Site alert bar (existing): July 13 update: CMMC Phase II is suspended. Level 1 and Level 2 self-assessments remain in force. What changed →
By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance.
Last reviewed: August 2026 · Last verified: August 22, 2026 · Next scheduled review: November 2026 · FedRAMP and FIPS status refresh: October 2026
Editorial research — not formally reviewed by a CMMC Subject Matter Advisor. Confirm scope and applicability with a CMMC Registered Practitioner (RP), a Registered Provider Organization (RPO), or a qualified federal-contracts attorney before acting.
The Defense Compliance Report is not affiliated with, endorsed by, or acting on behalf of the Cyber AB, the Department of War, the Department of Defense, DCMA DIBCAC, NIST, SPRS, or any U.S. government agency. This is educational research, not legal, contractual, export-control, or compliance advice.
The bottom line
An enclave and Microsoft 365 GCC High are not two options. They are two different kinds of thing. An enclave is the boundary around the users, systems, and services that touch or protect Controlled Unclassified Information (CUI). GCC High is a platform that can sit inside that boundary. There are five real architecture paths, not two — and the one that fits you depends on where CUI actually moves, whether any of it is export-controlled, and whether your people can live inside the boundary you draw.
That is the whole answer. Here is the part almost nobody tells you: when a contractor searches enclave vs GCC High for CMMC, they may be comparing proposals that use the same word — "enclave" — for fundamentally different architectures. One vendor may mean a slice of GCC High. Another may mean a protected environment designed to keep CUI out of GCC High entirely. Until you know which one you were sold, you are not comparing anything.
We read the rule, the clause, the export regulation almost everyone skips, and the vendor documentation on both sides. Then we built the comparison the market hasn't.
Find your row:
| Your situation | Path to price first | Your first move |
|---|---|---|
| A contract or prime names GCC High, IL4, or U.S.-person support in writing | Path 2 or 3 | Get the requirement in writing before you price anything else |
| CUI is limited to one stable team, mostly email and files | Path 1 | Confirm your commercial tenant can genuinely stay off the CUI path |
| A small group needs protected Microsoft email, Teams, and SharePoint | Path 2 | Price split-tenant operations honestly, including identity, licensing, and cross-tenant administration |
| CUI moves through most departments and mailboxes | Path 3 | Compare full-company GCC High against a broader hybrid; do not assume a narrow enclave is cheaper |
| CAD, CAM, ERP, CNC, test equipment, or OT touches CUI | Path 4 | A collaboration platform alone will not cover it |
| Local, disconnected, or shop-floor work with limited cloud collaboration | Path 5 | Decide who operates the security stack before you buy it |
| Only Federal Contract Information (FCI), no CUI | None of them | You are on the wrong page — see CMMC Level 1 vs Level 2 |
Best for an enclave: a narrow, stable CUI flow with a boundary your people can realistically follow. Best for broader GCC High: pervasive Microsoft collaboration and no appetite for running two environments. Neither one solves by itself: endpoints, administrators, shared security tools, backups, paper CUI, CAD, ERP, OT, and the evidence file an assessor will actually read.
The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.
Your situation changes the answer
The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The contract clause sets your level, not a checklist. Because a general answer can't resolve those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.
- What it asks: your required CMMC level, FCI vs CUI handling, assessment type, IT/cloud environment, and contract timeline
- What you get: the provider category that fits your situation and the readiness steps to get there
- Educational triage only: free · 2-minute assessment · no obligation
What we actually verified for this page
Verified August 22, 2026, at the issuing source:
- The CMMC Program rule — 32 CFR Part 170, effective December 16, 2024, including the Level 2 asset categories at § 170.19(c)(1) and the external service provider table at § 170.19(c)(2). (eCFR; Federal Register, 89 FR 83092.)
- The acquisition rule — the DFARS CMMC rule took effect November 10, 2025, starting Phase 1.
- The suspension — the Department of War suspended CMMC Phase II on July 13, 2026. Phase 1 self-assessment requirements, DFARS 252.204-7012, NIST SP 800-171 Revision 2, SPRS posting, and annual affirmations all continue. (DoW release; implementing memorandum 26-P-1023.)
- The cloud clause — DFARS 252.204-7012(b)(2)(ii)(D) requires an external cloud service handling covered defense information to meet security requirements equivalent to the FedRAMP Moderate baseline and comply with paragraphs (c) through (g). (Acquisition.gov.)
- The equivalency memo — the DoD CIO memorandum on FedRAMP Moderate Equivalency (signed December 21, 2023, released January 2, 2024) and what it does and does not apply to.
- The export regulation — 22 CFR § 120.54(a)(5), § 120.54(b)(1), § 120.54(c), and § 120.55, plus the EAR companion at 15 CFR § 734.18. (eCFR; Cornell Legal Information Institute.)
- The small-business record — the SBA Office of Advocacy comment letter on the proposed CMMC rule (February 2024, commenting on 88 FR 89058) and Advocacy's comment letter to the CMMC Reform Task Force (August 17, 2026).
- Microsoft's own architecture guidance for multitenant defense organizations, and Microsoft's 2026 U.S. Government pricing update effective July 1, 2026.
What we did not verify, and will not claim: any private vendor quote; whether a specific vendor's equivalency evidence package is current today; whether any specific contractor's environment is correctly scoped; whether any assessor will accept any particular boundary; or that any product or provider produces a certification outcome. Nobody can promise that, and anyone who does is telling you something the rule does not support.
Is a CMMC enclave the same thing as GCC High?
No. A CMMC enclave is the defined boundary around the users, systems, services, and workflows that handle or protect CUI. Microsoft 365 GCC High is a government-cloud platform that may host some or all of the workloads inside that boundary. The boundary is a scoping decision. The platform is a purchasing decision. They are made in that order.
This sounds like a semantic point. It can decide whether you migrate a narrow workflow or most of the company.
Here is why. Under 32 CFR § 170.19, your CMMC Assessment Scope is determined by what processes, stores, or transmits CUI, and by what provides security protection to those assets. It is not determined by which logo is on your cloud contract. Two companies can buy identical GCC High tenants and end up with wildly different assessment scopes, because one of them let CUI leak into commercial email and unmanaged laptops and the other didn't.
So when a vendor says "we'll build you an enclave," the correct follow-up is not how much. It's what's inside it, and what's outside it, and can you write that down.
What "enclave" means in practice
The word is doing double duty in the market right now, and neither camp tells you the other definition exists.
Some vendors use enclave to mean a slice of GCC High — you license and migrate only the people who touch CUI, and everyone else stays in your commercial Microsoft 365 tenant. In this usage, the enclave is a deployment shape of GCC High, not an alternative to it. Split-tenant designs commonly require separate commercial and government identities for at least some CUI users, although the exact identity design is architecture-specific. Microsoft documents multitenant defense scenarios, and CMMC-focused implementation providers commonly describe variants such as split-tenant or data-enclave designs.
Other vendors use enclave to mean a way to avoid GCC High — an encrypted workspace, a hosted desktop, or a segmented on-premises environment where CUI lives, while your commercial Microsoft 365 keeps running as the everyday workplace.
Same word. Opposite architectures. Very different bills.
One more data point worth knowing before anyone sells you a second tenant: Microsoft's own architecture guidance for multitenant defense organizations tells customers they "should strive to have your data, Microsoft 365, and Azure cloud services in a single tenant," and that organizations already running multiple Microsoft Entra tenants "should consider consolidating." Microsoft does document multitenant use cases and supports them. But the default recommendation from the platform vendor is one tenant — which is not the message you get from most partners selling a split-tenant build.
Boundary versus platform, in one table
| Term | What it actually is | What it determines | What it does not determine |
|---|---|---|---|
| CMMC enclave | A logically or physically separated CUI security domain | Which users, systems, services, and data flows fall inside the assessment scope | Which cloud product you have to buy |
| Microsoft 365 GCC High | A U.S. government-cloud productivity and collaboration platform | Where covered email, Teams, SharePoint, OneDrive, and identity workloads may run | Your complete CMMC assessment scope, or your compliance outcome |
| GCC High enclave | A GCC High environment used by a defined subset of users and workloads | A narrower Microsoft collaboration boundary while the rest of the company stays commercial | Automatic exclusion of endpoints, administrators, identity, backups, or security tooling |
| Full-company GCC High | Most or all users moved into one government tenant | Fewer seams between commercial and government environments | Automatic coverage of ERP, CAD, on-premises servers, OT, test equipment, or paper CUI |
| Hybrid CUI environment | A boundary spanning GCC High plus Azure Government, VDI, on-premises systems, or OT | Support for workflows that cannot live inside Microsoft 365 | Simplicity — every interface still needs its own evidence |
The middle column is our editorial organization of the scoping concepts in 32 CFR § 170.19 and Microsoft's published product descriptions. The architecture decision itself stays company-specific, and the rule is deliberately silent on how to build one. More on that in a moment — it's the most useful thing in the federal record on this topic and almost nobody cites it.
