The Defense Compliance ReportCMMC 2.0 & the Defense Industrial Base

CMMC cloud decision guide · primary-sourced · last reviewed August 2026

FedRAMP vs GCC High: What CMMC Actually Requires

Last updated:

Last verified: against the CMMC Program Rule, DFARS 252.204-7012, FedRAMP 2026 definitions, and live Marketplace records.

FedRAMP versus GCC High cloud decision paths for CMMC compliance

CMMC Cloud Decision Guide · Primary-Sourced · Last reviewed August 2026

By The Defense Compliance Report Editorial Team — an independent trade publication on CMMC 2.0 and DIB compliance.

Last verified: August 24, 2026 · FedRAMP Marketplace records re-checked monthly · Next scheduled review: November 2026 · We have no compensation relationship with Microsoft, Amazon, or any cloud provider named on this page.

This guide is educational research. It is not legal, contractual, export-control, or compliance advice.


FedRAMP vs GCC High is not a choice between two products. FedRAMP is the U.S. government program that assesses and certifies cloud services. Microsoft 365 GCC High is one cloud service that holds a FedRAMP certification. For CMMC Level 2, the rule sets a Moderate floor — not High — and it never names GCC High. GCC High is not the only environment worth evaluating against that floor.

That is the whole answer, and if you stop reading here you already know more than the vendor who quoted you.

But there's a wrinkle that showed up in the summer of 2026, and it's the reason we built this page. The status word the CMMC rule tells you to verify is no longer the status word the FedRAMP Marketplace shows you. The rule says Authorized. The live product pages say Certified. And although those pages may display labels such as Class C (Moderate), FedRAMP says Certification Class is not a one-for-one impact-level crosswalk. On top of that, two different Microsoft packages now sit on the Marketplace under the exact same product name — with different classes, different statuses, and a 98-to-zero gap in authorizations. One of them is certified. One of them isn't. If you or your assessor cite the wrong one, your cloud evidence is wrong and nobody will notice until it matters.

We pulled all five records ourselves on August 24, 2026. They're below.

Your situation, your answer

If this is you — Then — Your first move
If this is youThenYour first move
You handle Federal Contract Information (FCI) only, no CUIGCC High is almost certainly unnecessaryConfirm in writing that no CUI is in contract scope
CUI in Microsoft 365, nothing export-controlled, no prime mandateThe certified GCC package is a legitimate candidate. Class C alone is not a one-line CMMC answerPull and date the exact package record; document how the offering supports the Moderate-or-higher requirement
Any CUI is ITAR or EAR export-controlledGCC High is usually the Microsoft environment to evaluate firstConfirm the export determination with qualified counsel before you choose the environment
A contract or prime names GCC High in writingThe written requirement controls this procurementGet it in writing, then budget the migration
Your vendor says "FedRAMP equivalent" instead of certifiedA much heavier evidence path — and part of the burden lands on youRequest the complete body of evidence before you sign
You opened the Marketplace and saw "Class C (Moderate)," while the rule says "FedRAMP Authorized at Moderate or higher"You're looking at two vocabularies layered togetherRead the crosswalk below before treating the class as the answer

The Defense Compliance Report is an independent trade publication and decision resource for CMMC and Defense Industrial Base compliance — explaining the CMMC Final Rule with primary-source citations for material regulatory claims and mapping a contractor's level, CUI scope, assessment type, and timeline to the right provider category, so DIB contractors choose the right CMMC path before they commit budget.

The right CMMC provider isn't the same for every contractor — the category you need (a C3PAO, an RPO, an MSSP, a GRC platform, or a CUI enclave) depends on your required CMMC level, whether you handle FCI or CUI, your assessment type, your cloud and IT environment, and your contract timeline. The solicitation or contract requirement sets your level, not a checklist. Because a general answer can't resolve those for you, use The Defense Compliance Report's Find My CMMC Path tool to map your situation to the right provider category before you request quotes — and do not submit CUI, drawings, or sensitive contract details.


What is the actual difference between FedRAMP and GCC High?

