in ,

Exostar Adds Secure Exchange to CMMC Ready Suite for CUI Sharing

Exostar Adds Secure Exchange to CMMC Ready Suite for CUI Sharing
Logo: Exostar
  • Tool pairs chat-style messaging with file sharing for CUI
  • Secure Exchange runs in a Microsoft 365 GCC High environment with end-to-end encryption
  • The application is bundled into Exostar’s CMMC Ready Suite

Exostar has launched Secure Exchange, an application offering defense contractors a secure way to discuss controlled unclassified information and share related files with authorized recipients both inside and outside their organizations.

The company said Tuesday the messaging and file-sharing tool is integrated into its CMMC Ready Suite built on a Microsoft 365 GCC High environment that meets Federal Risk and Authorization Management Program Moderate equivalency requirements.

The CMMC Ready Suite also includes a certification assistant for Cybersecurity Maturity Model Certification self-assessments and Supplier Performance Risk System scoring, the PolicyPro policy management and optimization platform, and CMMC consulting services.

What Can Users Do With Exostar Secure Exchange?

Senders can mark messages and attachments as CUI before transmitting them. Clicking a document in a conversation’s file panel returns the reader to the message that carried it, preserving any instructions that came with it. If a project changes hands, an eligible participant can take over managing the thread without losing its message and file history.

Users sign in through the Exostar Managed Access Gateway and see only the conversations they are cleared to view. Email alerts direct them back to the application without exposing sensitive data.

Exostar emphasized that customer organizations remain responsible for data governance, proper information handling and security controls.

How Does Exostar Secure Exchange Fit the CMMC Landscape?

Exostar earned CMMC Maturity Level 2 certification in December, confirming compliance with all 110 controls in the National Institute of Standards and Technology Special Publication 800-171 Revision 2.

The Department of War suspended CMMC Phase 2 requirements on July 13, four months before the verification framework was scheduled to take effect, and stood up a reform task force. Phase 1 self-assessment requirements remain in force during the CMMC review. DOW said the review aims to align the program with DOW Secretary and Wash100 Award recipient Pete Hegseth‘s Acquisition Transformation System directives.

Supply chain readiness has failed to keep pace with broader program requirements. CyberSheath reported in October 2025 that only 1 percent of defense contractors were prepared for the CMMC final rule, down from 8 percent in 2023 and 4 percent in 2024. The firm found a median Supplier Performance Risk System score of 60, compared with a required 110, with 17 percent of respondents reporting negative scores.

ExecutiveBiz Logo

Sign Up Now! ExecutiveBiz provides you with Daily Updates and News Briefings about Cybersecurity

mm

Written by Kristen Smith

CGI Federal’s Clay Goldwein Talks His Unique Ascent to GovCon Leadership
CGI Federal’s Clay Goldwein Talks His Unique Ascent to GovCon Leadership
Future Technologies Hires Former Cambium Executive Kent Brown as Sales SVP
Future Technologies Hires Former Cambium Executive Kent Brown as Sales SVP