Do you need GCC High for CMMC Level 2?
No CMMC or DFARS authority names Microsoft GCC High as a universal requirement. CMMC Level 2 requires implementation of the 110 security requirements in NIST SP 800-171 Revision 2, organized into 14 families. The current CMMC Level 2 Assessment Guide presents 320 assessment objectives using the NIST SP 800-171A assessment criteria. Separately, DFARS 252.204-7012 requires an external cloud service handling covered defense information to meet FedRAMP Moderate-equivalent security and comply with the clause's specified incident-response and forensic-support obligations. Several architectures can satisfy those requirements when correctly implemented.
Let's take the two requirements one at a time, because contractors routinely collapse them into one and then overbuy.
What CMMC Level 2 requires
CMMC Level 2 is built on NIST SP 800-171 Revision 2 — 110 security requirements across 14 families, from Access Control to System and Information Integrity. The current DoD CMMC Level 2 Assessment Guide expresses those requirements through 320 assessment objectives, using the assessment procedures incorporated from NIST SP 800-171A. That count does not change based on where you put the data. What changes is which assets, services, people, and evidence paths are inside the assessment scope.
One nuance to keep straight, because it trips up sharp people: NIST itself withdrew Revision 2 and superseded it with Revision 3. For CMMC purposes, Revision 2 is still the controlling version, pinned by 32 CFR Part 170 and reaffirmed in the Department's July 2026 implementation materials. Do not let a consultant hand you a Rev 3 gap assessment and call it a CMMC gap assessment. They are different documents.
The solicitation provision DFARS 252.204-7025 identifies the CMMC level and assessment type designated for the procurement, and the contract clause DFARS 252.204-7021 requires the contractor to have and maintain the required CMMC status when the clause applies. A C3PAO is a CMMC Third-Party Assessment Organization authorized to conduct Level 2 certification assessments. DIBCAC is the Defense Industrial Base Cybersecurity Assessment Center, the government assessment organization for Level 3. Under the current CMMC framework, Level 3 adds 24 selected requirements from NIST SP 800-172 on top of Level 2.
Notice what is not in any of that: a product name.
What DFARS 252.204-7012 requires of your cloud
This is the clause that actually pulls a platform into the conversation, and it has been in DoD contracts since 2016.
DFARS 252.204-7012(b)(2)(ii)(D) says that if you use an external cloud service provider to store, process, or transmit covered defense information, that provider must meet security requirements equivalent to those established by the Government for the FedRAMP Moderate baseline and comply with paragraphs (c) through (g) of the clause — cyber incident reporting, malicious software submission, media preservation, access to additional information and equipment for forensic analysis, and cyber incident damage assessment.
Read that twice. It is a security bar plus a set of contractual duties. It is not a brand.
The evidence asymmetry nobody publishes
Here is where two architectures that both "meet FedRAMP Moderate" stop being equivalent — for you, the buyer.
There are two doors into that requirement, and they cost you different amounts of work:
| Question | Door 1: FedRAMP Authorized | Door 2: FedRAMP Moderate Equivalency |
|---|---|---|
| What it is | The cloud service offering carries a live listing in the FedRAMP Marketplace | The provider was independently assessed as 100% compliant with the FedRAMP Moderate control baseline |
| What the DoD CIO memo requires | The memorandum states it does not apply to offerings already FedRAMP Moderate Authorized — those "can be leveraged without further assessment to meet the equivalency requirements" | 100% of the FedRAMP Moderate baseline, a body of evidence assessed by a third-party assessment organization, and no open POA&Ms |
| What you have to obtain and hold | A dated Marketplace record and the provider's Customer Responsibility Matrix | The full body of evidence, plus the Customer Responsibility Matrix — and you have to be able to actually get it |
| Where an authorized government-cloud offering sits | Door 1 when the exact cloud service offering relied upon is currently FedRAMP Authorized | — |
| Where a non-authorized CUI cloud offering may sit | — | Door 2 only when its evidence package actually satisfies the DoD equivalency criteria |
| The buyer question | "What is the package ID and status, as of our contract date?" | "Who assessed you, when, against which baseline, and are any POA&Ms open?" |
Door 1 / Door 2 framing is ours. The underlying requirements are from DFARS 252.204-7012(b)(2)(ii)(D) and the DoD CIO FedRAMP Moderate Equivalency memorandum, verified August 22, 2026.
Neither door is inferior. Door 2 is a legitimate, DoD-defined path, and at least one CUI enclave provider states publicly that it was the first cloud service provider to meet the Department's equivalency criteria and that its evidence went through DIBCAC review — a company-stated claim about a government process, which you should confirm in writing with the provider rather than take from a marketing page.
But the work is different. Door 1 gives you a public record you can screenshot and file. Door 2 gives you a document set you have to request, read, and keep current. Budget the difference in effort, not just in dollars.
One more piece of that clause that almost no comparison covers: paragraphs (c) through (g) are a separate obligation from the FedRAMP bar. Ask any cloud provider — Microsoft, an enclave vendor, anyone — where their written position on 7012 (c)–(g) is published. Some publish a specific statement. Some don't. That answer is checkable, it costs you one email, and it tells you a great deal about how seriously a vendor takes the defense market.
So where does "GCC High is required" come from?
Three legitimate places, none of which is a regulation.
Microsoft's own guidance points organizations handling export-controlled and the most sensitive CUI categories toward GCC High. Most of the content ranking for these searches is written by firms that sell GCC High migrations — that isn't sinister, but it shapes the framing. And some primes flow a GCC High requirement down to subcontractors to keep the supply chain simple. A written GCC High requirement incorporated into your subcontract or purchase order can bind you even when CMMC itself does not name the product. Get the requirement in writing and review the actual subcontract terms before you buy around it.
What is not accurate is the claim, common in vendor content, that GCC High "isn't optional" for organizations handling CUI. The clause sets a security standard and a set of duties. More than one environment can meet them. We'd rather you know that before the purchase order than after.
Enclave vs GCC High for CMMC: the five architecture paths
There are five defensible architecture patterns, not two. They differ on what enters your assessment scope, how the FedRAMP requirement is satisfied, which legal theory covers export-controlled data, what happens to your endpoints, and which failure mode is most likely to bite you. The right path is the smallest boundary you can honestly contain, operate, document, and defend — not the smallest one you can draw.
This is the grid we built because nobody else had. Every column is a question a C3PAO or a self-assessment record will eventually make you answer.
The DCR CMMC Environment Decision Grid
Part of The CMMC Path Framework. It maps CUI flow, assessment scope, platform needs, endpoints, and operating constraints to an architecture pattern and a provider category. It is not a score, a ranking, a certification determination, or compliance advice, and it routes to a category — never to a named provider.
