The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

Independent research · CMMC enclaves, GCC High, scope, evidence, and architecture

Enclave vs GCC High for CMMC: Which Architecture Should You Choose?

Last updated:

Last verified: against 32 CFR Part 170, DFARS 252.204-7012, NIST SP 800-171 Revision 2, 22 CFR § 120.54, the DoD CIO FedRAMP Moderate Equivalency memorandum, Microsoft guidance, SBA records, Cyber AB materials, and related primary sources.

Site alert bar (existing): July 13 update: CMMC Phase II is suspended. Level 1 and Level 2 self-assessments remain in force. What changed →

By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance.

Last reviewed: August 2026 · Last verified: August 22, 2026 · Next scheduled review: November 2026 · FedRAMP and FIPS status refresh: October 2026

Editorial research — not formally reviewed by a CMMC Subject Matter Advisor. Confirm scope and applicability with a CMMC Registered Practitioner (RP), a Registered Provider Organization (RPO), or a qualified federal-contracts attorney before acting.

The Defense Compliance Report is not affiliated with, endorsed by, or acting on behalf of the Cyber AB, the Department of War, the Department of Defense, DCMA DIBCAC, NIST, SPRS, or any U.S. government agency. This is educational research, not legal, contractual, export-control, or compliance advice.


The bottom line

An enclave and Microsoft 365 GCC High are not two options. They are two different kinds of thing. An enclave is the boundary around the users, systems, and services that touch or protect Controlled Unclassified Information (CUI). GCC High is a platform that can sit inside that boundary. There are five real architecture paths, not two — and the one that fits you depends on where CUI actually moves, whether any of it is export-controlled, and whether your people can live inside the boundary you draw.

That is the whole answer. Here is the part almost nobody tells you: when a contractor searches enclave vs GCC High for CMMC, they may be comparing proposals that use the same word — "enclave" — for fundamentally different architectures. One vendor may mean a slice of GCC High. Another may mean a protected environment designed to keep CUI out of GCC High entirely. Until you know which one you were sold, you are not comparing anything.

We read the rule, the clause, the export regulation almost everyone skips, and the vendor documentation on both sides. Then we built the comparison the market hasn't.

Find your row:

Your situation — Path to price first — Your first move
Your situationPath to price firstYour first move
A contract or prime names GCC High, IL4, or U.S.-person support in writingPath 2 or 3Get the requirement in writing before you price anything else
CUI is limited to one stable team, mostly email and filesPath 1Confirm your commercial tenant can genuinely stay off the CUI path
A small group needs protected Microsoft email, Teams, and SharePointPath 2Price split-tenant operations honestly, including identity, licensing, and cross-tenant administration
CUI moves through most departments and mailboxesPath 3Compare full-company GCC High against a broader hybrid; do not assume a narrow enclave is cheaper
CAD, CAM, ERP, CNC, test equipment, or OT touches CUIPath 4A collaboration platform alone will not cover it
Local, disconnected, or shop-floor work with limited cloud collaborationPath 5Decide who operates the security stack before you buy it
Only Federal Contract Information (FCI), no CUINone of themYou are on the wrong page — see CMMC Level 1 vs Level 2

Best for an enclave: a narrow, stable CUI flow with a boundary your people can realistically follow. Best for broader GCC High: pervasive Microsoft collaboration and no appetite for running two environments. Neither one solves by itself: endpoints, administrators, shared security tools, backups, paper CUI, CAD, ERP, OT, and the evidence file an assessor will actually read.


The Defense Compliance Report is the independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citation on every claim and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they spend six figures.


Your situation changes the answer

The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The contract clause sets your level, not a checklist. Because a general answer can't resolve those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.

  • What it asks: your required CMMC level, FCI vs CUI handling, assessment type, IT/cloud environment, and contract timeline
  • What you get: the provider category that fits your situation and the readiness steps to get there
  • Educational triage only: free · 2-minute assessment · no obligation

Find My CMMC Path →


What we actually verified for this page

Verified August 22, 2026, at the issuing source:

  • The CMMC Program rule — 32 CFR Part 170, effective December 16, 2024, including the Level 2 asset categories at § 170.19(c)(1) and the external service provider table at § 170.19(c)(2). (eCFR; Federal Register, 89 FR 83092.)
  • The acquisition rule — the DFARS CMMC rule took effect November 10, 2025, starting Phase 1.
  • The suspension — the Department of War suspended CMMC Phase II on July 13, 2026. Phase 1 self-assessment requirements, DFARS 252.204-7012, NIST SP 800-171 Revision 2, SPRS posting, and annual affirmations all continue. (DoW release; implementing memorandum 26-P-1023.)
  • The cloud clause — DFARS 252.204-7012(b)(2)(ii)(D) requires an external cloud service handling covered defense information to meet security requirements equivalent to the FedRAMP Moderate baseline and comply with paragraphs (c) through (g). (Acquisition.gov.)
  • The equivalency memo — the DoD CIO memorandum on FedRAMP Moderate Equivalency (signed December 21, 2023, released January 2, 2024) and what it does and does not apply to.
  • The export regulation22 CFR § 120.54(a)(5), § 120.54(b)(1), § 120.54(c), and § 120.55, plus the EAR companion at 15 CFR § 734.18. (eCFR; Cornell Legal Information Institute.)
  • The small-business record — the SBA Office of Advocacy comment letter on the proposed CMMC rule (February 2024, commenting on 88 FR 89058) and Advocacy's comment letter to the CMMC Reform Task Force (August 17, 2026).
  • Microsoft's own architecture guidance for multitenant defense organizations, and Microsoft's 2026 U.S. Government pricing update effective July 1, 2026.

What we did not verify, and will not claim: any private vendor quote; whether a specific vendor's equivalency evidence package is current today; whether any specific contractor's environment is correctly scoped; whether any assessor will accept any particular boundary; or that any product or provider produces a certification outcome. Nobody can promise that, and anyone who does is telling you something the rule does not support.


Is a CMMC enclave the same thing as GCC High?

No. A CMMC enclave is the defined boundary around the users, systems, services, and workflows that handle or protect CUI. Microsoft 365 GCC High is a government-cloud platform that may host some or all of the workloads inside that boundary. The boundary is a scoping decision. The platform is a purchasing decision. They are made in that order.

This sounds like a semantic point. It can decide whether you migrate a narrow workflow or most of the company.

Here is why. Under 32 CFR § 170.19, your CMMC Assessment Scope is determined by what processes, stores, or transmits CUI, and by what provides security protection to those assets. It is not determined by which logo is on your cloud contract. Two companies can buy identical GCC High tenants and end up with wildly different assessment scopes, because one of them let CUI leak into commercial email and unmanaged laptops and the other didn't.

So when a vendor says "we'll build you an enclave," the correct follow-up is not how much. It's what's inside it, and what's outside it, and can you write that down.

What "enclave" means in practice

The word is doing double duty in the market right now, and neither camp tells you the other definition exists.

Some vendors use enclave to mean a slice of GCC High — you license and migrate only the people who touch CUI, and everyone else stays in your commercial Microsoft 365 tenant. In this usage, the enclave is a deployment shape of GCC High, not an alternative to it. Split-tenant designs commonly require separate commercial and government identities for at least some CUI users, although the exact identity design is architecture-specific. Microsoft documents multitenant defense scenarios, and CMMC-focused implementation providers commonly describe variants such as split-tenant or data-enclave designs.

Other vendors use enclave to mean a way to avoid GCC High — an encrypted workspace, a hosted desktop, or a segmented on-premises environment where CUI lives, while your commercial Microsoft 365 keeps running as the everyday workplace.

Same word. Opposite architectures. Very different bills.

One more data point worth knowing before anyone sells you a second tenant: Microsoft's own architecture guidance for multitenant defense organizations tells customers they "should strive to have your data, Microsoft 365, and Azure cloud services in a single tenant," and that organizations already running multiple Microsoft Entra tenants "should consider consolidating." Microsoft does document multitenant use cases and supports them. But the default recommendation from the platform vendor is one tenant — which is not the message you get from most partners selling a split-tenant build.

