ITAR Registration Code:
M49438 / Cage Code: 94U86

GCC vs. GCC High for CMMC: What Defense Contractors Need to Know About DFARS 252.204-7012

Table of Contents

A practical guide to understanding what CMMC and DFARS require from a cloud environment, and where Microsoft GCC and GCC High fit in.

Microsoft GCC and GCC High are government-focused Microsoft 365 environments that defense contractors often evaluate when determining how to handle CUI under DFARS 252.204-7012 and CMMC Level 2.

Quick Answer

CMMC does not state that every organization handling Controlled Unclassified Information (CUI) must use Microsoft GCC High. What CMMC requires is narrower and more specific: when a Cloud Service Provider (CSP) processes, stores, or transmits CUI, that cloud offering must be FedRAMP Authorized at the Moderate baseline or higher, or meet FedRAMP Moderate equivalency in accordance with Department of War (DOW) policy. GCC High is one Microsoft environment that organizations evaluate to help satisfy that requirement, but it is not automatically mandated by the rule itself, and using it does not, by itself, make an organization compliant. This guide walks through what the requirement actually says, where GCC and GCC High differ, and what else remains your responsibility regardless of which environment you choose.

Key takeaway: CMMC Level 2 does not mandate Microsoft GCC High by name. When a CSP processes, stores, or transmits CUI, the applicable cloud offering must satisfy the FedRAMP Moderate-or-higher or FedRAMP Moderate-equivalency requirements established by DOW.

What Is Microsoft GCC?

Microsoft GCC (Government Community Cloud) is a version of Microsoft 365 built for U.S. government agencies, state and local governments, and contractors who handle sensitive but unclassified data. It is generally positioned by Microsoft as meeting FedRAMP Moderate baseline requirements, which can make it suitable for contractors who need to demonstrate basic federal compliance for data that does not rise to the level of CUI covered by DFARS clauses.

What Is Microsoft GCC High?

GCC High is a higher-assurance Microsoft 365 environment marketed to contractors and subcontractors handling CUI, Controlled Unclassified Information (CUI), or data subject to the International Traffic in Arms Regulations (ITAR). Microsoft positions GCC High around a higher FedRAMP baseline, additional personnel screening, and U.S.-based data residency. Because specific technical claims about screening, data center locations, and impact-level alignment come from Microsoft’s own service descriptions rather than the CMMC rule itself, confirm the current details directly with Microsoft’s official documentation before relying on them for a compliance decision.

Does CMMC Require GCC High?

This is the question worth answering directly, because it is the one most often gotten wrong.

CMMC does not name Microsoft GCC High as a requirement. The rule requires that a CSP processing, storing, or transmitting CUI be FedRAMP Authorized at the Moderate baseline or higher, or meet FedRAMP Moderate equivalency under DOW policy. Organizations considering GCC High should verify that the specific Microsoft cloud service offering they intend to use has the required current FedRAMP authorization or otherwise meets the applicable DOW requirements, since the CMMC Assessment Process directs assessors to verify the specific cloud service offering, not merely the provider name, against the FedRAMP Marketplace. The decision of which environment to use is a scoping and risk decision your organization makes, not a fixed mandate naming one product.

That said, in practice, many defense contractors and primes converge on GCC High because it is purpose-built around DOW contractual language and ITAR considerations. But the compliance obligation is the FedRAMP Moderate-or-equivalent standard, not the brand name.

GCC vs. GCC High: Side-by-Side Comparison

The rows below reflect how Microsoft generally positions these two environments. The FedRAMP requirement itself comes from DFARS and CMMC, but the product-specific details, current FedRAMP authorization status, personnel screening, data residency, and pricing, are Microsoft’s to confirm. Check Microsoft’s current official documentation and the FedRAMP Marketplace listing for the specific offering before relying on any of this for a compliance decision.

FeatureGCCGCC High
Typical FedRAMP positioningModerateModerate to High, verify current Microsoft authorization
Designed for CUI/CDINot typically recommendedPurpose-built for this use case
ITAR considerationsNot designed for ITAR dataMarketed toward ITAR-related use cases
Data residencyContinental U.S.Continental U.S., isolated tenant
Typical usersState/local government, general federal workDOW contractors and subcontractors handling CUI
Licensing costGenerally lowerGenerally higher, verify current pricing

Does CMMC Level 2 Use NIST SP 800-171 Rev. 2 or Rev. 3?

