A project engineer needs to send a drawing package to a subcontractor by end of day. The file has CUI markings buried in the metadata nobody bothered to check. The fastest path is a personal Gmail account, a consumer Dropbox link, or an AirDrop to a phone that isn’t enrolled in mobile device management. None of that shows up in a firewall log. None of it trips an antivirus alert. It just happens, quietly, dozens of times a week, in nearly every defense contractor environment running a hybrid workforce.
File sharing is the control that breaks compliance programs that look airtight on paper. You can have a hardened perimeter, phishing-resistant MFA, and a SIEM catching every anomaly, and still fail an assessment because a project manager routinely shared technical data through a personal cloud account that was never sanctioned, never encrypted to standard, and never included in your System Security Plan. Hybrid teams make this worse by design — people work from home offices, jobsite trailers, client sites, and personal devices, and every one of those locations is a place a file can leave your boundary without anyone noticing.
This piece covers what secure file sharing actually requires for organizations working toward or maintaining CMMC compliance, why the tenant you’re on matters as much as the tool you pick, and how to build a policy that survives contact with an assessor instead of collapsing under the first pointed question.
What NIST SP 800-171 Actually Requires for CUI in Transit and at Rest
Secure file sharing isn’t a single control — it’s the intersection of several. Under NIST SP 800-171 Revision 3, organizations processing, storing, or transmitting Controlled Unclassified Information have to demonstrate encryption in transit, encryption at rest, access control tied to least privilege, and audit logging that can reconstruct who touched a file and when. File sharing sits at the center of nearly all of these because a shared file is, by definition, moving between people, systems, and sometimes organizations.
The practical problem is that “encrypted” gets treated as a checkbox rather than a configuration. A file shared through a link with no expiration, no authentication requirement, and no logging technically travels over TLS — but it fails the access control and audit requirements the moment that link gets forwarded outside the intended recipient list. DFARS clause 252.204-7012 requires safeguarding covered defense information and reporting cyber incidents within 72 hours of discovery, which means a mishandled file isn’t just a compliance gap — it can trigger a reporting obligation you didn’t know you had until it’s too late to meet the deadline cleanly. Getting your compliance posture right on file sharing starts with treating every shared document as a control point, not a convenience feature.
CUI itself carries specific handling requirements independent of the platform. The National Archives CUI program defines marking, dissemination, and decontrol requirements that apply regardless of whether the file lives in SharePoint, an email attachment, or a USB drive, and organizations frequently underestimate how much of their day-to-day project documentation actually qualifies. If your team hasn’t reviewed the current CUI marking guidance against the drawings, specs, and correspondence flowing through daily project work, that’s a gap worth closing before it becomes an assessor’s finding.

Choosing the Right Microsoft 365 Tenant Before You Build a File-Sharing Policy
None of the access control or encryption work matters if the underlying platform can’t support it. This is where a lot of contractors get the sequencing backwards — they write a file-sharing policy, then discover the commercial Microsoft 365 tenant they’re running can’t actually enforce it because Conditional Access, Customer Lockbox, and FedRAMP-authorized data boundaries simply aren’t available at that licensing tier.
The decision between commercial Microsoft 365, Microsoft 365 GCC, and GCC High isn’t cosmetic — it determines who can access your data, where it physically resides, and whether your support vendor’s personnel even qualify to touch your environment. We’ve written in detail about how to evaluate GCC High versus GCC versus commercial tenants against your actual flow-down requirements, because contractors frequently over-buy or under-buy based on what a prime’s contract language implies rather than what the CMMC scoping actually demands. Get this decision wrong and every file-sharing control you build on top of it inherits the same weakness.
Cloud transformation work in this space isn’t just a lift-and-shift exercise — it’s rebuilding the sharing, permissions, and retention architecture around the tenant you actually need, not the one you happened to sign up for three renewal cycles ago.
Shadow IT and the SaaS Tools Quietly Moving CUI
Every organization has an approved file-sharing platform. Almost none of them have full visibility into what’s actually being used. A design team standardizes on a rendering tool with its own cloud storage. A finance team starts using a personal-tier file converter that caches uploaded documents on third-party servers. An estimator installs a PDF markup app that syncs to iCloud by default. None of this shows up in your asset inventory, and none of it was ever evaluated against your security requirements — it’s shadow IT, and it’s one of the fastest-growing sources of CUI exposure we see in contractor environments.
We cover this pattern in more depth in our piece on how unauthorized apps create hidden security risks, and the file-sharing angle is usually the most damaging version of it. A tool doesn’t need malicious intent to become a liability — it just needs a default sync setting nobody reviewed.
The fix isn’t a memo telling people to stop. It’s visibility. SaaS Security Posture Management gives you the ability to see which applications actually have access to your Microsoft 365 or Google Workspace data, what permissions they were granted, and which of those permissions nobody remembers approving. Our breakdown of SaaS Security Posture Management walks through how to build that inventory before an assessor asks for it and you realize you can’t produce one. Pairing that visibility with managed IT services that actively monitor new app connections closes the loop instead of just documenting the problem after the fact.
Access Control: Who Can See a File, and For How Long
A secure file-sharing policy has to answer three questions for every document: who can open it, what can they do with it once they have it, and when does that access end. Most environments handle the first question reasonably well and completely ignore the third.
The offboarding gap is the clearest example. A subcontractor’s employee rolls off a project, and their access to shared drives, project folders, and file links often survives the transition by days or weeks because revocation isn’t tied to an automated trigger — it’s tied to someone remembering to do it. We’ve documented this exact failure pattern in our piece on access revocation timing under CMMC, where a departed contractor’s account sat active well past their last day with zero malicious activity, but a very real finding waiting to happen the moment an assessor checked timestamps against HR records.
