Does CMMC Require GCC High? What the Rules Say
The Cybersecurity Maturity Model Certification (CMMC) final rule, 32 Code of Federal Regulations (CFR) Part 170, published in October 2024, sets assessment requirements without naming Microsoft 365 Government Community Cloud High (GCC High) or any other cloud platform.
Confusing CMMC with a GCC High mandate is expensive for defense contractors and the SaaS vendors that serve them: GCC High licensing carries a premium over commercial and GCC tiers, and moving into it requires a tenant rebuild.
The data an organization handles and the clauses in its contracts determine the cloud path. CMMC sets assessment mechanics by level, while Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 sets cloud obligations, and Phase Two, starting in November 2026, affects the certification timeline without changing the underlying obligations. That gap between what CMMC assesses and what DFARS actually requires shapes every downstream environment decision.
Key Takeaways
- GCC High. The CMMC cloud-service rule requires cloud services handling Controlled Unclassified Information (CUI) to be authorized at the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline or equivalent. Contract clauses and export-control obligations are what push organizations toward GCC High.
- Level Split. Level 1 covers Federal Contract Information (FCI) with an annual self-assessment and no cloud mandate; Level 2 covers CUI, where environment decisions carry real cost.
- DFARS 7012. DFARS 252.204-7012 is the operative mechanism. The clause has required FedRAMP Moderate-equivalent cloud environments for covered defense information since 2017, years before CMMC enforcement began.
- Phase Two. CMMC Phase 1 remains active through November 9, 2026, with Level 1 and Level 2 self-assessment requirements appearing in applicable solicitations; Phase 2 had been scheduled to begin November 10, 2026, when Level 2 third-party certifications become mandatory in applicable contracts.
Contract Language Drives GCC High Decisions Under CMMC
For Level 2 and Level 3 assessments, the CMMC final rule 32 CFR 170.17 published on October 15, 2024, requires that any cloud service offering processing, storing, or transmitting CUI be FedRAMP Authorized at the FedRAMP Security Controls Baseline Rev5 (Current) Moderate baseline or higher, or meet security requirements equivalent to that baseline.
The Federal Register preamble states: "The CMMC rule does not add new requirements on the use of CSPs, which are found in DFARS clause 252.204-7012." Obligations in the DFARS 7012 clause must be flowed down when a subcontractor provides operationally critical support or when performance involves covered contractor information systems or covered defense information, which can include certain subcontractors handling CUI.
This trigger is narrower than every subcontractor tier that handles CUI; export-control clauses narrow the set of environments a cloud service provider (CSP) will contractually stand behind. Whether that trigger fires in the first place depends on the assessment level a contract falls under.
CMMC Level 1 Rarely Requires GCC High
Level 1 applies to contractors handling FCI: the Federal Acquisition Regulation (FAR) FCI definition covers information not intended for public release that is provided by or generated for the government under a contract. The governing clause is FAR 52.204-21, and the assessment mechanics at this tier are deliberately lightweight.
A few specifics define what Level 1 actually asks of a contractor:
- Assessment mechanics. Annual self-assessment rules apply, with results entered in the Supplier Performance Risk System (SPRS) and affirmed by a senior official. No third-party assessment is required.
- Control count. The Department of Defense (DoD) Level 1 guide, Version 2.13, counts 15 basic safeguarding requirements drawn from FAR 52.204-21, mapped to 17 assessment objectives because FAR (b)(1)(ix) covers three of them.
- Cloud requirement. No FedRAMP requirement appears at this level, so commercial Microsoft 365 is defensible for FCI alongside government clouds.
- Upgrade path. A contractor that later wins CUI work cannot upgrade a commercial tenant in place, so organizations expecting Level 2 obligations should price that migration debt into the initial choice.
That expectation becomes concrete the moment CUI enters the contract.
CMMC Level 2 Brings the GCC High Question Into Scope
Level 2 applies when a contractor processes, stores, or transmits CUI. It aligns with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Rev2, and contracts involving CUI carry DFARS 252.204-7012, the clause that actually reaches into cloud decisions. That makes Level 2 the point where assessment scope, contract language, and cloud architecture begin to converge.
Four specifics define the Level 2 obligations:
- Control set. CMMC Level 2 comprises the 110 NIST SP 800-171 Rev2 requirements across 14 control families, including Access Control with 22 requirements and System and Communications Protection with 16.