FedRAMP (the Federal Risk and Authorization Management Program) is a governmentwide program that assesses cloud services and publishes the result on a public Marketplace. Microsoft 365 GCC High is a Microsoft government-cloud product that has been through that program. Comparing them as competing options is like comparing a health inspection to a restaurant — one is the process, the other is a thing the process evaluates.

Almost every argument a defense contractor has about this topic is really an argument about a category error. Someone in the room is treating FedRAMP as a product you can buy instead of GCC High. You can't. There is no "FedRAMP" you subscribe to.

Here is the cleanest way we've found to hold the two apart:

Question — FedRAMP — Microsoft 365 GCC High
QuestionFedRAMPMicrosoft 365 GCC High
What is it?A federal cloud security assessment and certification program administered by GSAA Microsoft 365 government-cloud environment
Can you buy it?NoYes, after Microsoft eligibility validation through Volume Licensing
What does it produce?A Marketplace record and a certification package for a defined cloud service offeringEmail, Teams, SharePoint, OneDrive, and related services inside the offering boundary
Where do you verify it?The FedRAMP Marketplace, by exact package IDYour Microsoft agreement and the Marketplace record for the exact package
Does CMMC name it?CMMC references the FedRAMP Moderate-or-higher baseline and the MarketplaceNo. CMMC never names GCC High
What still belongs to you?The use decision and your documentationConfiguration, identities, endpoints, policies, evidence, and affirmation

FedRAMP certifies offerings, not companies

This is one of the most expensive misunderstandings in cloud procurement for the Defense Industrial Base, and it costs contractors real money at assessment time.

FedRAMP does not certify Microsoft. It does not certify Amazon. It certifies a specific cloud service offering — a defined, packaged product with a defined boundary — and it gives that offering a package ID.

Microsoft alone currently holds at least three separate Marketplace records that a DIB contractor might reasonably think of as "Microsoft government cloud." They have different IDs, different classes, and different statuses. We'll show you all three shortly. When a salesperson says "we're FedRAMP," the only correct response is: which package?

The four things people are actually comparing

When someone types "FedRAMP vs GCC High" into a search bar, they're usually holding four different concepts and assuming they're one:

  1. FedRAMP — the certification program.
  2. Microsoft 365 GCC — a government-community cloud product whose live certified package displays Class C (Moderate).
  3. Microsoft 365 GCC High — a more isolated government-community cloud product whose live certified package displays Class D (High).
  4. DoD Impact Levels (IL2, IL4, IL5) — a separate DoD cloud-security framework under the DoD Cloud Computing Security Requirements Guide, which adds DoD-specific requirements to a FedRAMP baseline.

Four different rulers. A vendor who says "we're IL4" has told you something real, but they have not told you their FedRAMP class. A vendor who says "we're FedRAMP High" has not told you their package ID. Both answers are incomplete.


Does DFARS 252.204-7012 require FedRAMP High or FedRAMP Moderate?

Moderate. DFARS 252.204-7012, the Safeguarding Covered Defense Information and Cyber Incident Reporting clause, requires a contractor using an external cloud service for covered defense information to ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline, and complies with the clause's paragraphs (c) through (g). The clause names the Moderate baseline, not the High baseline. Do not turn that into a Class C-equals-Moderate shortcut: FedRAMP says its 2026 Certification Classes are not one-for-one impact-level replacements.

We're being blunt about this because we found pages telling readers the opposite — that the clause requires FedRAMP High for clouds processing CUI. It doesn't. Repeated by a reseller with a quote in hand, that error can push a supplier into a materially more expensive environment it did not need.

Read the clause yourself on Acquisition.gov. Paragraph (b)(2)(ii)(D) is the one that matters. It says the contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the FedRAMP Moderate baseline — and that the provider complies with paragraphs (c) through (g).

The half of the clause nobody quotes

Everyone argues about Moderate versus High. Almost nobody reads the second half of that same sentence, which is where the real vendor negotiation lives.

Paragraphs (c) through (g) of DFARS 252.204-7012 obligate a chain of behavior your cloud provider has to actually agree to:

  • Cyber incident reporting — a rapid report through the DoD reporting mechanism when a covered incident occurs.
  • Malicious software submission — turning over malware discovered in connection with a reportable incident.
  • Media preservation and protection — retaining images and monitoring data for at least 90 days from the incident report.
  • Access to additional information and equipment — providing what DoD needs for forensic analysis.
  • Cyber incident damage assessment — supporting DoD's assessment if it's conducted.