Boundary versus platform, in one table

Term — What it actually is — What it determines — What it does not determine
TermWhat it actually isWhat it determinesWhat it does not determine
CMMC enclaveA logically or physically separated CUI security domainWhich users, systems, services, and data flows fall inside the assessment scopeWhich cloud product you have to buy
Microsoft 365 GCC HighA U.S. government-cloud productivity and collaboration platformWhere covered email, Teams, SharePoint, OneDrive, and identity workloads may runYour complete CMMC assessment scope, or your compliance outcome
GCC High enclaveA GCC High environment used by a defined subset of users and workloadsA narrower Microsoft collaboration boundary while the rest of the company stays commercialAutomatic exclusion of endpoints, administrators, identity, backups, or security tooling
Full-company GCC HighMost or all users moved into one government tenantFewer seams between commercial and government environmentsAutomatic coverage of ERP, CAD, on-premises servers, OT, test equipment, or paper CUI
Hybrid CUI environmentA boundary spanning GCC High plus Azure Government, VDI, on-premises systems, or OTSupport for workflows that cannot live inside Microsoft 365Simplicity — every interface still needs its own evidence

The middle column is our editorial organization of the scoping concepts in 32 CFR § 170.19 and Microsoft's published product descriptions. The architecture decision itself stays company-specific, and the rule is deliberately silent on how to build one. More on that in a moment — it's the most useful thing in the federal record on this topic and almost nobody cites it.


Do you need GCC High for CMMC Level 2?

No CMMC or DFARS authority names Microsoft GCC High as a universal requirement. CMMC Level 2 requires implementation of the 110 security requirements in NIST SP 800-171 Revision 2, organized into 14 families. The current CMMC Level 2 Assessment Guide presents 320 assessment objectives using the NIST SP 800-171A assessment criteria. Separately, DFARS 252.204-7012 requires an external cloud service handling covered defense information to meet FedRAMP Moderate-equivalent security and comply with the clause's specified incident-response and forensic-support obligations. Several architectures can satisfy those requirements when correctly implemented.

Let's take the two requirements one at a time, because contractors routinely collapse them into one and then overbuy.

What CMMC Level 2 requires

CMMC Level 2 is built on NIST SP 800-171 Revision 2 — 110 security requirements across 14 families, from Access Control to System and Information Integrity. The current DoD CMMC Level 2 Assessment Guide expresses those requirements through 320 assessment objectives, using the assessment procedures incorporated from NIST SP 800-171A. That count does not change based on where you put the data. What changes is which assets, services, people, and evidence paths are inside the assessment scope.

One nuance to keep straight, because it trips up sharp people: NIST itself withdrew Revision 2 and superseded it with Revision 3. For CMMC purposes, Revision 2 is still the controlling version, pinned by 32 CFR Part 170 and reaffirmed in the Department's July 2026 implementation materials. Do not let a consultant hand you a Rev 3 gap assessment and call it a CMMC gap assessment. They are different documents.

The solicitation provision DFARS 252.204-7025 identifies the CMMC level and assessment type designated for the procurement, and the contract clause DFARS 252.204-7021 requires the contractor to have and maintain the required CMMC status when the clause applies. A C3PAO is a CMMC Third-Party Assessment Organization authorized to conduct Level 2 certification assessments. DIBCAC is the Defense Industrial Base Cybersecurity Assessment Center, the government assessment organization for Level 3. Under the current CMMC framework, Level 3 adds 24 selected requirements from NIST SP 800-172 on top of Level 2.

Notice what is not in any of that: a product name.

What DFARS 252.204-7012 requires of your cloud

This is the clause that actually pulls a platform into the conversation, and it has been in DoD contracts since 2016.

DFARS 252.204-7012(b)(2)(ii)(D) says that if you use an external cloud service provider to store, process, or transmit covered defense information, that provider must meet security requirements equivalent to those established by the Government for the FedRAMP Moderate baseline and comply with paragraphs (c) through (g) of the clause — cyber incident reporting, malicious software submission, media preservation, access to additional information and equipment for forensic analysis, and cyber incident damage assessment.

Read that twice. It is a security bar plus a set of contractual duties. It is not a brand.

The evidence asymmetry nobody publishes

Here is where two architectures that both "meet FedRAMP Moderate" stop being equivalent — for you, the buyer.

There are two doors into that requirement, and they cost you different amounts of work:

Question — Door 1: FedRAMP AuthorizedDoor 2: FedRAMP Moderate Equivalency
QuestionDoor 1: FedRAMP AuthorizedDoor 2: FedRAMP Moderate Equivalency
What it isThe cloud service offering carries a live listing in the FedRAMP MarketplaceThe provider was independently assessed as 100% compliant with the FedRAMP Moderate control baseline
What the DoD CIO memo requiresThe memorandum states it does not apply to offerings already FedRAMP Moderate Authorized — those "can be leveraged without further assessment to meet the equivalency requirements"100% of the FedRAMP Moderate baseline, a body of evidence assessed by a third-party assessment organization, and no open POA&Ms
What you have to obtain and holdA dated Marketplace record and the provider's Customer Responsibility MatrixThe full body of evidence, plus the Customer Responsibility Matrix — and you have to be able to actually get it
Where an authorized government-cloud offering sitsDoor 1 when the exact cloud service offering relied upon is currently FedRAMP Authorized
Where a non-authorized CUI cloud offering may sitDoor 2 only when its evidence package actually satisfies the DoD equivalency criteria
The buyer question"What is the package ID and status, as of our contract date?""Who assessed you, when, against which baseline, and are any POA&Ms open?"

Door 1 / Door 2 framing is ours. The underlying requirements are from DFARS 252.204-7012(b)(2)(ii)(D) and the DoD CIO FedRAMP Moderate Equivalency memorandum, verified August 22, 2026.

Neither door is inferior. Door 2 is a legitimate, DoD-defined path, and at least one CUI enclave provider states publicly that it was the first cloud service provider to meet the Department's equivalency criteria and that its evidence went through DIBCAC review — a company-stated claim about a government process, which you should confirm in writing with the provider rather than take from a marketing page.

But the work is different. Door 1 gives you a public record you can screenshot and file. Door 2 gives you a document set you have to request, read, and keep current. Budget the difference in effort, not just in dollars.

One more piece of that clause that almost no comparison covers: paragraphs (c) through (g) are a separate obligation from the FedRAMP bar. Ask any cloud provider — Microsoft, an enclave vendor, anyone — where their written position on 7012 (c)–(g) is published. Some publish a specific statement. Some don't. That answer is checkable, it costs you one email, and it tells you a great deal about how seriously a vendor takes the defense market.

So where does "GCC High is required" come from?

Three legitimate places, none of which is a regulation.

Microsoft's own guidance points organizations handling export-controlled and the most sensitive CUI categories toward GCC High. Most of the content ranking for these searches is written by firms that sell GCC High migrations — that isn't sinister, but it shapes the framing. And some primes flow a GCC High requirement down to subcontractors to keep the supply chain simple. A written GCC High requirement incorporated into your subcontract or purchase order can bind you even when CMMC itself does not name the product. Get the requirement in writing and review the actual subcontract terms before you buy around it.

What is not accurate is the claim, common in vendor content, that GCC High "isn't optional" for organizations handling CUI. The clause sets a security standard and a set of duties. More than one environment can meet them. We'd rather you know that before the purchase order than after.


Enclave vs GCC High for CMMC: the five architecture paths

There are five defensible architecture patterns, not two. They differ on what enters your assessment scope, how the FedRAMP requirement is satisfied, which legal theory covers export-controlled data, what happens to your endpoints, and which failure mode is most likely to bite you. The right path is the smallest boundary you can honestly contain, operate, document, and defend — not the smallest one you can draw.

This is the grid we built because nobody else had. Every column is a question a C3PAO or a self-assessment record will eventually make you answer.

The DCR CMMC Environment Decision Grid

Part of The CMMC Path Framework. It maps CUI flow, assessment scope, platform needs, endpoints, and operating constraints to an architecture pattern and a provider category. It is not a score, a ranking, a certification determination, or compliance advice, and it routes to a category — never to a named provider.

