Does CMMC Require GCC High?
Virtual Data Room    3341 views

Does CMMC Require GCC High?

Published on July 3, 2026

Short answer: No – CMMC does not explicitly require GCC High. But for most contractors that handle Controlled Unclassified Information (CUI), and for anyone touching ITAR or export-controlled data, GCC High is the most direct – and often the only practical – Microsoft 365 path to meeting what a CMMC assessor actually checks.

The confusion around whether CMMC requires GCC High comes from conflating two different rules. CMMC defines what protection you must prove. A separate clause, DFARS 252.204-7012, effectively dictates where your cloud can live. Once you follow that chain, GCC High stops looking optional. Here’s the nuance that matters before you spend a dollar on migration.

The short answer: no, but usually yes

CMMC 2.0 is a framework of security controls and third-party assessment. It maps to the 110 controls in NIST SP 800-171 and tells you how your implementation will be verified. It does not mandate any specific cloud platform, vendor, or product. So on a literal reading, the answer to “does CMMC require GCC High” is no.

In practice, though, the requirements that sit underneath CMMC narrow your options fast – and for the majority of the Defense Industrial Base (DIB) handling CUI, GCC High becomes the safe default. The rest of this post explains why.

What CMMC actually requires

CMMC exists to enforce two things you already agreed to in your contracts:

  • NIST SP 800-171 – the 110 controls that protect CUI across access control, audit, media protection, and more.
  • DFARS 252.204-7012 – the “safeguarding covered defense information” clause in most DoD contracts involving CUI.

That second clause is the one that quietly makes the platform decision for you. DFARS 7012 requires that any cloud service used to store, process, or transmit covered defense information meet the FedRAMP Moderate baseline (or equivalent) and comply with paragraphs (c) through (g) – which cover cyber-incident reporting, media preservation, and granting the DoD access to forensic data. Your cloud has to clear that bar before your NIST 800-171 implementation even counts.

Why commercial Microsoft 365 falls short

This is where a lot of contractors get caught. Commercial Microsoft 365 holds no FedRAMP authorization at any level. That means it cannot be used to store, process, or transmit CUI under CMMC Level 2 – regardless of how you configure it.

A common misconception is that encrypting CUI in a commercial tenant solves the problem. It doesn’t. The DoD’s CMMC FAQ (Revision 2.1, November 2025) is explicit: encrypted CUI is still CUI, subject to the full set of NIST SP 800-171 protections. Assessors evaluate the authorization status of the platform, not the encryption you layer on top of it. Bitlocker and sensitivity labels are good practice – they are not a substitute for a FedRAMP-authorized environment.

GCC vs GCC High: the real dividing line

Microsoft offers three relevant environments, and the differences decide your answer.

EnvironmentFedRAMP statusSuitable for CUI?ITAR / export-controlled dataBest fit
Commercial M365NoneNoNoGeneral business data, no CUI
GCCFedRAMP High (services vary)Some non-export CUINo – support may include non-US persons; runs on Azure Commercial infrastructureBasic CUI, no export-control exposure
GCC HighFedRAMP High, DoD SRG IL4/IL5YesYes – US-sovereign cloud, screened US-person support, contractual ITAR commitmentsCUI Specified, ITAR/EAR, most CMMC Level 2

GCC (standard) can support DFARS 7012 for basic CUI that is not export-controlled, but it carries caveats that matter to assessors: data sits in US data centers while the underlying infrastructure runs on Azure Commercial, and support personnel may include non-US persons. For a contractor that wants one environment to cover the widest range of CUI without re-litigating scope on every program, GCC High removes the ambiguity.

When GCC High is non-negotiable: ITAR and export-controlled data

Here’s the part that flips the answer from “maybe” to “yes.” If your CUI is subject to ITAR, EAR, or the DFARS 7012 (c)-(g) requirements, GCC High is the only Microsoft 365 environment where Microsoft provides contractual ITAR commitments and guarantees US-person access and US data sovereignty.

As one way to frame it: GCC High’s role in ITAR compliance is arguably more important than its role in CMMC. CMMC made GCC High famous, but export control is what makes it mandatory. If you build, handle, or exchange technical data tied to a munitions-list or dual-use item, this is not a judgment call – it’s the price of staying inside the law.