A FedRAMP class does not prove that a provider will contractually commit to any of that. This is the difference between a cloud that has a certification and a cloud that works for a defense contract. Ask about (c) through (g) in writing, by paragraph, before you sign anything.

A useful note for the "just use commercial and lock it down" crowd: the clause is about the offering, not the configuration. Hardening a commercial tenant does not create FedRAMP Moderate equivalence. Equivalence is established by assessment, which we cover in detail below.

Do not confuse the four DFARS clauses

Only DFARS 252.204-7012 sets the cloud baseline discussed on this page. The other three clauses answer different questions, and they often appear together.

Clause — What it actually does — The practical check
ClauseWhat it actually doesThe practical check
DFARS 252.204-7012Sets the safeguarding and cyber-incident duties, including the external-cloud FedRAMP Moderate-equivalence requirement and paragraphs (c) through (g)Verify the exact cloud offering and the provider's written incident-response commitments
DFARS 252.204-7019Makes a current NIST SP 800-171 DoD Assessment a condition of award when the provision appliesConfirm the relevant summary score is current and posted in SPRS
DFARS 252.204-7020Gives the Government access needed for Medium or High assessments, governs summary-score posting, and includes subcontract flow-down dutiesConfirm access, score, and subcontract obligations before treating a 7019 check as complete
DFARS 252.204-7021Requires the CMMC status inserted in the contract and a corresponding current affirmation; the CMMC UID is reflected in SPRSRead the contract's inserted level and verify the status and affirmation are current

When included, these clauses stack. They are not interchangeable, and a clean SPRS score does not answer the cloud question by itself.


What does the CMMC rule say about your cloud?

The CMMC Program Rule at 32 CFR Part 170 permits an organization to use a cloud environment for CUI under two circumstances: the cloud service offering is FedRAMP Authorized at the Moderate baseline or higher according to the FedRAMP Marketplace, or it is not so authorized but meets equivalent security requirements per DoD policy. The same language governs both Level 2 self-assessment and Level 2 certification assessment.

Some quick definitions, because we'll use these terms freely from here.

CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense program that verifies whether contractors have implemented the cybersecurity requirements they already agreed to. CUI (Controlled Unclassified Information) is unclassified information the government requires you to safeguard. A C3PAO (CMMC Third-Party Assessment Organization) is a firm authorized to perform Level 2 certification assessments. DIBCAC (the Defense Industrial Base Cybersecurity Assessment Center, within the Defense Contract Management Agency) is the government body that performs Level 3 assessments and may review cloud-equivalency evidence. SPRS (the Supplier Performance Risk System) receives Level 1 and Level 2 self-assessment results and affirmations; C3PAO and DIBCAC assessment results are entered through CMMC eMASS and transmitted to SPRS.

The two paragraphs that govern your cloud

The Program Rule handles this in two nearly identical places, and the fact that they're identical matters:

Provision — Applies to — What it permits
ProvisionApplies toWhat it permits
32 CFR § 170.16Level 2 (Self)A cloud offering that is FedRAMP Authorized at Moderate or higher according to the Marketplace — or one that meets equivalent requirements under DoD policy
32 CFR § 170.17Level 2 (C3PAO)The same two doors, with the same cloud floor

Read that table again. The cloud bar does not change when you move from self-assessment to third-party assessment. The scrutiny changes. The evidence burden changes. The bar does not. Any vendor telling you that a C3PAO assessment requires a "higher" cloud than a self-assessment is describing their own comfort level, not the rule.

The scope trap in the third subparagraph

Both sections carry a third clause that gets skipped in every vendor deck we've read: your on-premises infrastructure that connects to the cloud offering is part of the CMMC Assessment Scope, in accordance with § 170.19, and will also be assessed.

Buying a certified cloud does not shrink your boundary by itself. A well-designed enclave can shrink your boundary. A license does not. That distinction is the difference between a contained project and a company-wide migration, and it's why we always tell people to map CUI flow before they map SKUs. Our CMMC scoping guide walks the asset categories.

