AEROSPACE & DEFENSE • CUI-READY MANAGED FILE TRANSFER

    FedRAMP-Authorized MFT for the CMMC Level 2 Reality

    Sharetru Federal is an Authorized Service running inside a FedRAMP Moderate JAB-ATO boundary across IaaS, PaaS, and SaaS—pre-configured to the NIST 800-53 Rev 5 (FedRAMP Moderate) baseline—so setup is light and you start with the controls auditors expect. Move big CAD/CAE files over SFTP/FTPS/FTPeS with FIPS-validated encryption and audit-ready logs.

    FEDRAMP
    ITAR
    SOC-2
    FIPS

    Your next DoD award will ask for proof, not promises

    CMMC is now codified (32 CFR Part 170), and DFARS (48 CFR, DoD) clauses make it contractual—252.204-7021 for CMMC in awards, 252.204-7012 for safeguarding CUI and 72-hour incident reporting, and 252.204-7019/7020 for SPRS scoring and potential assessments.

    Translation: you need a platform that gives you strong identity, logging, encryption, evidence on demand, and simple supplier onboarding—without slowing down your teams. Build evidence into file transfer so you’re ready when contracting asks:

    Decision Authorized boundary (Sharetru Federal) “Equivalency” workaround (Others)
    Contract posture FedRAMP Moderate JAB-ATO across IaaS/PaaS/SaaS Varies by vendor/interpretation of control
    Audit evidence Pre-configured 800-53 r5 controls + exportable logs/SIEM Gaps often filled by policy, not platform
    Future risk Cleaner reciprocity to CMMC; durable Re-justification risk at each review

    How this ties to CMMC & DFARS

    White-check

    Establishes the program and assessment approach for protecting FCI/CUI.

    CMMC (32 CFR Part 170):

    White-check

    Allows contracting officers to require a current CMMC level and flow it down to subs.

    DFARS 252.204-7021 (CMMC):

    White-check

    Safeguard CUI, report incidents within 72 hours, preserve evidence, and flow down to subs.

    DFARS 252.204-7012 (CUI):

    White-check

    Maintain your NIST SP 800-171 score in SPRS and be prepared for Government assessments.

    DFARS 252.204-7019/7020/7021 (SPRS & assessments):

    Download Icon

    Finding Sharetru in the FedRAMP Marketplace

    Real-authorization-not-a-workaround

    Real authorization, not a workaround

    FedRAMP Moderate JAB-authorized boundary across IaaS/PaaS/SaaS for durable assurance and cleaner reciprocity to CMMC—no “equivalency” hand-waving.

    Quote_Icon

    “We stopped debating paperwork and started shipping CMMC evidence. Procurement noticed.”

    — Rachel B., CIO, Aerospace Manufacturer

    Scales-with-your-supply-chain

    Scales with your supply chain

    Optional unlimited users so primes and subs can participate without license friction.

    Quote_Icon

    “Unlimited users meant every supplier touching CUI got onboarded—no license math to slow us down.”

    — David K., Program Director, R&D firm

    No-file-type-roadblocks

    No file-type roadblocks

    Share and receive .dwg, .dxf, .catpart/.catproduct, .step/.iges .sldprt/.sldas m, .prt, .zip/.7z, .xlsx, .csv, .pdf, imagery, firmware blobs— no “extension banned” surprises.

    Quote_Icon

    “Sharetru gave us a file transfer system we could immediately point to in our audit prep. We didn’t need to explain how we encrypt files or manage access — it was all documented and centralized.”

    — IT Security Lead, Tier 2 Government Services Provider

    Built-for-big-engineering-payloads

    Built for big engineering payloads

    Native SFTP/FTPS/FTPeS integration moves massive CAD/CAE assemblies reliably; teams keep their toolchains and automations.

    Quote_Icon

    “Terabyte-scale assemblies move over SFTP without timing out, reconnections occcurred automatically, and even though our CAD workflow changed, it only got better.

    — Paul S., VP Engineering, Electronics & PCB Assembly Provider

    Controls-auditors-actually-ask-for

    Controls auditors actually ask for

    FIPS 140-3, TLS 1.3, dual authorization for new user creation, account lockout policies, clickwrap, geo-blocking/IP allowlists, SIEM integration, and exportable activity logs.

    Quote_Icon

    “When 7012 came up in a tabletop, we could show the access trail in minutes.”

    — Megan T., Compliance Manager, Machining & Precision Fabricator

    Three compliant ways to share files

    All three methods run inside the same FedRAMP Moderate JAB-ATO boundary and are pre-configured to NIST 800-53 Rev 5, so rollout is light and day-one controls are already in place.