- Cloud clause. DFARS 252.204-7012 paragraph (b)(2)(ii)(D) requires external cloud services handling covered defense information to meet security requirements "equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline."
- Equivalency evidence. A defensible package means full compliance with the FedRAMP Moderate baseline, assessment by a FedRAMP-recognized Third-Party Assessment Organization (3PAO), a complete Body of Evidence, and no open Plans of Action and Milestones (POA\&Ms).
- Incident obligations. The clause also obligates the CSP to support 72-hour cyber incident reporting, malicious software submission to DoD, and media preservation for forensic analysis.
An important note: NIST published Rev 3 in May 2024, but DoD Class Deviation 2024-O0013 directs contractors to implement Rev2 wherever DFARS 252.204-7012 appears. Rev 3 transition guidance will happen through separate rulemaking.
Organizations Typically Choose Among Three Environments for CUI
For Microsoft-centric contractors, the CUI environment decision usually reduces to three options, each with a different relationship to DFARS 7012 and export-control regimes.
- Commercial Microsoft 365. Commercial Microsoft 365 has no DFARS 252.204-7012 contractual basis for CUI regardless of configuration. The encryption workaround has closed: encrypted CUI is still CUI, subject to all NIST SP 800-171 Rev2 protections.
- GCC. GCC holds a FedRAMP Moderate Authority to Operate (ATO) and meets DFARS 252.204-7012 for non-export-controlled CUI. Because GCC does not natively support International Traffic in Arms Regulations (ITAR) or Export Administration Regulations (EAR) data, contractors choosing GCC must document that no export-controlled data enters the tenant.
- GCC High. Runs on Azure Government, physically separated from commercial Azure and staffed by screened U.S. persons only, with FedRAMP High authorization and DoD Cloud Computing Security Requirements Guide (SRG) V1R6, December 2025, Impact Level 4 and 5 provisional authorizations. GCC High supports full DFARS 7012 flow-down and offers a contractual amendment for ITAR with NOFORN markings.
Narrowing to one of these options is less about brand preference than about a repeatable evaluation that the assessor and the prime can both follow.
Deciding on GCC High Follows a Practical Sequence
That environment choice should follow a documented sequence. Each step below narrows the field of viable cloud environments.
1. Identify the Data Categories in Scope
The first step is confirming whether the organization handles CUI or export-controlled data. Contracts involving only FCI trigger no FedRAMP cloud requirement. CUI carrying ITAR, EAR, or NOFORN markings makes GCC High effectively required; CUI without export controls opens up GCC and other FedRAMP Moderate environments.
2. Confirm What the Prime Contractor or Contract Actually Requires
Review whether DFARS 252.204-7012 appears in the subcontract clauses and whether those clauses require the entire environment to meet the standard, even if the contractor planned to isolate CUI in one segment. Read the subcontract clauses before pricing any migration, because prime-level interpretation often exceeds the baseline clause language.
3. Scope a CUI Enclave Rather Than Migrating the Full Tenant
Isolating the users and systems that touch CUI in a compliant environment leaves everyone else on commercial licensing. A partial enclave can sharply reduce the number of GCC High accounts required and preserves flexibility for future contract growth.
4. Document the Environment in the System Security Plan
NIST SP 800-171 Rev2 requirement 3.12.4 mandates a documented system boundary, and assessors scrutinize enclave boundaries closely. The System Security Plan (SSP) must show where CUI lives and how controls are implemented, including controls inherited from the cloud provider.
A rigorous sequence like this only pays off if the assessment regime it prepares for remains stable, and recent policy moves have changed that regime meaningfully.
CMMC Level 2 and Level 3 Third-Party Certification Is Currently Paused
On July 13, 2026, the Department of War suspended CMMC Phase Two, effective immediately, under Memo 26-P-1023. Phase Two would have made Level 2 certification by a Certified Third-Party Assessment Organization (C3PAO) the default condition of contract award beginning November 10, 2026.
The suspension also freezes Phase Three and Phase Four milestones, and agencies were directed to amend active solicitations to remove Level 2 and Level 3 certification requirements "as soon as practicable." A CMMC Reform Task Force is due within 60 days of the announcement, a request for information on reducing compliance burden carries an August 14, 2026 deadline, and no revised certification date has been announced.
