Zoom, Zoom for Government and CMMC: which one do you actually need?
Short answer
CMMC does not automatically require every defense contractor to use Zoom for Government.
The correct choice depends on what information will be processed, stored, or transmitted through the Zoom environment, what your DoD contract requires, and which Zoom service offering is being evaluated.
The most important dividing line is Controlled Unclassified Information, or CUI.
Under current DoD CMMC guidance and DFARS 252.204-7012, when an external Cloud Service Provider is used to process, store, or transmit CUI in contract performance, the applicable cloud service offering must meet security requirements equivalent to the FedRAMP Moderate baseline. DoD guidance explains that this can be satisfied through a FedRAMP Moderate authorized offering or through DoD's defined FedRAMP Moderate equivalency process.
Zoom for Government is a separate Zoom environment with FedRAMP Moderate authorization. Zoom also describes its government environments as supporting additional public sector requirements, including DoD Impact Level 4 capabilities for applicable offerings.
That does not mean:
Defense contractor = Zoom for Government automatically required
and it also does not mean:
Commercial Zoom = automatically acceptable for CUI
The correct analysis is:
What information will enter Zoom?
→ Which Zoom services and features will process or store it?
→ What does the contract require?
→ What cloud security requirements apply?
→ Which specific Zoom offering satisfies those requirements?
Important: This article is educational and is not legal, contractual, CMMC certification, or C3PAO assessment advice. Product authorizations and features change. Verify the current Zoom authorization boundary, DoD CMMC guidance, FedRAMP status, DFARS requirements, and your specific contract before designing a CUI workflow.
Two separate environments, not two licence tiers
What Is the Difference Between Commercial Zoom and Zoom for Government?
Commercial Zoom and Zoom for Government are separate environments.
Zoom states that Zoom for Government is independent of the standard commercial Zoom platform and is hosted using AWS GovCloud and U.S. based infrastructure, with the government platform managed by U.S. persons.
Zoom for Government is designed for organizations with U.S. government security and compliance requirements.
Commercial Zoom serves the broader commercial market and has its own security certifications and attestations.
The fact that the interfaces may look familiar does not make the authorization boundaries identical.
Is Zoom for Government Just a More Secure Zoom License?
That description is too simplistic.
It is better to think of Zoom for Government as a separate authorized environment.
The distinction can involve:
- Infrastructure
- Authorization boundary
- Data handling
- Personnel requirements
- Available products
- Available features
- Integrations
- Compliance documentation
- Government security requirements
Organizations should evaluate the actual service offering rather than assuming it is merely a setting that can be enabled on a commercial Zoom tenant.
FedRAMP: what it is, and what it is not
Is Zoom for Government FedRAMP Authorized?
Yes.
Zoom identifies Zoom for Government as a FedRAMP Moderate authorized environment.
Zoom's current compliance materials identify FedRAMP Moderate among the authorizations associated with Zoom for Government.
Organizations should still verify that the specific product or capability they intend to use is included within the current authorization boundary.
Why Does FedRAMP Moderate Matter to a Defense Contractor?
Because DFARS 252.204-7012 contains requirements for external cloud services used to store, process, or transmit covered defense information.
For CUI in an external cloud service, current DoD CMMC guidance states that the cloud service offering must meet FedRAMP Moderate or DoD FedRAMP Moderate equivalency requirements.
This can make the authorization status of a collaboration platform highly relevant to CMMC architecture.
Does CMMC Require FedRAMP Moderate for Every Cloud Application?
No.
The key question is whether the Cloud Service Provider's offering processes, stores, or transmits CUI.
Current DoD CMMC guidance states that if CUI is not processed, stored, or transmitted in the cloud, FedRAMP authorization is not required solely on that basis, although the service can still be relevant to CMMC scope when it provides security protection to the CUI environment.
Is FedRAMP the Same as CMMC?
No.
This distinction is critical.
FedRAMP addresses security authorization for cloud products and services used by government.
CMMC evaluates the defense contractor's implementation of applicable cybersecurity requirements within its defined assessment scope.
A contractor does not become CMMC certified because one cloud provider is FedRAMP authorized.
