A drawback claim needs part numbers, quantities, values and dates, not technical data.
Why we draw the line:
- Sealed is a control, not a certification. It is not CMMC certification, not FedRAMP Moderate equivalence, and not an ITAR or EAR authorization.
Defense rules expect things Sealed doesn't do. DFARS 252.204-7012 requires cloud security equivalent to FedRAMP Moderate for covered defense information, reporting within 72 hours, and preserving images of affected systems for at least 90 days.
Sealed erases its working copy, which would conflict.
ITAR's encryption carve-out covers data "continuously encrypted at all times while outside of an authorized security boundary."
Processing decrypts data inside a processor at a third-party site, and we found no State or Commerce guidance that treats that as covered.
- CMMC still applies. DoD suspended Phase 2 on July 13, 2026, but "all Phase I self-assessment requirements remain firmly in place."
What Sealed does protect for defense and aerospace suppliers is commercial data: supplier prices, landed costs and customer lists.
- DFARS 252.204-7012[1]
- 22 CFR 120.54[2]
- Federal Register, Dec 26, 2019[2]
- DoD CIO, CMMC[1]
- 15 CFR 734.18[3]
- Does Sealed make us CMMC, ITAR or FedRAMP compliant?
- Can defense suppliers use NexQloud Drawback?
Written by the NexQloud Drawback team from the primary sources linked on this page.
Not legal advice. NexQloud Drawback is not a government agency.
NexQloud Drawback is software used by licensed customs brokers.