Phase One Requirements Remain Active
The suspension announcement states that "All Phase I self-assessment requirements remain firmly in place." Level 1 and Level 2 self-assessment clauses, in effect since November 2025, still appear in solicitations where contractors may handle FCI or CUI. DFARS 252.204-7012 also remains fully in force: contractors "remain contractually obligated to safeguard covered defense information," and the Department will enforce the NIST SP 800-171 Rev2 standard through self-assessments and select government-led assessments during the interim.
Contractors Should Continue Scoping CUI Now
Certification timing has moved once and may move again; the suspension holds milestones "in abeyance until further notice," which cuts both ways. Most cybersecurity requirements in DoD contracts, including the NIST SP 800-171 Rev2 controls and rapid incident reporting, arise outside the CMMC program and are untouched by the pause. Inaccurate SPRS self-assessments also carry False Claims Act exposure that no pause suspends. The same clauses that survive the pause reach past the contractor and into the products it buys.
SaaS Vendors Weighing GCC High Face a Cost and Timing Trade-Off
DFARS 252.204-7012 reaches past the contractor's IT into the vendor's own product: the same cloud obligations apply to any SaaS product that touches covered defense information on a contractor's behalf. For vendors serving CMMC-scoped contractors, that turns the tenant question into a cost question, and the line items compound:
- GCC High licensing carries a premium over GCC equivalents, and the delta scales with every seat, integration, and workload that touches the tenant.
- A GCC High migration requires a complete tenant rebuild, adding implementation work and extending contractor timelines.
- FedRAMP Moderate equivalency means demonstrating all 323 FedRAMP Security Controls Baseline Rev5 (Current) Moderate controls to a 3PAO, a bar that can be impractical for cloud service providers.
- Traditional FedRAMP Moderate authorization includes assessment, remediation, and program overhead, typically running 12 to 36 months and upwards of $3.5 million.
Whether the vendor lands on GCC High or a separately authorized environment, the underlying question is the same: build a compliant boundary from scratch, or step into one that already exists. That build-or-inherit choice, more than any single cloud label, is what determines how fast and how affordably a SaaS product can reach a CMMC-scoped customer.
A Clear CUI Boundary Matters More Than the Cloud Label Attached to It
Organizations run into trouble when the SSP lacks a defensible boundary, not when they pick the "wrong" cloud tier. GCC High answers the boundary question for export-controlled work, a focused enclave does the same for CUI without ITAR or EAR markings, and FedRAMP Moderate authorization can cover a SaaS product sitting inside a customer's covered environment.
Knox Systems is a FedRAMP-as-a-Service provider that enables federal authorization in approximately 90 days at approximately 90% less cost than traditional methods. SaaS vendors deploy into the pre-authorized Knox FedRAMP boundary, and customers inherit 60% to 80% of required controls, with continuous monitoring capabilities handling ongoing control mapping and documentation.
The government cloud platform currently supports FedRAMP Moderate, FedRAMP High, and Defense Information Systems Agency Impact Level 4 (DISA IL-4); DISA IL-5 authorization is in process, with an estimated completion date of December 2026.
Book a meeting to map the fastest path to an authorized boundary.
FAQs about CMMC and GCC High
Does GCC High Alone Make an Organization CMMC Compliant?
No. GCC High may support the hosting layer, but CMMC evidence still has to cover people, endpoints, policies, procedures, and operations. The tenant is only one part of the assessed boundary.
Are There Alternatives to GCC High for Hosting CUI?
Yes, if the CUI is not export-controlled and the selected boundary satisfies DFARS 252.204-7012. The SSP should identify the enclave, inherited controls, and services in scope.
How Much Does a Small Contractor Spend Getting Onto GCC High?
Spending varies with the number of users, workloads, and integrations that touch CUI. Many small contractors contain cost by placing only the CUI population in a GCC High enclave.
Who Validates a Cloud Provider's FedRAMP Moderate Equivalency?
The defense contractor is responsible for accepting and retaining the evidence. If the provider lacks an authorization, the contractor needs a complete equivalency package for each CUI service.
Does the Phase Two Suspension Change DFARS 7012 Cloud Obligations?
No. DFARS 252.204-7012 predates CMMC enforcement and continues to operate independently. The FedRAMP Moderate-equivalent requirement for CSPs handling covered defense information remains binding regardless of certification timing.