State of M&A Data Rooms — Q2 2026 Read the report →
Peony LogoPeony

CMMC-Compliant File Sharing in 2026: Levels, Requirements, and 8 Platforms Mapped

Co-founder and CEO at Peony. I built the data room platform with a background in document security, file systems, and AI. Founded Peony in 2021 in San Francisco.

CMMC-Compliant File Sharing in 2026: Levels, Requirements, and 8 Platforms Mapped

Last updated: July 2026

Quick answer: "CMMC-compliant file sharing" is not a product you buy — CMMC certifies contractors, not software. What you buy is a platform whose controls can pass, then you scope it into your System Security Plan (SSP). The first gate is what data you touch: if you handle only Federal Contract Information (FCI), CMMC Level 1 is 15 basic safeguards and an annual self-assessment; the moment Controlled Unclassified Information (CUI) flows down, you are at Level 2 — 110 controls identical to NIST SP 800-171 Revision 2 — and DFARS 252.204-7012 requires any cloud service that stores CUI to meet the "FedRAMP Moderate baseline or equivalent." That splits the market in two: platforms with a full FedRAMP Moderate authorization on the marketplace (Kiteworks, Box for Government, Sharetru, and Microsoft 365 GCC High at FedRAMP High) versus platforms claiming DoD-recognized FedRAMP Moderate equivalency (PreVeil, Egnyte) — a distinction where the contractor bears the burden of validating the body of evidence. The archetype decision — a full GCC High migration, a small CUI enclave, or keeping the FCI-and-deal layer on a lighter tool — matters more than the brand. Peony's honest position: it is not FedRAMP authorized or equivalent and not CMMC-certified, so it is not a CUI system of record; it fits the FCI-tier and deal layer (proposal and teaming shares, supplier drawings that are FCI-not-CUI, and Defense Industrial Base M&A rooms).

Three paths to CMMC-compliant file sharing: GCC High migration, CUI enclave, and the FCI-plus-deal layer

I'm Deqian Jia, co-founder of Peony, a data room company. Today 6,800+ customers run their document sharing on our platform, which holds $26.3B in client assets — and a growing share of them are in the Defense Industrial Base (DIB), the roughly 220,000 companies the Department of Defense estimates its CMMC program will eventually touch (per DoD's regulatory impact analysis; the count is revised across the program and acquisition rules, so treat it as "about 220,000," not a fixed figure). The question I get from those companies is almost always some version of "what is CMMC-compliant file sharing, and which tool do I buy?" — and the honest answer starts by correcting the question.

There is no such thing as a CMMC-certified file-sharing tool. CMMC (Cybersecurity Maturity Model Certification) certifies contractors — organizations that hold FCI or CUI — not the software they use. Microsoft says it plainly on its own CMMC page: its cloud services "provide capabilities that can help support" CMMC requirements, and "CMMC compliance depends on customer configuration, implementation, and operational controls, as well as the use of qualified assessors and partners." That is the frame for this entire post. A platform is a component of your compliance environment; your assessor — a Certified Third-Party Assessor Organization (C3PAO) or, at the top level, the government — decides whether that environment passes. So the useful work is not hunting for a badge. It is (1) knowing which CMMC level your contracts trigger, (2) knowing what the rules actually require of a file-sharing system, and (3) choosing the right architecture — full migration, enclave, or a lighter layer — for a shop your size. This post walks all three, then maps eight platforms to them.

This is the CMMC-specific companion to our broader ITAR-compliant data room guide and defense solutions overview. It is general information, not legal or compliance advice — your C3PAO and your contracting officer own the actual determinations.

What does CMMC actually require for file sharing?

CMMC requires that the security controls governing how you store, transmit, and grant access to federal information — including the files you share — meet a defined control set for the level your contract assigns, and that you can prove it through a self-assessment or a third-party assessment. It does not prescribe a specific product or feature list; it prescribes controls, and file sharing is where several of those controls live: access control, identification and authentication, audit and accountability, and protection of data in transit and at rest. The single most important thing to get right first is which level applies, because the jump from Level 1 to Level 2 changes almost everything.

The dividing line is the data. FCI — Federal Contract Information — is defined at FAR 48 CFR 4.1901 as information "not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service," excluding public information and simple transactional data. CUI — Controlled Unclassified Information — is defined at 32 CFR 2002.4 as information the Government (or an entity acting for it) creates or possesses "that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls." FCI maps to Level 1; CUI maps to Level 2 and, for the most sensitive programs, Level 3. That mapping is the spine of the whole decision.