| Decision factor | Path 1: Encrypted overlay enclave (commercial M365 retained) | Path 2: GCC High enclave (split tenant) | Path 3: Full-company GCC High | Path 4: Hybrid (GCC High + Azure Gov / VDI / on-prem / OT) | Path 5: On-prem or VDI enclave (no GCC High) |
|---|---|---|---|---|---|
| What it is | An encrypted email-and-file workspace over your existing commercial tenant; only CUI users licensed | A separate GCC High tenant for the people who touch CUI; everyone else stays commercial | Most or all users and Microsoft workloads move into one government tenant | GCC High for collaboration, plus a controlled layer for compute, engineering, or production | CUI stays in a hardened local environment or a remote-access session |
| Where CUI lives | Inside the overlay only | Inside the GCC High tenant | Inside the GCC High tenant | Split across layers by workload | On controlled local systems or the hosted desktop |
| Your commercial tenant becomes | Configuration-dependent: it may be Out-of-Scope, a CRMA, an SPA, or a CUI Asset depending on what it can process and what it protects | Same analysis: keeping CUI out does not automatically make the tenant out of scope | Usually retired from CUI use or retained only for defined non-CUI functions | Depends on whether the commercial tenant participates in the protected workflow or protects in-scope assets | Often retained for ordinary business, with category determined by actual use |
| Microsoft tenants operated | One | Two | One | Two or more, plus non-Microsoft layers | One or none for CUI |
| Identity design | Often one primary identity, but depends on the overlay | Commonly separate commercial and government identities for some users; exact design varies | One primary government identity for most users | One or more identity systems depending on the layers | Depends on the directory and remote-access design |
| Identity provider in scope | A shared identity system is a Security Protection Asset when it provides security protection to CUI Assets | Government identity is in scope; commercial identity may also be in scope if it authenticates or protects the boundary | Government identity is in scope | Each identity layer must be analyzed by function | The directory controlling enclave access is in scope when it protects CUI Assets |
| How DFARS 7012(b)(2)(ii)(D) is met | If an external CSP handles covered defense information, verify the exact offering against FedRAMP Moderate authorization or DoD-defined equivalency and paragraphs (c)–(g) | Same rule; do not infer it from the product family name | Same rule | Verify each external CSP separately | Door 1, Door 2, or not applicable when no external CSP stores, processes, or transmits covered defense information |
| Export-control analysis | May rely on the conditions in 22 CFR § 120.54(a)(5) for qualifying encrypted ITAR technical data; EAR must be analyzed separately | Often selected for Microsoft's U.S. data-residency and screened-personnel commitments; counsel still confirms applicability | Same | Depends on the data category and layer | Depends on the data, access model, and whether § 120.54 or another authorization applies |
| Endpoint disposition | Endpoints running the client are usually in scope | Endpoints joined to the GCC High tenant are in scope | Broad endpoint population in scope | Role-specific; VDI clients can qualify for the narrow carve-out | Best chance of the VDI keyboard/video/mouse carve-out |
| External collaboration | Often the easiest — many overlays allow free external accounts for subs | Native GCC High sharing is restricted; cross-cloud collaboration is configurable but is real admin work | Same restrictions, applied company-wide | Varies by layer | Usually requires a separate exchange mechanism |
| Dominant failure mode | Boundary leakage — CUI walks back into commercial email one forward at a time | User confusion — people work in the wrong tenant | Cost and disruption — you migrated people who never touch CUI | Ownership gaps — nobody owns the seams between layers | Operating burden — you run and evidence more of the stack yourself |
| Cost shape | Keep 100% of commercial licensing, add overlay for CUI users | Pay for a commercial seat and a GCC High seat for every enclave user, permanently | Broadest licensing and migration, one environment to run | Highest integration complexity | Capital or hosting cost, plus internal labor |
| Best fit | Small, contained CUI footprint; email and files | A defined program team that needs full Microsoft collaboration for CUI work | Defense work is the core business | Manufacturers, engineering firms, anyone with CAD/ERP/OT in the CUI path | Solo operators, single-station shops, disconnected work |
Sources: architecture characteristics reflect 32 CFR § 170.19 asset categories, DFARS 252.204-7012, 22 CFR § 120.54, and vendor-published product documentation. Cost shapes are structural, not price quotes — see the cost section below. Verified August 22, 2026.
Our decision rules
These are editorial conclusions drawn from the verified facts above. They are not regulatory determinations, and your contract governs.
- Only FCI, no CUI? This comparison is the wrong page for you. Level 1 is built on the 15 basic safeguarding requirements in FAR 52.204-21, not the 110 CUI controls. Go to CMMC Level 1 vs Level 2 and stop shopping for enclaves.
- A narrow, stable CUI group with enforceable workflows? Price Path 1 first.
- A narrow group that genuinely lives inside Microsoft email, Teams, and SharePoint? Price Path 2 before you assume an overlay will feel acceptable to them.
- CUI in most departments and mailboxes? Compare Path 3 against a broader hybrid. Do not force an artificially narrow boundary — you will pay for it twice.
- CAD, CAM, ERP, CNC, PLC, test equipment, or OT in the CUI path? A collaboration platform alone is incomplete. Go to Path 4, and read the manufacturing section below before you sign anything.
- Export-controlled technical data anywhere in the flow? Do not let the platform decide the legal question. Read the export-control section next.
- Shared identity, SIEM, EDR, backup, device management, or an external administrator crossing the proposed boundary? Those assets or services may stay in scope no matter which path you choose. That analysis comes before the purchase order.
What happens to your commercial Microsoft 365 tenant?
Under a full GCC High migration, the commercial tenant is decommissioned or emptied of CUI-adjacent work. Under a GCC High enclave, it keeps running and you must prove it never touches CUI. Under an overlay or on-premises enclave, it remains your primary workplace — which is where scope quietly comes back. Under 32 CFR § 170.19(c)(1), an Out-of-Scope Asset must be unable to process, store, or transmit CUI, must provide no security protection to CUI assets, and must be physically or logically separated from them. All three conditions, not one.
Most enclave conversations stop at "where does the CUI go." The expensive question is what happens to everything else. Here is our disposition map — the same fifteen systems, run through all five paths, with the evidence each category demands.
The Commercial Tenant Disposition Map
Asset categories are defined at 32 CFR § 170.19(c)(1). The dispositions below are decision conditions, not automatic labels. The same commercial system can be a CUI Asset, Security Protection Asset (SPA), Contractor Risk Managed Asset (CRMA), or Out-of-Scope Asset depending on what it actually processes and protects.
| System or service | When it becomes a CUI Asset | When SPA / ESP treatment can apply | When CRMA or Out-of-Scope treatment may be possible | Evidence to keep |
|---|---|---|---|---|
| Commercial Exchange / email | CUI is received, stored, cached, forwarded, or otherwise processed there | A connected service protects CUI mail or security data | CRMA only when it can handle CUI but policy and practice keep CUI out; Out-of-Scope only when all § 170.19 conditions are met | Mail-flow diagram, transport and forwarding rules, mobile-client settings, spill procedure |
| Commercial SharePoint / OneDrive | CUI is uploaded, synced, cached, or shared there | Security tooling protecting in-scope repositories can be SPA/ESP | CRMA or Out-of-Scope depends on capability, intended use, protection role, and separation | Sharing settings, sync-client policy, inventory, SSP treatment |
| Commercial Teams | CUI appears in chat, files, meeting artifacts, recordings, or transcripts | Connected protection services may be SPA/ESP | CRMA or Out-of-Scope only when the regulatory conditions actually fit | Retention configuration, guest access, file-location map |
| Identity provider (Entra ID / AD / other IdP) | Rarely because of identity alone; categorize by the data and functions it handles | SPA when it provides security protection to CUI Assets | Out-of-Scope only if it neither handles CUI nor protects CUI Assets and is properly separated | Identity architecture, privileged roles, authentication paths, conditional-access evidence |
| MDM / Intune | CUI is stored or processed in the service itself | SPA when it configures or protects CUI endpoints; external provider may be an ESP | Outside the CMMC scope only when it neither handles CUI nor protects in-scope assets | Enrollment scope, policy baselines, admin roles |
| EDR | CUI itself is collected into telemetry or artifacts | SPA when it protects CUI Assets; hosted provider may be an ESP | Outside scope only if it does not protect in-scope assets or receive relevant data | Coverage report, data-flow map, admin list, responsibility matrix |
| SIEM / log retention | CUI appears in logs or captured content | SPA when it receives Security Protection Data; hosted provider may be an ESP | Outside scope only if it neither receives protected data nor protects CUI Assets | Log-flow diagram, retention, provider CRM, access evidence |
| Backup | CUI is copied into the backup set | Can also be SPA when it protects availability/integrity of CUI systems or stores security configuration data | Outside scope only if neither CUI nor security-protection data is present and it does not protect CUI Assets | Backup map, encryption, restore tests, repository authorization |
| Help desk / MSP / administrator | Provider-managed assets may become CUI Assets if they receive CUI | Provider and supporting assets may be in scope as an ESP/SPA when they administer or protect the CUI environment | Outside only when there is no CUI or security-protection role | Contract, role list, access logs, CRM, privileged-access design |
| CUI-user endpoints | CUI is processed, stored, or transmitted locally | Endpoint security tooling can be SPA | A VDI endpoint may qualify as out of scope only under the narrow keyboard/video/mouse condition in the Scoping Guide | Device baseline, local-storage controls, print/clipboard/USB policy |
| Non-CUI endpoints | CUI reaches or is processed by the device | Shared security or admin functions may pull related assets into scope | CRMA or Out-of-Scope depending on capability, intended use, and separation | Inventory and separation evidence |
| Engineering workstations | CUI drawings/models/programs are created, viewed, edited, cached, or stored locally | Shared protection services can be SPA | Out-of-Scope only when the workstation does not handle or protect CUI Assets | Data-flow map, local controls, application inventory |
| CAD / PLM / ERP | CUI is processed, stored, or transmitted by the application or database | Shared security services may be SPA | Some systems may remain CRMA or out of scope if the actual data and architecture support it | Categorization rationale, network diagram, SSP treatment |
| Shop-floor / test equipment | CUI processing can make the asset a CUI Asset; qualifying OT, IoT/IIoT, GFE, restricted systems, or test equipment may instead be treated as Specialized Assets under the rule | Protection services around the equipment may be SPA | Never label it "specialized" solely because it is on a shop floor; document why the regulatory definition fits | Inventory, classification rationale, segmentation and access evidence |
| Printers / MFPs | CUI is processed, cached, scanned, faxed, or stored by the device | Print-management or monitoring services may be SPA | Some print paths can be excluded only when they never handle or protect CUI | Print controls, device storage settings, physical handling, destruction records |
CRMA = Contractor Risk Managed Asset. SPA = Security Protection Asset. ESP = External Service Provider. Categories per 32 CFR § 170.19(c)(1) and § 170.19(c)(2), verified August 22, 2026.