This is a genuinely confusing point, and it is worth addressing head-on.

NIST SP 800-171 Revision 2 was formally withdrawn and superseded by Revision 3 in May 2024. However, current CMMC assessment requirements are aligned to Revision 2, not Revision 3. Organizations may choose to implement Revision 3 security requirements, but for purposes of the current CMMC assessment requirements, they must still comply with any Revision 2 security requirements that are not covered by Revision 3.

In short: Revision 3 is the current published version of the standard, but Revision 2 remains the version CMMC assessments are measured against until the rule is updated to reference Revision 3 directly. Confirm which version applies to your specific contract and assessment window, as this can change.

Using GCC High Doesn’t Remove Your CMMC Responsibilities

One of the most common misunderstandings in this space is treating cloud selection as the finish line. It is not.

Even after selecting a CSP that meets the required FedRAMP baseline, your organization’s own infrastructure connecting to that cloud environment remains within the scope of your CMMC assessment. When you use a CSP, the CSP typically publishes a Customer Responsibility Matrix (CRM) that divides security responsibilities between the provider and the customer. The responsibilities assigned to you in that CRM must be documented and addressed in your own System Security Plan (SSP), not simply assumed to be handled because the underlying cloud is authorized.

In practical terms, this means:

  • Your tenant configuration, identity controls, and endpoint security are still your responsibility.
  • Your SSP needs to reflect which controls the CSP covers and which controls you must implement yourself.
  • Choosing a qualifying cloud environment is necessary but not sufficient for certification.

Common Misconceptions

“We are FedRAMP authorized, so we are compliant.” FedRAMP authorization applies to the cloud service provider’s platform. It does not automatically mean that your organization’s specific configuration, identity management, and data-handling practices meet the full set of CMMC Level 2 requirements. You still need your own SSP, and typically a Plan of Action and Milestones (POA&M) for any gaps.

“Any FedRAMP Moderate cloud is automatically fine for CUI.” The requirement is FedRAMP Moderate or higher, or FedRAMP Moderate equivalency under DOW policy, applied to the specific cloud service offering handling the CUI. Whether a given offering, tenant, or configuration actually qualifies is worth confirming rather than assuming.

“We can sort out our cloud environment after we win the contract.” Cloud migrations involve tenant setup, data migration, user training, and reconfiguration of existing controls. Starting this process after contract award creates schedule risk, particularly if compliance deadlines are tied to contract performance.

How to Approach the GCC vs. GCC High Decision

Rather than starting from “do I need GCC High,” start from these questions:

  1. Will your systems create, receive, store, or transmit CUI or CDI under this contract?
  2. Does your contract include DFARS 252.204-7012?
  3. Is any of your data subject to ITAR?
  4. Are you pursuing or maintaining CMMC Level 2 certification, and if so, under Rev. 2 or a transitional Rev. 3 posture?
  5. Does your prime contractor specify a required cloud environment as a flow-down condition?
  6. If you choose a CSP, do you have (or can you obtain) its Customer Responsibility Matrix, and can you map those responsibilities into your SSP?

If your environment will use a CSP to process, store, or transmit CUI, the applicable cloud offering must meet the FedRAMP Moderate-or-higher or FedRAMP Moderate-equivalency requirement referenced by CMMC and DFARS. ITAR requirements should be evaluated separately based on the data and contract involved. If your work does not involve CUI, standard GCC or another FedRAMP Moderate-aligned option may be sufficient.

Next Steps for Defense Contractors

Before committing to a migration, confirm the specific DFARS clauses that apply to your contract, review the current DoD CMMC program requirements, and check which revision of NIST SP 800-171 applies to your assessment. Many organizations bring in a Registered Practitioner Organization (RPO) or a Certified Third-Party Assessment Organization (C3PAO) early to validate scope, including how the Customer Responsibility Matrix maps to their SSP, before investing in a cloud migration.

Frequently Asked Questions

Does CMMC require GCC High? No. CMMC requires that a CSP handling CUI be FedRAMP Authorized at the Moderate baseline or higher, or meet FedRAMP Moderate equivalency under DOW policy. GCC High is a common way to meet that standard, but it is not named as a mandatory product in the rule.