What about Level 3?

Level 3 does not raise the cloud floor. Under § 170.18, the cloud provision still speaks in terms of Moderate or higher. What changes is everything on your side: Level 3 adds 24 selected requirements drawn from the February 2021 edition of NIST SP 800-172 on top of the Level 2 control set, requires a Final Level 2 (C3PAO) status for that scope first, and is assessed by DIBCAC. If any of those enhanced requirements are inherited from your cloud, you need the responsibility documentation and supporting evidence to prove it.

Level 2 remains the 110 security requirements across 14 families in NIST SP 800-171 Revision 2. NIST has since published newer editions and marks the standalone SP 800-171 Revision 2 and SP 800-172 pages as withdrawn. That does not make Revision 3 the controlling CMMC version. The current CMMC rule incorporates NIST SP 800-171 Revision 2 and the named February 2021 SP 800-172 edition; a later NIST publication does not change the assessment standard unless DoD amends the rule.

Before you price a single environment, price the right scope.

The most expensive CMMC mistake we see isn't buying the wrong cloud. It's buying any cloud before confirming what's actually in scope. Tell the Find My CMMC Path tool your level, your FCI/CUI handling, your assessment type, your current environment, and your timeline, and it maps your situation to the provider category to compare first — readiness, managed compliance, GRC, or enclave.

Map my contract, CUI flow, and cloud needs to the right provider category →

Free. No obligation. Do not submit CUI, drawings, export-controlled content, or contract details.


Why does the Marketplace say "Certified" when the CMMC rule says "Authorized"?

*Because FedRAMP rebuilt its vocabulary in 2026. The CMMC rule still says a cloud offering must be FedRAMP Authorized at Moderate or higher. Live Marketplace product pages now show a status of FedRAMP Certified plus a Certification Class — sometimes with a parenthetical label such as Class C (Moderate). FedRAMP states that Certification satisfies the legal requirement to be authorized, but it also states that Certification Class does not correspond directly to FIPS 199 impact level.*

This is the synthesis we could not find published in one place, so we'll show our work.

On June 24, 2026, FedRAMP launched its Consolidated Rules for 2026. Three definitional changes matter to anyone reading a CMMC clause:

1. The Marketplace status label changed from "Authorized" to "Certified." FedRAMP's definition of FedRAMP Certified is the status of an offering that has received FedRAMP Certification and meets the legal requirement to be FedRAMP authorized. FedRAMP explicitly notes it now uses "FedRAMP Certified" as the current program term for offerings that satisfy the statutory concept of authorization. The legal meaning survived intact. The label on the page did not.

2. Marketplace profiles now display Certification Classes. A Certification Profile is the combination of a Type (Rev5 or 20x), a Path (Program or Agency), and a Class (A, B, C, or D). Class runs from a lighter assurance commitment at A to a deeper assurance commitment at D.

3. Class is not impact level. FedRAMP is unusually direct about this on its Certification Classes guidance for agencies: classes indicate "the level of assurance provided, not the level of security or protection provided." FedRAMP goes further, noting that many cloud services with strong security programs choose to invest only in Class A or B certifications to keep government pricing aligned with commercial pricing.

That last point deserves a beat. A low Certification Class is not evidence of a weak product. It can simply mean the provider declined to make an expensive, ongoing assurance commitment to federal customers. If you are evaluating a smaller CUI enclave or secure-collaboration vendor, do not read Class A or B as a red flag on its own. Read it as a question to ask.

The crosswalk: what the rule says vs. what you'll actually see

This is the table we wish someone had handed us. Every row verified August 24, 2026.