Likewise, a CMMC certification does not transform every cloud service the contractor uses into a FedRAMP authorized service.
Does FedRAMP Moderate Authorization Automatically Mean the Contractor Is CMMC Compliant?
No.
A FedRAMP authorized cloud service can be an important component of the architecture.
The contractor still has responsibilities involving:
- CMMC scope
- Asset inventory
- Access control
- Identity
- Endpoint security
- Network security
- Policies
- Procedures
- Incident response
- Audit and accountability
- Configuration management
- User training
- System Security Plan
- Evidence
- Assessment
Cloud authorization is one piece of the larger system.
If you only handle FCI: the Level 1 case
What if We Only Handle FCI, Not CUI?
This is where most small defense suppliers actually sit, and it is the case the rest of this article does not cover — so take it first.
If your contracts give you Federal Contract Information but no CUI, you are looking at CMMC Level 1, which is a self-assessment against the fifteen basic safeguarding requirements at 48 CFR 52.204-21. There is no FedRAMP Moderate requirement at Level 1. The FedRAMP equivalency question in this article is driven by CUI in an external cloud service under DFARS 252.204-7012 — if CUI never enters the platform, that analysis does not start.
Practically: a Level 1 supplier does not need Zoom for Government in order to be compliant. Commercial Zoom, configured sensibly and documented, is not disqualifying.
Two cautions before you conclude you are Level 1. First, check the contract rather than assuming — suppliers are routinely surprised by CUI arriving in a drawing package or a statement of work. Second, FCI still has to be protected; Level 1 is a lower bar, not an absent one.
The rest of this article is about what happens once CUI is in play.
Which platform do you actually need?
Does CMMC Automatically Require Zoom for Government?
No.
If the organization's Zoom environment does not process, store, or transmit CUI, the cloud requirement associated with CUI may not be triggered merely because the company has a DoD contract.
For example, a contractor could potentially use a commercial collaboration platform only for:
- Public webinars
- General sales meetings
- Recruiting
- Public marketing
- Non CUI corporate meetings
while using a separate controlled environment for CUI.
The architecture and actual user behavior must support that boundary.
Can Commercial Zoom Be Used by a Defense Contractor?
Being a defense contractor does not, by itself, prohibit use of commercial Zoom.
The relevant question is what the contractor is using it for.
A company may have many information categories:
- Public information
- Ordinary corporate information
- FCI
- CUI
- Export controlled information
- Proprietary information
The communications architecture should define where each category is permitted.
Can Commercial Zoom Be Used for CUI?
Do not answer this question solely from the brand name.
If a commercial cloud offering will process, store, or transmit CUI under a contract subject to DFARS 252.204-7012, the contractor must ensure that the specific Cloud Service Offering meets the applicable FedRAMP Moderate or equivalency requirements and the other relevant contractual requirements.
Therefore, the organization should verify the authorization or equivalency status of the specific commercial offering, not assume that security certifications elsewhere in the vendor's portfolio apply to it.
Why Is the Specific Cloud Service Offering Important?
Cloud compliance attaches to defined service offerings and authorization boundaries.
A vendor can operate multiple environments.
For example:
Vendor A
→ Commercial SaaS environment
→ Government SaaS environment
→ DoD specific environment
One environment's authorization does not automatically extend to every other environment sold under the same brand.
Does Zoom for Government Include Zoom Phone?
Zoom identifies Zoom Phone among the products available within the Zoom for Government platform and its government authorization materials.
Organizations should verify current product availability, authorization status, licensing, carrier design, emergency calling, integrations, and specific feature support before deployment.
Does Zoom for Government Include Contact Center?
Zoom announced in June 2024 that Zoom Contact Center was authorized within Zoom for Government.
Two points of precision, because both are commonly got wrong. First, Contact Center is inside the existing Zoom for Government authorization boundary (FedRAMP package FR1825941347A, Moderate) rather than a separately listed FedRAMP package. Second, that authorization came through the Joint Authorization Board, which no longer exists — OMB Memorandum M-24-15 (25 July 2024) modernised FedRAMP, and FedRAMP retired the JAB/Agency tiers in favour of a single "FedRAMP Authorized" designation under the FedRAMP Board. FedRAMP's own marketplace listing now uses the past tense: Zoom for Government "previously became FedRAMP-Authorized by the Joint Authorization Board (JAB)."