Decision factor — Path 1: Encrypted overlay enclave (commercial M365 retained) — Path 2: GCC High enclave (split tenant) — Path 3: Full-company GCC HighPath 4: Hybrid (GCC High + Azure Gov / VDI / on-prem / OT) — Path 5: On-prem or VDI enclave (no GCC High)
Decision factorPath 1: Encrypted overlay enclave (commercial M365 retained)Path 2: GCC High enclave (split tenant)Path 3: Full-company GCC HighPath 4: Hybrid (GCC High + Azure Gov / VDI / on-prem / OT)Path 5: On-prem or VDI enclave (no GCC High)
What it isAn encrypted email-and-file workspace over your existing commercial tenant; only CUI users licensedA separate GCC High tenant for the people who touch CUI; everyone else stays commercialMost or all users and Microsoft workloads move into one government tenantGCC High for collaboration, plus a controlled layer for compute, engineering, or productionCUI stays in a hardened local environment or a remote-access session
Where CUI livesInside the overlay onlyInside the GCC High tenantInside the GCC High tenantSplit across layers by workloadOn controlled local systems or the hosted desktop
Your commercial tenant becomesConfiguration-dependent: it may be Out-of-Scope, a CRMA, an SPA, or a CUI Asset depending on what it can process and what it protectsSame analysis: keeping CUI out does not automatically make the tenant out of scopeUsually retired from CUI use or retained only for defined non-CUI functionsDepends on whether the commercial tenant participates in the protected workflow or protects in-scope assetsOften retained for ordinary business, with category determined by actual use
Microsoft tenants operatedOneTwoOneTwo or more, plus non-Microsoft layersOne or none for CUI
Identity designOften one primary identity, but depends on the overlayCommonly separate commercial and government identities for some users; exact design variesOne primary government identity for most usersOne or more identity systems depending on the layersDepends on the directory and remote-access design
Identity provider in scopeA shared identity system is a Security Protection Asset when it provides security protection to CUI AssetsGovernment identity is in scope; commercial identity may also be in scope if it authenticates or protects the boundaryGovernment identity is in scopeEach identity layer must be analyzed by functionThe directory controlling enclave access is in scope when it protects CUI Assets
How DFARS 7012(b)(2)(ii)(D) is metIf an external CSP handles covered defense information, verify the exact offering against FedRAMP Moderate authorization or DoD-defined equivalency and paragraphs (c)–(g)Same rule; do not infer it from the product family nameSame ruleVerify each external CSP separatelyDoor 1, Door 2, or not applicable when no external CSP stores, processes, or transmits covered defense information
Export-control analysisMay rely on the conditions in 22 CFR § 120.54(a)(5) for qualifying encrypted ITAR technical data; EAR must be analyzed separatelyOften selected for Microsoft's U.S. data-residency and screened-personnel commitments; counsel still confirms applicabilitySameDepends on the data category and layerDepends on the data, access model, and whether § 120.54 or another authorization applies
Endpoint dispositionEndpoints running the client are usually in scopeEndpoints joined to the GCC High tenant are in scopeBroad endpoint population in scopeRole-specific; VDI clients can qualify for the narrow carve-outBest chance of the VDI keyboard/video/mouse carve-out
External collaborationOften the easiest — many overlays allow free external accounts for subsNative GCC High sharing is restricted; cross-cloud collaboration is configurable but is real admin workSame restrictions, applied company-wideVaries by layerUsually requires a separate exchange mechanism
Dominant failure modeBoundary leakage — CUI walks back into commercial email one forward at a timeUser confusion — people work in the wrong tenantCost and disruption — you migrated people who never touch CUIOwnership gaps — nobody owns the seams between layersOperating burden — you run and evidence more of the stack yourself
Cost shapeKeep 100% of commercial licensing, add overlay for CUI usersPay for a commercial seat and a GCC High seat for every enclave user, permanentlyBroadest licensing and migration, one environment to runHighest integration complexityCapital or hosting cost, plus internal labor
Best fitSmall, contained CUI footprint; email and filesA defined program team that needs full Microsoft collaboration for CUI workDefense work is the core businessManufacturers, engineering firms, anyone with CAD/ERP/OT in the CUI pathSolo operators, single-station shops, disconnected work

Sources: architecture characteristics reflect 32 CFR § 170.19 asset categories, DFARS 252.204-7012, 22 CFR § 120.54, and vendor-published product documentation. Cost shapes are structural, not price quotes — see the cost section below. Verified August 22, 2026.

Our decision rules

These are editorial conclusions drawn from the verified facts above. They are not regulatory determinations, and your contract governs.

  • Only FCI, no CUI? This comparison is the wrong page for you. Level 1 is built on the 15 basic safeguarding requirements in FAR 52.204-21, not the 110 CUI controls. Go to CMMC Level 1 vs Level 2 and stop shopping for enclaves.
  • A narrow, stable CUI group with enforceable workflows? Price Path 1 first.
  • A narrow group that genuinely lives inside Microsoft email, Teams, and SharePoint? Price Path 2 before you assume an overlay will feel acceptable to them.
  • CUI in most departments and mailboxes? Compare Path 3 against a broader hybrid. Do not force an artificially narrow boundary — you will pay for it twice.
  • CAD, CAM, ERP, CNC, PLC, test equipment, or OT in the CUI path? A collaboration platform alone is incomplete. Go to Path 4, and read the manufacturing section below before you sign anything.
  • Export-controlled technical data anywhere in the flow? Do not let the platform decide the legal question. Read the export-control section next.
  • Shared identity, SIEM, EDR, backup, device management, or an external administrator crossing the proposed boundary? Those assets or services may stay in scope no matter which path you choose. That analysis comes before the purchase order.

What happens to your commercial Microsoft 365 tenant?

Under a full GCC High migration, the commercial tenant is decommissioned or emptied of CUI-adjacent work. Under a GCC High enclave, it keeps running and you must prove it never touches CUI. Under an overlay or on-premises enclave, it remains your primary workplace — which is where scope quietly comes back. Under 32 CFR § 170.19(c)(1), an Out-of-Scope Asset must be unable to process, store, or transmit CUI, must provide no security protection to CUI assets, and must be physically or logically separated from them. All three conditions, not one.

Most enclave conversations stop at "where does the CUI go." The expensive question is what happens to everything else. Here is our disposition map — the same fifteen systems, run through all five paths, with the evidence each category demands.

The Commercial Tenant Disposition Map

Asset categories are defined at 32 CFR § 170.19(c)(1). The dispositions below are decision conditions, not automatic labels. The same commercial system can be a CUI Asset, Security Protection Asset (SPA), Contractor Risk Managed Asset (CRMA), or Out-of-Scope Asset depending on what it actually processes and protects.