    Web Application

    Fastest path for humans

    Drag-and-drop, no extension roadblocks (.dwg, .step, .zip, .xslx, etc.), "Send Files" / "Receive Files" flows, receipt confirmations, comment history, and exportable activity logs.

    Quote_Icon

    “No more ‘can’t upload that extension.’ Engineers don’t even think about the platform—which is the point.”

    Lena M., Director of Quality, Aerospace Structures Supplier

    SFTP / FTPS / FTPeS

    Best for Big, Automated moves

    Protocol access for huge CAD/CAE payloads and scheduled jobs; keep your existing scripts; resumable transfers; clean fit with PLM/ERP.

    Quote_Icon

    Our large file sets move over SFTP easily now, and our CAD workflow didn’t change at all. We tried using APIs through other tools first, but the failure rate created too many interruptions— the SFTP integration through Sharetru has been far more reliable for large or high-volume transfers.

    Paul S., VP Engineering, Defense Systems Integrator

    Guest File Sharing

    Registration + TOTP

    Invite non-users to send/receive files through a governed flow: TOTP MFA, optional domain allowlists, link expiration, download limits, and a per-link audit trail.

    Quote_Icon

    “We starting inviting subs to donwload using guest registrants and TOTP links. Sharetru automatically logged the evidence trail — and compliance stopped asking questions about how our less technical team members were sharing CUI.”

    Ava R., Program Manager, Avionics Prime

    Where this lands in your day-to-day

    OEM

    OEM ↔ supplier CUI exchange

    Simple folder entitlements, IP allowlists when needed, and an immutable access history you can export in minutes.

    Quote_Icon

    “We onboard subs in hours, not weeks—and we can prove who downloaded CUI whether it's with the link-based file sharing, the web application, or our SFTP automations."

    Andre F., Supplier Performance Lead, Defense OEM

    File

    Engineering change packages (ECO/ECR)

    Move big assemblies via SFTP/FTPS/FTPeS; capture comments/approvals with full history alongside the files so the evidence trail writes itself.

    Quote_Icon

    “ECOs stopped living in inboxes. We move the assembly over SFTP, capture approvals right next to the file, and the audit trail basically writes itself.”

    Erin P., Director of Configuration Management, Airframe OEM

    CDRLs

    Program deliverables (CDRLs/SOWs)

    Timestamped delivery and receipt; zero guesswork when auditors ask, “Who had access and when?”

    Quote_Icon

    “CDRLs arrive with a timestamp and a receipt. When auditors asked ‘who downloaded the file and when?,’ we answered with a single export—no email archaeology.”

    Marcus T., Program Manager, Defense Systems Integrator

    Export-controlled-collaboration

    Export-controlled collaboration

    U.S.-only hosting, U.S.-person admin, optional geo-blocking and IP allowlists to fence access by partner or region.

    Quote_Icon

    “US-only hosting and US-person admins, plus geo/IP fences, gave us the export-control posture we needed to include every supplier without losing sleep.”

    Dana R., ITAR Empowered Official, Defense Electronics Supplier

    Incident-response-readiness

    Incident-response readiness

    Centralized logs and SIEM integration for fast, forensics-useful answers if an event ever triggers your plan.

    Quote_Icon

    “When CMMC came up in a tabletop, we could show the access trail inside sharetru and all viewers instantly.

    Megan T., Compliance Manager, Tier-2 Machining Supplier

    What you get on day one

    FedRAMP Moderate (JAB-ATO) authorized boundary at IaaS/PaaS/SaaS—pre-configured to the NIST 800-53 Rev 5 (FedRAMP Moderate) baseline.

    The foundational controls (access, logging, encryption, incident response, configuration management) are are pre-configured, so your IT team isn’t building from scratch—the lift is light and focused on users, groups, folders, and supplier onboarding.

    Capability Authorized boundary (Sharetru Federal)
    SFTP/FTPS/FTPeS built in Move big CAD/CAE packages reliably while keeping your existing toolchain and automations.
    No file-extension roadblocks Share .dwg, .dxf, .catpart/.catproduct, .step/.iges, .sldprt/.sldasm, .prt, .zip/.7z, .csv, .pdf, .xlsx without bans.
    Evidence on tap Exportable activity logs and SIEM integration provide CMMC/DFARS proof without manual reconciliation.
    Strong defaults in Sharetru Federal FIPS 140-3, TLS 1.3, automatic suspension and deletion of users, and pre-configured account lockout policies.
    Policy guardrails Geo-IP blocking; IP and protocol allowlists; domain allowlists for link sending to fence access by partner or region.
    Scales with your supply chain Optional unlimited users so primes and subs can participate without license friction.