Anyone still writing "JAB authorized" in the present tense in 2026 is working from stale material.
Because boundaries and product availability change, verify the current status before designing a CUI contact center workflow.
What About Zoom AI Companion?
Zoom announced in September 2024 that AI Companion was authorized within Zoom for Government — again, inside the same FR1825941347A boundary rather than as a separate FedRAMP package.
That is important for organizations considering AI generated meeting summaries and related workflows in government environments.
However, AI governance still requires an information flow review.
FedRAMP authorization does not remove the need to determine:
- What data the AI processes
- What output it creates
- Where the output is stored
- Who can access it
- What integrations receive it
- What organizational policy permits
Where CUI actually lands in Zoom
Can CUI Appear in a Zoom Meeting?
Yes.
CUI can appear through:
- Spoken discussion
- Screen sharing
- Chat
- Whiteboards
- Files
- Meeting recordings
- Transcripts
- AI summaries
- Notes
- Shared applications
A meeting platform should therefore be evaluated as an information system, not merely as a video connection.
Does a Meeting Become CUI Just Because a Defense Contractor Hosts It?
No.
The information being discussed or shared determines whether CUI is present.
A defense contractor's company picnic planning meeting does not become CUI simply because the company performs DoD work.
What Happens When a Meeting Is Recorded?
Recording changes the information flow.
A live conversation becomes a persistent data object.
The organization should determine:
- Where recordings are stored
- Whether local recording is allowed
- Whether cloud recording is allowed
- Who can access recordings
- How long they are retained
- Whether recordings can be downloaded
- Whether links can be shared
- Whether transcripts are generated
- Whether AI processes the recording
What About Meeting Transcripts?
Transcripts can contain the same controlled information discussed verbally.
They may also be easier to search, copy, export, email, or integrate into other systems.
That can expand the CUI boundary.
What About Zoom Team Chat?
If users are permitted to enter CUI into Team Chat, then the chat service becomes part of the CUI information flow.
Review:
- Messages
- Files
- Screenshots
- External participants
- Retention
- Search
- Export
- Integrations
- Mobile access
What About Zoom Whiteboard?
A whiteboard can contain technical drawings, architecture, engineering notes, program information, or other controlled content.
Treat it according to the information users place on it.
What About Zoom Phone?
Zoom Phone can create multiple CUI pathways:
- Voice conversations
- Voicemail
- SMS
- MMS
- Call recording
- Transcription
- Contact center handoff
- Integrations
- Administrative data
This is why the previous article in this series asks:
Does CMMC Apply to Your Phone System?
Does Using Zoom for Government Automatically Make Zoom Phone CMMC Compliant?
No product automatically makes the customer compliant.
Zoom for Government can provide an authorized cloud environment relevant to the contractor's architecture.
The contractor must still configure and operate the service appropriately.
Zoom for Defense and DoD Impact Level 4
What About Zoom for Defense?
Zoom currently markets Zoom for Defense alongside Zoom for Government for DoD specific use cases.
Zoom states that its government platforms provide DoD IL4 capabilities and describes Zoom for Defense as supporting secure collaboration on the NIPRNet and approved internet facing environments.
A contractor should not assume that it needs Zoom for Defense simply because it is in the Defense Industrial Base.
The requirement depends on the mission, contract, connectivity, information classification, government environment, and specific service authorization.
What Is DoD Impact Level 4?
DoD Impact Level 4, commonly called IL4, is associated with cloud services handling certain CUI and other mission information under DoD cloud security requirements.
IL4 and CMMC are not the same thing.
A DoD cloud authorization addresses the cloud environment.
CMMC addresses the contractor's cybersecurity program and assessment scope.
Is DoD IL4 the Same as FedRAMP Moderate?
No.
They are related in government cloud security architecture but represent different requirements and authorization frameworks.
Do not use the terms interchangeably.