System or service — When it becomes a CUI Asset — When SPA / ESP treatment can apply — When CRMA or Out-of-Scope treatment may be possible — Evidence to keep
System or serviceWhen it becomes a CUI AssetWhen SPA / ESP treatment can applyWhen CRMA or Out-of-Scope treatment may be possibleEvidence to keep
Commercial Exchange / emailCUI is received, stored, cached, forwarded, or otherwise processed thereA connected service protects CUI mail or security dataCRMA only when it can handle CUI but policy and practice keep CUI out; Out-of-Scope only when all § 170.19 conditions are metMail-flow diagram, transport and forwarding rules, mobile-client settings, spill procedure
Commercial SharePoint / OneDriveCUI is uploaded, synced, cached, or shared thereSecurity tooling protecting in-scope repositories can be SPA/ESPCRMA or Out-of-Scope depends on capability, intended use, protection role, and separationSharing settings, sync-client policy, inventory, SSP treatment
Commercial TeamsCUI appears in chat, files, meeting artifacts, recordings, or transcriptsConnected protection services may be SPA/ESPCRMA or Out-of-Scope only when the regulatory conditions actually fitRetention configuration, guest access, file-location map
Identity provider (Entra ID / AD / other IdP)Rarely because of identity alone; categorize by the data and functions it handlesSPA when it provides security protection to CUI AssetsOut-of-Scope only if it neither handles CUI nor protects CUI Assets and is properly separatedIdentity architecture, privileged roles, authentication paths, conditional-access evidence
MDM / IntuneCUI is stored or processed in the service itselfSPA when it configures or protects CUI endpoints; external provider may be an ESPOutside the CMMC scope only when it neither handles CUI nor protects in-scope assetsEnrollment scope, policy baselines, admin roles
EDRCUI itself is collected into telemetry or artifactsSPA when it protects CUI Assets; hosted provider may be an ESPOutside scope only if it does not protect in-scope assets or receive relevant dataCoverage report, data-flow map, admin list, responsibility matrix
SIEM / log retentionCUI appears in logs or captured contentSPA when it receives Security Protection Data; hosted provider may be an ESPOutside scope only if it neither receives protected data nor protects CUI AssetsLog-flow diagram, retention, provider CRM, access evidence
BackupCUI is copied into the backup setCan also be SPA when it protects availability/integrity of CUI systems or stores security configuration dataOutside scope only if neither CUI nor security-protection data is present and it does not protect CUI AssetsBackup map, encryption, restore tests, repository authorization
Help desk / MSP / administratorProvider-managed assets may become CUI Assets if they receive CUIProvider and supporting assets may be in scope as an ESP/SPA when they administer or protect the CUI environmentOutside only when there is no CUI or security-protection roleContract, role list, access logs, CRM, privileged-access design
CUI-user endpointsCUI is processed, stored, or transmitted locallyEndpoint security tooling can be SPAA VDI endpoint may qualify as out of scope only under the narrow keyboard/video/mouse condition in the Scoping GuideDevice baseline, local-storage controls, print/clipboard/USB policy
Non-CUI endpointsCUI reaches or is processed by the deviceShared security or admin functions may pull related assets into scopeCRMA or Out-of-Scope depending on capability, intended use, and separationInventory and separation evidence
Engineering workstationsCUI drawings/models/programs are created, viewed, edited, cached, or stored locallyShared protection services can be SPAOut-of-Scope only when the workstation does not handle or protect CUI AssetsData-flow map, local controls, application inventory
CAD / PLM / ERPCUI is processed, stored, or transmitted by the application or databaseShared security services may be SPASome systems may remain CRMA or out of scope if the actual data and architecture support itCategorization rationale, network diagram, SSP treatment
Shop-floor / test equipmentCUI processing can make the asset a CUI Asset; qualifying OT, IoT/IIoT, GFE, restricted systems, or test equipment may instead be treated as Specialized Assets under the ruleProtection services around the equipment may be SPANever label it "specialized" solely because it is on a shop floor; document why the regulatory definition fitsInventory, classification rationale, segmentation and access evidence
Printers / MFPsCUI is processed, cached, scanned, faxed, or stored by the devicePrint-management or monitoring services may be SPASome print paths can be excluded only when they never handle or protect CUIPrint controls, device storage settings, physical handling, destruction records

CRMA = Contractor Risk Managed Asset. SPA = Security Protection Asset. ESP = External Service Provider. Categories per 32 CFR § 170.19(c)(1) and § 170.19(c)(2), verified August 22, 2026.

The part we'd rather you hear from us than from an assessor

Here is the honest admission, and we're putting it before our own comparison so you can weigh everything that follows.

A narrower enclave is not automatically cheaper. The pitch — license fewer users, migrate fewer mailboxes, assess fewer systems — is real, and for a genuinely contained CUI footprint it can be transformative. But two identities, two collaboration environments, transfer controls, user training, spill response, duplicate administration, and evidence spanning the boundary can erase the savings entirely. And under Paths 1 and 5, your commercial Microsoft 365 tenant does not disappear. Depending on what it can process, what it actually handles, and whether it protects CUI Assets, it may be a Contractor Risk Managed Asset, Security Protection Asset, CUI Asset, or Out-of-Scope Asset. The label follows the architecture — not the sales pitch.

Now the part that makes that a reason to keep going rather than to give up.

A Contractor Risk Managed Asset is a real, rule-recognized category with a deliberately light burden. Under 32 CFR § 170.19(c)(1), a CRMA is an asset that can but is not intended to process, store, or transmit CUI because of your policies and practices, it is not required to be physically or logically separated from CUI assets, and where it is sufficiently documented in the SSP, the assessor does not assess it against the other requirements. The rule goes further and states that any limited check "shall not materially increase the assessment duration nor the assessment cost." That is an entirely different obligation from bringing your tenant in as a CUI Asset.

So the trade you are actually making is migration cost now versus boundary discipline forever. For a small, contained CUI footprint, that trade is frequently worth taking. What kills the narrow path is not the architecture. It's buying it and then not enforcing it.

If this is you, stop here and go elsewhere: If CUI already lives in your Outlook, SharePoint, and Teams — and has for a while — none of this comparison is your first problem. Those systems are already CUI Assets. Start with discovery and remediation, not a purchase order. See GCC High for CMMC for the "CUI already touched Microsoft 365" playbook. And if defense work is most of your revenue and most of your staff touch CUI, stop comparing enclaves entirely — see CMMC enclave vs enterprise-wide compliance for the scope-size decision that comes before this one.


Which path does your situation actually point to?

If you are still unsure whether you need an enclave provider, GCC High implementation help, an MSSP, an RPO/RP, a GRC platform, or an assessor, use The Defense Compliance Report's Find My CMMC Path tool. It uses your general CMMC level, FCI/CUI handling, assessment type, IT/cloud environment, and contract timeline to route you to the provider category and readiness steps that fit your stage.

Find My CMMC Path →

General answers only. Do not enter CUI, drawings, technical data, contract numbers, system diagrams, credentials, or vulnerability details.


Do you need GCC High for ITAR or export-controlled technical data?

Both architectures can be viable for some export-controlled workflows, but they do not rely on the same facts. Microsoft positions GCC High around U.S. data residency and screened-personnel commitments. Separately, 22 CFR § 120.54(a)(5) says that sending, taking, or storing qualifying unclassified technical data is not an export, reexport, retransfer, or temporary import when every listed condition is satisfied. Which path works for your data is an export-control determination for qualified counsel, not a vendor slogan.

This is the section that changes the most decisions, and it is the one nobody on page one engages.

Almost every article on this topic says some version of "ITAR means GCC High." That is a reasonable default and it is often the right practical answer. It is not what the regulation says.

What 22 CFR § 120.54 actually provides

The International Traffic in Arms Regulations (ITAR) control the export of defense articles and technical data. In a 2020 rulemaking, the State Department's Directorate of Defense Trade Controls added § 120.54 — "Activities that are not exports, reexports, retransfers, or temporary imports."

§ 120.54(a)(5) provides that sending, taking, or storing technical data is not an export, reexport, retransfer, or temporary import if the data is:

  1. Unclassified;
  2. secured using end-to-end encryption;
  3. secured using cryptographic modules compliant with FIPS 140-2 or its successors, supplemented by key management and controls consistent with current NIST guidance — or by other means providing security strength at least comparable to AES-128; and
  4. not intentionally sent to a person in, or stored in, a country proscribed in § 126.1; and
  5. not sent from a country proscribed in § 126.1.

§ 120.54(b)(1) defines end-to-end encryption to require cryptographic protection between the originator (or its in-country security boundary) and the intended recipient (or the recipient's in-country security boundary), and the means of decryption may not be provided to any third party. Paragraph (b)(2) also limits who may be the intended recipient. If a platform provider or another third party can decrypt the data, do not assume the § 120.54(a)(5) path applies.

§ 120.54(c) adds that the ability to access technical data in encrypted form meeting those criteria "does not constitute the release or export of such technical data."

There is a companion provision under the Export Administration Regulations at 15 CFR § 734.18.

That is the mechanism at least one CUI enclave vendor's architecture rests on, and it is a real one. Verified at eCFR and the Cornell Legal Information Institute, August 22, 2026.

Two theories, side by side

Question — GCC High operational approach§ 120.54 encrypted-data approach
QuestionGCC High operational approach§ 120.54 encrypted-data approach
Primary basis for the architecture decisionMicrosoft service commitments around U.S. data location and screened personnel; counsel still confirms the actual export-control requirement22 CFR § 120.54(a)(5) when every condition in that section is satisfied
What must be trueThe exact Microsoft service and configuration must provide the commitments your data and contract requireData is unclassified; end-to-end encrypted; qualifying cryptography is used; means of decryption are not provided to a third party; it is not intentionally sent to a person in or stored in a § 126.1 country; and it is not sent from a § 126.1 country
What you must proveTenant configuration, service terms, personnel commitments, where data residesEncryption architecture, exclusive key control, FIPS validation certificates, storage locations
What breaks itCUI leaving the sovereign environment; support interactions outside the boundaryAny third party holding decryption capability; non-compliant crypto; plaintext exposure
What it does not coverThe rest of your CMMC scopeThe DFARS 7012 FedRAMP requirement, which applies independently
Who confirms applicabilityQualified export counsel or another appropriately qualified authority based on your factsQualified export counsel or another appropriately qualified authority based on your facts

Framework ours; underlying requirements from 22 CFR § 120.54 and Microsoft's published service descriptions. Verified August 22, 2026.

