- Historical status is not revocation. The certificate does not vanish and the system does not stop working.
- CMVP supports purchase and use of historical modules for existing systems, subject to the relevant agency or customer risk decision.
- NIST's certificate pages warn federal agencies not to include historical modules in new procurements unless the agency makes an appropriate risk determination.
- For a defense contractor, the practical assessment question is whether you can identify the module, certificate, product version, approved mode, operational environment, status, and basis for continued use.
So the action is small and specific. Ask Zoom—or any vendor in your CUI path—for the CMVP certificate number covering the module that protects your CUI. NIST tells buyers to ask the vendor for a signed letter tied to the validation certificate, then compare it with the CMVP record. Save the result in your SSP evidence.
Ten minutes of work. It converts a marketing phrase into evidence.
For the full control and scoring analysis, see our CMMC FIPS 140-2 requirements guide.
The settings to lock before the first CUI meeting
Start from a restrictive meeting profile and enable only what has a documented business need and approved data path. Authentication, guests, sharing, chat, files, recording, AI, apps, retention, and rooms should be set at the account or group level, locked where practical, and exported as evidence.
This is our recommended starting posture—not a mandated configuration and not a substitute for your own system design or assessment evidence.
| Control area | Restrictive starting posture | Evidence to capture |
|---|---|---|
| Authentication | Require an approved authentication profile; use SSO and MFA | Zoom admin export plus identity-provider configuration |
| External participants | Deny by default; use a documented exception path with a named approver | Participant policy, approvals, attendee records |
| Screen sharing | Host and approved presenters only; use specific-window sharing where practical | Locked setting plus meeting procedure |
| In-meeting and private chat | Restrict or disable private chat for CUI profiles | Account and group setting exports |
| Chat saving | Disable, or tightly restrict with defined retention | Setting, retention rule, and deletion evidence |
| File transfer | Disable unless an approved workflow exists | Setting plus documented exception |
| Screen capture | Disable in-app capture where available; address OS-level capture through endpoint controls and training | Setting, policy, and training records |
| Recording | Off by default; prior approval required; use only a deliberately approved local or cloud path | Settings, approvals, storage map, access and retention evidence |
| Transcription and AI | Off until exact feature, data path, recipients, retention, and boundary are documented | Feature inventory and written vendor confirmation |
| Marketplace apps | Block installs or maintain an account-level allowlist | App inventory, approvals, data-flow records |
| Conference rooms | Managed devices, current patches, physical access controls, controlled peripherals | Room asset inventory and configuration evidence |
| Change management | Lock settings at the appropriate level; review after material releases and on a defined cadence | Change log, screenshots/exports, review records |
One habit worth building: every time you set one of these, export or screenshot it with a date. Assessment evidence is not “we configured it.” Assessment evidence is “here is the configuration, here is when it was captured, here is who approved it, and here is how we know it still operates.”
What Zoom for Government costs, and how you buy it
Zoom does not publish a universal list price for Zoom for Government or Zoom for Defense. Carahsoft's current contracts page lists a GSA Multiple Award Schedule (MAS) procurement route for Zoom, while some Zoom and Carahsoft pages still use the legacy “Schedule 70” label. The only specific public figures we could verify are one university's internal Zoom for Government rates and a July 2026 partner statement that Zoom for Defense starts at ten annual base licenses.
We're not going to invent a per-user number, and you should be skeptical of pages that do. Here is what is actually public and what each number is not.
| Data point | What it is | What it is not |
|---|---|---|
| $32.85/month per voice-only line and $57.85/month per Phone-and-Meetings user | University of Michigan's published internal Zoom for Government rates, checked August 14, 2026 | Zoom's public list price. These are institutional chargeback rates and may include university administration or support. |
| Minimum 10 base licenses on an annual subscription | Stated entry point in the July 24, 2026 Carahsoft briefing | A dollar price or a guarantee that every contractor is eligible |
| GSA Multiple Award Schedule (MAS) through Carahsoft | A current procurement route on Carahsoft's Zoom contracts page; some Zoom pages still use the legacy “Schedule 70” name | The only possible contractual route or a substitute for checking the exact seller, contract vehicle, terms, and authorization |
The costs that don't appear on the quote
This is where government-platform projects go over budget, and it is not the licenses:
- Configuration and administrative policy work
- SSP updates, data-flow diagrams, and asset inventory changes
- CRM review and responsibility mapping
- Contract work for DFARS paragraphs (c) through (g)
- Identity-provider integration and conditional-access changes
- Running two environments during transition
- Retraining people who must know which client and tenant to use
- Conference-room hardware that has to be managed, not just plugged in
- Evidence capture, recurring review, incident exercises, and change management
Build the comparison as a two-year total, not a monthly seat price. Use the same line items for every quote:
Core licenses · Rooms and room hardware · Phone · Contact Center · Recording and cloud storage · Webinars and Events · AI features · implementation and migration · premium support · identity integration · contract and documentation work · total year one · total renewal year
Ask two qualified sellers to fill in the same table. The differences will teach you more than either proposal. For the broader budget, use our CMMC Level 2 cost guide.