Is DoD IL4 the Same as CMMC Level 2?
No.
This is a common and potentially expensive misunderstanding.
IL4 is a DoD cloud impact level.
CMMC Level 2 is a cybersecurity maturity and assessment level for organizations handling CUI under applicable DoD requirements.
The number 4 and the number 2 do not represent comparable scales.
Encryption, FIPS and what a certificate actually proves
Is FIPS the Same as FedRAMP?
No.
FIPS standards address specific federal information processing requirements.
In CMMC discussions, FIPS validated cryptography is frequently relevant to cryptographic protection requirements.
FedRAMP is a broader cloud security authorization framework.
A product saying it uses encryption does not automatically establish FedRAMP authorization or CMMC compliance.
Does Zoom Hold a FIPS Validated Cryptographic Module?
No, and this matters more than it first appears.
FIPS validation is not a claim a vendor can make about itself. It is a certificate issued by NIST's Cryptographic Module Validation Program, and the validated modules list is public and searchable. Searched on 18 August 2026 for vendor Zoom and for Zoom Video Communications, across active, historical and revoked certificates, CMVP returns the same result every time:
No certificates match the search criteria
So Zoom Video Communications holds no FIPS 140-2 or FIPS 140-3 validated cryptographic module.
Be careful here, because there is FIPS language on Zoom's own site that is easy to misread. Zoom's AWS government page describes Zoom for Government as designed for agencies that "need validated compliance with FIPS 140-2 cryptography." That sentence describes the customer's requirement, not a Zoom certificate. It is not a claim of validation and should never be quoted as one.
If your contract or your SSP requires FIPS-validated cryptography for a given data flow, that requirement is not satisfied by pointing at Zoom for Government's FedRAMP authorization. Ask Zoom directly for the cryptographic-module documentation in the ZfG System Security Plan, and take the answer in writing.
What About End to End Encryption?
End to end encryption can provide important confidentiality protections, but it is not a substitute for the complete CMMC or FedRAMP framework.
Organizations must still consider:
- Identity
- Access control
- Logging
- Configuration
- Endpoints
- Malware
- Incident response
- Retention
- Integrations
- User behavior
- Administrative access
Encryption is one control, not the whole program.
Does Zoom for Government Keep Data in the United States?
Zoom describes Zoom for Government as a U.S. based platform hosted in AWS GovCloud, separate from the commercial Zoom platform, and managed by U.S. persons. That much is on Zoom's own pages.
Be careful about going further than that. A phrase that circulates widely — that customer content is "stored and encrypted in the continental United States" — does not appear on Zoom's current documentation, and we could not source it. If a data-residency commitment is a contractual requirement for you, get the current wording from Zoom in writing rather than from a summary. Feature-specific exceptions are exactly where this sort of claim breaks.
Why Do U.S. Persons Matter?
Some government contracts and security architectures impose requirements around personnel access, support, operations, and data handling.
A U.S. persons operated environment can therefore be important for particular government workloads.
But CMMC itself should not be reduced to a generic "U.S. persons only" rule.
Always trace the requirement to the applicable contract or framework.
Migrating, and what you give up
Can We Migrate From Commercial Zoom to Zoom for Government?
Potentially, but treat it as an environment migration rather than assuming a simple license conversion.
Zoom states that Zoom for Government is independent from the standard commercial Zoom platform.
Migration planning should review:
- Users
- Accounts
- Meetings
- Phone numbers
- Recordings
- Chat
- Contacts
- Rooms
- Devices
- Integrations
- APIs
- SSO
- Calendars
- Retention
- Data migration
- User training
Feature parity should be validated before the migration.
Are All Commercial Zoom Features Available in Zoom for Government?
Not necessarily.
Zoom itself notes that not all products may be available on its government platforms.
Organizations should validate the specific feature set they require.
This is especially important for:
- AI
- Contact center
- Marketplace applications
- APIs
- Integrations
- New features
- Third party applications
Integrations, identity and guests
Can We Connect Commercial Applications to Zoom for Government?
Potentially, depending on the integration and availability.
But every integration should be evaluated because it can create another data path.