Least-privilege access for shared files means default-deny external sharing, expiring links instead of permanent ones, and permission sets scoped to the specific folder or project rather than the entire drive. It also means treating “external sharing enabled” as an exception that requires justification, not a default setting left over from a trial tenant configuration years ago. Getting the governance model right here is exactly the kind of strategic work a fractional or full vCIO engagement is built for — someone who owns the policy decisions, not just the technical implementation, and who revisits them as project rosters and subcontractor relationships change.
![]()
Encryption, Endpoints, and the Physical Reality of Shared Files
Encryption in transit gets most of the attention because it’s the easiest to explain. Encryption at rest and the physical lifecycle of the media a file touches gets far less, and it’s where a surprising number of findings originate. A file downloaded to a laptop for offline editing, synced to a personal OneDrive folder, or copied to a USB drive for a client meeting has left every logical control you built and now depends entirely on the endpoint and the physical device.
This is also where cybersecurity strategy and physical security requirements intersect more than people expect. When old laptops, external drives, or decommissioned printers with cached print jobs leave a facility without proper sanitization, any CUI they once held travels with them. We’ve written specifically about the media sanitization requirements under CMMC — clear, purge, and destroy — because “we wiped it” and “we sanitized it to NIST standard” are not the same claim, and only one of them holds up under assessment.
Backup and recovery infrastructure deserves the same scrutiny. A shared file that’s encrypted on the primary platform but replicated into an unencrypted or under-governed backup target hasn’t actually been secured — it’s been duplicated into a second point of failure. Backup and disaster recovery planning for CUI-handling environments has to extend the same encryption, access control, and retention standards to every copy of a file, not just the one users see day to day.
Vendors, Subcontractors, and Your External Service Provider
Hybrid teams don’t stop at your own employees. Primes, subcontractors, auditors, and specialty vendors all need access to shared files at some point, and every one of those relationships extends your attack surface into an organization you don’t control. A secure file-sharing policy that only governs internal staff and ignores the vendor ecosystem is solving half the problem.
This is also where your MSP’s own status matters more than most contractors realize. If your IT provider has administrative access to systems that store, process, or transmit CUI, they meet the definition of an External Service Provider under CMMC scoping, which carries its own set of assessment obligations. We break down exactly what counts as an ESP and what that means for your MSP relationship in detail, because contractors are frequently surprised to learn their support vendor needs to be assessed alongside them, not treated as an outside party exempt from scrutiny.
A co-managed IT arrangement can actually simplify this — internal staff retain visibility and control over sensitive data flows while a specialized partner handles the security tooling, monitoring, and documentation that a compliance program demands. The key is making sure the boundary between what your team controls and what your vendor controls is documented clearly enough that an assessor doesn’t have to guess where responsibility sits.
Building a Secure File-Sharing Policy Your Assessor Will Actually Accept
A policy document that exists but doesn’t match observed behavior is worse than no policy at all — it gives an assessor a written standard to measure you against, and every gap between the document and reality becomes a finding. A workable policy needs to be specific enough to enforce and simple enough that people actually follow it under deadline pressure. At minimum, it should address:
- Approved platforms only — name the specific sanctioned tools (SharePoint, Teams, GCC High OneDrive) and explicitly prohibit personal cloud storage, consumer email, and unmanaged file conversion tools for anything touching CUI
- Default link behavior — sharing links should expire, require authentication, and default to internal-only unless a documented exception applies
- Device requirements — files should only be accessible from managed, encrypted devices enrolled in your mobile device management platform, not personal phones or unmanaged home computers
- Vendor and subcontractor access — a documented process for granting, reviewing, and revoking external access tied to contract milestones rather than informal requests
- Logging and review cadence — sharing activity logs reviewed on a defined schedule, not just pulled reactively after an incident
None of this holds up without people actually understanding why it matters, which is where training closes the loop. Annual slideshow training doesn’t move the needle on file-sharing behavior — people need to understand specifically why the convenience of a personal cloud link creates risk their organization can’t absorb. Our guide to what security awareness training actually requires under AT.L2 covers how to build training that changes behavior instead of just satisfying a checkbox.
Different industries carry different flavors of this problem. Engineering firms move large CAD and drawing files that don’t fit neatly into email attachments, which pushes teams toward whatever transfer tool is fastest rather than what’s approved. Manufacturing environments often have production floor staff sharing specs and work orders from shared terminals with weaker identity controls than office endpoints. The platform and policy specifics should reflect how your actual teams work, not a generic template pulled from a compliance vendor.
![]()
Conclusion
Secure file sharing sounds like a small piece of a much larger CMMC program, and that’s exactly why it gets underfunded relative to the risk it carries. It touches your tenant architecture, your access control model, your vendor relationships, your training program, and the physical handling of every device that ever holds a copy of a file. Get the sequencing right — the right Microsoft 365 tenant, visibility into shadow IT, access tied to actual project timelines, sanitized media, and vendors held to the same standard you hold yourself — and file sharing stops being the finding that undoes an otherwise solid assessment.
Whether your team operates out of Boston, Tampa, or Sarasota, the fundamentals don’t change: know where your CUI lives, know who can move it, and build infrastructure that makes the secure path the easy path. Review the DoD’s CMMC Program requirements against your current file-sharing environment and you’ll likely find gaps worth closing before an assessor finds them for you.
If your organization is planning its CMMC compliance journey, contact Stealth Technology Group today at (617) 903-5559 or visit the website to learn how modern cybersecurity infrastructure can accelerate your path toward certification readiness.