Here is what each level requires:

LevelControl setWhat it assessesHow it is assessedPOA&M / conditional status
Level 1The 15 basic safeguarding requirements at FAR 52.204-21(b)(1)(i) through (xv)Basic protection of FCIAnnual self-assessment; results and an annual affirmation submitted in SPRSNo POA&Ms permitted — you must meet all 15
Level 2110 requirements identical to NIST SP 800-171 Revision 2Protection of CUIEither a self-assessment (Level 2 Self) or a triennial C3PAO certification (Level 2 C3PAO)Conditional status at a minimum 80% score; remaining items on a POA&M closed within 180 days
Level 3The 110 Level 2 requirements PLUS 24 selected enhanced requirements from NIST SP 800-172Protection of CUI against advanced persistent threatsGovernment-led assessment by DCMA's DIBCAC; a Final Level 2 (C3PAO) is a prerequisiteAssessed against NIST SP 800-172A

A few points on that table are easy to get wrong, so I will be precise. First, the count at Level 1 is 15 because FAR 52.204-21(b)(1) runs from item (i) through item (xv). Second — and this is the fact most stale content gets wrong — Level 2 is locked to NIST SP 800-171 Revision 2, not Revision 3. NIST published 800-171 Rev 3 in May 2024, but the operative CMMC rule at 32 CFR 170.14(c)(3) states the Level 2 requirements "are identical to the requirements in NIST SP 800-171 R2" and incorporates R2 by reference. The 110-control number is the Rev 2 count. Egnyte's own CMMC page independently corroborates the split — "CMMC includes 15 Level 1 practice requirements and 110 Level 2 practice requirements" — as does Sharetru's blog, titled "Meeting NIST SP 800-171 Rev 2." Third, Level 3 is not "24 requirements"; it is the full Level 2 baseline plus 24 enhanced controls selected from 800-172, and it is assessed by the government (DIBCAC), not a commercial C3PAO.

The rule timeline: two rules, four phases

Two separate federal rules put CMMC into force, and people conflate them constantly. The program rule — the framework — was published in the Federal Register on October 15, 2024 (89 FR 83092) and became effective December 16, 2024, codified at 32 CFR Part 170. It is the rule that establishes the levels, the assessment process, and the phased rollout. The acquisition rule — the one that actually puts CMMC clauses into contracts — is DFARS Case 2019-D041, published September 10, 2025 and effective November 10, 2025; it adds DFARS 252.204-7021 ("Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements") and 252.204-7025. In short: the program rule defines the game, and the acquisition rule starts the clock.

That clock is a four-phase rollout defined at 32 CFR 170.3(e), which reads in part: "Implementation of CMMC Program requirements will occur over four (4) phases." The structure is worth quoting closely, because the discretionary steps get oversimplified:

  • Phase 1 "begins on the effective date of the complementary 48 CFR part 204 CMMC Acquisition final rule" (November 10, 2025). DoD intends to require CMMC Status of Level 1 (Self) or Level 2 (Self) as a condition of contract award. Note that Level 2 (Self) can be required from day one — Phase 1 is not "Level 1 only."
  • Phase 2 begins one year after Phase 1. It adds the requirement for Level 2 (C3PAO) as a condition of award, though DoD "may, at its discretion, delay" that to an option period, and "may also, at its discretion, include the requirement for CMMC Status of Level 3 (DIBCAC)."
  • Phase 3 begins one year after Phase 2. It makes Level 2 (C3PAO) a condition of award and of exercising an option, and DoD "intends to include the requirement for CMMC Status of Level 3 (DIBCAC)" as a condition of award (again with discretion to delay to an option period).
  • Phase 4, full implementation, begins one year after Phase 3, when "DoD will include CMMC Program requirements in all applicable DoD solicitations and contracts including option periods on contracts awarded prior to the beginning of Phase 4."

For the 45-person shop this post is written for, the practical read is: if you handle FCI, Level 1 self-assessment is already in scope; if CUI is flowing down, Level 2 (Self) can appear in a solicitation now, and the C3PAO requirement lands as the phases advance. Waiting for a specific date is the wrong mental model — the requirement arrives with the contract, and the phase structure means it arrives sooner for CUI work than most small suppliers expect.

Do you need FedRAMP Moderate authorized file sharing to handle CUI?

You need a cloud service that meets the FedRAMP Moderate baseline or its equivalent — and the word "equivalent" is doing enormous work in that sentence, because it is the difference between two categories of platform that get marketed as if they were the same thing. The requirement itself comes from DFARS 252.204-7012, the clause that governs covered defense information (which includes CUI) in external cloud services. The operative language, at 252.204-7012(b)(2)(ii)(D), is that when a contractor uses an external cloud service provider to store, process, or transmit CUI, "the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline" — plus the clause's incident-reporting, malware, media-preservation, forensic-access, and damage-assessment obligations. So no, you do not strictly need a platform sitting on the FedRAMP marketplace; you need one that meets that baseline or a validated equivalent.

