Want to learn more about services? Book a free introductory call - "Here"

Is Microsoft 365 GCC High (or Your Cloud Tool) Actually Enough for CUI?

Buying Microsoft 365 GCC High solves one CMMC requirement, not all of them. Here's what FedRAMP Moderate equivalency covers and what your organization still owns.

CMMC BLOG

Daniel McLain

8/28/20266 min read

Is Microsoft 365 GCC High (or Your Cloud Tool) Actually Enough for CUI?

If your organization just bought Microsoft 365 Government Community Cloud High (GCC High) licenses, or is about to, you've probably asked some version of this question: "Now that we have GCC High, are we covered?" It's a reasonable thing to assume, given what those licenses cost. It's also not quite right.

Here's the honest answer. GCC High solves one specific requirement: the cloud platform your organization uses has to meet a particular security bar. That's a real requirement under DFARS 252.204-7012, and GCC High generally clears it. But the platform decision doesn't touch the rest of your compliance picture, which is how you configure that environment, who has access to it, and whether Controlled Unclassified Information (CUI) actually stays inside it. A lot of companies buy the right tool and then keep doing business the old way around it, and that gap is where problems show up in an assessment.

The actual DFARS 7012 requirement, in plain terms

DFARS clause 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting) applies when your contract involves covered defense information, the Department of Defense's (DoD's) term that in practice overlaps heavily with CUI. If you use an external cloud service provider (CSP) to store, process, or transmit that information, the clause requires the provider to meet security requirements "equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline." (DFARS 252.204-7012, Acquisition.gov)

FedRAMP itself is the federal government's standardized process for security-vetting cloud products before agencies use them, with three impact levels (Low, Moderate, High) that scale with the sensitivity of the data involved. "Moderate" is the bar DFARS 7012 sets for CUI handling in the cloud.

The same clause also requires the cloud provider to support rapid cyber incident reporting (within 72 hours of discovery, to DoD via dibnet.mil), preserve any malicious software connected to a reported incident for DoD Cyber Crime Center analysis, retain forensic data for 90 days, and cooperate with any DoD damage assessment. Those obligations sit alongside the FedRAMP Moderate equivalency requirement, not instead of it.

What "equivalent to FedRAMP Moderate" actually means

A cloud provider doesn't have to hold a formal FedRAMP authorization to satisfy DFARS 7012. The clause allows for something functionally the same, or "equivalent." For years, exactly what counted as equivalent was left fairly open to interpretation, which created inconsistency across the Defense Industrial Base.

DoD narrowed that in a December 21, 2023 memo from the DoD Chief Information Officer that set out how a cloud service provider demonstrates FedRAMP Moderate equivalency. Coverage of the memo describes three elements: assessment by a FedRAMP-recognized Third Party Assessment Organization (3PAO), full implementation of the FedRAMP Moderate control baseline with no open, control-related Plans of Action and Milestones (POA&Ms), and a documented body of evidence, including a System Security Plan, Security Assessment Plan and Report, and continuous monitoring artifacts. A cloud offering that already holds a FedRAMP Moderate or FedRAMP High authorization listed on the FedRAMP Marketplace satisfies the requirement directly, without needing a separate equivalency package. (Ankura, coverage of the DoD memo; Summit 7, coverage of the DoD memo)

We're citing industry coverage of this memo rather than a DoD primary-source link because we were not able to independently confirm a public DoD.mil or defense.gov posting of the memo's text during research for this article. If your compliance program is leaning on the specifics of this memo, particularly the "no open POA&Ms" detail, it's worth having your RPO or C3PAO confirm the current DoD guidance directly before you rely on it for a contractual position.

Where GCC High fits into that

Microsoft 365 GCC High holds FedRAMP authorization at the High impact level, which we confirmed directly on the FedRAMP Marketplace listing for the product. FedRAMP High is a higher bar than FedRAMP Moderate, so a platform authorized at High satisfies the Moderate equivalency requirement DFARS 7012 asks for. (FedRAMP Marketplace: Microsoft 365 Government Community Cloud-High)

That's a genuinely useful fact if you're choosing a cloud platform for CUI. It's also the entire extent of what GCC High's authorization gets you. It tells you the underlying infrastructure clears the bar. It says nothing about whether your organization has configured that environment correctly, restricted access the way NIST SP 800-171 requires, or kept CUI from leaking into tools that were never in scope to begin with.