The limits, stated as plainly as the opportunity

We are not telling you the encryption carve-out lets you ignore export control. It does not, and a page that implied otherwise would deserve to be ignored.

  • The plaintext stays controlled. § 120.54 exempts the encrypted transmission and storage. The underlying unencrypted technical data remains subject to ITAR.
  • Access information is separately controlled. 22 CFR § 120.55 defines "Access Information" — decryption keys, network access codes, passwords — as information that allows access to encrypted technical data in unencrypted form. Handing those to the wrong person is its own problem.
  • A deemed export is still a deemed export. Showing plaintext technical data to a foreign person in the United States is a release, regardless of how it was stored.
  • § 120.54 is export control only. It says nothing about DFARS 252.204-7012's FedRAMP requirement, which applies whether or not the encryption carve-out is available.
  • FIPS 140-2 has a date on it. § 120.54(a)(5)(iii) says "FIPS 140-2 or its successors," so the regulatory language is not frozen to one validation generation. NIST says FIPS 140-2 validations remain on the Active List through September 21, 2026; on September 22, 2026, only FIPS 140-3 validations remain active and the FIPS 140-2 certificates move to the Historical List. Historical is not the same as revoked, but NIST says historical modules should not be selected for new Federal procurements without the relevant risk determination. NIST SP 800-171 Rev. 2 requirement 3.13.11 (SC.L2-3.13.11) separately requires FIPS-validated cryptography when cryptography is used to protect the confidentiality of CUI. Ask every vendor for the certificate number, validation status, and standard its module relies on.

Our editorial conclusion: if any of your CUI may be export-controlled, the determination belongs to qualified export counsel before it belongs to a vendor. And whichever path you take, the vendor's answer should be a written architecture statement naming its legal basis — not a logo on a slide.


Before a vendor answers the export-control question for you

Our free CMMC Readiness Checklist is mapped to all 14 NIST SP 800-171 Rev. 2 control families, with the evidence each family expects. It's the fastest way to see which parts of the answer belong to your provider and which stay yours no matter what you buy.

Download the CMMC Readiness Checklist →


Will endpoints, email, identity, backups, and security tools pull your scope back open?

They can, and this is how most narrow boundaries fail. CMMC scope is not limited to where the CUI file sits. Under 32 CFR § 170.19(c)(1), assets that process, store, or transmit CUI and assets that provide security protection to those assets are both relevant to the Level 2 assessment scope — whether or not they sit inside the environment you're calling the enclave.

We built the matrix below because "the boundary leaked" is not a useful post-mortem. Each row is a specific question with a specific consequence and a specific artifact to demand.

The Boundary Leakage Matrix

Leakage path — The question you must answer — Potential scope consequence — Evidence to request from the vendor
Leakage pathThe question you must answerPotential scope consequenceEvidence to request from the vendor
EmailCan CUI reach a commercial mailbox, a forwarding rule, an archive, a mobile client, or personal storage?Commercial messaging assets stop qualifying as out of scopeMail-flow diagram, transport rules, DLP configuration, forwarding controls, spill procedure
EndpointsCan users download, cache, copy, or otherwise process CUI locally?The endpoint may become a CUI Asset when it processes, stores, or transmits CUIDevice configuration baseline, endpoint inventory, local-storage controls, print policy
VDIDoes the endpoint transmit only keyboard, video, and mouse interaction — with no CUI processing, storage, or transmission beyond that?Only an endpoint meeting that exact condition is treated as out of scopeVDI policy, clipboard/drive-mapping/print/USB restrictions, technical test evidence
IdentityDoes a commercial identity system authenticate, administer, or otherwise protect the enclave?It may be a Security Protection Asset when it provides security protection to CUI AssetsIdentity architecture, privileged-role inventory, conditional-access evidence, CRM
Logging / SIEMDo enclave logs or security configuration data leave for an external platform?The platform and its provider may enter scope as an SPA or ESPLog-flow diagram, provider CRM, retention and access evidence
EDR / device managementDoes a shared platform protect CUI endpoints?The protecting assets may be SPAs; an external provider may be an ESPCoverage report, administrative-access list, responsibility matrix
BackupsAre CUI or enclave configurations copied into commercial backup repositories?Backup systems become CUI Assets or SPAsBackup data-flow map, encryption, restore tests, repository authorization
Administrators / MSPCan external administrators reach CUI, security data, or enclave configuration?Provider services and supporting assets enter scopeContracts, role lists, CRM, access logs, personnel controls
Printing and paperCan users print CUI or move it into physical workflows?Physical locations, processes, and storage join the protection problemPrint controls, physical handling procedure, destruction records
CAD / ERP / OTDoes CUI move into engineering, production, inspection, or test systems?Those systems become CUI Assets or Specialized AssetsData-flow map, categorization rationale, SSP treatment, network diagram
Third-party sharingCan suppliers or customers receive CUI from the enclave?Subcontractor flow-down, external-service, and transfer requirements may apply depending on the contract and dataApproved transfer method, recipient validation process, applicable flow-down records

Consequences reflect the asset definitions at 32 CFR § 170.19(c)(1) and the external service provider requirements at § 170.19(c)(2). Verified August 22, 2026.

The VDI carve-out, stated exactly

There is one clean way to keep an ordinary endpoint out of scope, and it is narrow. An endpoint hosting a virtual desktop client can be treated as out of scope only when it is configured so that it does not process, store, or transmit CUI beyond keyboard, video, and mouse interaction with the virtual desktop.

If redirected drives, clipboard, printing, USB, caching, or another feature causes the endpoint to process, store, or transmit CUI beyond the keyboard/video/mouse interaction described in the Scoping Guide, the endpoint no longer fits that out-of-scope condition.

Do not accept "we use VDI, so the laptops are out of scope" from any vendor. Ask them to show you the configuration and the test evidence that proves the restriction. That artifact is the difference between an out-of-scope claim and an out-of-scope finding.


Which path works for manufacturers — CAD, CNC, test equipment, and OT?

Manufacturers often need to evaluate a hybrid answer, because Microsoft 365 GCC High can handle collaboration workloads but does not, by itself, define the treatment of a local CAD workstation, ERP database, CNC program, PLC, coordinate measuring machine, or paper traveler. Under 32 CFR § 170.19, each asset must be categorized by what it actually does: some will be CUI Assets, and qualifying OT, IoT/IIoT, Government Furnished Equipment, restricted information systems, or test equipment may be Specialized Assets. The cloud purchase does not make those systems disappear from the scoping analysis.

If you make things, this section matters more than everything above it.

Follow the drawing, not the org chart

The office-only model of CMMC assumes CUI arrives in an inbox, gets read, and gets filed. In a machine shop, technical data has a journey:

  1. A drawing arrives from the prime.
  2. Estimating opens it to quote the job.
  3. Engineering reviews or modifies the model.
  4. CAM generates tool paths from it.
  5. The program lands on a machine or a shop-floor file share.
  6. Inspection compares finished parts against the model.
  7. Quality records reference dimensions from it.
  8. Files go back to the customer.
  9. Everything gets archived, often for years.

Count the systems in that list. Now count how many of them are in Microsoft 365. That gap is the reason a "GCC High solves CMMC" pitch falls apart on a shop floor — and the reason a pure overlay enclave often doesn't fit either.

Specialized Assets are not ignored assets

The rule identifies a distinct category for this problem. Specialized Assets under 32 CFR § 170.19 include Internet of Things and Industrial IoT devices, Operational Technology, Government Furnished Equipment, restricted information systems, and test equipment when they meet the rule's definition and scoping treatment. A machine does not become a Specialized Asset merely because it sits on a shop floor.

Specialized Assets receive different assessment treatment. They do not receive no treatment. They must be documented and treated consistently with the applicable CMMC scoping guidance. If a vendor tells you a CNC, PLC, or test system simply "doesn't count," ask for the written asset-category rationale before you rely on that answer.

