Preparing for CMMC 2.0 in Microsoft 365 GCC High
What defense contractors need to know about achieving CMMC 2.0 compliance on Microsoft 365 GCC High—covering CUI boundaries, tenant selection, and the controls that matter most.
If your organization handles Controlled Unclassified Information (CUI) for the Department of Defense, CMMC 2.0 compliance is becoming a contractual requirement rather than a nice-to-have. Microsoft 365 GCC High is purpose-built for this workload, but choosing and configuring it correctly is where most contractors struggle—and where an incorrect decision can cost months of rework and a failed assessment.
CMMC—the Cybersecurity Maturity Model Certification—exists to verify that contractors in the Defense Industrial Base actually implement the security controls they have long been required to attest to. Version 2.0 streamlined the model into three levels and aligned Level 2 directly with the 110 controls of NIST SP 800-171. For most contractors handling CUI, Level 2 with a third-party assessment is the target.
The platform does not make you compliant. GCC High gives you the technical capability to meet the controls, but scoping, configuration, policy, and evidence are still entirely your responsibility.
Understand the CMMC 2.0 levels
Before making any platform decision, be clear about which level your contracts actually require. Over-scoping wastes money; under-scoping fails assessments.
- Level 1 (Foundational) — 15 basic safeguarding requirements for Federal Contract Information (FCI), verified by annual self-assessment.
- Level 2 (Advanced) — the 110 controls of NIST SP 800-171 for protecting CUI, verified by a triennial third-party assessment for most contracts.
- Level 3 (Expert) — an enhanced set of controls based on NIST SP 800-172 for the highest-priority programs, assessed by the government.
Do you actually need GCC High?
GCC High is designed for organizations handling CUI, ITAR data, and export-controlled information. It runs in a segregated cloud environment that meets FedRAMP High and supports DFARS 7012 requirements, including data residency within the United States and access limited to screened U.S. persons. It is more restrictive—and more expensive—than commercial Microsoft 365 or standard GCC.
GCC High vs. Commercial vs. GCC
- Commercial Microsoft 365 can meet many NIST 800-171 controls but does not guarantee U.S. data residency or U.S.-person access, which is a problem for ITAR and certain CUI categories.
- GCC (moderate) offers U.S. data residency and a government community cloud but does not meet the ITAR and DFARS 7012 requirements that GCC High does.
- GCC High meets FedRAMP High, DFARS 7012, and ITAR requirements, making it the safe choice for contractors with export-controlled CUI.
Selecting the wrong tenant is a costly mistake to unwind—migrations between these environments are non-trivial and disruptive. Validate your data types against your contract flow-downs and speak with your prime or contracting officer before you commit.
Define your CUI boundary early
CMMC assessments hinge on a clearly documented scope. The assessor needs to see exactly where CUI lives and how it is protected. Map where CUI is created, stored, processed, and transmitted, then design your architecture to keep that boundary as small and defensible as possible. A smaller boundary means fewer systems to secure, fewer controls to implement, and a faster, cheaper assessment.
- Identify every source and destination of CUI, including email, file storage, endpoints, and any third-party services.
- Segment CUI workloads away from general collaboration so that the assessment scope does not sprawl across your whole environment.
- Apply Microsoft Purview sensitivity labels and data loss prevention policies to classify and protect CUI automatically.
- Document data flows in diagrams that your assessor can follow without ambiguity.
Map controls to NIST 800-171
CMMC Level 2 aligns with the 110 controls in NIST SP 800-171, organized across 14 control families ranging from Access Control and Audit and Accountability to Incident Response and System and Communications Protection. Microsoft 365 GCC High provides the technical capabilities—encryption, multifactor authentication, access control, and audit logging—but you still own configuration, policy, and evidence.
The documents you cannot skip
- A System Security Plan (SSP) describing how each of the 110 controls is implemented in your environment.
- A Plan of Action and Milestones (POA&M) tracking any control not yet fully met, with owners and target dates.
- Supporting evidence—policies, procedures, screenshots, and logs—that demonstrates each control is operating, not just documented.
Your SPRS (Supplier Performance Risk System) score is derived directly from your SSP and POA&M. An honest, well-documented score is far better than an inflated one that collapses under assessment.
A realistic readiness timeline
Most contractors underestimate how long CMMC readiness takes. Between tenant migration, control implementation, policy development, and evidence collection, a realistic timeline for a mid-sized contractor is six to twelve months before an assessment. Starting early—and sequencing the work—keeps the effort manageable.
- Scope and gap assessment: determine your CUI boundary and measure current state against the 110 controls.
- Platform and architecture: stand up or migrate to GCC High and configure the technical controls.
- Policy and process: write the SSP, POA&M, and supporting policies, and operationalize them.
- Evidence and pre-assessment: collect artifacts, run an internal mock assessment, and close remaining gaps before the C3PAO arrives.
Common mistakes contractors make
- Choosing commercial Microsoft 365 to save money, then discovering ITAR or DFARS requirements force a costly migration to GCC High.
- Letting the CUI boundary sprawl across the entire tenant, ballooning the assessment scope and cost.
- Treating documentation as an afterthought—assessors evaluate evidence, not intentions.
- Assuming the cloud provider handles compliance for you rather than understanding the shared-responsibility model.
Where FelxTek fits in
We help defense contractors assess GCC High readiness, design compliant Microsoft 365 architectures, define defensible CUI boundaries, and align controls to NIST 800-171 so CMMC assessments go smoothly. From gap assessment to SSP development to pre-assessment support, we guide you through the full journey. Reach out for a CMMC compliance readiness review.
Ready to secure and modernize your Microsoft environment?
FelxTek helps Southern California organizations design, secure, and manage Azure and Microsoft 365. Book a consultation or a security assessment.
Schedule a Consultation