If CUI leaves the authorized environment and enters an unapproved external cloud service, the architecture can create a serious compliance problem.
What About Salesforce, HubSpot, or Other CRM Integrations?
Do not assume that because Zoom for Government is authorized, every connected CRM automatically inherits that authorization.
Map the data flow.
Zoom for Government
→ Integration
→ CRM
If CUI crosses that boundary, evaluate the CRM and integration against the applicable requirements.
What About Calendar Integrations?
Calendar metadata can reveal information.
Meeting names, participant names, project names, descriptions, attachments, and links can sometimes contain sensitive information.
Review what data is exchanged.
What About Outlook and Microsoft 365?
The same principle applies.
The Microsoft environment should be evaluated independently based on the specific cloud offering, configuration, contract requirements, and CUI workflow.
One authorized service does not authorize the entire connected ecosystem.
What About Single Sign On?
SSO can strengthen identity management and simplify access control.
But the identity provider becomes an important part of the security architecture.
If it provides security protection to the CUI environment, it may be relevant to CMMC scope.
What About MFA?
MFA is an important component of CMMC Level 2 identity and access protection.
Organizations should review MFA for:
- Users
- Administrators
- Privileged roles
- Remote access
- Identity providers
The implementation should match the applicable CMMC requirements.
What About Guest Users?
External participants create an important policy question.
Ask:
- Are external users allowed?
- Can they receive CUI?
- Can they join CUI meetings?
- Can they access chat or files?
- How are they authenticated?
- Can they download content?
- Are they authorized recipients?
Meeting security is not only a technical problem.
What About Meeting Links?
A meeting link should not be treated as the sole access control for sensitive collaboration.
Organizations should configure appropriate authentication, waiting room, participant controls, and meeting policies based on risk and requirements.
Running two environments
Can We Use Zoom for Public Meetings and Zoom for Government for CUI?
Potentially.
Some organizations deliberately separate workflows.
For example:
Commercial Zoom
→ Public webinars
→ Marketing
→ General corporate collaboration
Zoom for Government
→ Approved government workflows
→ CUI collaboration where authorized and configured
The organization must train users clearly so information does not cross the wrong boundary.
Is Running Two Zoom Environments Too Complicated?
It can be.
Multiple environments create challenges involving:
- User confusion
- Licensing
- Administration
- Calendaring
- Support
- Integrations
- Data movement
- Meeting invitations
- Training
For some organizations, separation reduces CMMC scope.
For others, standardizing on an appropriate government environment may be operationally simpler.
Architecture should balance compliance, usability, cost, and risk.
Can We Simply Ban CUI From Zoom?
Potentially, if the business can operate that way and the policy is enforced in practice.
The organization should then determine:
- Where CUI collaboration occurs instead
- How users recognize CUI
- How users are trained
- What technical restrictions exist
- What happens if CUI is accidentally entered
- How incidents are reported
- How the scope boundary is documented
A policy that everyone ignores does not create a reliable boundary.
Deciding, and what to ask
How Do We Decide Which Zoom Platform We Need?
Use a structured decision process.
Question 1: Do We Have DoD Contracts?
If no, CMMC may not be the driver, although other government requirements may still apply.
Question 2: Do We Handle CUI?
Identify actual CUI workflows.
Question 3: Will CUI Enter Zoom?
Consider voice, video, chat, files, whiteboards, recordings, transcripts, SMS, voicemail, and AI.
Question 4: Will Zoom Process, Store, or Transmit CUI?
If yes, cloud service requirements become highly relevant.
Question 5: Which Specific Zoom Offering Are We Evaluating?
Do not evaluate "Zoom" generically.
Question 6: Is the Offering FedRAMP Moderate Authorized or Does It Meet Applicable DoD Equivalency Requirements?
Verify current evidence.
Question 7: Does the Specific Product We Need Fall Within the Authorization Boundary?
Check Meetings, Phone, Contact Center, AI, Rooms, APIs, and other required capabilities.
Question 8: Do We Have Additional DoD Requirements?
Consider IL4, NIPRNet, contract clauses, customer requirements, and mission specific restrictions.