Four patterns that actually work in a shop

Pattern — How it works — Where it usually breaks
PatternHow it worksWhere it usually breaks
GCC High collaboration + on-premises engineering enclaveEmail, Teams, and files in GCC High; CAD, CAM, and program storage in a segmented internal networkThe transfer step between them — who moves files, how, and with what logging
GCC High + Azure Government VDI + segmented production networkEngineering runs in a hosted desktop; shop floor sits behind its own boundaryCAD/CAM graphics performance and machine-side file delivery
On-premises enclave + controlled external exchange serviceEverything controlled stays inside; an authorized service handles prime and supplier exchangeYou own more of the security stack and all of the evidence
Dedicated engineering and production environment with controlled transfer stationsA physically separated CUI environment with defined transfer pointsDiscipline — transfer stations become the whole control story

A practical note on performance: a cloud-only virtual desktop can simplify endpoint containment and still be a poor fit for heavy CAD/CAM work or locally connected measurement equipment. Test the actual workflow with representative files, peripherals, latency, and production constraints before you commit.

If you're a manufacturer, our CMMC for manufacturers and CMMC for machine shops guides go deeper on shop-floor scoping than this page can.


Which is actually cheaper — and what changes the answer?

The trade is broader migration and licensing against boundary engineering and dual-environment operations. There is no defensible employee-count breakpoint where one architecture automatically becomes cheaper. A narrow enclave deserves a serious look when the CUI population and workflows are genuinely contained; broader GCC High or a hybrid deserves a serious look when CUI crosses most collaboration paths or the cost of running two environments starts to dominate.

We keep the full five-layer cost model and the price catalog on our CMMC enclave cost guide, where it can be refreshed independently. What belongs here is the difference between paths — which is the number vendors never quote you.

Where the money actually goes, by path

Cost driver — Path 1 (overlay) — Path 2 (GCC High enclave) — Path 3 (full GCC High) — Path 4 (hybrid) — Path 5 (on-prem/VDI)
Cost driverPath 1 (overlay)Path 2 (GCC High enclave)Path 3 (full GCC High)Path 4 (hybrid)Path 5 (on-prem/VDI)
License breadthCommercial retained + overlay/service licensing for CUI usersCommercial and government licensing may overlap for users who remain active in both environmentsBroadest government-cloud licensing footprintMixedCapital, hosting, or software depending on design
Migration breadthMinimalSelectiveBroadestWorkload by workloadBuild, not migrate
Boundary complexityHighest relative to sizeHigh — two tenants, two identitiesLowest tenant-boundary complexityHighest integration complexityModerate
Commercial integrationsPreservedPreserved outside the enclaveOften require replacementPreserved selectivelyPreserved
User trainingWhich environment for which taskWhich account for which taskBroad change managementRole-specificTransfer discipline
Evidence burdenFewer assets if the boundary holdsTwo environments to evidenceMore assets, fewer seamsMultiple layers and interfacesYou produce most of it
The line item people forgetThe commercial environment may still require documented scope treatmentSplit-tenant licensing, identity, and support can persist as long as both environments are in useMigration overlap and integration replacement can be materialOwnership of seams between layersHardware lifecycle, internal labor, and evidence operations

Three dated facts to put in your model

  • Microsoft raised U.S. Government pricing effective July 1, 2026 — Microsoft 365 G3 GCC High up 8%, G5 GCC High up 5%. Build that into a multi-year budget rather than a first-year quote.
  • Microsoft does not publish GCC High list prices the way it publishes commercial ones. Every figure you see, including ours, is a planning range pending an authorized-partner quote by SKU.
  • DoD's own published cost estimates exclude implementation. The Final Rule's regulatory impact analysis put a small-entity Level 2 C3PAO path at roughly $104,670 over three years and an other-than-small entity at about $117,768, with the Level 2 self-assessment path around $37,000 for a small entity. Those figures cover assessment, certification, and affirmation activity. They do not include building your environment. The enclave or the tenant sits entirely on top.

The comparison trap

A low enclave quote and a high GCC High quote may not be comparable because each vendor can be pricing a different boundary. One may price only a small user group and collaboration layer; another may include endpoint management, identity, documentation, migration, and ongoing security operations. Normalize the scope before you compare the total.

The fix is to make every vendor quote the same boundary. Which is exactly what the letter further down this page is for.


Comparing quotes that don't compare?

Tell us your CMMC level, rough CUI user count, current environment, and timeline — nothing sensitive — and we'll route you to source-checked provider categories that can quote against the same non-sensitive scope, so you're comparing like for like instead of guessing.

See scoped quotes from matched provider categories →

Matching may generate lead-routing compensation when disclosed. It never changes our regulatory analysis or category routing. Do not submit CUI, drawings, contract numbers, or system diagrams.


How long does each path take?

There is no defensible universal timeline, because the work is driven by scope discovery, tenant complexity, endpoint count, integrations, and documentation maturity — not by the platform. Microsoft's own CMMC guidance advises organizations to allocate at least three months for cloud migration, which is vendor planning guidance rather than a typical duration for any specific environment.

A short platform-deployment quote is not the same thing as a CMMC-ready program. Scope discovery, evidence, policies, remediation, operations, and migration risk still exist outside the provisioning task.

Here are the workstreams that actually consume the calendar:

Workstream — Overlay — GCC High enclave — Full GCC High — Hybrid
WorkstreamOverlayGCC High enclaveFull GCC HighHybrid
CUI discovery and boundary designCriticalCriticalCriticalCritical, and usually longest
Platform or tenant provisioningProvider-dependentEligibility and provisioning requiredEligibility and provisioning requiredMultiple environments may need separate provisioning
Identity designBoundary-focusedSplit-tenant identity and cross-tenant settings where usedOrganization-wide government identity designCross-platform
Data and mailbox migrationMinimalSelectiveBroadBy workload
Endpoint configurationCUI populationCUI population, joined to the new tenantBroad populationRole-specific
Integration remediationBoundary interfacesBoundary interfacesEnterprise integrationsMultiple technical interfaces
SSP, diagrams, and evidenceEnclave boundaryTwo environmentsEnterprise boundaryMulti-layer boundary
Stabilization and adoptionBoundary disciplineWhich-account disciplineBroad change managementWorkflow-specific

The real urgency questions — the ones worth building a schedule around — are these. What date is in the solicitation or contract? When does your prime expect evidence? Is your SPRS score current and supportable? Do you need a coexistence period? Can production pause for a cutover?

And one that catches people: a significant change to your architecture or boundary can require a new assessment, while ordinary changes inside an established boundary are handled through continued compliance and your annual affirmation. If you are going to change the boundary, change it before you are assessed, not after.


Does the CMMC Phase 2 suspension change this decision?

No — and that is precisely the point. The Department of War suspended CMMC Phase II on July 13, 2026, pausing the third-party certification milestone that had been scheduled for November 10, 2026. It did not touch DFARS 252.204-7012, NIST SP 800-171 Revision 2, SPRS score posting, or annual affirmations. The cloud requirement driving this entire architecture decision is untouched.

Let's be precise about what changed, because a lot of contractors have drawn exactly the wrong conclusion.

What was suspended: the Phase II transition and all pending and future CMMC implementation milestones. During the suspension, Department procurement requirements may designate only Level 1 (Self) or Level 2 (Self). New Level 2 (C3PAO) and Level 3 (DIBCAC) designations are suspended. Active solicitations containing those requirements are to be amended; existing contracts containing them are to be modified before the next option period or scheduled administrative modification.

What was not suspended: DFARS 252.204-7012. NIST SP 800-171 Revision 2. Your self-assessment. Your SPRS score. Your annual affirmation. The FedRAMP requirement for any cloud holding your CUI.

What prime-contractor flow-downs can still do: independently impose requirements through the terms of your subcontract or purchase order. The suspension memorandum governs Department implementation; it does not automatically rewrite every private subcontract. Confirm the actual requirement and timing in writing with each relevant prime and review the governing agreement.

The dangerous wrong conclusion, stated plainly so nobody makes it: "CMMC is paused, so the cloud question can wait." It cannot. The clause that decides where your CUI is allowed to live has been in DoD contracts since 2016 and is in force today.

Why this is a good moment to decide the environment and a bad moment to book an assessment

There is real timing here, and we won't manufacture any that isn't.