The part we'd rather you hear from us than from an assessor
Here is the honest admission, and we're putting it before our own comparison so you can weigh everything that follows.
A narrower enclave is not automatically cheaper. The pitch — license fewer users, migrate fewer mailboxes, assess fewer systems — is real, and for a genuinely contained CUI footprint it can be transformative. But two identities, two collaboration environments, transfer controls, user training, spill response, duplicate administration, and evidence spanning the boundary can erase the savings entirely. And under Paths 1 and 5, your commercial Microsoft 365 tenant does not disappear. Depending on what it can process, what it actually handles, and whether it protects CUI Assets, it may be a Contractor Risk Managed Asset, Security Protection Asset, CUI Asset, or Out-of-Scope Asset. The label follows the architecture — not the sales pitch.
Now the part that makes that a reason to keep going rather than to give up.
A Contractor Risk Managed Asset is a real, rule-recognized category with a deliberately light burden. Under 32 CFR § 170.19(c)(1), a CRMA is an asset that can but is not intended to process, store, or transmit CUI because of your policies and practices, it is not required to be physically or logically separated from CUI assets, and where it is sufficiently documented in the SSP, the assessor does not assess it against the other requirements. The rule goes further and states that any limited check "shall not materially increase the assessment duration nor the assessment cost." That is an entirely different obligation from bringing your tenant in as a CUI Asset.
So the trade you are actually making is migration cost now versus boundary discipline forever. For a small, contained CUI footprint, that trade is frequently worth taking. What kills the narrow path is not the architecture. It's buying it and then not enforcing it.
If this is you, stop here and go elsewhere: If CUI already lives in your Outlook, SharePoint, and Teams — and has for a while — none of this comparison is your first problem. Those systems are already CUI Assets. Start with discovery and remediation, not a purchase order. See GCC High for CMMC for the "CUI already touched Microsoft 365" playbook. And if defense work is most of your revenue and most of your staff touch CUI, stop comparing enclaves entirely — see CMMC enclave vs enterprise-wide compliance for the scope-size decision that comes before this one.
Which path does your situation actually point to?
If you are still unsure whether you need an enclave provider, GCC High implementation help, an MSSP, an RPO/RP, a GRC platform, or an assessor, use The Defense Compliance Report's Find My CMMC Path tool. It uses your general CMMC level, FCI/CUI handling, assessment type, IT/cloud environment, and contract timeline to route you to the provider category and readiness steps that fit your stage.
General answers only. Do not enter CUI, drawings, technical data, contract numbers, system diagrams, credentials, or vulnerability details.
Do you need GCC High for ITAR or export-controlled technical data?
Both architectures can be viable for some export-controlled workflows, but they do not rely on the same facts. Microsoft positions GCC High around U.S. data residency and screened-personnel commitments. Separately, 22 CFR § 120.54(a)(5) says that sending, taking, or storing qualifying unclassified technical data is not an export, reexport, retransfer, or temporary import when every listed condition is satisfied. Which path works for your data is an export-control determination for qualified counsel, not a vendor slogan.
This is the section that changes the most decisions, and it is the one nobody on page one engages.
Almost every article on this topic says some version of "ITAR means GCC High." That is a reasonable default and it is often the right practical answer. It is not what the regulation says.
What 22 CFR § 120.54 actually provides
The International Traffic in Arms Regulations (ITAR) control the export of defense articles and technical data. In a 2020 rulemaking, the State Department's Directorate of Defense Trade Controls added § 120.54 — "Activities that are not exports, reexports, retransfers, or temporary imports."
§ 120.54(a)(5) provides that sending, taking, or storing technical data is not an export, reexport, retransfer, or temporary import if the data is:
- Unclassified;
- secured using end-to-end encryption;
- secured using cryptographic modules compliant with FIPS 140-2 or its successors, supplemented by key management and controls consistent with current NIST guidance — or by other means providing security strength at least comparable to AES-128; and
- not intentionally sent to a person in, or stored in, a country proscribed in § 126.1; and
- not sent from a country proscribed in § 126.1.
§ 120.54(b)(1) defines end-to-end encryption to require cryptographic protection between the originator (or its in-country security boundary) and the intended recipient (or the recipient's in-country security boundary), and the means of decryption may not be provided to any third party. Paragraph (b)(2) also limits who may be the intended recipient. If a platform provider or another third party can decrypt the data, do not assume the § 120.54(a)(5) path applies.
§ 120.54(c) adds that the ability to access technical data in encrypted form meeting those criteria "does not constitute the release or export of such technical data."
There is a companion provision under the Export Administration Regulations at 15 CFR § 734.18.
That is the mechanism at least one CUI enclave vendor's architecture rests on, and it is a real one. Verified at eCFR and the Cornell Legal Information Institute, August 22, 2026.
Two theories, side by side
| Question | GCC High operational approach | § 120.54 encrypted-data approach |
|---|---|---|
| Primary basis for the architecture decision | Microsoft service commitments around U.S. data location and screened personnel; counsel still confirms the actual export-control requirement | 22 CFR § 120.54(a)(5) when every condition in that section is satisfied |
| What must be true | The exact Microsoft service and configuration must provide the commitments your data and contract require | Data is unclassified; end-to-end encrypted; qualifying cryptography is used; means of decryption are not provided to a third party; it is not intentionally sent to a person in or stored in a § 126.1 country; and it is not sent from a § 126.1 country |
| What you must prove | Tenant configuration, service terms, personnel commitments, where data resides | Encryption architecture, exclusive key control, FIPS validation certificates, storage locations |
| What breaks it | CUI leaving the sovereign environment; support interactions outside the boundary | Any third party holding decryption capability; non-compliant crypto; plaintext exposure |
| What it does not cover | The rest of your CMMC scope | The DFARS 7012 FedRAMP requirement, which applies independently |
| Who confirms applicability | Qualified export counsel or another appropriately qualified authority based on your facts | Qualified export counsel or another appropriately qualified authority based on your facts |
Framework ours; underlying requirements from 22 CFR § 120.54 and Microsoft's published service descriptions. Verified August 22, 2026.
The limits, stated as plainly as the opportunity
We are not telling you the encryption carve-out lets you ignore export control. It does not, and a page that implied otherwise would deserve to be ignored.
- The plaintext stays controlled. § 120.54 exempts the encrypted transmission and storage. The underlying unencrypted technical data remains subject to ITAR.
- Access information is separately controlled. 22 CFR § 120.55 defines "Access Information" — decryption keys, network access codes, passwords — as information that allows access to encrypted technical data in unencrypted form. Handing those to the wrong person is its own problem.
- A deemed export is still a deemed export. Showing plaintext technical data to a foreign person in the United States is a release, regardless of how it was stored.
- § 120.54 is export control only. It says nothing about DFARS 252.204-7012's FedRAMP requirement, which applies whether or not the encryption carve-out is available.