The part teams underestimate: collaborating on CUI inside GCC High

Getting into GCC High is the first challenge. Working within its boundary is the one that surprises people. GCC High is deliberately walled off – external collaboration is genuinely hard by design. Cross-cloud guest access between commercial and GCC High tenants requires explicit Entra ID federation configured on both sides, B2B Direct Connect isn’t supported between the two due to ITAR, and native SharePoint sharing tends to create standing “guest sprawl” with weak time-boxing and no data-room-grade controls.

That gap – securely running M&A diligence, subcontractor exchanges, and CMMC evidence rooms without pulling CUI back out of your accredited boundary – is exactly what Govern 365 was built to close. It turns your accredited GCC High tenant into a controlled data room, so you get virtual data room outcomes (watermarking, time-boxed access, full audit, disposition) with the controlled data never leaving the fence.

What this means for your November 2026 deadline

Timing is the reason this question is urgent, not academic. Phase 2 of the CMMC rollout makes third-party Level 2 certification a contract gate as of November 10, 2026. Two clocks run against you:

  • Remediating your environment against the 110 NIST SP 800-171 controls typically takes 4 to 8 months.
  • A GCC High migration typically takes 60 to 180 days, depending on complexity.

Stack those sequentially and the runway is shorter than it looks – especially with authorized C3PAO assessors already booked out. If GCC High is in your future, the decision is better made now than discovered during an assessment. Our CMMC Level 2 readiness guide walks through the sequence.

A quick decision framework

Ask three questions in order:

  1. Do you handle ITAR or export-controlled technical data? If yes → GCC High. Stop here.
  2. Do you store, process, or transmit CUI on DoD contracts with DFARS 7012? If yes → commercial is out; GCC High is the safest single environment, and often simpler than defending GCC’s edge cases to an assessor.
  3. Do you only handle FCI (Federal Contract Information), not CUI? Then CMMC Level 1 may apply, and GCC High may be more than you need.

If you answered “yes” to 1 or 2 – which describes most of the DIB – then the practical answer to does CMMC require GCC High is “effectively, yes.”

Frequently Asked Questions

Does CMMC require GCC High?

Not explicitly. CMMC mandates NIST SP 800-171 controls and third-party assessment, not a specific platform. But DFARS 252.204-7012 requires a FedRAMP-authorized cloud, and within Microsoft 365, GCC High is the most direct way to meet that bar for CUI – and the only option that covers ITAR and export-controlled data.

Can I use commercial Microsoft 365 for CMMC Level 2?

No. Commercial M365 has no FedRAMP authorization and cannot be used to store, process, or transmit CUI under CMMC Level 2. Encryption does not change that – the DoD evaluates the platform’s authorization status, not the encryption on top.

Is GCC enough, or do I need GCC High?

GCC can support some non-export-controlled CUI, but it runs on Azure Commercial infrastructure and support may include non-US persons. GCC High provides US-sovereign data, screened US-person support, and contractual ITAR commitments – making it the safer, more comprehensive choice for most CMMC Level 2 contractors.

Does GCC High make me automatically CMMC compliant?

No. GCC High is a compliant foundation – it satisfies the platform requirement. You still have to implement, document (SSP and POA&M), and pass assessment against all 110 NIST SP 800-171 controls, and govern how CUI is actually used and shared inside the tenant.

When do I need to have this in place?

Phase 2 makes third-party CMMC Level 2 certification a contract gate on November 10, 2026. With multi-month remediation and migration timelines, contractors handling CUI should be making the environment decision now.

Niraj Tenany

President, CEO and Co-founder, Netwoven | Product Owner, Govern 365

38 years of Enterprise Technology experience. Worked on early version of SharePoint at Microsoft in 1999. Also leads the AI and Security practice.

Author of Secure by Design: How Modern Organizations Collaborate Without Compromise, the executive playbook for delivering VDR-grade outcomes inside Microsoft 365.

I wrote this book after watching enterprises use a category of software called Virtual Data Rooms (VDR) for M&A types of transactions only, whereas the broader category of secure collaboration needed organizations to think about Virtual Data Rooms in a broader context to be able to secure their crown jewels from all across the organizations. This book frames VDR from a software category to VDR as an outcome.

Get the book →

Leave a comment

Your email address will not be published. Required fields are marked *

4000 Pimlico Drive, Suite 114-103 Pleasanton, CA 94588
Linkedin Twitter Facebook Youtube
 
Microsoft
Govern 365 - Member of Microsoft Intelligent Security Association
7 minutes
Request a Demo