Here is the distinction that matters, and it is the accuracy beat of this whole post because vendors blur it:

  • FedRAMP Moderate authorized means the cloud service has been through the FedRAMP process and holds an authorization listed on the FedRAMP marketplace — assessed by an accredited Third-Party Assessment Organization (3PAO) and continuously monitored. This is a public, verifiable status. Kiteworks, Box for Government, and Sharetru hold full FedRAMP authorizations (Box and GCC High at the higher FedRAMP High level).
  • FedRAMP Moderate equivalent means the vendor asserts it meets the FedRAMP Moderate control set under the DoD's equivalency standard — defined by a December 2023 DoD CIO memo — without holding a marketplace authorization. The equivalency bar is strict: it requires meeting 100% of the FedRAMP Moderate baseline controls with no open plans of action, assessed by a 3PAO, and documented in a "body of evidence." PreVeil and Egnyte position themselves here, claiming FedRAMP Moderate equivalency, not authorization.

Why does the distinction matter to you rather than being vendor trivia? Because with the equivalency path, the contractor bears the burden. With an authorized platform, the authorization is the government's own artifact — you can point to the marketplace listing. With an equivalent platform, you as the contractor are responsible for holding and validating the vendor's body of evidence and being prepared to defend it to your assessor. That does not make equivalency worse — PreVeil, for instance, states it was the first cloud service provider to meet the DoD's FedRAMP Moderate equivalency requirement, and that DIBCAC assessors concurred it met the criteria — but it does mean you should collect and retain that evidence package the same way you would any other assessment artifact. The one thing you must never do is treat "equivalent" and "authorized" as interchangeable words in your SSP; they describe different things, and conflating them is a factual error an assessor can catch. When a vendor says "FedRAMP," read the next word.

Is emailing CUI drawings to a supplier a CMMC violation?

In almost every real-world case, yes — emailing CUI drawings as an ordinary attachment fails the controls a Level 2 assessment checks, and it is the single most common practice small suppliers need to stop first. The reason is not that "email is banned"; it is that standard email breaks three specific control families at once. First, protection of data in transit: NIST SP 800-171 requires cryptographic protection of CUI, and ordinary email does not guarantee end-to-end, FIPS-validated encryption from your outbox to the recipient's inbox — it hops through mail servers that may or may not encrypt each leg. Second, access control: once a drawing is sent as an attachment, you have no way to restrict who ultimately opens it. It can be forwarded, saved, and re-shared with no gate, which is the opposite of the "limit access to authorized users" requirement. Third, audit and accountability: you cannot produce a per-recipient, per-access log of who opened the file and when — which is exactly the evidence an assessor asks for.

The practical answer, then, is not "never send CUI to a supplier" — you obviously have to — but "send it through a channel that keeps the encryption, the access control, and the audit trail intact." A compliant alternative looks like one of three things: a CUI-capable file-sharing platform (FedRAMP-authorized or a validated equivalent) where the supplier is a named, authenticated recipient and every access is logged; a secure email system built on that same authorized/equivalent backbone (PreVeil, for example, is end-to-end-encrypted email plus file sharing on a FedRAMP-Moderate-equivalent footing); or, inside a GCC High tenant, sharing through the tenant's own controlled services rather than as an open attachment. The common thread is that the file lives in a controlled boundary and the recipient reaches it by authenticating, so you retain the ability to say exactly who accessed which CUI file and when.

One honest nuance for the small shop: your supplier's hygiene is partly your problem. If you share CUI to a supplier who is themselves in scope, they inherit the same obligations, and the flow-down clauses in your contract are what push those requirements down the chain. This is why "just email it" is not a shortcut you can quietly keep using — the moment CUI is involved, the channel is a control, and the control is assessed.

The three paths: GCC High migration, CUI enclave, or a lighter FCI-and-deal layer

Once you know your level, the real decision is architectural, and it comes down to three paths. Choosing the wrong one is how a 45-person shop ends up either overspending on an enterprise migration it did not need or, worse, quietly out of compliance because it never scoped its CUI at all. The thesis worth internalizing: compliance is a property of the boundary you draw, not the brand you buy. The narrower and better-defined that boundary, the cheaper and more defensible your assessment.

Path 1 — Full GCC High migration. You move the whole company — email, files, identity, collaboration — into Microsoft 365 GCC High (or an equivalent sovereign environment) and make that tenant your compliance boundary. Microsoft states GCC High "supports organizations in meeting CMMC Level 2 and Level 3 requirements (when configured appropriately), FedRAMP High, DFARS, DISA Cloud Computing Security Requirement Guide (CC SRG) Impact Level 4, and ITAR." This is the right path when CUI is pervasive — it touches most roles, most files, and most of your daily workflow — or when a contract requires the ITAR sovereignty and IL4 handling that only GCC High offers (plain GCC is only Impact Level 2 and, in Microsoft's words, "isn't suitable to hold CUI Specified"). The trade-off is cost and effort: GCC High is a gated, licensing-and-validation-heavy program, not a checkout-cart purchase, and migrating a whole company is a multi-month project. For a shop where CUI is everywhere, it is often still the cleanest answer.