Authority or record — The words it uses — What you see now — What the bridge supports
Authority or recordThe words it usesWhat you see nowWhat the bridge supports
DFARS 252.204-7012(b)(2)(ii)(D)"FedRAMP Moderate baseline"A Marketplace status plus a Certification ClassClass is evidence about assurance; FedRAMP says it is not a one-for-one replacement for an impact level
32 CFR §§ 170.16–170.17"FedRAMP Authorized" at Moderate or higher, according to the MarketplaceThe status field now reads "FedRAMP Certified"FedRAMP defines Certified as satisfying the legal requirement to be authorized
Live GCC package MSO365MT"FedRAMP Certified" and "Class C (Moderate)"A current certified record with a package ID and certification packageStrong evidence to evaluate, but the class label alone is not a formal DoD crosswalk
DoD CIO memo, Dec. 21, 2023"FedRAMP-recognized 3PAO"FedRAMP now uses "FedRAMP Recognized" for the assessor statusAsk for the assessor's current status by name and date rather than relying on the retired role label

FedRAMP's own Presumption of Adequacy table offers the closest thing to a bridge, and it is deliberately loose: Class C is described as adequate for most Low or Moderate impact systems and some High impact systems with appropriate compensating controls. Class D is described as adequate for most systems regardless of impact level.

Our one damaging admission on this page

We can't tell you how a C3PAO will treat a "Class C" record against a rule whose text says "Moderate baseline."

We looked. As of August 24, 2026, we could not find published guidance from DoD, the CMMC Program Management Office, the Cyber AB, or FedRAMP that formally reconciles the 2026 Marketplace vocabulary with the wording inside 32 CFR Part 170. We're telling you that we searched and did not find it, rather than telling you it doesn't exist. Anyone who tells you this question is settled is telling you more than the public record supports.

Here's why that does not have to slow you down — and why it's actually good news.

The ambiguity is precisely the reason to save a dated record instead of accepting a verbal assurance. A screenshot of the package's Marketplace page on the day you scoped, filed alongside FedRAMP's published definition bridging "Certified" and "authorized," gives you a contemporaneous evidence trail before an assessor asks. It does not manufacture a missing DoD crosswalk. It costs you five minutes and zero dollars.

Ambiguity gets expensive when nobody documented the reasoning or re-checked the record.


Is GCC High FedRAMP certified? Five records verified August 2026

Yes. Microsoft 365 Government Community Cloud-High, package FR1824057433, is listed as FedRAMP Certified, Class D (High), in Ongoing Certification, certified since December 26, 2024. That verifies one specific offering. It does not mean every Microsoft government-cloud package carries the same status — and as of August 24, 2026, two Microsoft packages share an identical product name with different classes and different statuses.

Here is our full pull. Five cloud service offerings a Defense Industrial Base contractor is likely to encounter, every field taken directly from the FedRAMP Marketplace product page on August 24, 2026.

Cloud service offering — Package ID — Phase — Status — Type — Path — Class — Certified since — Authorizations
Cloud service offeringPackage IDPhaseStatusTypePathClassCertified sinceAuthorizations
Microsoft 365 Government Community Cloud & Supporting Services (GCC)MSO365MTOngoing CertificationFedRAMP Certified (as of 8/14/2015)Rev5AgencyClass C (Moderate)11/20/201498
Microsoft 365 Government Community Cloud & Supporting Services (GCC)MSO365MTAInitial ImplementationFedRAMP In Process (as of 7/20/2026)Rev5AgencyClass D (High)N/A — not certified0
Microsoft 365 Government Community Cloud-High (GCC High)FR1824057433Ongoing CertificationFedRAMP Certified (as of 12/26/2024)Rev5AgencyClass D (High)12/26/20245
Azure Government (includes Dynamics 365)F1603087869Ongoing CertificationFedRAMP Certified (as of 4/29/2020)Rev5JABClass D (High)4/29/202069
AWS GovCloudF1603047866Ongoing CertificationFedRAMP Certified (as of 6/21/2016)Rev5JABClass D (High)6/21/201683

Source: FedRAMP Marketplace product records, retrieved August 24, 2026. Verify the live record before relying on any row.

The finding: two packages, one name

Look at rows one and two.

Both are titled "Microsoft 365 Government Community Cloud & Supporting Services." Character for character, the same product name.

One is MSO365MT — certified, Class C (Moderate), 98 authorizations, certified since 2014. The other is MSO365MTA — Class D (High), but with a status of FedRAMP In Process as of July 20, 2026, zero authorizations, and no certification date at all.

The Marketplace appears to show Microsoft pursuing a Class D certification for the GCC product family alongside its existing Class C record. We cannot state Microsoft's reason from the public record. What we can state is that a buyer or assessor searching by product name gets two results and one of them is not certified.