The 12 questions to ask before you sign
Before purchase, confirm the legal entity, exact platform and services, authorization covering each service, data locations for every artifact type, DFARS obligations, CRM, and what the reseller commits to independently of Zoom. A license invoice and a FedRAMP logo are not an evidence package.
Send these in writing. Keep the answers in your evidence folder.
- Which legal entity is supplying the service to us?
- Is this order specifically for Zoom for Government or Zoom for Defense, and what tenant/domain will we receive?
- Which exact services, features, and SKUs are included?
- Which current authorization or equivalency evidence covers each service, and what package, authorization, or certificate identifier should we cite?
- Will any enabled feature, integration, support process, or subprocessor transfer customer data outside that boundary?
- Where do recordings, transcripts, chat, whiteboards, voicemail, SMS, files, and AI output reside?
- Which cyber-incident notification obligations are you contractually accepting, and on what timeline?
- How will you support malicious-software submission, preservation, and forensic-access requests?
- What tenant evidence will you preserve after an incident, for how long, and how do we invoke preservation?
- Which responsibilities remain ours, and can we receive the current CRM and service description?
- How will you notify us if a service's authorization, boundary, cryptographic module, subprocessor, or availability changes?
- What does the reseller commit to in writing, separately from Zoom?
Questions 4 and 12 are the two most people skip. They're also the two that decide whether your file survives contact with an assessor.
Not sure which kind of firm should own this work?
Configuration and documentation are readiness work. Environment and enclave design are architecture work. Evidence management is tooling. A Level 2 certification assessment is a separate service delivered by an authorized or accredited C3PAO.
The independence rule is specific: under the Cyber AB Code of Professional Conduct v2.0, a C3PAO and its assessment-team members cannot perform your Level 2 certification assessment if they provided preparatory, advisory, or consulting services for any CMMC assessment within the prior three years. Implementation templates and tools can count as advisory activity. This is not a blanket rule that every remediator is forever barred; it is a defined three-year conflict rule.
Compare the CMMC provider categories and read Who to Hire First before you sign two incompatible scopes.
Zoom for Government or Microsoft Teams in GCC High?
This is an architecture question, not a brand preference. If CUI lives across email, files, identity, and chat, the decision is a tenant decision and a meeting platform will not resolve it. If CUI genuinely lives in live conversations while documents already move through a separate approved path, a government Zoom tenant can be the smaller move.
| The question | What it points to |
|---|---|
| Where does most of your CUI actually sit? | Email and files point toward a tenant or enclave decision. Live conversations and screen shares point toward a meeting-platform decision. |
| Does a solicitation, contract, prime, or customer instruction name a platform or impact level? | Follow the written requirement until it is changed in writing. |
| Do export-control or dissemination restrictions apply? | They can change eligibility, personnel, location, and architecture requirements. CMMC Level 2 alone does not answer every ITAR/EAR or CUI-Specified question. |
| Can you realistically run two ecosystems? | Many small contractors can. Some cannot, and that is a legitimate reason to consolidate. |
| What does your prime or program office use? | Interoperability, guest access, and support boundaries are real costs, not soft factors. |
| Where will recordings, transcripts, files, and AI artifacts land? | The secondary artifacts often decide the architecture before the live meeting does. |
We've written the Microsoft side in depth. See GCC High for CMMC and GCC High cost and licensing. We will not rebuild that comparison here.
Does the CMMC Phase II suspension change any of this?
No—not the DFARS cloud duty. The acquisition rollout changed; DFARS 252.204-7012 did not. On July 13, 2026, the Department of War suspended CMMC Phase II and later implementation milestones while keeping Phase I self-assessment requirements in place. The Department's release also says contractors remain contractually obligated to safeguard covered defense information under DFARS 252.204-7012.
The dates matter:
- The CMMC acquisition rule became effective November 10, 2025.
- Under the original four-phase schedule, Phase I ran from November 10, 2025 through November 9, 2026.
- Phase II was originally scheduled to begin November 10, 2026.