Path 2 — A CUI enclave. Instead of migrating the whole company, you stand up a small, validated boundary — an enclave — that holds only CUI and only the handful of people who touch it, and you leave the rest of the business on its existing tools. This is frequently the best fit for the archetypal small subcontractor: CUI arrives from one or two primes, only your engineering lead and a couple of others ever handle it, and there is no reason to drag your entire 45-person operation through a full migration. The enclave can be a purpose-built CUI platform (PreVeil's model is explicitly enclave-shaped for exactly this SMB case; Egnyte's "secure data enclave" is the same idea) or a scoped GCC High tenant used only for the CUI workflow. The win is that your assessment scope shrinks to the enclave, which makes both the cost and the C3PAO assessment dramatically smaller. The discipline it demands is real: you must actually keep CUI inside the enclave and prove it never leaks into the lighter side of the business.

Path 3 — Keep the FCI-and-deal layer on a lighter tool. Not everything a defense contractor shares is CUI. Proposals and teaming agreements before award, supplier drawings that are FCI but not CUI, NDA-gated business documents, and the M&A data room when you sell the company — these live at the FCI tier or outside CMMC's CUI scope entirely, and forcing them into a heavyweight CUI platform is overkill. This is the layer where a purpose-built data room fits: it needs strong access control, NDA gates, watermarking, screenshot protection, and audit trails, but it does not need — and should not claim — CUI hosting. Most small contractors end up with a combination: an enclave (Path 2) for the CUI that flows down, and a lighter deal-and-FCI layer (Path 3) for everything else, with a full GCC High migration (Path 1) reserved for when CUI genuinely saturates the business.

The enclave pattern is the one most small contractors under-appreciate, so it is worth stating directly: the goal is to make your CUI boundary as small as you honestly can. A tiny, well-documented enclave that ten people touch is far easier to secure, assess, and afford than a company-wide environment where CUI could be anywhere. Draw the smallest boundary that holds all your CUI, put a FedRAMP-authorized or validated-equivalent platform around it, and keep the rest of your sharing — the FCI and the deal work — on tools sized for that lighter job.

Which platforms fit which path? (8 platforms mapped)

Here are eight platforms mapped to the three paths, with each vendor's FedRAMP status stated in its own exact terms — because, as the accuracy section above argued, "authorized" and "equivalent" are not synonyms. Every CMMC positioning claim below is the vendor's own; I attribute each one rather than assert it as fact, and I hedge pricing wherever the vendor does not publish a firm number. A recurring truth to keep in mind: none of these platforms is "CMMC-certified," because that status does not exist for products — each one provides capabilities that can support your CMMC compliance, which your assessor then evaluates.

PlatformFedRAMP status (exact language)CMMC positioning (vendor's own claim, attributed)Published priceFits which path
Microsoft 365 GCC HighFedRAMP High; DISA CC SRG Impact Level 4; ITAR-capablePer Microsoft, GCC High "supports organizations in meeting CMMC Level 2 and Level 3 requirements (when configured appropriately)"Licensing- and validation-gated (no simple public per-seat price; purchased via authorized reseller after an eligibility validation)Path 1 (full migration); scoped Path 2
PreVeilFedRAMP Moderate Equivalent (PreVeil states it was the first CSP to meet the DoD FedRAMP Moderate Equivalency requirement)Per PreVeil, supports "all 110 CMMC controls" for Level 2; cites customers with "perfect 110/110 CMMC scores""PreVeil Pass" for SMB contractors "starting at $450/month" (published; fuller pricing is calculator/quote-based)Path 2 (CUI enclave)
KiteworksFedRAMP Moderate Authorized (independently assessed by Coalfire, continuously monitored since June 2017); FedRAMP High "In Process" for its Secure Gov CloudPer Kiteworks, its platform "supports 90% of Level 2 requirements for CMMC compliance" out of the box (a vendor-stated figure, not an independent assessment)Quote-based enterprise pricing (a self-serve Business tier (5-100 seats) is published around $25.50/user/month, but the government/CMMC configuration is quote-based)Path 2 (enclave); governance-heavy CUI
Box for GovernmentFedRAMP High Authorized (ATO via the U.S. Dept. of Veterans Affairs); DoD SRG Impact Level 4 (IL4), not IL5Per Box, a FedRAMP High environment that helps meet requirements including "DoD SRG IL4, NIST 800-171, FIPS 140-2"Quote-based (Box for Government / Enterprise tier; not the standard commercial price)Path 2 (enclave); enterprise CUI
EgnyteFedRAMP Moderate Equivalent ("EgnyteGov" government offering)Per Egnyte, "EgnyteGov's Compliance Center maps all 110 Level 2 controls to CMMC standards," delivered by "a proven FedRAMP Moderate Equivalent provider"Quote-based (EgnyteGov; commercial Egnyte lists around $10/user/month, but that is not the government tier)Path 2 (CUI enclave)
SharetruFedRAMP Moderate Authorized under a JAB-ATO ("Sharetru Federal")Per Sharetru, it "aligns with all 110 NIST SP 800-171 controls... directly supporting CMMC Level 2" and "satisfies the cybersecurity requirements under DFARS 252.204-7012"Quote-based (Sharetru Federal)Path 2 (enclave); secure file transfer of CUI
Commercial Microsoft 365 / Google WorkspaceCommercial tiers are not CUI-authorized (plain GCC is only Impact Level 2; commercial Workspace/365 is not a CUI boundary)No CUI claim; Microsoft is explicit that plain GCC "isn't suitable to hold CUI Specified." Adequate for FCI-only Level 1 when configured to the 15 safeguardsStandard commercial per-user pricingPath 3 (FCI-only, when commercial is enough)
PeonyNot FedRAMP authorized and not FedRAMP Moderate equivalent; SOC 2 Type IINot CMMC-certified and makes no CUI-hosting claim. Positioned for FCI-tier external sharing and DIB deal/M&A rooms — see the honest section belowFree $0 / Business $30 / Data Room $52 per admin/monthPath 3 (FCI-and-deal layer only)