Question 9: What Integrations Touch the Environment?
Map every external service.
Question 10: Can We Operate and Document the Environment Correctly?
Technology selection is only the beginning.
What Should We Ask Zoom or Our Zoom Partner?
Ask for current documentation covering:
- Exact service offering
- FedRAMP authorization
- Authorization boundary
- DoD IL4 status where relevant
- Product inclusion
- Zoom Phone
- Contact Center
- AI Companion
- Meetings
- Team Chat
- Whiteboard
- Rooms
- APIs
- Marketplace
- Data location
- U.S. persons operations
- Encryption
- Cryptographic module documentation, if your contract requires FIPS validation
- Logging
- Administrative controls
- Identity integration
- Retention
- Migration requirements
- Feature differences
Do not rely solely on a sales slide.
What Should We Ask Our CMMC Consultant or C3PAO?
Ask:
- Is Zoom in our assessment scope?
- Does CUI enter it?
- How is the cloud service categorized?
- What evidence do we need?
- How should it appear in the SSP?
- How should it appear on the network diagram?
- Which integrations expand scope?
- What external service provider documentation is required?
- What contract clauses govern the environment?
The technology architecture and CMMC assessment strategy should agree.
Documenting Zoom for an assessor
Should Zoom Appear in the SSP?
If Zoom is part of the CMMC Assessment Scope, its role should be documented appropriately in the System Security Plan.
Describe what the service does, what information it handles, what security functions it provides, and how responsibilities are divided between the organization and provider.
Should Zoom Appear on the Network Diagram?
If it is in scope, the logical architecture should be represented appropriately.
A useful diagram might show:
Managed endpoint
→ Corporate network
→ Boundary security
→ Internet
→ Zoom for Government
and separately:
Identity provider
→ Zoom for Government
Zoom for Government
→ SIEM or logging
Zoom for Government
→ Approved integration
The diagram should make the security boundary understandable.
Should Zoom Appear in the Asset Inventory?
Applicable in scope cloud services and supporting assets should be documented according to current DoD CMMC scoping requirements.
The inventory should use terminology consistent with the organization's assessment scope.
What Evidence Should We Keep?
Depending on scope:
- Contract requirements
- Service agreement
- Authorization documentation
- Product boundary documentation
- Administrative settings
- User roles
- MFA configuration
- SSO configuration
- Recording settings
- Chat settings
- File transfer settings
- Retention
- AI settings
- Integration inventory
- Audit logs
- Change records
- User training
- Policies
- Data flow diagrams
- Incident procedures
Evidence should demonstrate the implemented environment.
The five mistakes
What Is the Biggest Mistake?
Assuming:
"We are a defense contractor, so we must buy Zoom for Government."
That skips the scoping analysis.
What Is the Second Biggest Mistake?
Assuming:
"We already use commercial Zoom, so it must be fine for CUI."
That skips the cloud authorization analysis.
What Is the Third Biggest Mistake?
Assuming:
"Zoom for Government is FedRAMP authorized, so our company is now CMMC compliant."
That confuses a cloud authorization with an organizational cybersecurity assessment.
What Is the Fourth Biggest Mistake?
Ignoring integrations.
CUI can leave an authorized collaboration platform through:
- CRM
- AI
- Storage
- Ticketing
- APIs
- Webhooks
- Downloads
The connected architecture matters.
What Is the Fifth Biggest Mistake?
Buying the government platform before checking feature requirements.
Government environments can differ from commercial environments.
Validate the exact capabilities your users need.
What to do right now
What Should a Small Defense Contractor Do Right Now?
1. Review Your Contracts
Identify CMMC, DFARS, CUI, cloud, and DoD requirements.
2. Identify CUI
Know what controlled information your organization handles.
3. Map Collaboration Workflows
Determine whether CUI enters meetings, phone, chat, recordings, transcripts, whiteboards, SMS, voicemail, or AI.
4. Identify Your Current Zoom Environment
Commercial Zoom, Zoom for Government, Zoom for Defense, or another architecture.
5. Identify the Exact Products Used
Meetings, Phone, Contact Center, Team Chat, Rooms, AI, APIs, Marketplace.