- FIPS 140-2 has a date on it. § 120.54(a)(5)(iii) says "FIPS 140-2 or its successors," so the regulatory language is not frozen to one validation generation. NIST says FIPS 140-2 validations remain on the Active List through September 21, 2026; on September 22, 2026, only FIPS 140-3 validations remain active and the FIPS 140-2 certificates move to the Historical List. Historical is not the same as revoked, but NIST says historical modules should not be selected for new Federal procurements without the relevant risk determination. NIST SP 800-171 Rev. 2 requirement 3.13.11 (SC.L2-3.13.11) separately requires FIPS-validated cryptography when cryptography is used to protect the confidentiality of CUI. Ask every vendor for the certificate number, validation status, and standard its module relies on.
Our editorial conclusion: if any of your CUI may be export-controlled, the determination belongs to qualified export counsel before it belongs to a vendor. And whichever path you take, the vendor's answer should be a written architecture statement naming its legal basis — not a logo on a slide.
Before a vendor answers the export-control question for you
Our free CMMC Readiness Checklist is mapped to all 14 NIST SP 800-171 Rev. 2 control families, with the evidence each family expects. It's the fastest way to see which parts of the answer belong to your provider and which stay yours no matter what you buy.
Download the CMMC Readiness Checklist →
Will endpoints, email, identity, backups, and security tools pull your scope back open?
They can, and this is how most narrow boundaries fail. CMMC scope is not limited to where the CUI file sits. Under 32 CFR § 170.19(c)(1), assets that process, store, or transmit CUI and assets that provide security protection to those assets are both relevant to the Level 2 assessment scope — whether or not they sit inside the environment you're calling the enclave.
We built the matrix below because "the boundary leaked" is not a useful post-mortem. Each row is a specific question with a specific consequence and a specific artifact to demand.
The Boundary Leakage Matrix
| Leakage path | The question you must answer | Potential scope consequence | Evidence to request from the vendor |
|---|---|---|---|
| Can CUI reach a commercial mailbox, a forwarding rule, an archive, a mobile client, or personal storage? | Commercial messaging assets stop qualifying as out of scope | Mail-flow diagram, transport rules, DLP configuration, forwarding controls, spill procedure | |
| Endpoints | Can users download, cache, copy, or otherwise process CUI locally? | The endpoint may become a CUI Asset when it processes, stores, or transmits CUI | Device configuration baseline, endpoint inventory, local-storage controls, print policy |
| VDI | Does the endpoint transmit only keyboard, video, and mouse interaction — with no CUI processing, storage, or transmission beyond that? | Only an endpoint meeting that exact condition is treated as out of scope | VDI policy, clipboard/drive-mapping/print/USB restrictions, technical test evidence |
| Identity | Does a commercial identity system authenticate, administer, or otherwise protect the enclave? | It may be a Security Protection Asset when it provides security protection to CUI Assets | Identity architecture, privileged-role inventory, conditional-access evidence, CRM |
| Logging / SIEM | Do enclave logs or security configuration data leave for an external platform? | The platform and its provider may enter scope as an SPA or ESP | Log-flow diagram, provider CRM, retention and access evidence |
| EDR / device management | Does a shared platform protect CUI endpoints? | The protecting assets may be SPAs; an external provider may be an ESP | Coverage report, administrative-access list, responsibility matrix |
| Backups | Are CUI or enclave configurations copied into commercial backup repositories? | Backup systems become CUI Assets or SPAs | Backup data-flow map, encryption, restore tests, repository authorization |
| Administrators / MSP | Can external administrators reach CUI, security data, or enclave configuration? | Provider services and supporting assets enter scope | Contracts, role lists, CRM, access logs, personnel controls |
| Printing and paper | Can users print CUI or move it into physical workflows? | Physical locations, processes, and storage join the protection problem | Print controls, physical handling procedure, destruction records |
| CAD / ERP / OT | Does CUI move into engineering, production, inspection, or test systems? | Those systems become CUI Assets or Specialized Assets | Data-flow map, categorization rationale, SSP treatment, network diagram |
| Third-party sharing | Can suppliers or customers receive CUI from the enclave? | Subcontractor flow-down, external-service, and transfer requirements may apply depending on the contract and data | Approved transfer method, recipient validation process, applicable flow-down records |
Consequences reflect the asset definitions at 32 CFR § 170.19(c)(1) and the external service provider requirements at § 170.19(c)(2). Verified August 22, 2026.
The VDI carve-out, stated exactly
There is one clean way to keep an ordinary endpoint out of scope, and it is narrow. An endpoint hosting a virtual desktop client can be treated as out of scope only when it is configured so that it does not process, store, or transmit CUI beyond keyboard, video, and mouse interaction with the virtual desktop.
If redirected drives, clipboard, printing, USB, caching, or another feature causes the endpoint to process, store, or transmit CUI beyond the keyboard/video/mouse interaction described in the Scoping Guide, the endpoint no longer fits that out-of-scope condition.
Do not accept "we use VDI, so the laptops are out of scope" from any vendor. Ask them to show you the configuration and the test evidence that proves the restriction. That artifact is the difference between an out-of-scope claim and an out-of-scope finding.
Which path works for manufacturers — CAD, CNC, test equipment, and OT?
Manufacturers often need to evaluate a hybrid answer, because Microsoft 365 GCC High can handle collaboration workloads but does not, by itself, define the treatment of a local CAD workstation, ERP database, CNC program, PLC, coordinate measuring machine, or paper traveler. Under 32 CFR § 170.19, each asset must be categorized by what it actually does: some will be CUI Assets, and qualifying OT, IoT/IIoT, Government Furnished Equipment, restricted information systems, or test equipment may be Specialized Assets. The cloud purchase does not make those systems disappear from the scoping analysis.
If you make things, this section matters more than everything above it.
Follow the drawing, not the org chart
The office-only model of CMMC assumes CUI arrives in an inbox, gets read, and gets filed. In a machine shop, technical data has a journey:
- A drawing arrives from the prime.
- Estimating opens it to quote the job.
- Engineering reviews or modifies the model.
- CAM generates tool paths from it.
- The program lands on a machine or a shop-floor file share.
- Inspection compares finished parts against the model.
- Quality records reference dimensions from it.
- Files go back to the customer.
- Everything gets archived, often for years.
Count the systems in that list. Now count how many of them are in Microsoft 365. That gap is the reason a "GCC High solves CMMC" pitch falls apart on a shop floor — and the reason a pure overlay enclave often doesn't fit either.
Specialized Assets are not ignored assets
The rule identifies a distinct category for this problem. Specialized Assets under 32 CFR § 170.19 include Internet of Things and Industrial IoT devices, Operational Technology, Government Furnished Equipment, restricted information systems, and test equipment when they meet the rule's definition and scoping treatment. A machine does not become a Specialized Asset merely because it sits on a shop floor.
Specialized Assets receive different assessment treatment. They do not receive no treatment. They must be documented and treated consistently with the applicable CMMC scoping guidance. If a vendor tells you a CNC, PLC, or test system simply "doesn't count," ask for the written asset-category rationale before you rely on that answer.
Four patterns that actually work in a shop
| Pattern | How it works | Where it usually breaks |
|---|---|---|
| GCC High collaboration + on-premises engineering enclave | Email, Teams, and files in GCC High; CAD, CAM, and program storage in a segmented internal network | The transfer step between them — who moves files, how, and with what logging |
| GCC High + Azure Government VDI + segmented production network | Engineering runs in a hosted desktop; shop floor sits behind its own boundary | CAD/CAM graphics performance and machine-side file delivery |
| On-premises enclave + controlled external exchange service | Everything controlled stays inside; an authorized service handles prime and supplier exchange | You own more of the security stack and all of the evidence |
| Dedicated engineering and production environment with controlled transfer stations | A physically separated CUI environment with defined transfer points | Discipline — transfer stations become the whole control story |
A practical note on performance: a cloud-only virtual desktop can simplify endpoint containment and still be a poor fit for heavy CAD/CAM work or locally connected measurement equipment. Test the actual workflow with representative files, peripherals, latency, and production constraints before you commit.
If you're a manufacturer, our CMMC for manufacturers and CMMC for machine shops guides go deeper on shop-floor scoping than this page can.
Which is actually cheaper — and what changes the answer?
The trade is broader migration and licensing against boundary engineering and dual-environment operations. There is no defensible employee-count breakpoint where one architecture automatically becomes cheaper. A narrow enclave deserves a serious look when the CUI population and workflows are genuinely contained; broader GCC High or a hybrid deserves a serious look when CUI crosses most collaboration paths or the cost of running two environments starts to dominate.
We keep the full five-layer cost model and the price catalog on our CMMC enclave cost guide, where it can be refreshed independently. What belongs here is the difference between paths — which is the number vendors never quote you.
