# Consus achieves FedRAMP Equivalency

October 3, 2026 · Eric Magliarditi

Canonical: https://consus.io/blog/fedramp-high-audit-complete

> Our 3PAO assessed Consus against all 410 FedRAMP High controls, 87 more than DFARS 7012 requires. Here is what that means for your CMMC assessment.

Consus has completed a third-party assessment against the full FedRAMP High baseline. A FedRAMP-recognized Third-Party Assessment Organization (3PAO) tested & verified that Consus meets all 410 FedRAMP High controls.

This post explains what was assessed, why we went past the Moderate baseline, and what you can hand to your CMMC assessor as a result.

## Why this matters for your contracts

If you handle Controlled Unclassified Information (CUI) on a DoD contract, [DFARS 252.204-7012](https://www.acq.osd.mil/dpap/dars/dfars/html/current/252204.htm) requires any cloud service that stores, processes, or transmits that CUI to meet the FedRAMP Moderate baseline or its equivalent. The DoD CIO's [December 2023 memorandum](https://dodcio.defense.gov/Portals/0/Documents/Library/FEDRAMP-EquivalencyCloudServiceProviders.pdf) defines what "equivalent" means: 100 percent of the 323 Moderate controls, assessed by a 3PAO, with a body of evidence the contractor keeps on file.

Your CMMC assessor will ask for that evidence for every cloud in your boundary that touches CUI. AI inference is no exception. If your engineers send CUI to a model, the service running that model has to clear this bar, and you have to be able to prove it.

## What we assessed

We asked our 3PAO to assess Consus against the FedRAMP High baseline rather than Moderate. High adds 87 controls on top of the 323 Moderate controls, for a total of 410. The additional controls concentrate on the areas that matter most for defense data: stricter access control, more detailed audit logging, tighter configuration management, and stronger incident response and contingency planning.

The assessment covered the Consus boundary end to end:

- The gateway that receives your requests and routes them to models
- The US-only cloud regions and the model providers inside the boundary
- Personnel, access, and the controls that keep prompts and completions from persisting
- The audit logging that feeds your own evidence trail

## What you get

The Body of Evidence package is available under NDA to customers and to companies evaluating Consus. It contains the documents your CMMC assessor expects for a cloud service in your boundary:

- System Security Plan (SSP) with appendices
- Security Assessment Plan (SAP) and Security Assessment Report (SAR) from the 3PAO
- Plan of Action and Milestones (POA&M) and the continuous monitoring strategy

## Why we went past Moderate

Equivalency at Moderate is what DFARS 7012 requires. We chose High because Moderate is the floor for CUI, not the ceiling.

Under [32 CFR 2002.14](https://www.ecfr.gov/current/title-32/subtitle-B/chapter-XX/part-2002/subpart-B/section-2002.14), CUI is protected at no less than the Moderate confidentiality level, and an agency can require more by agreement. In the DoD Cloud Computing Security Requirements Guide, higher-sensitivity CUI and unclassified National Security Systems sit at Impact Level 5, and IL5 starts from the FedRAMP High baseline before adding DoD-specific requirements.

Our customers in aerospace, defense, and energy work on programs where that higher bar comes up. Assessing against all 410 High controls means the Consus boundary already meets the FedRAMP baseline those programs start from, and your evidence package covers the 323 Moderate controls DFARS 7012 asks for along the way.

To be clear: this assessment is against the FedRAMP High baseline only. It is not a DoD Impact Level 5 authorization. IL5 adds DoD-specific requirements that were not part of this assessment, and a Consus-specific IL5 authorization remains on our roadmap.

## What this does not claim

Consus is not a FedRAMP Authorized service and does not appear on the FedRAMP Marketplace as authorized. 

What we hold is a 3PAO assessment against the High baseline and the body of evidence that supports equivalency under DFARS 7012. This is what your CMMC assessment needs from a cloud service provider that stores, processes, or transmits covered defense information.

## Next steps

If you are a current customer, contact your Consus representative for the evidence package. If you are evaluating Consus, [book a call](https://cal.com/emagliarditi/consus-gateway-intro-discussion) and we will set up an NDA and walk your compliance team through the documents on a working call.

The full compliance summary, including ITAR and zero data retention, is on our [compliance page](https://consus.io/compliance).
