← Back to Blog

Data Sovereignty and Residency in CMMC Compliance

XQ + Meerkat Position Paper

Authors:

Chris Haigh, Meerkat Cyber

Brian Wane , XQ Message, Inc

Under CMMC requirements, data sovereignty plays a critical role in ensuring that Controlled Unclassified Information (CUI) is stored, processed, and accessed in compliance with regulatory mandates.

Microsoft’s guidance asserts that certain CUI categories—such as Defense and Export-Controlled data—must reside within a U.S. Sovereign Cloud, such as GCC High or DoD environments.

However, for other CUI categories, data residency requirements may vary depending on the specific contractual and regulatory obligations.

XQ’s Zero Trust Data Security solution eliminates data sovereignty concerns by enforcing encryption at the endpoint before CUI is transmitted or stored. This ensures that:

  • CUI remains encrypted in transit and at rest, regardless of where it is stored.
  • Organizations maintain full control over decryption keys, preventing unauthorized access—even by cloud providers.
  • Data residency requirements become less restrictive, as encrypted CUI remains unreadable outside authorized environments.

By securing CUI at the point of creation, XQ enables organizations to comply with CMMC, DFARS, and ITAR regulations while maintaining operational flexibility in choosing storage and collaboration environments.

This approach provides a viable alternative to sovereign cloud mandates without compromising security or compliance.

References

https://www.federalregister.gov/d/2019-27438/page-70889

  • Activities that are not exports, reexports, retransfers, or temporary imports
    • “5) Sending, taking, or storing technical data that is:
    • (i) Unclassified;
    • (ii) Secured using end-to-end encryption;
    • (iii) Secured using cryptographic modules (hardware or software) compliant with the Federal Information Processing Standards Publication 140-2 (FIPS 140-2) or its successors, supplemented by software implementation, cryptographic key management, and other procedures and controls that are in accordance with guidance provided in current U.S. National Institute for Standards and Technology (NIST) publications, or by other cryptographic means that provide security strength that is at least comparable to the minimum 128 bits of security strength achieved by the Advanced Encryption Standard (AES-128);”

Frequently asked questions

Does CMMC require Controlled Unclassified Information to be stored in a U.S. sovereign cloud?

It depends on the CUI category and the contract. Microsoft's guidance holds that certain Controlled Unclassified Information (CUI) categories, such as Defense and Export-Controlled data, must reside in a U.S. sovereign cloud like GCC High or DoD environments. For other CUI categories, data residency requirements vary with the specific contractual and regulatory obligations, according to the XQ and Meerkat Cyber position paper.

How does XQ address data sovereignty concerns for CUI?

XQ addresses data sovereignty concerns by encrypting CUI at the endpoint before it is transmitted or stored. CUI stays encrypted in transit and at rest regardless of location, organizations keep full control of decryption keys so even cloud providers cannot read it, and residency requirements become less restrictive because encrypted CUI is unreadable outside authorized environments. This gives flexibility in choosing storage and collaboration environments.

What does ITAR say about storing encrypted technical data?

ITAR treats sending, taking or storing unclassified technical data as not an export when it is secured with end-to-end encryption. The International Traffic in Arms Regulations (ITAR) language cited in the XQ and Meerkat paper requires cryptographic modules compliant with FIPS 140-2 or its successors, or other means providing security strength at least comparable to AES-128, along with key management and procedures consistent with NIST guidance.

Want the full technical detail behind this post?

Talk to the team