Where the money actually goes, by path
| Cost driver | Path 1 (overlay) | Path 2 (GCC High enclave) | Path 3 (full GCC High) | Path 4 (hybrid) | Path 5 (on-prem/VDI) |
|---|---|---|---|---|---|
| License breadth | Commercial retained + overlay/service licensing for CUI users | Commercial and government licensing may overlap for users who remain active in both environments | Broadest government-cloud licensing footprint | Mixed | Capital, hosting, or software depending on design |
| Migration breadth | Minimal | Selective | Broadest | Workload by workload | Build, not migrate |
| Boundary complexity | Highest relative to size | High — two tenants, two identities | Lowest tenant-boundary complexity | Highest integration complexity | Moderate |
| Commercial integrations | Preserved | Preserved outside the enclave | Often require replacement | Preserved selectively | Preserved |
| User training | Which environment for which task | Which account for which task | Broad change management | Role-specific | Transfer discipline |
| Evidence burden | Fewer assets if the boundary holds | Two environments to evidence | More assets, fewer seams | Multiple layers and interfaces | You produce most of it |
| The line item people forget | The commercial environment may still require documented scope treatment | Split-tenant licensing, identity, and support can persist as long as both environments are in use | Migration overlap and integration replacement can be material | Ownership of seams between layers | Hardware lifecycle, internal labor, and evidence operations |
Three dated facts to put in your model
- Microsoft raised U.S. Government pricing effective July 1, 2026 — Microsoft 365 G3 GCC High up 8%, G5 GCC High up 5%. Build that into a multi-year budget rather than a first-year quote.
- Microsoft does not publish GCC High list prices the way it publishes commercial ones. Every figure you see, including ours, is a planning range pending an authorized-partner quote by SKU.
- DoD's own published cost estimates exclude implementation. The Final Rule's regulatory impact analysis put a small-entity Level 2 C3PAO path at roughly $104,670 over three years and an other-than-small entity at about $117,768, with the Level 2 self-assessment path around $37,000 for a small entity. Those figures cover assessment, certification, and affirmation activity. They do not include building your environment. The enclave or the tenant sits entirely on top.
The comparison trap
A low enclave quote and a high GCC High quote may not be comparable because each vendor can be pricing a different boundary. One may price only a small user group and collaboration layer; another may include endpoint management, identity, documentation, migration, and ongoing security operations. Normalize the scope before you compare the total.
The fix is to make every vendor quote the same boundary. Which is exactly what the letter further down this page is for.
Comparing quotes that don't compare?
Tell us your CMMC level, rough CUI user count, current environment, and timeline — nothing sensitive — and we'll route you to source-checked provider categories that can quote against the same non-sensitive scope, so you're comparing like for like instead of guessing.
See scoped quotes from matched provider categories →
Matching may generate lead-routing compensation when disclosed. It never changes our regulatory analysis or category routing. Do not submit CUI, drawings, contract numbers, or system diagrams.
How long does each path take?
There is no defensible universal timeline, because the work is driven by scope discovery, tenant complexity, endpoint count, integrations, and documentation maturity — not by the platform. Microsoft's own CMMC guidance advises organizations to allocate at least three months for cloud migration, which is vendor planning guidance rather than a typical duration for any specific environment.
A short platform-deployment quote is not the same thing as a CMMC-ready program. Scope discovery, evidence, policies, remediation, operations, and migration risk still exist outside the provisioning task.
Here are the workstreams that actually consume the calendar:
| Workstream | Overlay | GCC High enclave | Full GCC High | Hybrid |
|---|---|---|---|---|
| CUI discovery and boundary design | Critical | Critical | Critical | Critical, and usually longest |
| Platform or tenant provisioning | Provider-dependent | Eligibility and provisioning required | Eligibility and provisioning required | Multiple environments may need separate provisioning |
| Identity design | Boundary-focused | Split-tenant identity and cross-tenant settings where used | Organization-wide government identity design | Cross-platform |
| Data and mailbox migration | Minimal | Selective | Broad | By workload |
| Endpoint configuration | CUI population | CUI population, joined to the new tenant | Broad population | Role-specific |
| Integration remediation | Boundary interfaces | Boundary interfaces | Enterprise integrations | Multiple technical interfaces |
| SSP, diagrams, and evidence | Enclave boundary | Two environments | Enterprise boundary | Multi-layer boundary |
| Stabilization and adoption | Boundary discipline | Which-account discipline | Broad change management | Workflow-specific |
The real urgency questions — the ones worth building a schedule around — are these. What date is in the solicitation or contract? When does your prime expect evidence? Is your SPRS score current and supportable? Do you need a coexistence period? Can production pause for a cutover?
And one that catches people: a significant change to your architecture or boundary can require a new assessment, while ordinary changes inside an established boundary are handled through continued compliance and your annual affirmation. If you are going to change the boundary, change it before you are assessed, not after.
Does the CMMC Phase 2 suspension change this decision?
No — and that is precisely the point. The Department of War suspended CMMC Phase II on July 13, 2026, pausing the third-party certification milestone that had been scheduled for November 10, 2026. It did not touch DFARS 252.204-7012, NIST SP 800-171 Revision 2, SPRS score posting, or annual affirmations. The cloud requirement driving this entire architecture decision is untouched.
Let's be precise about what changed, because a lot of contractors have drawn exactly the wrong conclusion.
What was suspended: the Phase II transition and all pending and future CMMC implementation milestones. During the suspension, Department procurement requirements may designate only Level 1 (Self) or Level 2 (Self). New Level 2 (C3PAO) and Level 3 (DIBCAC) designations are suspended. Active solicitations containing those requirements are to be amended; existing contracts containing them are to be modified before the next option period or scheduled administrative modification.
What was not suspended: DFARS 252.204-7012. NIST SP 800-171 Revision 2. Your self-assessment. Your SPRS score. Your annual affirmation. The FedRAMP requirement for any cloud holding your CUI.
What prime-contractor flow-downs can still do: independently impose requirements through the terms of your subcontract or purchase order. The suspension memorandum governs Department implementation; it does not automatically rewrite every private subcontract. Confirm the actual requirement and timing in writing with each relevant prime and review the governing agreement.
The dangerous wrong conclusion, stated plainly so nobody makes it: "CMMC is paused, so the cloud question can wait." It cannot. The clause that decides where your CUI is allowed to live has been in DoD contracts since 2016 and is in force today.
Why this is a good moment to decide the environment and a bad moment to book an assessment
There is real timing here, and we won't manufacture any that isn't.
A CMMC Reform Task Force was established alongside the suspension, with a 60-day mandate. Its public Request for Information closed at 12:00 p.m. Eastern on August 14, 2026, and its recommendations to the Department CIO are expected in the mid-September 2026 timeframe.
That matters to you in one specific way. The suspension does not remove the existing duty to safeguard covered defense information under DFARS 252.204-7012. Future policy changes can still alter CMMC assessment and acquisition mechanics, so do not treat the current suspension as permission to postpone protection work — or as a reason to book a third-party assessment your contract does not currently require.
Before you commit assessment spend, confirm in writing what CMMC assessment type, if any, currently applies to your solicitation, contract, or subcontract after the suspension.
The federal record says the scoping problem is real
We looked for a legitimate case study rather than a vendor testimonial. The best one is in the rulemaking record.
When the CMMC Program rule was proposed, the SBA Office of Advocacy — an independent office inside the Small Business Administration that represents small entities before federal agencies — filed a comment letter in February 2024. Among its central concerns: "Advocacy requests clarification from DoD as to how to create enclaves within businesses." Reporting on that letter quoted Advocacy's position that the rule "does not provide clear guidance on the process to create enclaves, which would allow more small business subcontractors to participate in DoD contracts without meeting the full requirements necessary for the prime contractor."
The Department acknowledged Advocacy's concerns in the Final Rule and committed to enhanced training and small-business outreach. It did not prescribe a standard enclave configuration — reasonably, since enclave architecture has to be tailored to each business.
Then, on August 17, 2026, Advocacy filed again — this time with the CMMC Reform Task Force. Among the cost drivers it named for small firms: unclear CUI scoping.
Two and a half years apart, the same federal small-business advocate identified the same gap. That is the gap this page exists to close. It is also the reason you should be suspicious of anyone who tells you the enclave question has one obvious answer — the government's own advocate has been asking for that answer since 2024 and hasn't received a blueprint.