Here's what that means in practice:

  • "Microsoft 365 GCC" is no longer a precise status statement. It hasn't been since at least July 2026. The package ID is now the only reproducible identifier.
  • If someone tells you "GCC is Class D / FedRAMP High," ask for the package ID. If the answer is MSO365MTA, the honest description is "In Process," not "certified." Those are different words on the Marketplace for a reason.
  • This is the exact kind of detail that survives a good assessment and exposes a sloppy evidence file. A package that is still in process is not evidence of FedRAMP certification.

We are not suggesting anyone is being deceptive. We're pointing out that a naming collision on a federal registry is a live procurement risk, and that citing by ID is now free insurance.

Three more details we noticed while pulling these records

Two records show "Path: JAB." Azure Government and AWS GovCloud both display a Path of JAB, the legacy Joint Authorization Board label. FedRAMP's 2026 definitions describe current Certification Paths as Program or Agency, yet the live records still render JAB. That does not invalidate the records. It is another reason to date what you capture.

The GCC record shows two different dates. MSO365MT displays a status of Certified "as of 8/14/2015" and a Certified Since date of 11/20/2014. Both are on the same page. They label different fields, so if you cite one in your SSP, cite the field name too.

Every package in the ledger is Type: Rev5. None of the five records is Type 20x yet. That matters for 2027 planning, and we cover it below.

What this all means for the GCC High question

GCC High is certified. Its live record displays Class D (High), which gives it the least ambiguous Microsoft evidence story against a Moderate-or-higher floor. Nobody should be nervous about the status shown on that exact package record.

But notice something in the ledger: GCC High shows 5 authorizations against GCC's 98, Azure Government's 69, and AWS GovCloud's 83, and its certification date is December 26, 2024 — recent compared with the others. Older vendor and DCR pages may still describe GCC High with equivalency language. The live package record now controls the status statement.

None of that is a problem. It's a reminder: status changes, so date what you capture.

Get the record before you get the quote.

Find My CMMC Path asks non-sensitive questions about your contract, CUI handling, current environment, readiness, and timeline, then routes you to the provider category that fits the problem — readiness, managed compliance, GRC, or enclave.

Check my CMMC cloud path →

Free. No CUI required. Do not enter drawings, contract numbers, network diagrams, credentials, or export-controlled content.


When is Class C (Moderate) enough, and when is GCC High the better fit?

The live MSO365MT GCC package is FedRAMP Certified and displays Class C (Moderate), which makes it a real candidate against a Moderate-or-higher requirement. It is not an automatic pass: FedRAMP says Certification Classes are not one-for-one impact-level substitutes, and we found no public DoD crosswalk resolving that new vocabulary for CMMC. GCC High becomes the stronger Microsoft choice when CUI lives across Microsoft 365 and the organization's contract, export-control, impact-level, or sovereignty obligations call for capabilities Microsoft attributes to that environment.

Three separate tests decide this, and most arguments happen because two people are answering different ones:

  1. The status test. Does the exact offering have a current Marketplace status and package that support the Moderate-or-higher requirement, or a complete DoD-equivalency body of evidence? This is more than reading the class label.
  2. The fit test. Does the offering suit your data category, your collaboration pattern, your integrations, and your incident obligations? This is architecture.
  3. The proof test. Can you demonstrate your side of the shared-responsibility split? This is evidence.

Passing test one tells you nothing about tests two and three. That's the whole reason "is GCC Moderate?" never actually settles the argument in the room.

The scenario matrix

The "likely path" column below is our editorial conclusion, derived from the rule text and Marketplace records cited on this page. It is not a determination, and it is not legal advice.

