Is Microsoft GCC High required for CMMC?
No regulation names GCC High. CMMC Level 2 and DFARS 252.204-7012 require any cloud that holds CUI to be FedRAMP Moderate authorized or equivalent and to meet the clause's incident-reporting terms. For Microsoft 365, Microsoft documents those DFARS commitments for its U.S. Government clouds, which is why most defense contractors storing CUI in Microsoft 365 choose GCC High.
What the rules actually require
DFARS 252.204-7012 requires that a cloud service provider storing, processing or transmitting covered defense information meet security requirements equivalent to the FedRAMP Moderate baseline and comply with the clause's paragraphs (c) through (g) on cyber incident reporting, malicious software, media preservation, access and damage assessment. Rapid reporting under the clause means within 72 hours of discovery.
The CMMC rule, 32 CFR Part 170, carries the same test into Level 2: a cloud product holding CUI must be FedRAMP Authorized at Moderate or higher, or meet equivalent requirements under DoD policy. Your on-premises systems that connect to it stay in your assessment scope.
Where Microsoft 365 options land
Microsoft's DFARS documentation says its support for the cloud-provider requirements of 252.204-7012 applies to Azure Government and Office 365 U.S. Government Defense services, and that Office 365 U.S. Government and U.S. Government Defense hold FedRAMP Moderate authorizations adequate for DFARS. Microsoft describes GCC High as built to DoD Impact Level 4 controls for federal agencies, the Defense Industrial Base and government contractors.
Commercial Microsoft 365 is not on that list. GCC (moderate) is aimed at government entities and contractors, but most defense contractors with CUI choose GCC High because Microsoft's DFARS 7012 commitments for Microsoft 365 are documented for its U.S. Government Defense services.
When you might not need it
Whichever route you choose, document it in your SSP and be ready to show the provider's FedRAMP authorization or equivalency evidence to an assessor or contracting officer.
- You handle only FCI, not CUI, so Level 1 applies.
- CUI is confined to an on-premises enclave or another FedRAMP Moderate-equivalent service.
- Your CUI volume is small enough that a separate enclave for the few people who touch it is cheaper than moving the whole company.
Questions to settle before migrating
Decide who actually needs CUI, whether you also hold export-controlled technical data, and whether a full tenant move or a CUI enclave fits better. Get Microsoft's customer responsibility matrix into your SSP, because the provider's authorization covers only its side. The July 2026 Phase 2 suspension does not change these cloud requirements; DFARS 252.204-7012 remains in effect.
Common follow-up questions
Is commercial Microsoft 365 enough for CUI?
Microsoft's DFARS documentation does not list commercial Microsoft 365 among the services meeting 252.204-7012 cloud requirements. Holding CUI there means you would need to show FedRAMP Moderate equivalence and incident-reporting compliance yourself, which is difficult.
Can I use GCC instead of GCC High?
Microsoft offers GCC to government entities and contractors and lists in-scope GCC services, but its 7012 commitments are documented for U.S. Government Defense services. Confirm against your contract and Microsoft's current documentation before relying on GCC for CUI.
Does moving to GCC High make me CMMC compliant?
No. GCC High covers the cloud provider's responsibilities. You still configure it correctly, secure endpoints and on-premises systems that connect to it, document everything in your SSP and meet all 110 requirements.
LAN Service Group migrates and administers Microsoft 365 GCC High and SharePoint environments for defense contractors, with CUI scoping and SSP documentation handled by its ISSO-led CMMC practice.
Talk to LAN Service Group (888) 281-7243Sources
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- 32 CFR Part 170, CMMC Program final rule (Federal Register, Oct 15, 2024)
- Microsoft Learn: DFARS compliance offering (Microsoft 365 / Office 365)
- Under Secretary of War memo: Implementing Suspension of CMMC Phase 2 Requirements (Jul 13, 2026)