The part licenses don't solve: your own NIST SP 800-171 practices

Cybersecurity Maturity Model Certification (CMMC) Level 2 is built on the 110 security requirements in NIST SP 800-171. Standing up GCC High (or any FedRAMP-equivalent platform) doesn't automatically satisfy those requirements. You still have to implement and document your own side of the environment, including:

  • Access control: who actually has accounts and permissions in the CUI-handling environment, scoped to people who need it

  • Multi-factor authentication (MFA) configured correctly across the accounts that touch CUI, not just enabled somewhere in the tenant

  • Logging and monitoring configured to actually capture and retain the activity NIST SP 800-171 expects you to review

  • Encryption configured per the applicable requirements, not just "available because the platform supports it"

  • Documented data handling procedures that tell your employees which systems CUI is allowed to touch

This is our professional read on how the pieces fit together, not a rule phrased this exact way in any DoD publication. DoD doesn't say "buying GCC High doesn't satisfy 800-171" in a single sentence anywhere. But DFARS 7012's CSP requirement and CMMC's 110-practice requirement are separate obligations that happen to both apply when you're handling CUI in the cloud, and satisfying one doesn't retire the other. An assessor looking at your environment is going to ask about your access control lists and your MFA configuration, not just which cloud SKU you're paying for.

Where the real risk lives: CUI leaking outside the approved environment

The most common failure mode we see isn't a bad cloud platform choice. It's scope creep: CUI moving into systems that were never configured, or never intended, to hold it.

Say a 60-person engineering firm buys GCC High for its DoD-related work and rolls it out to the program team. Six months later, a project manager forwards a CUI-marked drawing package to a subcontractor's personal Gmail account because it's faster than remembering the GCC High workflow, or a design file gets shared through the company's regular (non-GCC High) Microsoft 365 tenant because that's the tenant everyone already has muscle memory for. Nobody did anything malicious. They just took the path of least resistance, and CUI ended up somewhere the company's compliance story never accounted for.

Commercial (non-GCC High) Microsoft 365, standard Slack, and standard Google Workspace are extremely common business tools, and there's nothing inherently wrong with using them for ordinary business communication. But these tools typically don't meet the FedRAMP Moderate equivalency bar out of the box, which is exactly why they're a frequent source of accidental CUI exposure when employees default to familiar tools instead of the approved, in-scope environment. That's not a blanket rule that CUI can never touch a commercial tool under any circumstance. It's a reason to evaluate each system deliberately, document what's actually in scope, and train people on the boundary, rather than assuming either "we're fine" or "we're automatically disqualified."

What this means for your organization

If you've already invested in GCC High or a similar FedRAMP-equivalent platform, that's a real step, not a wasted one. What's worth checking next:

  • Is CUI actually confined to the GCC High tenant, or is it still showing up in the regular Microsoft 365 tenant, personal devices, or messaging tools that were never brought into scope?

  • Are access control and MFA configured specifically for the accounts and systems that touch CUI, and documented that way?

  • Does your System Security Plan (SSP) reflect how the environment is actually configured today, not how it was designed on paper at rollout?

  • Do your employees know, in practical terms, which systems CUI is and isn't allowed to move through?

None of this guarantees a successful assessment or a specific CMMC Status. It's the set of questions that determine whether the platform you bought is doing the compliance work you're expecting it to do.

Official resources

A closing note, and where ICTS USA fits

This is general informational guidance, not legal advice, and it isn't a substitute for consulting a Registered Practitioner Organization (RPO) or a Certified Third-Party Assessment Organization (C3PAO) for a specific compliance determination or assessment. The FedRAMP Moderate equivalency memo details above come from industry reporting rather than a DoD primary-source link we could independently verify; confirm the current DoD position with a qualified professional before treating those specifics as binding.

Before investing in tools, documentation, or an assessment, make sure you understand what the contract requires and which parts of your environment are actually in scope. ICTS USA can help you evaluate the opportunity, identify the gaps between your cloud platform and your actual configuration, and determine a practical next step.

Copyright © 2026 ICTS USA LLC - All Rights Reserved.