6. Verify Authorization Status
Verify the current authorization for the specific service offering and products.
7. Map Integrations
Identify every system exchanging information with Zoom.
8. Review Endpoints
Understand how users access the environment.
9. Review Identity
SSO, MFA, administrators, roles, guests.
10. Review Data Persistence
Recordings, transcripts, voicemail, chat, files, AI outputs.
11. Determine CMMC Scope
Document the environment according to current DoD guidance.
12. Decide the Architecture
Commercial environment with CUI prohibited, government environment for CUI, separate environments, or another defensible design.
13. Document the Decision
Update policies, SSP, diagrams, inventory, procedures, and training.
14. Validate With Qualified CMMC Professionals
Do this before the formal assessment.
Decision checklist
Zoom and CMMC Decision Checklist
Contract
- DoD contracts identified
- DFARS clauses reviewed
- CMMC requirement identified
- Cloud requirements reviewed
- Customer specific requirements reviewed
Information
- FCI identified
- CUI identified
- CUI categories documented
- Collaboration workflows mapped
Zoom Services
- Meetings reviewed
- Phone reviewed
- Contact Center reviewed
- Team Chat reviewed
- Whiteboard reviewed
- Rooms reviewed
- Recording reviewed
- Transcription reviewed
- AI Companion reviewed
- APIs reviewed
- Marketplace applications reviewed
Platform
- Current Zoom environment identified
- Specific service offering documented
- FedRAMP status verified
- Authorization boundary reviewed
- IL4 requirements reviewed where applicable
- Product inclusion verified
- Feature availability verified
Security
- SSO reviewed
- MFA reviewed
- Administrative roles reviewed
- Guest access reviewed
- Recording controls reviewed
- Chat controls reviewed
- File controls reviewed
- Retention reviewed
- Logging reviewed
- Endpoint access reviewed
Integrations
- CRM documented
- Email documented
- Calendar documented
- Storage documented
- AI integrations documented
- SIEM documented
- APIs documented
- Webhooks documented
CMMC Documentation
- Asset inventory updated
- SSP updated
- Network diagram updated
- Data flow diagram updated
- External providers documented
- Policies updated
- User training updated
- Evidence library updated
Decision
- Commercial Zoom use cases defined
- CUI prohibited or permitted explicitly
- Zoom for Government requirement determined
- Zoom for Defense requirement evaluated where applicable
- Migration requirements reviewed
- CMMC professional validation completed
Frequently asked questions
Does CMMC require Zoom for Government?
Not automatically. The decision depends on whether CUI will be processed, stored, or transmitted in the Zoom environment, the applicable contract requirements, and the authorization status of the specific cloud service offering.
Can a defense contractor use commercial Zoom?
Potentially, yes, for workflows where the selected offering and use comply with the organization's contractual and security requirements. Being a defense contractor does not automatically prohibit commercial Zoom.
Can commercial Zoom be used for CUI?
If a cloud service offering processes, stores, or transmits CUI under applicable DFARS requirements, the contractor must ensure the specific offering meets the required FedRAMP Moderate or DoD equivalency requirements. Verify the actual offering rather than relying on vendor wide certifications.
Is Zoom for Government FedRAMP authorized?
Yes. Zoom identifies Zoom for Government as FedRAMP Moderate authorized.
Is Zoom for Government CMMC certified?
CMMC certification applies to organizations and assessment scopes under the DoD CMMC program. A cloud service's authorization can support the contractor's architecture but does not automatically certify the contractor.
Is FedRAMP the same as CMMC?
No. FedRAMP addresses cloud service security authorization. CMMC evaluates the contractor's implementation of applicable cybersecurity requirements.
Is DoD IL4 the same as CMMC Level 2?
No. IL4 is a DoD cloud impact level. CMMC Level 2 is an organizational cybersecurity assessment level associated with protection of CUI.
Does Zoom for Government include Zoom Phone?
Zoom identifies Zoom Phone among products available in the Zoom for Government environment. Verify current authorization and feature availability for the intended deployment.
Does Zoom for Government include Contact Center?