Three reading notes on that table. First, the FedRAMP column is where the authorized-vs-equivalent line lives: Kiteworks, Box for Government, and Sharetru hold full authorizations (Box and GCC High at the higher FedRAMP High tier), while PreVeil and Egnyte claim DoD-recognized equivalency — collect their bodies of evidence accordingly. Second, on pricing, only PreVeil publishes a clean SMB entry number ("starting at $450/month" for PreVeil Pass); the enterprise and government tiers of the others are quote-based or licensing-gated, so any specific per-seat figure you see quoted for GCC High or Box for Government should be treated as an estimate, not a list price. Third, the "when commercial is enough" row is not a loophole — it is the honest read that if you handle only FCI and never CUI, commercial Microsoft 365 or Google Workspace, configured to the 15 Level 1 safeguards, can satisfy Level 1. The instant CUI enters, you move up to a platform in the authorized/equivalent group. For a broader, non-CMMC-specific comparison of the general file-sharing field, see our top 10 file-sharing solutions and enterprise file transfer guides; this post is the dedicated CMMC map.

Where a data room fits — and where it does not

Let me be completely unambiguous about where Peony fits, because the honest answer is the useful one. Peony is not FedRAMP authorized. Peony is not FedRAMP Moderate equivalent. Peony is not CMMC-certified — and it could not be, because CMMC certifies contractors, not products. Peony makes no claim to host CUI. If your contract requires a CUI system of record under DFARS 252.204-7012, Peony is the wrong tool, and I will point you to the right ones: for CUI, use a FedRAMP-authorized or validated-equivalent platform — Kiteworks, Box for Government, or Sharetru (authorized), or PreVeil or GCC High (equivalent/sovereign) — from the table above. This is the same honest-NO we hold on our defense page and in our ITAR guide: a platform can only support your compliance program by providing controls that map to requirements; your assessor, not any vendor, owns the CMMC call. Any vendor selling you a "CMMC-certified" or "CMMC-compliant" file-sharing product does not understand the regime.

So what is Peony for in the Defense Industrial Base? It is the Path 3 layer — the FCI-tier and deal work that does not belong in a CUI enclave:

  • NDA-gated proposal and teaming shares. Before award, you are circulating proposals, teaming agreements, and technical approaches that are sensitive and often FCI, but not CUI. Peony gates access behind NDA signatures, stamps every page with the viewer's identity via dynamic watermarks, and blocks screen capture with screenshot protection — so a proposal does not leak to a competitor.
  • Supplier drawings that are FCI, not CUI. Plenty of the drawings and specs a machine shop exchanges with a prime are Federal Contract Information rather than Controlled Unclassified Information. For that FCI-tier sharing, a data room with strong access control and a full audit trail is a right-sized fit — and keeps the heavyweight CUI platform reserved for actual CUI.
  • DIB M&A data rooms. When a defense-adjacent company raises capital or sells, the diligence data room holds financials, contracts, and cap-table material — deal documents, not CUI. This is squarely what Peony is built for: SOC 2 Type II infrastructure, AES-256 encryption at rest and TLS 1.3 in transit, mandatory 2FA, NDA gates, per-viewer watermarks, screenshot blocking, and exportable, timestamped audit trails (IP, device, and page-by-page view history).