What evidence makes your boundary defensible?
An assessor evaluates your implementation, not your purchase order. Whichever path you choose, you need to be able to show where CUI moves, how each asset was categorized, what each external provider is responsible for, and how the controls you claim actually operate over time. A Customer Responsibility Matrix from your provider is assessment evidence, not a sales attachment.
Here is the artifact list, split by what every path needs and what each path adds.
Every path needs these
- CUI data-flow diagram
- Asset inventory, tagged to the 32 CFR § 170.19 categories
- Network diagram showing the boundary
- System Security Plan with the boundary described accurately
- Asset-category rationale — why each system landed where it did
- User and role inventory
- Approved transfer paths in and out of the boundary
- External service provider inventory, service descriptions, and contracts
- Customer Responsibility Matrix for every provider touching CUI or security protection data
- Configuration baselines and access-control evidence
- Logging, alerting, and retention evidence
- Backup and restore evidence
- Incident response and spill procedures
- Training records
- Change records and periodic boundary tests
- POA&M status and closeout plan
- A named owner for the annual affirmation in SPRS
What a dual-environment path adds
Commercial-to-government mail-flow rules. Cross-tenant access restrictions. Identity separation design. Forwarding controls. Clipboard, download, and print restrictions. Approved sharing pathways. User acknowledgment and training. Spill-detection tests. Mobile-client restrictions. Backup separation between environments.
What a GCC High path adds
Tenant eligibility documentation. The list of licensed services actually in use. Current authorization or assurance evidence for the exact cloud service offering your boundary relies on, including a dated public status snapshot where one exists. Microsoft's current service description for the features in scope. Privileged-role assignments. And a support process that prevents controlled or sensitive information from being disclosed to support personnel who are not authorized to receive it.
What an equivalency-path enclave adds
The FedRAMP Moderate Equivalency body of evidence, the assessing organization, the assessment date, and the POA&M status. FIPS validation certificate numbers and the standard they're against. The written 7012 (c)–(g) position. And, if the architecture relies on the encryption carve-out, a written statement of exclusive key control.
What a manufacturing or OT path adds
Specialized Asset classification and rationale. Network placement and segmentation evidence. Risk-based treatment documented in the SSP. Access methods and transfer controls. Maintenance and vendor-access process.
The sentences an assessor will not accept
No matter how confidently they're delivered: "We bought GCC High." "Microsoft handles that." "Our MSP said it was compliant." "CUI probably doesn't go there." "Users know not to upload it." "We'll document it later."
Every one of those is a sentence. An assessment runs on artifacts.
What to put in writing before you sign either quote
Send the same questions to both vendors and compare the answers, not the brochures. Six questions apply to any architecture, four are specific to a GCC High path, and four are specific to an equivalency-path enclave. If a vendor won't answer these in writing, that is your answer.
Copy this. Use it. It is free, it is not gated, and it will do more for your negotiation than anything else on this page.
To any vendor, any path
- Which of the five architecture paths are you quoting — encrypted overlay, GCC High enclave, full-company GCC High, hybrid, or on-premises/VDI enclave?
- Under 32 CFR § 170.19(c)(1), what asset category does each of our systems land in after your build — and will you put that categorization in writing?
- Provide the Customer Responsibility Matrix before contract signature, not after go-live.
- Which identity provider authenticates or protects access to the CUI environment after your build, and how are you categorizing it under § 170.19?
- Is assessment support included, separate, or excluded — and to be explicit, is the C3PAO assessment itself in your price?
- What is your written position on DFARS 252.204-7012 paragraphs (c) through (g), and where is it published?
If they're quoting a GCC High path
- Confirm the current FedRAMP Marketplace record and package ID for the exact offering our CUI will touch, as of our contract date.
- What is the dual-license overlap period in your quote, and what happens to it if migration runs long?
- Which of our existing third-party tools do not support GCC High, and what replaces them?
- If this is a split-tenant build, how many identities will each CUI user hold, and what is the cross-tenant collaboration design for working with primes and subs?
If they're quoting an equivalency-path enclave
- Provide the FedRAMP Moderate Equivalency body of evidence, the assessing organization, and the assessment date — and state whether any POA&Ms are open.
- Identify your FIPS validation certificate numbers, current status, and standard (140-2 or 140-3), given that FIPS 140-2 validations remain active through September 21, 2026 and move to the Historical List on September 22.
- If our data may include ITAR-controlled technical data, state in writing whether your architecture relies on 22 CFR § 120.54(a)(5), identify how every condition is met, and state who holds the means of decryption. Address EAR-controlled data separately.
- How do you keep your FedRAMP Moderate equivalency evidence package current, and what events trigger a reassessment or evidence refresh?
One rule that protects you: do not attach CUI, drawings, technical data, system diagrams, vulnerability reports, or contract documents to any of these emails. Describe your environment in general terms. Everything on this list can be answered without you sending a single controlled file.
Which CMMC provider category should you hire first?
Most contractors making this decision need scoping and readiness help before they need an assessor. Use an RPO/RP, a CMMC-focused MSP or MSSP, or a government-cloud implementation partner to define and build the environment. Engage a C3PAO for the formal certification assessment only when your scope and evidence are ready. Under the CMMC conflict-of-interest framework, the C3PAO and assessment team must account for prohibited consulting, preparation, or implementation assistance provided to the same organization during the preceding three years. Verify that history before you sign either engagement.
Getting the category right matters more than getting the brand right. The wrong category at the wrong stage is how contractors overspend, under-scope, or end up paying for a second migration.
| Where you are right now | Start with this category | What to verify before you engage | What it is not a substitute for |
|---|---|---|---|
| "We don't know where our CUI actually flows" | RPO / RP (Registered Provider Organization / Registered Practitioner) or readiness consultant | Cyber AB Marketplace listing if they claim RPO status; scoping methodology; independence from your assessor | Building or operating the environment |
| "We've picked a path and need it built" | CUI enclave or government-cloud implementation partner | Authorized-partner status where relevant; FedRAMP evidence for the offering; a Customer Responsibility Matrix | Owning your SSP and evidence |
| "We need someone to run it day to day" | MSSP (Managed Security Service Provider) or managed compliance provider | Scope of "managed"; references at your size; ESP documentation; what stays yours | The formal assessment |
| "We need evidence workflows and SSP/POA&M support" | GRC platform | How it maps to NIST SP 800-171 Rev. 2; whether CUI or security protection data is stored in it | Implementing the controls — software alone never makes you compliant |
| "We're scoped, remediated, and ready for the audit" | C3PAO | Current authorization in the Cyber AB Marketplace; three-year conflict history; assessment scope and contract | Readiness or implementation work that would create a prohibited conflict for that assessment |
If you want named firms, verify the category and status before you route the lead
This article intentionally does not publish a named-provider ranking or current-status table. Cyber AB authorization, partner programs, product evidence, and service scope can change. Use the Cyber AB Marketplace for current ecosystem status where relevant, verify the provider's role and evidence directly, and keep readiness/implementation separate from formal assessment when the conflict rules require it.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. No provider paid for inclusion or position in this guide, and no provider can guarantee a CMMC outcome.
How we built this comparison
We separate three kinds of claim, because mixing them is how comparison articles mislead people.
Regulatory facts are cited to the issuing authority — eCFR, the Federal Register, Acquisition.gov, NIST's Computer Security Resource Center, and the Department's published memoranda. We do not publish a requirement without its source.
Current-state facts — FedRAMP Marketplace records, vendor-published positions, pricing — carry a verification date and a label: provider-stated, industry-reported, or government-published. A vendor's claim about its own certifications, assessment history, or customer outcomes is attributed as company-stated and is not repeated as our finding.
Editorial judgments — which path fits which contractor, what to verify, what order to do things in — are labeled as our conclusions drawn from the verified facts above. They are defensible, they are consistent with the sources on this page, and they are not compliance advice.
We do not blur CMMC levels. We do not blur Level 2 self-assessment with a Level 2 C3PAO assessment. We do not blur NIST SP 800-171 Revision 2 with Revision 3 for CMMC purposes. We do not blur readiness help with formal assessment. And we do not tell you a product makes you compliant, because no product does.
Corrections: we publish and date them. See our Methodology, Editorial Standards, and Corrections Policy.
Frequently asked questions
Is a CMMC enclave an alternative to GCC High?