Your situation — Regulatory or contractual floor — Likely path — What can change the answer — Proof to collect before you buy
Your situationRegulatory or contractual floorLikely pathWhat can change the answerProof to collect before you buy
FCI only, no CUIUsually a Level 1 / FAR 52.204-21 problem — 15 basic safeguardsGCC High is normally unnecessaryA prime or agency-specific requirement; CUI entering the workflow laterContract clauses, FCI/CUI inventory, documented Level 1 scope
CUI in Microsoft 365, nothing export-controlled, no prime mandateExact offering must support the Moderate-or-higher requirement or meet DoD equivalency, plus DFARS (c)–(g)Compare the certified GCC package, GCC High, and a scoped enclave. Do not presume the class label settles the choiceExact CUI category; service terms; external sharing needs; how your prime interprets flow-downPackage ID, current status, certification package, responsibility matrix, written (c)–(g) commitment, CUI data-flow map
Export-controlled CUI, or a written IL4/GCC High requirementThe CMMC cloud floor is unchanged; the overlay drives architectureGCC High is a strong Microsoft fit. Microsoft states that it supports DoD IL4 and ITAR when properly configuredThe actual export-control classification and authorized-user model, confirmed by counselContract language, export-control determination, Microsoft service boundary, access and support model
A handful of users exchange a narrow set of CUI filesThe service handling CUI still needs to meet the cloud requirementA secure transfer service or managed CUI enclave is often more proportionate than a company-wide migrationWhether CUI leaks back into ordinary email, local drives, or unmanaged devicesEnforced boundary evidence, download controls, device rules, logging, responsibility matrix
CUI lives in custom apps, databases, VMs, or engineering workloadsThe exact IaaS/PaaS services must support the requirement and be configured correctlyAzure Government or AWS GovCloud architecture — and you may still need a collaboration answer separatelyExisting cloud skills in-house; export-control or impact-level overlays; which exact services are in scopeServices-in-scope list, responsibility matrix, architecture and network diagrams, logging evidence
Level 3 programCloud floor remains Moderate or higher; 24 selected February 2021 SP 800-172 requirements apply on your sideChoose a platform that can carry the enhanced implementation and evidence burden. Do not assume a Class D label satisfies Level 3Which enhanced requirements you intend to inherit, and whether the provider will supply evidenceResponsibility matrix, body of evidence for inherited requirements, Final Level 2 (C3PAO) foundation
Your CSP claims "FedRAMP equivalent" but isn't listedMust meet DoD's full Moderate-equivalency policyTreat it as a high-evidence path. A certified alternative is often operationally simplerCompleteness and recency of the body of evidence; the assessor's current FedRAMP standingSSP, SAP, SAR, POA&M materials, evidence of full-baseline compliance, responsibility matrix, (c)–(g) terms

Where we'd push back on both camps

To the "GCC High or nothing" crowd: the rule doesn't say that, DFARS doesn't say that, and 32 CFR Part 170 doesn't name any product. If your CUI isn't export-controlled and no contract demands sovereignty, you are making a defensible architecture choice — not following a mandate. Say so honestly in the budget meeting.

To the "GCC is Moderate, so we're fine" crowd: the certified GCC package is real evidence. The Class C label alone does not resolve the missing DoD crosswalk, the fit test, or the proof test. And if you handle export-controlled technical data, "we cleared the FedRAMP question" will not help you with a completely different body of law.

Our editorial read, stated plainly: the deciding variables are whether any of your CUI is quietly export-controlled, whether your prime expects GCC High in writing, and how much configuration-and-proof burden you're willing to carry yourself. If you're confident on all three, the certified GCC package is a legitimate lower-cost candidate to document and validate. If any one is shaky, the GCC High premium buys a less ambiguous evidence story — and that matters more than it looks the week before an assessment.

For the full environment-by-environment breakdown inside the Microsoft lineup, including cost and migration reality, see our companion guide: GCC High for CMMC: when you need it and when you don't.


What does "FedRAMP Moderate equivalent" actually require?

FedRAMP Moderate equivalency is a DoD-defined alternate path, not a lighter version of certification and not a vendor's word. Under the DoD CIO memorandum dated December 21, 2023, a cloud service offering must achieve 100% compliance with the FedRAMP Moderate baseline through an assessment by a FedRAMP-recognized third-party assessor, with no POA&Ms remaining from that assessment, and must supply a body of evidence to the contractor.

Equivalency exists because 32 CFR § 170.16 and § 170.17 both open a second door: a CSP that is not FedRAMP Authorized at Moderate or higher may still be used if it meets equivalent security requirements in accordance with DoD policy. The DoD CIO memorandum is that policy.