The controls Peony brings to that layer are real and assessment-relevant even though Peony is not itself a CUI platform: NIST 800-171-aligned access controls, mandatory 2FA, granular per-group permissions, and complete audit trails that can support your NIST 800-171 access-control documentation and CMMC assessment-evidence collection for the FCI-tier systems in your scope. That is the ceiling — "supports CMMC readiness" and "CMMC-aligned audit trails," never "certified." The honest boundary is the same one I draw everywhere: Peony makes the right behavior enforceable and the record provable for the FCI-and-deal layer; it does not turn itself into a CUI system of record, and it does not replace your C3PAO. Today 6,800+ customers run on Peony precisely because that honest segmentation — the right tool for the right tier — is how you keep both your costs and your compliance defensible. For the full defense picture, see our defense and aerospace solution and the ITAR-compliant data room guide, which walks the parallel export-control lane.

What does CMMC-compliant file sharing cost?

The honest answer is that cost is driven far more by your architecture choice than by any single platform's sticker price — the enclave-versus-migration decision moves the number by an order of magnitude, not a few dollars per seat. Let me give you the figures that are actually published, hedge the ones that are not, and then walk the logic that determines the total.

On published prices, the cleanest SMB number in this market is PreVeil's: "PreVeil Pass" for small-to-medium contractors starts at $450/month per PreVeil's own site, with fuller pricing available through its CMMC cost calculator and tiered plans. That is a real entry point for a small shop putting its CUI in an enclave. For GCC High, there is no honest single per-user number to quote: it is licensing- and validation-gated, purchased through an authorized reseller after an eligibility validation, and the all-in cost includes licensing, migration labor, and often a managed-service partner. Anyone quoting you a precise "GCC High costs $X/user/month" is quoting an estimate; the defensible statement is that it is materially more expensive and more effort than a commercial tenant, which is exactly why the enclave path exists. Kiteworks, Box for Government, Egnyte's EgnyteGov, and Sharetru Federal are likewise quote-based at their government tiers.

The cost logic that actually matters is enclave versus full migration. A full GCC High migration prices your whole company — every seat, plus the migration project and ongoing management — into the compliance boundary. An enclave prices only the handful of people and files that touch CUI. For a 45-person shop where CUI touches five people, the enclave can be a small fraction of a company-wide migration, because you are paying to secure and assess a small boundary rather than the entire business. That is the single biggest lever on your CMMC file-sharing cost: shrink the CUI boundary, and the cost shrinks with it — the platform price is often the smaller half of the equation next to assessment scope and migration labor. (For the adjacent question of what a diligence data room costs, our virtual data room cost guide has the full breakdown; FedRAMP, not CMMC, is the government cert named there.)

For the FCI-and-deal layer — Path 3 — the numbers are simple and public. Peony is Free at $0, Business at $30 per admin per month, and Data Room at $52 per admin per month, with no per-viewer, per-page, or per-link fees — so your suppliers, primes, and diligence counterparties are free recipients and never count against your admin bill. That layer is a rounding error against a CUI migration, which is the whole point of segmenting: you pay enclave/migration money only for the CUI that genuinely requires it, and a right-sized data-room price for the FCI and deal work that does not. Set against the cost of failing a Level 2 assessment — a lost or delayed contract, since Phase-appropriate CMMC status is a condition of award — getting the architecture right is the cheap decision.

Frequently Asked Questions

We're a 45-person machine shop with CUI starting to flow down — should we go Microsoft GCC High or a dedicated platform like PreVeil for compliant file sharing?

It depends on how much of your business CUI actually touches. If CUI is pervasive across roles and workflows, a full Microsoft 365 GCC High migration makes your whole tenant the compliance boundary — Microsoft says GCC High "supports organizations in meeting CMMC Level 2 and Level 3 requirements (when configured appropriately)." But for a 45-person shop where CUI arrives from one or two primes and only a few people touch it, a dedicated enclave is usually the better fit and far cheaper. PreVeil is built for exactly this SMB case (it claims DoD FedRAMP Moderate Equivalency and support for "all 110 CMMC controls," with PreVeil Pass starting at $450/month). The principle: draw the smallest honest CUI boundary you can, put an authorized or validated-equivalent platform around it, and keep the rest of the business on lighter tools. Your assessor owns the final call.

When is commercial Microsoft 365 actually enough for CMMC, and when does GCC High become necessary?

Commercial Microsoft 365 (or Google Workspace) can be enough when you handle only Federal Contract Information and never Controlled Unclassified Information — CMMC Level 1 is 15 basic safeguards, and a properly configured commercial tenant can meet them. The moment CUI flows down, commercial tiers fall short: plain GCC is only DISA Impact Level 2, and Microsoft states it "isn't suitable to hold CUI Specified." GCC High becomes necessary when CUI is pervasive across your environment, or when a contract requires the US sovereignty, FedRAMP High, IL4 handling, or ITAR capability that only GCC High offers. The middle path many small contractors miss: rather than migrating everything to GCC High, put just the CUI in a small enclave and leave the rest of the business on commercial tools. So the honest test is your data, not your size — FCI-only can stay commercial; CUI moves you up.

Do I need FedRAMP Moderate authorized file sharing to handle CUI from our primes?