Sometimes. It depends on which kind of enclave a vendor is selling. A GCC High enclave is a deployment shape of GCC High — a subset of users licensed and migrated into a government tenant. A third-party encrypted enclave is an alternative to GCC High, keeping CUI outside Microsoft while your commercial tenant continues for everyday work. Ask which one you're being quoted before you compare prices.
Is GCC High required for CMMC Level 2?
No universal Microsoft-product requirement appears in 32 CFR Part 170 or DFARS 252.204-7012. Level 2 requires implementing the 110 requirements in NIST SP 800-171 Revision 2. Separately, any external cloud service handling covered defense information must meet FedRAMP Moderate-equivalent security and comply with DFARS 252.204-7012 paragraphs (c) through (g). Several environments can meet that bar.
Can only the employees who handle CUI use GCC High?
Yes, that's the split-tenant or "enclave" pattern, and it is a legitimate architecture. But it does not automatically put everyone else out of scope. You still have to account for endpoints, identity, administrators, security tooling, backups, and every transfer path between the two environments.
Does an enclave reduce the number of CMMC Level 2 requirements?
No. Level 2 still requires all 110 security requirements from NIST SP 800-171 Revision 2 across 14 families. A defensible enclave reduces the number of assets, users, and systems those requirements apply to — which reduces remediation, evidence, and assessment effort. Fewer assets, not fewer requirements.
Can commercial Microsoft 365 stay outside the enclave?
Only to the extent it cannot process, store, or transmit CUI, provides no security protection to CUI Assets, and is physically or logically separated from them — all three conditions, per 32 CFR § 170.19(c)(1). If those conditions do not fit, analyze the tenant against the other rule-defined categories instead of forcing an out-of-scope label.
Can VDI keep ordinary laptops out of CMMC scope?
Only under the narrow condition in the Level 2 Scoping Guide: the endpoint must be configured so it does not process, store, or transmit CUI beyond keyboard, video, and mouse interaction with the virtual desktop client. Any feature that causes the endpoint to process, store, or transmit CUI beyond that interaction can disqualify the endpoint from that out-of-scope treatment.
Does GCC High cover CAD, ERP, CNC, or OT systems?
Not by moving Microsoft collaboration workloads. Any local or third-party system that processes, stores, or transmits CUI — or that protects CUI Assets — still requires its own scoping analysis. Some shop-floor and test systems may qualify as Specialized Assets; others may be CUI Assets. The category depends on the rule's definitions and the system's actual role.
Does ITAR require GCC High?
No regulation names a Microsoft product. GCC High is often selected because of Microsoft's U.S. data-residency and screened-personnel commitments. Separately, 22 CFR § 120.54(a)(5) provides a specific path for qualifying encrypted unclassified technical data when all of its conditions are met — including the destination and source-country restrictions and the rule that the means of decryption are not provided to a third party. Which approach fits your data is a legal determination for qualified export counsel.
What is FedRAMP Moderate equivalency, and is it as good as FedRAMP authorization?
Equivalency is a DoD-defined path in which a cloud provider is independently assessed as 100% compliant with the FedRAMP Moderate control baseline, with a body of evidence assessed by a third-party assessment organization. The DoD CIO's equivalency memorandum states it does not apply to offerings already FedRAMP Moderate Authorized — those can be relied on without further assessment. Both are legitimate. The difference for you is the amount of evidence you have to obtain and hold.
Will a C3PAO accept an enclave boundary?
Enclave scoping is permitted — the acquisition rulemaking record states a contractor may pursue a CMMC level for its entire enterprise network or for particular segments or enclaves. What an assessor evaluates is whether your documented boundary matches reality and whether your evidence supports it. No page, and no vendor, can promise you a specific assessor's conclusion.
How many Microsoft tenants will I end up running?
One under a full GCC High migration or a pure overlay model. Two under a split-tenant GCC High enclave, with most CUI users holding an account in each. Two or more under a hybrid. Ask any vendor quoting a "GCC High enclave" to state the tenant count and the identity design in the proposal — it is the single biggest driver of day-to-day friction.
Does the CMMC Phase 2 suspension mean I can wait on this?
No. The July 13, 2026 suspension paused the third-party certification milestone. It expressly preserved Phase 1 self-assessment requirements and left DFARS 252.204-7012 in force — and 7012 is the clause that governs where your CUI is allowed to live. The environment decision is unaffected. The assessment-type decision is what's under review.
Can the company that builds my enclave also assess me?
Not when the C3PAO or assessment team has a prohibited conflict from consulting, preparation, or implementation assistance provided to that organization during the preceding three years. Keep readiness and formal assessment separated early enough to preserve independence, and verify the C3PAO's conflict history before booking the assessment.
What should I do first?
Map your CUI flow. Until you know where CUI enters, who touches it, where it's stored, what protects it, and whether it can be contained, every architecture quote is a guess dressed up as a proposal.
Need help deciding what type of CMMC provider you need?
Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.
The match is based on provider category, your stage, your environment, and your general timeline — not a paid ranking. Matching is not an endorsement, a certification guarantee, legal advice, or affiliation with the Cyber AB or the Department of War.
Get Matched With Source-Checked Options →
Do not submit CUI, drawings, export-controlled content, contract numbers, system diagrams, vulnerability details, or sensitive contract information through this or any web form.
Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.
Which provider category fits your situation
- Choose a CUI enclave provider if CUI touches only part of your business and you can draw a boundary your people will actually follow.
- Choose a GCC High implementation partner if your CUI users need full Microsoft collaboration inside the boundary, or a contract requires it in writing.
- Choose an MSSP if you can't operate the controls day to day inside whichever boundary you pick.
- Choose an RPO/RP or readiness consultant if you do not yet know where your CUI flows — architecture pricing is premature until the boundary is understood.
- You don't need a C3PAO yet if your boundary isn't locked and your evidence isn't assembled. An enclave can make a required assessment smaller; it never removes the requirement.
Related guides
- CMMC Enclave vs Enterprise-Wide Compliance — the scope-size decision that comes before this one
- CMMC Enclave Cost: What You'll Actually Pay — the full five-layer cost model and quote normalizer
- GCC High for CMMC: When You Need It and When You Don't — the Microsoft-internal comparison
- Microsoft 365 GCC High Migration for CMMC — migration mechanics by phase
- CMMC Secure Enclave: Scope, Cost & Architecture — how to design one
- CMMC Scoping Guide — the full scoping method
- CMMC External Service Provider Requirements — how MSPs, MSSPs, and CSPs affect your scope
- CMMC Level 2 Self-Assessment vs C3PAO — which assessment path applies
- CMMC Readiness Checklist — mapped to all 14 control families
- CMMC for Manufacturers and CMMC for Machine Shops — shop-floor scoping
Primary sources
- eCFR — 32 CFR Part 170, including § 170.19 (CMMC scoping)
- Federal Register — CMMC Program Final Rule, 89 FR 83092 (Oct. 15, 2024; effective Dec. 16, 2024)
- Federal Register — DFARS CMMC acquisition final rule, DFARS Case 2019-D041 (effective Nov. 10, 2025)
- Acquisition.gov — DFARS 252.204-7012, 252.204-7021, 252.204-7025
- DoD CIO — "FedRAMP Moderate Equivalency for Cloud Service Provider's Cloud Service Offerings" (signed Dec. 21, 2023; released Jan. 2, 2024)
- NIST CSRC — SP 800-171 Rev. 2; SP 800-171A; SP 800-172
- NIST — FIPS 140-3 Transition Effort: FIPS 140-2 validations remain active through September 21, 2026 and move to the Historical List on September 22, 2026
- eCFR — 22 CFR § 120.54 and § 120.55; 15 CFR § 734.18
- Department of War — Phase II suspension release (July 13, 2026) and implementing procedures memorandum 26-P-1023
- SBA Office of Advocacy — Comment letter on the CMMC Program proposed rule (February 2024); comment letter to the CMMC Reform Task Force (August 17, 2026)
- Microsoft Learn — Microsoft and CMMC; Microsoft 365 U.S. Government service descriptions; multitenant defense organization architecture guidance; 2026 Microsoft 365 pricing and packaging update
- Cyber AB — CMMC Assessment Process; Code of Professional Conduct; Marketplace
Last verified: August 22, 2026. Next scheduled review: November 2026.
This guide is educational analysis, not legal, contractual, export-control, or compliance advice. The Defense Compliance Report is not affiliated with, endorsed by, or sponsored by the Cyber AB, the Department of War, the Department of Defense, DCMA DIBCAC, NIST, Microsoft, or any U.S. government agency.