- The Department announced the immediate suspension on July 13, 2026, before Phase II began, and suspended pending and future implementation milestones across solicitations and contracts.
The current Department CMMC page says Phase I self-assessment requirements remain and that the Department will enforce NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments. The July 13 release announced a 60-day study and reform task force. It did not announce a replacement Phase II date.
Here's the honest framing, and we'd rather lose a conversion than manufacture urgency: you may have more time before a new C3PAO requirement appears. You do not have permission to mishandle CUI in the meantime.
What remains relevant:
- DFARS 252.204-7012 safeguarding and incident obligations remain when the clause applies.
- DFARS 252.204-7019 requires an offeror, when the provision applies, to verify that SPRS contains a current assessment summary score for each covered contractor information system relevant to the offer. “Current” normally means not more than three years old unless the solicitation specifies a shorter period; if no current score is posted, the offeror may conduct and submit a Basic Assessment for posting.
- DFARS 252.204-7020 defines Basic, Medium, and High assessments, requires access for Government Medium or High assessments, governs SPRS posting and rebuttal, and imposes assessment-related subcontract duties when the clause applies.
- DFARS 252.204-7021 remains published and contains CMMC status, UID, validity, annual-affirmation, SPRS reporting, and flowdown requirements.
- Existing solicitations, contracts, and subcontracts should be read as written and checked for any suspension-related amendment, modification, or direction. Do not assume a requirement disappeared from your instrument because a press release changed the department-wide rollout.
For the submission mechanics, use our SPRS score guide.
If you were counting down to a universal November 10, 2026 C3PAO deadline, that countdown is stale. November 10 was the scheduled Phase II start, not a universal certification deadline for every contractor, and that transition is now suspended.
When Zoom is the wrong answer
Zoom is the wrong choice when a written requirement mandates another architecture, the capability you need is not inside the applicable authorization, you cannot control endpoints or guests, a required integration moves data outside the boundary, or you cannot obtain acceptable contract terms and evidence. In those cases, restricting the workflow or choosing another architecture is safer than forcing the tool to fit.
We'd rather send you away correctly than convert you incorrectly. Nine situations where the answer is something other than Zoom:
- Your solicitation, contract, flowdown, or authorized customer direction mandates another platform or impact level. Follow the written requirement until it changes in writing.
- The capability you need is “coming soon” or merely described as available. Product availability and authorization scope are not the same document.
- You cannot obtain defensible terms for DFARS 252.204-7012(c) through (g). No incident support, no defensible CSP workflow for CUI.
- Your people use unmanaged personal devices and you have no path to changing that.
- A required bot or integration moves data outside the boundary and cannot be removed or separately authorized.
- Your real problem is broad file collaboration, not meetings. That is a CUI-enclave or government-tenant decision. See PreVeil alternatives and enclave options.
- Your real problem is documentation and evidence, not where meetings happen. That may call for readiness help and a CMMC GRC platform, but software alone never satisfies CMMC.
- You handle FCI only and someone is selling you a CUI architecture. Slow down and confirm the data type and required level first.
- You need a formal Level 2 certification assessment. Select a C3PAO through the Cyber AB Marketplace and screen for the current three-year conflict rule. The C3PAO or assessment-team member that advised or prepared your organization for any CMMC assessment within the prior three years cannot conduct that Level 2 certification assessment.
What we actually verified
We are a publication, not an assessor. Here is exactly what we checked, on what date, and what we could not confirm.
Verified against primary sources on August 14, 2026:
- FedRAMP Marketplace—Zoom for Government, package FR1825941347A: package ID, lifecycle phase, status, certification date, profile, class, and 44 ATO/ATU letters.
- FedRAMP Consolidated Rules for 2026 timeline: January 1, 2027 mandatory adoption and June 11, 2027 end of applications for new Rev5 certifications.
- FedRAMP package-access guidance: provider trust-center access versus legacy FedRAMP-hosted repository access.
- 32 CFR Part 170 final rule: CMMC scope, Level 2 Rev. 2 standard, selected February 2021 SP 800-172 requirements for Level 3, ESP/CRM rules, scoring, and the statement that CMMC does not assess DFARS 252.204-7012(c) through (g).
- DFARS 252.204-7012: cloud requirements and paragraphs (c) through (g).
- DFARS 252.204-7019, 252.204-7020, and 252.204-7021: SPRS assessment information, Government assessments, CMMC status validity, UID, affirmation, and flowdown text.
- NIST SP 800-171 Rev. 2, SP 800-171A, and SP 800-172 February 2021: publication status and the versions still incorporated by the CMMC rule.