You need a cloud service that meets the FedRAMP Moderate baseline "or equivalent" — not necessarily a full authorization. DFARS 252.204-7012 requires that a cloud provider storing, processing, or transmitting CUI "meets security requirements equivalent to those established by the Government for the FedRAMP Moderate baseline." That "or equivalent" opens two paths. FedRAMP Moderate authorized means a marketplace-listed authorization assessed by a 3PAO and continuously monitored (Kiteworks, Box for Government, Sharetru; Box and GCC High at FedRAMP High). FedRAMP Moderate equivalent means the vendor meets the same controls under the DoD's December 2023 CIO memo standard without a marketplace listing (PreVeil, Egnyte). The catch: with equivalency, you the contractor bear the burden of holding and validating the vendor's body of evidence for your assessor. Never treat "authorized" and "equivalent" as interchangeable in your SSP — they describe different things.

Is emailing CUI drawings to a supplier or prime a CMMC violation?

In almost every real case, yes — ordinary email fails three control families a Level 2 assessment checks. Protection in transit: standard email does not guarantee end-to-end, FIPS-validated encryption across every mail hop. Access control: once sent as an attachment, a drawing can be forwarded and re-shared with no gate, breaking the "limit access to authorized users" requirement. Audit and accountability: you cannot produce a per-recipient log of who opened the file and when. The fix is not "never share with suppliers" — it is sharing through a controlled channel: a CUI-capable platform (FedRAMP-authorized or validated-equivalent) where the recipient authenticates and every access is logged, secure email on that same backbone (PreVeil), or a GCC High tenant's controlled services rather than an open attachment. The file must live in a controlled boundary so you can prove exactly who accessed which CUI file and when.

We only handle FCI today — do we need Level 2-grade file sharing now, or can we wait for the CUI contract?

If you genuinely handle only Federal Contract Information today, you are at CMMC Level 1 — 15 basic safeguards and an annual self-assessment — and you do not need Level 2-grade CUI file sharing yet. A properly configured commercial Microsoft 365 or Google Workspace can meet Level 1. But "wait" is risky if a CUI contract is in your pipeline, because under the 32 CFR 170.3(e) phased rollout, Level 2 (Self) can appear in a solicitation as a condition of award now, and standing up a compliant CUI environment takes time you may not have between award and start. The pragmatic middle path: keep your FCI and pre-award proposal work on a right-sized tool today, but plan your CUI enclave before the contract lands rather than after. Scope it, price it, and know which platform you will use — so the CUI requirement does not catch you flat.

Will Dropbox or Google Drive fail us at a CMMC assessment?

For CUI, consumer or standard-commercial Dropbox and Google Drive will generally fail, for the same reasons ordinary email does: they do not sit on a FedRAMP-authorized or validated-equivalent footing as DFARS 252.204-7012 requires for CUI in the cloud, and out of the box they lack the access control, FIPS-validated encryption posture, and per-access audit evidence a Level 2 assessment expects. Standard Google Workspace is not a CUI boundary, and plain link-sharing defeats access control. For FCI-only Level 1, a properly configured commercial tier can meet the 15 safeguards — the failure mode is specifically CUI. If CUI is in scope, move it into a CUI-capable enclave (PreVeil, Egnyte, GCC High) or an authorized platform (Kiteworks, Box for Government, Sharetru). The honest rule: the tool is not automatically disqualified for FCI, but it is the wrong home for CUI, and your C3PAO checks how you share externally.

Is a virtual data room CMMC compliant for sharing proposal documents and supplier drawings?

No data room is "CMMC compliant" as a product — CMMC certifies contractors, not software — but a data room is a strong fit for the FCI-tier and deal layer, which is different from CUI. Proposals and teaming agreements before award, supplier drawings that are FCI rather than CUI, and M&A diligence documents do not require a FedRAMP-authorized CUI system; they require strong access control, NDA gates, watermarking, screenshot blocking, and audit trails. That is exactly what a purpose-built data room like Peony provides (SOC 2 Type II, AES-256, mandatory 2FA, per-viewer watermarks, exportable page-by-page audit logs). The honest boundary: for actual CUI under DFARS 252.204-7012, use a FedRAMP-authorized or validated-equivalent platform (Kiteworks, Box for Government, Sharetru, PreVeil, GCC High) — not a data room. Peony makes no CUI-hosting claim; it fits the FCI-and-deal work that sits alongside your CUI environment, not inside it.

How much does GCC High cost for a 45-person defense contractor — and what's the cheaper compliant path?

There is no honest single per-user price for GCC High: it is licensing- and validation-gated, bought through an authorized reseller after an eligibility check, and the real cost includes licensing plus migration labor and often a managed-service partner — materially more than a commercial tenant. Anyone quoting a precise "$X/user/month" for GCC High is estimating. The cheaper compliant path for most small shops is an enclave: put only the CUI and the few people who touch it into a small validated boundary (PreVeil Pass starts at $450/month for SMB contractors), and leave the rest of the business on lighter tools. Because an enclave shrinks both your platform spend and your assessment scope, it is often a fraction of a company-wide GCC High migration. The biggest cost lever is boundary size — shrink the CUI boundary and the cost shrinks with it. Reserve full GCC High for when CUI is pervasive.

