Search the Dropbox Watchdog archive
There is no evidence that it is, as of 6 September 2026. An independent compliance tracker found no Dropbox listing in the FedRAMP Marketplace in August 2026, and Dropbox's own compliance page lists SOC 2 Type II, ISO 27001, HIPAA business-associate agreements, GDPR, and PCI DSS — with no mention of FedRAMP or CMMC anywhere on that page.
FedRAMP (the Federal Risk and Authorization Management Program) is the US government's standard process for authorizing cloud services for federal use; CMMC (the Cybersecurity Maturity Model Certification) is the Department of Defense's framework for certifying that contractors handling defense-related data meet a required security-maturity level. Neither is a claim Dropbox makes about itself.
The FedRAMP Marketplace is an interactive web application that this archive could not read programmatically, so the Marketplace finding rests on an independent check rather than our own fetch: the compliance-tracking site ThirdProof states "Dropbox was not found in the FedRAMP Marketplace. Checked August 2026." Dropbox's own trust and compliance pages, which we did read, make no FedRAMP or CMMC claim.
Dropbox's own "Standards and Regulations Compliance" page names the certifications and frameworks the company holds itself to: it describes SOC 2 as validated "through a series of audits by an independent third-party, Ernst & Young," ISO 27001 as an accreditation the company has obtained ("View the Dropbox Standard, Advanced, Enterprise and Education ISO 27001 certificate"), states that "Dropbox will sign business associate agreements (BAAs) with Dropbox Standard, Advanced, Enterprise and Education customers who require them" for HIPAA/HITECH, that "Dropbox is GDPR-compliant," and that "Dropbox is a Payment Card Industry Data Security Standard (PCI DSS) compliant merchant." FedRAMP and CMMC do not appear on that page.
If your organization is under DFARS/CMMC scope, or needs FedRAMP-authorized storage for federal work, treat that as disqualifying by default rather than something to infer from marketing claims about a percentage of NIST controls met — get written confirmation of Dropbox's current certification status directly from Dropbox (or your reseller/Trust Center contact) before relying on it for regulated or defense-related data.
This answer is informational, not legal or security advice. Dropbox Watchdog is independent and not affiliated with Dropbox, Inc.