Yes. Zoom announced in June 2024 that Contact Center was authorized within Zoom for Government, inside the existing FR1825941347A boundary rather than as a separate FedRAMP package. Verify current status before deployment.
Is AI Companion available in Zoom for Government?
Yes. Zoom announced in September 2024 that AI Companion was authorized within Zoom for Government, inside the same FR1825941347A boundary. Verify current capabilities and authorization status.
Are all commercial Zoom features available in Zoom for Government?
Not necessarily. Zoom advises customers to check specific product and feature availability.
Can Zoom recordings contain CUI?
Yes. If a meeting or call contains CUI and it is recorded, the recording may contain CUI.
Can Zoom transcripts contain CUI?
Yes. Transcription can turn spoken CUI into persistent text.
Can Zoom AI summaries contain CUI?
Yes. AI generated output can preserve or restate controlled information from the source interaction.
Can integrations expand CMMC scope?
Yes. CRM, email, storage, AI, APIs, and other integrations can create additional CUI processing, storage, and transmission paths.
Related articles
- Zoom + Microsoft Teams: Complete Integration Guide — do not design commercial Operator Connect into GCC High; Microsoft delivers Phone System there via Direct Routing.
- CMMC for the small defense supplier: what did the 48 CFR rule change? — how CMMC became a condition of award, and what the 2026 suspension did.
- What network monitoring evidence does a CMMC Level 2 assessment ask for? — the evidence an assessor will actually ask you to produce.
- Does Zoom train AI on your meetings? — the commercial-platform data question behind the AI Companion scoping problem.
- Zoom Epic FHIR Integration — commercial healthcare video visits (Hyperspace / MyChart). That Marketplace app is not a FedRAMP authorization and not a CMMC Level 2 certification.
References
Primary sources only — NIST, FedRAMP, OMB and the CFR, plus Zoom's own trust pages where the claim is Zoom's to make. Where a claim could not be sourced, this article says so rather than repeating it.
- NIST — Cryptographic Module Validation Program, validated modules search— searched 18 August 2026 for vendor Zoom and Zoom Video Communications across active, historical and revoked certificates. Result each time: "No certificates match the search criteria."
- FedRAMP Marketplace — Zoom for Government— package FR1825941347A, Moderate. FedRAMP's own listing describes the authorization in the past tense: Zoom for Government "previously became FedRAMP-Authorized by the Joint Authorization Board (JAB)." Contact Center and AI Companion sit inside this boundary.
- OMB Memorandum M-24-15 — Modernizing the Federal Risk and Authorization Management Program— 25 July 2024. The basis for retiring the JAB/Agency authorization tiers in favour of a single FedRAMP Authorized designation under the FedRAMP Board.
- FedRAMP — Moving to One FedRAMP Authorization: an update on the JAB transition— FedRAMP's own account of the change: "we are moving away from defining different tiers of authorizations (previously JAB and Agency) and toward one designation of FedRAMP Authorized."
- Zoom — FedRAMP compliance— Zoom's own FedRAMP page. Note what is not on it: no FIPS claim, and no "continental United States" data-residency wording.
- Zoom — Department of Defense compliance— the source for the IL4 position: "Zoom for Government (ZfG) has achieved Provisional Authorization (PA) from Defense Information Systems Agency (DISA) for the DoD at IL4." DISA's catalogue is not publicly searchable, so this rests on Zoom's own attestation.
- eCFR — 32 CFR part 170, CMMC Program— § 170.14 pins Level 2 to NIST SP 800-171 Revision 2; Level 1 is the fifteen requirements at 48 CFR 52.204-21.
- Acquisition.gov — DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting— the clause that drives the FedRAMP Moderate equivalency requirement when an external cloud service provider processes, stores or transmits CUI.
Managed Zoom and network services for defense suppliers, SDVOSB. We map where CUI actually enters a communications platform — meetings, recordings, transcripts, chat, phone, AI summaries and integrations — and document the result in a form an assessor will accept. CAGE 9QJS2 · UEI NJ7FKBV9X6L1. Support: (888) 989-4872 · support@adampulse.us