DoD SAFE works well for what it was built to do: securely deliver a package from one party to another. But its usefulness to a defense contractor depends heavily on whether someone at the company holds a Common Access Card (CAC).
Many smaller defense contractors and subcontractors have no CAC holders on staff. Those companies cannot independently initiate a DoD SAFE exchange. They can use the service only after a CAC holder—often at a government customer or prime contractor—sends them a one-time request.
That limitation is a reflection of how DoD SAFE was designed. It was not built as a file-exchange platform that defense contractors could independently administer. It was built as a government-operated delivery service centered on CAC-authenticated users, with non-CAC contractors participating as guests (and only guests). The CAC requirement is therefore not an incidental inconvenience; it is part of the service’s underlying permission model.
Companies that do employ CAC holders face a different problem. As file exchanges become more frequent, requests can begin funneling through the few employees who hold cards. Those individuals become a bottleneck, and the company still has no independently managed user directory, shared administrative view, persistent file environment, or integration with its internal systems.
Where My Bias Is
I run Sharetru, and we provide one of the platforms companies consider when DoD SAFE stops fitting due to the bottlenecks it creates over time. But, you should read this as you would anything written by a vendor: verify our claims against DoD SAFE’s documentation, the relevant DFARS clauses, and the FedRAMP Marketplace. I’ll also explain where DoD SAFE remains an ok choice if you have the right personnel.
DoD SAFE is built for individual deliveries
DoD SAFE is a government-operated drop-off and pick-up service. A sender uploads a package, the recipient retrieves it, and the package is eventually deleted.
That model makes sense for an occasional submission. If you need to send one package to one government point of contact, a temporary delivery service may be all you need.
DoD SAFE also has several numerical limits that can create friction:
- Packages are limited to 25 files.
- A package cannot exceed 8 GB.
- Files must generally be retrieved within seven days.
Those limitations are real, but they are not the fundamental difference between DoD SAFE and an organization-managed file-exchange and sharing platform. Many contractors will never need to send more than 8 GB or upload thousands of files at once.
The more important distinction is who can initiate and control the exchange.
The Real Limitation of DoD SAFE Isn’t File Size or Package Limits
DoD SAFE works well for what it was built to do: securely deliver a package from one party to another. The frustration begins when a defense contractor needs to manage controlled unclassified information (CUI) exchange as an ongoing business process.
Without a Common Access Card (CAC), someone cannot independently originate a DoD SAFE exchange. They must wait for a CAC holder to create a one-time request. As exchanges become more frequent, that dependency can become a bottleneck—and the contractor still has no independently managed user directory, shared administrative view, persistent file environment, or integration with its internal systems.
That is the more consequential limitation of DoD SAFE. It provides a secure way to deliver a package, but it does not give contractors control over the users, files, and workflows involved in recurring CUI exchange.
At Sharetru, and we provide one of the platforms companies consider when DoD SAFE stops fitting. Read this as you should read anything written by a vendor: verify our claims against DoD SAFE’s documentation, the relevant DFARS clauses, and the FedRAMP Marketplace.
I’ll also explain where DoD SAFE remains the better choice.
The CAC requirement creates a permission bottleneck
To independently originate a DoD SAFE drop-off, a user must authenticate with a CAC.
A non-CAC user can still participate. A CAC holder can issue that person a one-time drop-off request, allowing the guest to upload files without a card or account. A recipient can also retrieve a package without a CAC using the information provided with the delivery notification.
So, the problem is not that information can never move without a CAC. The problem is that a non-CAC user cannot independently initiate the exchange.
In practice, that affects contractors in two common ways:
-
A company has only a handful of CAC holders. Transfers begin funneling through those people, who become an internal help desk for everyone else’s files. Their availability becomes part of the delivery schedule, and their departure can disrupt the company’s ability to originate exchanges.
-
A company has no CAC holders. Its employees and subcontractors must wait for a CAC holder—often a government point of contact or prime contractor—to create a request before they can send anything through DoD SAFE.
You cannot solve that dependency by redesigning your internal process. If your organization needs to authorize its own users and initiate recurring exchanges on its own schedule, it needs a different exchange model.

DoD SAFE is not an organization-managed file environment
DoD SAFE is deliberately designed for temporary, package-based delivery. It is not intended to provide your company with a persistent environment for managing files, users, and recurring exchanges.
Your organization does not receive its own independently administered user directory. You cannot centrally add and remove users, assign permissions, manage folders, establish organization-wide retention policies, or connect the service with all the internal systems involved in your workflows.
DoD SAFE also does not provide the kind of shared organizational history needed to answer questions such as:
-
What did our company send to this program office last quarter?
-
Which subcontractor accessed a particular file?
-
Who currently has permission to exchange information for this program?
-
How long are we required to retain these files?
-
Can this transfer be initiated automatically by another internal system?
For a one-time submission, none of that may matter. For recurring exchanges among employees, subcontractors, primes, and government partners, it can matter a great deal.
The meaningful alternative is therefore not simply “DoD SAFE without a CAC.” It is an organization-managed environment for recurring CUI exchange.
Choosing an alternative changes your responsibility
There is an important compliance distinction that many DoD SAFE comparisons overlook.