Can GCC be used for CUI? Standard GCC is generally positioned at FedRAMP Moderate for broader use across the federal and government communities. Whether a specific GCC offering and configuration meet the CUI-handling bar for your contract should be confirmed against the current FedRAMP authorization and your specific data-handling requirements, rather than assumed either way.

Does GCC High make an organization CMMC compliant? No. Using a qualifying cloud environment addresses part of the requirement, but your organization remains responsible for its own SSP, configuration, and any responsibilities assigned to you through the CSP’s Customer Responsibility Matrix.

What does DFARS 252.204-7012 require from a cloud provider? The clause requires safeguarding of covered defense information and reporting of cyber incidents, and it incorporates the FedRAMP Moderate baseline (or equivalent) requirement for cloud services used to process, store, or transmit covered defense information. The full clause text is available on Acquisition.gov. Cyber incident reporting for DOW contractors is generally submitted through the DOW Cyber Crime Center’s DIBNet portal, and related cybersecurity guidance is also published by the Cybersecurity and Infrastructure Security Agency (CISA).

Does a CSP handling CUI need a separate CMMC certification? For a CSP that processes, stores, or transmits CUI, the CMMC rule points to the FedRAMP requirements in DFARS 252.204-7012 rather than a separate CMMC certification for the CSP itself. The contractor remains responsible for documenting and implementing the responsibilities assigned to it through the CSP’s Customer Responsibility Matrix.

Does FedRAMP Moderate satisfy CMMC cloud requirements? Yes, for CSPs handling CUI, FedRAMP Authorization at the Moderate baseline or higher, or an accepted FedRAMP Moderate equivalency, is the standard referenced under DFARS 252.204-7012 and CMMC.

Is my Microsoft 365 tenant included in my CMMC assessment scope? If the tenant processes, stores, or transmits CUI, or provides security functions that protect the CMMC assessment scope, it may be relevant to the assessment. The organization’s connected infrastructure and customer-assigned responsibilities also remain part of the scoping analysis.

What is a Customer Responsibility Matrix (CRM) in a CMMC context? A CRM is a document published by a cloud service provider that divides which security requirements the provider handles versus which ones the customer must implement. Contractors are expected to reflect their assigned CRM responsibilities in their own SSP.

Does CMMC Level 2 use NIST SP 800-171 Rev. 2 or Rev. 3? Current CMMC assessment requirements are aligned to Revision 2, even though Revision 3 has formally superseded Rev. 2 as the published NIST standard. Organizations may implement Rev. 3, but must still satisfy any Rev. 2 security requirements not covered by Rev. 3 for current assessment purposes.

Schedule a free consultation with the Brea Networks team to review your current environment, identify compliance risks, and understand what steps are required to move forward. A short conversation can help you avoid costly mistakes and focus on what matters for contract eligibility and security.

About Brea Networks

Brea Networks is a cybersecurity and compliance-focused IT partner dedicated to supporting Defense Industrial Base (DIB) contractors. We help organizations understand and implement the security requirements outlined in FAR 52.204-21, DFARS 252.204-7012, and the CMMC framework from Level 1 self-assessments to Level 2 and Level 3 readiness. Our team works alongside contractors to strengthen system security, define assessment scope, prepare documentation such as System Security Plans (SSPs) and POA&Ms, and build sustainable cybersecurity programs that protect FCI and CUI. Whether you are preparing for a self-assessment or simply improving your security posture. Brea Networks provides practical guidance and technical expertise to help you move forward with confidence.

Brea Networks, LLC
471 W Lambert Rd Ste 105
Brea, CA 92821

https://www.cmmccompliance.us
https://www.breanetworks.com

Telephone: 714-592-0063


This article is for general informational purposes and is not legal advice. It reflects publicly available DOW, DFARS, and NIST source material as of the time of writing, and specific Microsoft product claims should be independently verified against Microsoft’s current official documentation. Contractors should confirm specific contractual and regulatory obligations with their contracting officer, legal counsel, or a qualified compliance advisor.

Redirecting to Download Full Offline Documents

Redirecting to Download GCC High Buyer`s Guide

Redirecting to ITAR Compliance Checklist

Redirecting to CMMC Level 2 Audit Checklist

Redirecting to CMMC Level 1 Audit Checklist

Redirecting to Discovery Call