A CMMC Reform Task Force was established alongside the suspension, with a 60-day mandate. Its public Request for Information closed at 12:00 p.m. Eastern on August 14, 2026, and its recommendations to the Department CIO are expected in the mid-September 2026 timeframe.

That matters to you in one specific way. The suspension does not remove the existing duty to safeguard covered defense information under DFARS 252.204-7012. Future policy changes can still alter CMMC assessment and acquisition mechanics, so do not treat the current suspension as permission to postpone protection work — or as a reason to book a third-party assessment your contract does not currently require.

Before you commit assessment spend, confirm in writing what CMMC assessment type, if any, currently applies to your solicitation, contract, or subcontract after the suspension.

The federal record says the scoping problem is real

We looked for a legitimate case study rather than a vendor testimonial. The best one is in the rulemaking record.

When the CMMC Program rule was proposed, the SBA Office of Advocacy — an independent office inside the Small Business Administration that represents small entities before federal agencies — filed a comment letter in February 2024. Among its central concerns: "Advocacy requests clarification from DoD as to how to create enclaves within businesses." Reporting on that letter quoted Advocacy's position that the rule "does not provide clear guidance on the process to create enclaves, which would allow more small business subcontractors to participate in DoD contracts without meeting the full requirements necessary for the prime contractor."

The Department acknowledged Advocacy's concerns in the Final Rule and committed to enhanced training and small-business outreach. It did not prescribe a standard enclave configuration — reasonably, since enclave architecture has to be tailored to each business.

Then, on August 17, 2026, Advocacy filed again — this time with the CMMC Reform Task Force. Among the cost drivers it named for small firms: unclear CUI scoping.

Two and a half years apart, the same federal small-business advocate identified the same gap. That is the gap this page exists to close. It is also the reason you should be suspicious of anyone who tells you the enclave question has one obvious answer — the government's own advocate has been asking for that answer since 2024 and hasn't received a blueprint.


What evidence makes your boundary defensible?

An assessor evaluates your implementation, not your purchase order. Whichever path you choose, you need to be able to show where CUI moves, how each asset was categorized, what each external provider is responsible for, and how the controls you claim actually operate over time. A Customer Responsibility Matrix from your provider is assessment evidence, not a sales attachment.

Here is the artifact list, split by what every path needs and what each path adds.

Every path needs these

  • CUI data-flow diagram
  • Asset inventory, tagged to the 32 CFR § 170.19 categories
  • Network diagram showing the boundary
  • System Security Plan with the boundary described accurately
  • Asset-category rationale — why each system landed where it did
  • User and role inventory
  • Approved transfer paths in and out of the boundary
  • External service provider inventory, service descriptions, and contracts
  • Customer Responsibility Matrix for every provider touching CUI or security protection data
  • Configuration baselines and access-control evidence
  • Logging, alerting, and retention evidence
  • Backup and restore evidence
  • Incident response and spill procedures
  • Training records
  • Change records and periodic boundary tests
  • POA&M status and closeout plan
  • A named owner for the annual affirmation in SPRS

What a dual-environment path adds

Commercial-to-government mail-flow rules. Cross-tenant access restrictions. Identity separation design. Forwarding controls. Clipboard, download, and print restrictions. Approved sharing pathways. User acknowledgment and training. Spill-detection tests. Mobile-client restrictions. Backup separation between environments.

What a GCC High path adds

Tenant eligibility documentation. The list of licensed services actually in use. Current authorization or assurance evidence for the exact cloud service offering your boundary relies on, including a dated public status snapshot where one exists. Microsoft's current service description for the features in scope. Privileged-role assignments. And a support process that prevents controlled or sensitive information from being disclosed to support personnel who are not authorized to receive it.

What an equivalency-path enclave adds

The FedRAMP Moderate Equivalency body of evidence, the assessing organization, the assessment date, and the POA&M status. FIPS validation certificate numbers and the standard they're against. The written 7012 (c)–(g) position. And, if the architecture relies on the encryption carve-out, a written statement of exclusive key control.

What a manufacturing or OT path adds

Specialized Asset classification and rationale. Network placement and segmentation evidence. Risk-based treatment documented in the SSP. Access methods and transfer controls. Maintenance and vendor-access process.

The sentences an assessor will not accept

No matter how confidently they're delivered: "We bought GCC High." "Microsoft handles that." "Our MSP said it was compliant." "CUI probably doesn't go there." "Users know not to upload it." "We'll document it later."

Every one of those is a sentence. An assessment runs on artifacts.


What to put in writing before you sign either quote

Send the same questions to both vendors and compare the answers, not the brochures. Six questions apply to any architecture, four are specific to a GCC High path, and four are specific to an equivalency-path enclave. If a vendor won't answer these in writing, that is your answer.

Copy this. Use it. It is free, it is not gated, and it will do more for your negotiation than anything else on this page.

To any vendor, any path

  1. Which of the five architecture paths are you quoting — encrypted overlay, GCC High enclave, full-company GCC High, hybrid, or on-premises/VDI enclave?
  2. Under 32 CFR § 170.19(c)(1), what asset category does each of our systems land in after your build — and will you put that categorization in writing?
  3. Provide the Customer Responsibility Matrix before contract signature, not after go-live.
  4. Which identity provider authenticates or protects access to the CUI environment after your build, and how are you categorizing it under § 170.19?
  5. Is assessment support included, separate, or excluded — and to be explicit, is the C3PAO assessment itself in your price?
  6. What is your written position on DFARS 252.204-7012 paragraphs (c) through (g), and where is it published?

If they're quoting a GCC High path

  1. Confirm the current FedRAMP Marketplace record and package ID for the exact offering our CUI will touch, as of our contract date.
  2. What is the dual-license overlap period in your quote, and what happens to it if migration runs long?
  3. Which of our existing third-party tools do not support GCC High, and what replaces them?
  4. If this is a split-tenant build, how many identities will each CUI user hold, and what is the cross-tenant collaboration design for working with primes and subs?

If they're quoting an equivalency-path enclave

  1. Provide the FedRAMP Moderate Equivalency body of evidence, the assessing organization, and the assessment date — and state whether any POA&Ms are open.
  2. Identify your FIPS validation certificate numbers, current status, and standard (140-2 or 140-3), given that FIPS 140-2 validations remain active through September 21, 2026 and move to the Historical List on September 22.
  3. If our data may include ITAR-controlled technical data, state in writing whether your architecture relies on 22 CFR § 120.54(a)(5), identify how every condition is met, and state who holds the means of decryption. Address EAR-controlled data separately.
  4. How do you keep your FedRAMP Moderate equivalency evidence package current, and what events trigger a reassessment or evidence refresh?

One rule that protects you: do not attach CUI, drawings, technical data, system diagrams, vulnerability reports, or contract documents to any of these emails. Describe your environment in general terms. Everything on this list can be answered without you sending a single controlled file.


Which CMMC provider category should you hire first?

Most contractors making this decision need scoping and readiness help before they need an assessor. Use an RPO/RP, a CMMC-focused MSP or MSSP, or a government-cloud implementation partner to define and build the environment. Engage a C3PAO for the formal certification assessment only when your scope and evidence are ready. Under the CMMC conflict-of-interest framework, the C3PAO and assessment team must account for prohibited consulting, preparation, or implementation assistance provided to the same organization during the preceding three years. Verify that history before you sign either engagement.

Getting the category right matters more than getting the brand right. The wrong category at the wrong stage is how contractors overspend, under-scope, or end up paying for a second migration.

Where you are right now — Start with this category — What to verify before you engage — What it is not a substitute for
Where you are right nowStart with this categoryWhat to verify before you engageWhat it is not a substitute for
"We don't know where our CUI actually flows"RPO / RP (Registered Provider Organization / Registered Practitioner) or readiness consultantCyber AB Marketplace listing if they claim RPO status; scoping methodology; independence from your assessorBuilding or operating the environment
"We've picked a path and need it built"CUI enclave or government-cloud implementation partnerAuthorized-partner status where relevant; FedRAMP evidence for the offering; a Customer Responsibility MatrixOwning your SSP and evidence
"We need someone to run it day to day"MSSP (Managed Security Service Provider) or managed compliance providerScope of "managed"; references at your size; ESP documentation; what stays yoursThe formal assessment
"We need evidence workflows and SSP/POA&M support"GRC platformHow it maps to NIST SP 800-171 Rev. 2; whether CUI or security protection data is stored in itImplementing the controls — software alone never makes you compliant
"We're scoped, remediated, and ready for the audit"C3PAOCurrent authorization in the Cyber AB Marketplace; three-year conflict history; assessment scope and contractReadiness or implementation work that would create a prohibited conflict for that assessment

If you want named firms, verify the category and status before you route the lead

This article intentionally does not publish a named-provider ranking or current-status table. Cyber AB authorization, partner programs, product evidence, and service scope can change. Use the Cyber AB Marketplace for current ecosystem status where relevant, verify the provider's role and evidence directly, and keep readiness/implementation separate from formal assessment when the conflict rules require it.