While a package resides in DoD SAFE, the government operates the system holding it. When a contractor moves that exchange onto an external cloud platform it selected, the contractor becomes responsible for ensuring that the provider satisfies the requirements in its contract.
For contractors subject to DFARS 252.204-7012, an external cloud service provider that stores, processes, or transmits covered defense information must meet security requirements equivalent to the FedRAMP Moderate baseline. The provider must also support the applicable cyber incident reporting, malicious-software submission, media-preservation, forensic-analysis, and damage-assessment requirements in paragraphs (c) through (g) of the clause.
A contractor will generally look for one of two forms of evidence:
-
A FedRAMP Moderate or High authorization for the specific cloud service being purchased.
-
A FedRAMP Moderate equivalency assessment supported by the required body of evidence, including an assessment conducted by a FedRAMP-recognized third-party assessment organization.
The obligation ultimately remains with the contractor. If an assessor or contracting officer asks how your organization protects CUI in an external cloud service, a vendor’s marketing language will not be enough. You need evidence that applies to the exact service you deployed.

Does using DoD SAFE solve your CMMC obligations?
Using DoD SAFE does not, by itself, make your organization compliant with the Cybersecurity Maturity Model Certification program.
DoD SAFE may secure the transfer, but CUI rarely exists only inside the transfer service. It may originate on an employee’s workstation, remain in a local folder, pass through an internal application, or be downloaded and retained after the exchange.
The contractor systems that process, store, or transmit that information remain part of the organization’s compliance responsibility.
The same principle applies when selecting a DoD SAFE alternative. The platform’s authorization matters, but it is only one part of your CUI environment. Your organization still needs to understand:
- Where the information originates.
- Which systems process or store it.
- Who is authorized to access it.
- Where recipients download it.
- How it is retained and deleted.
- What happens if a cyber incident occurs.
A compliant cloud service can support your CMMC program. It cannot make the rest of your environment compliant by itself.
How Sharetru Federal removes the CAC dependency
This is the part where I put in a word for us, clearly labeled as such.
We sell three service tiers, and only one is intended for CUI. Our commercial tier is SOC 2 Type II audited, and we also offer a tier for organizations handling HIPAA-regulated information.
Sharetru Federal is our FedRAMP Moderate authorized offering. It is the product intended for contracts involving CUI, and that exact service name should appear in your paperwork. There is no self-hosted or deploy-in-your-own-tenant version of Sharetru Federal, so customers cannot accidentally deploy it outside that boundary.
Sharetru Federal gives your organization its own independently managed user list. Authorized employees, contractors, and mission partners can initiate exchanges without waiting for a CAC holder or a government point of contact to issue a one-time request. Administrators can manage users, permissions, files, retention rules, and audit activity across the organization. Sharetru can also connect file exchange with existing systems and workflows, including through SFTP. The result is not simply DoD SAFE without a CAC. It is an organization-managed environment for recurring CUI exchange.
That control does not come at the expense of the compliance evidence your contract requires. Sharetru Federal’s file-sharing capabilities operate within its FedRAMP Moderate authorized service boundary.
Whether a particular government recipient can use Sharetru will still depend on that organization’s policies and the requirements of the applicable contract. A FedRAMP authorization does not override a recipient’s approved processes or authorize a transfer channel the receiving organization does not permit.
When you should keep using DoD SAFE
If you have a single package to send to a government point of contact, do not buy another platform solely for that transfer.
Ask the point of contact for a DoD SAFE drop-off request. DoD SAFE is free, government-operated, and already familiar to the recipient. Plenty of organizations continue using it for exactly that kind of one-time submission.
Sharetru Federal becomes a better fit when file exchange is recurring—particularly when your organization needs to:
- Authorize and manage its own users.
- Integrate transfers with internal systems.
- Support automated or protocol-based exchange.
- Initiate exchanges without depending on a CAC holder.
- Retain files under organization-defined policies.
- Administer access centrally.
- Review activity across the organization.
- Produce an organizational audit trail.
Adopting a managed file-exchange platform does not require you to stop using DoD SAFE. The two can serve different purposes: DoD SAFE for individual government-directed submissions and an organization-managed platform for recurring exchanges your company needs to control.
What I’d Do This Week
- Count the people who can originate an exchange. Not who can receive one. If that number is small, or zero, you’ve found your real throughput limit — and it isn’t file size.
- Separate one-off submissions from continuous exchange. Only the second group needs a platform. The first group needs a POC and a drop-off request.
- Find out where CUI actually comes to rest today — including the personal cloud drive and the email attachments everyone knows about and nobody writes down.
- Ask every candidate platform for the evidence. FedRAMP Marketplace listing, or the 3PAO assessment plus the full body of evidence — and confirm which product, at which impact level, and which deployment option it covers.
- Read the clauses in your own contracts. 7012 for handling, 7021 where it appears. They’ll tell you more about your obligations than any headline about a phase that moved.
If it would help to talk through which of your exchanges belong on a platform and which don’t, my team is glad to walk through it with you. And if the honest answer for your organization is “keep using DoD SAFE,” we’ll tell you that too.