- NIST FIPS 140-3 transition guidance and CMVP buyer guidance: FIPS 140-2 transition timing, Historical status, and certificate-verification steps.
- Zoom's current FedRAMP page: the public Zoom for Government product list.
- Zoom's September 2022 comparison white paper: the shorter historical product list and “help support” CMMC language.
- zoomgov.com: public platform, infrastructure, operations, eligibility, and release-schedule descriptions.
- Zoom's December 1, 2025 Zoom for Defense announcement: Zoom's DISA IL4 claim, named authorized capabilities, and “coming soon” labels for Phone and Contact Center.
- Carahsoft's current Zoom contracts page and July 24, 2026 Zoom for Defense briefing: current GSA MAS procurement route, stated ten-license minimum, contractor-eligibility language, and later capability descriptions.
- Zoom App Marketplace Terms of Use: third-party evaluation disclaimer and potential transfer outside the Zoom for Government FedRAMP boundary.
- Cyber AB CMMC Assessment Process v2.0 and Code of Professional Conduct v2.0: CRM availability, no-guarantee language, and the three-year consulting conflict rule.
- Department CMMC page and July 13, 2026 suspension release: Phase II suspension, continued Phase I self-assessment requirements, and continued DFARS 252.204-7012 safeguarding duty.
- FTC and IRS ZoomGov privacy assessments: artifact storage, recording, chat, screen-capture, and third-party recording observations.
- Federal Reserve Zoom for Government tenant, Stanford ZoomGov service page, and University of Michigan rates: published agency/institution configuration examples, feature caveats, and internal rates.
What we could not independently verify, and did not publish as an unqualified fact:
- A complete FedRAMP Moderate-equivalency body of evidence for Commercial Zoom.
- A CMVP certificate number that we could tie to the exact cryptographic module, product version, and configuration protecting a customer's Zoom for Government CUI.
- A public DFARS-specific contractual commitment from Zoom covering every obligation in paragraphs (c) through (g).
- Zoom's universal list pricing for Zoom for Government or Zoom for Defense.
- A DISA-hosted public authorization record independently corroborating every Zoom for Defense statement; the IL4 claim is attributed to Zoom.
- The post-launch IL4 authorization status of Zoom Phone, Zoom Contact Center, AI Companion, voicemail, or SMS for Zoom for Defense; availability statements were not treated as authorization evidence.
- Your tenant configuration, order form, private FedRAMP package, CRM, service description, or reseller flowthrough terms.
Evaluation depth: public-source and primary-source review. We did not deploy a tenant, inspect a private FedRAMP package, interview Zoom, review a customer contract, or observe a CMMC assessment.
Disclosure: The Defense Compliance Report is an independent trade publication covering CMMC and Defense Industrial Base compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed under our Editorial Standards. Compensation does not change the primary-source standard applied to regulatory claims or the requirement to verify Cyber AB status.
Zoom CMMC compliance FAQ
Is Zoom CMMC compliant?
No product is CMMC compliant on its own. CMMC status applies to a contractor information system within a defined assessment scope. Zoom for Government can be a defensible cloud component when the exact service, authorization, contract terms, configuration, endpoints, integrations, and evidence all fit that system.
Can I discuss CUI on regular Commercial Zoom?
We would not based on the public evidence reviewed. Commercial Zoom has no public FedRAMP package, and we found no public Moderate-equivalency body of evidence or DFARS-specific (c) through (g) commitment for that service. The live audio transmits CUI even when nobody records it.
Does screen sharing count as transmitting CUI?
Yes. When CUI is displayed to remote participants, the collaboration service carries the display stream and every participant endpoint receives it. Screen sharing is one of the easiest ways CUI enters a meeting platform without a file upload.
Is Zoom for Government FedRAMP authorized?
The current FedRAMP terminology is FedRAMP Certified. As of August 14, 2026, the Marketplace lists Zoom for Government under package FR1825941347A, Rev5, JAB, Class C (Moderate), certified since July 28, 2023, with 44 ATO/ATU letters.
What's the difference between Zoom for Government and Zoom for Defense?
Zoom for Government operates in the zoomgov.com environment and has the public FedRAMP package described above. Zoom for Defense operates on zoomgov.mil, and Zoom states that it holds DISA IL4 authorization on NIPRNet. Do not transfer a service-specific fact from one environment to the other.
Can a small defense contractor buy Zoom for Government?