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. No provider paid for inclusion or position in this guide, and no provider can guarantee a CMMC outcome.


How we built this comparison

We separate three kinds of claim, because mixing them is how comparison articles mislead people.

Regulatory facts are cited to the issuing authority — eCFR, the Federal Register, Acquisition.gov, NIST's Computer Security Resource Center, and the Department's published memoranda. We do not publish a requirement without its source.

Current-state facts — FedRAMP Marketplace records, vendor-published positions, pricing — carry a verification date and a label: provider-stated, industry-reported, or government-published. A vendor's claim about its own certifications, assessment history, or customer outcomes is attributed as company-stated and is not repeated as our finding.

Editorial judgments — which path fits which contractor, what to verify, what order to do things in — are labeled as our conclusions drawn from the verified facts above. They are defensible, they are consistent with the sources on this page, and they are not compliance advice.

We do not blur CMMC levels. We do not blur Level 2 self-assessment with a Level 2 C3PAO assessment. We do not blur NIST SP 800-171 Revision 2 with Revision 3 for CMMC purposes. We do not blur readiness help with formal assessment. And we do not tell you a product makes you compliant, because no product does.

Corrections: we publish and date them. See our Methodology, Editorial Standards, and Corrections Policy.


Frequently asked questions

Is a CMMC enclave an alternative to GCC High?

Sometimes. It depends on which kind of enclave a vendor is selling. A GCC High enclave is a deployment shape of GCC High — a subset of users licensed and migrated into a government tenant. A third-party encrypted enclave is an alternative to GCC High, keeping CUI outside Microsoft while your commercial tenant continues for everyday work. Ask which one you're being quoted before you compare prices.

Is GCC High required for CMMC Level 2?

No universal Microsoft-product requirement appears in 32 CFR Part 170 or DFARS 252.204-7012. Level 2 requires implementing the 110 requirements in NIST SP 800-171 Revision 2. Separately, any external cloud service handling covered defense information must meet FedRAMP Moderate-equivalent security and comply with DFARS 252.204-7012 paragraphs (c) through (g). Several environments can meet that bar.

Can only the employees who handle CUI use GCC High?

Yes, that's the split-tenant or "enclave" pattern, and it is a legitimate architecture. But it does not automatically put everyone else out of scope. You still have to account for endpoints, identity, administrators, security tooling, backups, and every transfer path between the two environments.

Does an enclave reduce the number of CMMC Level 2 requirements?

No. Level 2 still requires all 110 security requirements from NIST SP 800-171 Revision 2 across 14 families. A defensible enclave reduces the number of assets, users, and systems those requirements apply to — which reduces remediation, evidence, and assessment effort. Fewer assets, not fewer requirements.

Can commercial Microsoft 365 stay outside the enclave?

Only to the extent it cannot process, store, or transmit CUI, provides no security protection to CUI Assets, and is physically or logically separated from them — all three conditions, per 32 CFR § 170.19(c)(1). If those conditions do not fit, analyze the tenant against the other rule-defined categories instead of forcing an out-of-scope label.

Can VDI keep ordinary laptops out of CMMC scope?

Only under the narrow condition in the Level 2 Scoping Guide: the endpoint must be configured so it does not process, store, or transmit CUI beyond keyboard, video, and mouse interaction with the virtual desktop client. Any feature that causes the endpoint to process, store, or transmit CUI beyond that interaction can disqualify the endpoint from that out-of-scope treatment.

Does GCC High cover CAD, ERP, CNC, or OT systems?

Not by moving Microsoft collaboration workloads. Any local or third-party system that processes, stores, or transmits CUI — or that protects CUI Assets — still requires its own scoping analysis. Some shop-floor and test systems may qualify as Specialized Assets; others may be CUI Assets. The category depends on the rule's definitions and the system's actual role.

Does ITAR require GCC High?

No regulation names a Microsoft product. GCC High is often selected because of Microsoft's U.S. data-residency and screened-personnel commitments. Separately, 22 CFR § 120.54(a)(5) provides a specific path for qualifying encrypted unclassified technical data when all of its conditions are met — including the destination and source-country restrictions and the rule that the means of decryption are not provided to a third party. Which approach fits your data is a legal determination for qualified export counsel.

What is FedRAMP Moderate equivalency, and is it as good as FedRAMP authorization?

Equivalency is a DoD-defined path in which a cloud provider is independently assessed as 100% compliant with the FedRAMP Moderate control baseline, with a body of evidence assessed by a third-party assessment organization. The DoD CIO's equivalency memorandum states it does not apply to offerings already FedRAMP Moderate Authorized — those can be relied on without further assessment. Both are legitimate. The difference for you is the amount of evidence you have to obtain and hold.

Will a C3PAO accept an enclave boundary?

Enclave scoping is permitted — the acquisition rulemaking record states a contractor may pursue a CMMC level for its entire enterprise network or for particular segments or enclaves. What an assessor evaluates is whether your documented boundary matches reality and whether your evidence supports it. No page, and no vendor, can promise you a specific assessor's conclusion.

How many Microsoft tenants will I end up running?

One under a full GCC High migration or a pure overlay model. Two under a split-tenant GCC High enclave, with most CUI users holding an account in each. Two or more under a hybrid. Ask any vendor quoting a "GCC High enclave" to state the tenant count and the identity design in the proposal — it is the single biggest driver of day-to-day friction.

Does the CMMC Phase 2 suspension mean I can wait on this?

No. The July 13, 2026 suspension paused the third-party certification milestone. It expressly preserved Phase 1 self-assessment requirements and left DFARS 252.204-7012 in force — and 7012 is the clause that governs where your CUI is allowed to live. The environment decision is unaffected. The assessment-type decision is what's under review.

Can the company that builds my enclave also assess me?

Not when the C3PAO or assessment team has a prohibited conflict from consulting, preparation, or implementation assistance provided to that organization during the preceding three years. Keep readiness and formal assessment separated early enough to preserve independence, and verify the C3PAO's conflict history before booking the assessment.

What should I do first?

Map your CUI flow. Until you know where CUI enters, who touches it, where it's stored, what protects it, and whether it can be contained, every architecture quote is a guess dressed up as a proposal.


Need help deciding what type of CMMC provider you need?

Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.

The match is based on provider category, your stage, your environment, and your general timeline — not a paid ranking. Matching is not an endorsement, a certification guarantee, legal advice, or affiliation with the Cyber AB or the Department of War.

Get Matched With Source-Checked Options →

Do not submit CUI, drawings, export-controlled content, contract numbers, system diagrams, vulnerability details, or sensitive contract information through this or any web form.

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification.


Which provider category fits your situation

  • Choose a CUI enclave provider if CUI touches only part of your business and you can draw a boundary your people will actually follow.
  • Choose a GCC High implementation partner if your CUI users need full Microsoft collaboration inside the boundary, or a contract requires it in writing.
  • Choose an MSSP if you can't operate the controls day to day inside whichever boundary you pick.
  • Choose an RPO/RP or readiness consultant if you do not yet know where your CUI flows — architecture pricing is premature until the boundary is understood.
  • You don't need a C3PAO yet if your boundary isn't locked and your evidence isn't assembled. An enclave can make a required assessment smaller; it never removes the requirement.

Related guides


Primary sources

Last verified: August 22, 2026. Next scheduled review: November 2026.

This guide is educational analysis, not legal, contractual, export-control, or compliance advice. The Defense Compliance Report is not affiliated with, endorsed by, or sponsored by the Cyber AB, the Department of War, the Department of Defense, DCMA DIBCAC, NIST, Microsoft, or any U.S. government agency.