Does CUI file sharing require FIPS 140-2 validated encryption, or is any strong encryption acceptable?

For CUI, the relevant standard is FIPS-validated cryptography, not merely "strong" encryption — this is a point where marketing language and assessment language diverge. NIST SP 800-171 (which CMMC Level 2 assesses, at Revision 2) calls for FIPS-validated cryptographic modules to protect CUI, and DFARS 252.204-7012 ties CUI cloud services to the FedRAMP Moderate baseline "or equivalent," which itself expects validated cryptography. In practice that means the encryption module must carry a FIPS 140-2 (or successor) validation, not just implement AES. This is why CUI-focused platforms specifically cite FIPS validation — Sharetru notes FIPS 140-3 certified modules with AES-256 and TLS 1.3; PreVeil cites FIPS 140-3. AES-256 implemented in a non-validated module is generally not sufficient on its own for CUI. Confirm the specific validation with the vendor and document it in your SSP; your assessor will look for the validation, not the algorithm name alone.

What file-sharing controls does a Level 2 assessment actually check — audit logs, access control, SSP documentation?

A Level 2 assessment evaluates all 110 NIST SP 800-171 Revision 2 requirements, and several land directly on file sharing. Access control: whether you limit CUI access to authorized users and restrict external sharing per identity rather than open links. Identification and authentication: whether access is authenticated, typically with multi-factor authentication. Audit and accountability: whether you log access events and can produce who accessed which file, when — the per-access record. Encryption: whether CUI is protected in transit and at rest with FIPS-validated cryptography. Crucially, the assessor also checks your documentation — your System Security Plan must describe how each control is implemented for your file-sharing system, and your evidence must match practice. A conditional Level 2 status is available at a minimum 80% score with remaining items on a POA&M closed within 180 days. The through-line: controls plus provable evidence plus accurate SSP documentation, not a product label.

Sources

  • 32 CFR Part 170 (CMMC Program rule) — phased rollout — 32 CFR 170.3(e), the four-phase implementation structure: ecfr.gov
  • 32 CFR 170.14 (CMMC level security requirements) — Level 1 = FAR 52.204-21(b)(1)(i)–(xv) (15 requirements); Level 2 = "identical to the requirements in NIST SP 800-171 R2" (110); Level 3 = selected 800-172 enhanced requirements: ecfr.gov
  • CMMC Program final rule (89 FR 83092) — published October 15, 2024, effective December 16, 2024; the ~220,000 affected DIB entities estimate (per the regulatory impact analysis): federalregister.gov
  • DFARS Case 2019-D041 (CMMC acquisition final rule) — published September 10, 2025, effective November 10, 2025; adds DFARS 252.204-7021 and 252.204-7025: federalregister.gov
  • DFARS 252.204-7012 — the cloud provider must meet "security requirements equivalent to those established by the Government for the FedRAMP Moderate baseline": ecfr.gov
  • FAR 4.1901 — definition of Federal Contract Information (FCI): ecfr.gov
  • 32 CFR 2002.4 — definition of Controlled Unclassified Information (CUI): ecfr.gov
  • Microsoft Learn — CMMC and Microsoft 365 Government (GCC High) — GCC High "supports organizations in meeting CMMC Level 2 and Level 3 requirements (when configured appropriately)"; plain GCC "isn't suitable to hold CUI Specified"; compliance "depends on customer configuration... and the use of qualified assessors": learn.microsoft.com
  • PreVeil — FedRAMP story / CMMC — DoD FedRAMP Moderate Equivalency claim; support for "all 110 CMMC controls"; PreVeil Pass "starting at $450/month": preveil.com
  • Kiteworks — CMMC compliance — "supports 90% of Level 2 requirements for CMMC compliance" (vendor claim); FedRAMP Moderate Authorized: kiteworks.com
  • Box — FedRAMP / Box for Government — FedRAMP High ATO (via the U.S. Dept. of Veterans Affairs); DoD SRG Impact Level 4 (IL4): box.com
  • Egnyte — CMMC compliance — "EgnyteGov's Compliance Center maps all 110 Level 2 controls to CMMC standards"; "FedRAMP Moderate Equivalent provider"; 15 Level 1 and 110 Level 2 practice requirements: egnyte.com
  • Sharetru — FedRAMP Moderate Authorized file sharing for defense contractors — JAB-ATO; "aligns with all 110 NIST SP 800-171 controls... directly supporting CMMC Level 2"; satisfies DFARS 252.204-7012; TLS 1.3, FIPS 140-3 modules, AES-256: sharetru.com

Last updated: July 2026