Possibly. Zoom describes the platform as available to approved businesses and organizations that support government customers. Eligibility, tenant type, procurement route, minimums, and required proof should be confirmed with Zoom or the authorized seller before architecture work begins.
Do I need Zoom for Government if I only handle FCI?
Not automatically. FCI and CUI trigger different safeguarding requirements. Confirm your data type, written CMMC requirement, and actual workflow before imposing a CUI architecture on an FCI-only system.
Can I record a Zoom meeting that contains CUI?
Potentially, inside an approved architecture. The recording becomes a new CUI artifact. Storage, endpoint, access, encryption, retention, sharing, backup, legal hold, and deletion all have to be documented. A local recording can turn the receiving device into an in-scope CUI asset.
Is Zoom AI Companion safe for CUI?
There is no blanket yes. AI Companion for Zoom for Government appears on Zoom's current public FedRAMP product list, which is meaningful. Before enabling a specific AI feature for CUI, verify the feature, service boundary, model/data path, generated artifacts, recipients, retention, administrator controls, and contract in writing. Default it off until that file exists.
Are Zoom Marketplace apps covered by Zoom's FedRAMP authorization?
Do not assume so. Zoom's own Marketplace terms say it has not independently evaluated third-party content for FedRAMP or CMMC and that Marketplace use may transfer customer data outside the Zoom for Government FedRAMP boundary.
Is end-to-end encryption enough to make Commercial Zoom acceptable for CUI?
No. Encryption does not create a FedRAMP certification or equivalency package, CRM, or DFARS incident terms. Separately, NIST SP 800-171 Rev. 2 requirement 3.13.11 requires FIPS-validated cryptography where cryptography protects CUI confidentiality.
Does the FIPS 140-2 transition affect my Zoom evidence?
Yes, potentially. NIST says FIPS 140-2 validations move to the Historical list after the September 21, 2026 transition. Historical is not revoked, and existing-system use may continue, but you still need the module certificate, product version, approved configuration, status, and basis for use.
Does CMMC Level 2 use NIST SP 800-171 Rev. 3?
No—not under the current CMMC Final Rule. CMMC Level 2 remains tied to SP 800-171 Revision 2 unless the Department amends 32 CFR Part 170. A separate solicitation or contract requirement could create an additional obligation, but it does not silently rewrite the CMMC assessment standard.
Does Zoom require NIST SP 800-172 for CMMC Level 2?
No. SP 800-172 is not the Level 2 baseline. The current CMMC rule uses 110 SP 800-171 Rev. 2 requirements for Level 2 and adds 24 selected February 2021 SP 800-172 requirements at Level 3.
Does my cloud provider need its own CMMC certification?
Not automatically. A CSP handling CUI must meet the FedRAMP requirements in DFARS 252.204-7012. The CMMC rule allows an ESP to undergo a voluntary CMMC certification assessment, but that is one possible evidence path—not a universal prerequisite for every CSP.
What Zoom evidence will an assessor want to see?
For the CMMC assessment, expect to produce the exact platform and tenant, authorization or equivalency evidence, CRM, service description, SSP narrative, data-flow diagram, settings exports, user and administrator lists, endpoint and room inventory, guest procedure, app inventory, retention rules, training records, and evidence that the controls operate. Keep the separate DFARS 252.204-7012(c) through (g) contract and incident terms in your contractual evidence file even though the CMMC Program does not assess those paragraphs.
Does the CMMC Phase II suspension mean we can wait?
It changes the department-wide timing of new Phase II and later implementation milestones. It does not suspend DFARS 252.204-7012, and Phase I self-assessment requirements remain. Review your actual solicitation, contract, subcontract, and any amendments before changing course.
Choose the right CMMC path before you buy another license
A Zoom decision rarely stays inside Zoom. It touches your contract, FCI and CUI scope, endpoints, guests, cloud services, assessment type, incident obligations, and timeline. Map those first—then ask for the right kind of help, from the right kind of firm, with a scope you can evaluate.
Need help deciding what type of CMMC provider you need? Use Find My CMMC Path to map your level, scope, environment, and timeline. When you are ready for qualified introductions, use the request-a-quote form.
Do not submit CUI, drawings, system diagrams, contract documents, export-controlled content, vulnerabilities, incident details, or sensitive customer information. Provider introductions may generate compensation as disclosed under our editorial policy.
The Defense Compliance Report is an independent trade publication covering CMMC and DIB compliance. This page is educational research, not legal, contractual, cybersecurity, or compliance advice. Review our Methodology, Editorial Standards, and Corrections Policy.
Last verified: August 14, 2026 · The Defense Compliance Report Editorial Team