What the equivalency path demands

Requirement — What it means in practice
RequirementWhat it means in practice
100% of the FedRAMP Moderate baselineNot "substantially." Not "the ones that apply to us." All of it
Assessment by a FedRAMP-recognized third-party assessorSelf-attestation does not satisfy the memo, and a SOC 2 report alone does not replace the required assessment
No POA&Ms resulting from that assessmentAssessment findings must be corrected and validated as closed; operational POA&Ms not resulting from the assessor's review are treated separately in the memo
A complete body of evidenceSSP, SAP, SAR, POA&M and the supporting materials specified by the memo, available for DIBCAC review
Annual third-party assessmentThe CSP must have an annual assessment validating the required compliance, according to the memo
Contractor obligationsYou must validate the body of evidence, provide the responsibility matrix to assessors, contractually require continued equivalency, and retain responsibility for incident reporting

That last row is the one that surprises people. On the equivalency path, part of the burden is yours. The DoD memo puts the validation duty on the contractor, not only on the vendor.

The carve-out that saves you the whole exercise

The memorandum states that it does not apply to cloud service offerings that are already FedRAMP Moderate Authorized under the existing FedRAMP process. Those offerings, identified on the Marketplace, can be leveraged without further assessment to meet the equivalency requirements.

Translated: if the exact cloud offering is already FedRAMP Authorized at Moderate or higher, you are done with the equivalency body-of-evidence path. You are not done with DFARS paragraphs (c) through (g), customer configuration, scoping, or your own CMMC evidence. That carve-out is still a strong argument for starting the shortlist on the Marketplace.

The vocabulary problem nobody has flagged

The memorandum requires an assessment by a FedRAMP-recognized 3PAO — a Third-Party Assessment Organization.

FedRAMP has retired that term. Its 2026 definitions state that the program has moved away from the historical term "Third-Party Assessment Organization (3PAO)" to align with the terminology in the FedRAMP Authorization Act, and to avoid confusion when the same firms provide both assessment and advisory services. The current status is FedRAMP Recognized.

So a contractor executing the equivalency path in late 2026 is chasing a role name that the source program no longer uses. The practical fix is small but real: stop asking "is your assessor a 3PAO?" Ask for the assessor's current FedRAMP Recognized status, by name, in writing, with a date.

A documented example of what this path looks like

The clearest public example we could find of a company completing the equivalency path is PreVeil, which states that it was the first company to achieve DoD FedRAMP Moderate equivalency. According to the company, it engaged an accredited third-party assessor to conduct an independent assessment of its cloud service offering, then presented its assessment report and body of evidence to DIBCAC, which conducted a multi-week review before the company was notified that DoD concurred it met the equivalency requirements.

What we verified and what we didn't: these are the company's published statements about its own process, and we're presenting them as such. We did not independently verify the DIBCAC concurrence, the assessment report, or the contents of the body of evidence. We include it because it's the most detailed public account of the equivalency workflow we could find, and because it illustrates the real shape of the path — an accredited assessor, a full evidence package, and a government review measured in weeks, not days. If you're evaluating any provider on the equivalency door, ask to see the equivalent documentation for their offering, and verify it yourself.


What should you verify before you sign?

Verify the exact cloud service offering, its package ID, its current status and class, its included and dependent services, and the customer responsibility matrix — immediately before you sign, not months earlier. A FedRAMP certification supplies security information to support a risk decision; it does not certify your implementation and it does not transfer compliance to you.

We built this as a five-layer check because the failures we see almost always come from skipping a layer, not from getting a layer wrong.

The five-layer verification stack

Layer — The question you must answer — Evidence — The common mistake
LayerThe question you must answerEvidenceThe common mistake
1. Contract and dataWhat level and assessment type does the solicitation actually name, and is the information FCI, CUI Basic, or export-controlled CUI?Solicitation and contract clauses, prime flow-down in writing, CUI markingsLetting a reseller, checklist, or website quiz "set" your level. The contract requirement controls
2. WorkloadWhere does the information actually live — email, Teams, files, transfer portal, custom apps, VMs, engineering tools, on-premises systems?A current and proposed CUI data-flow mapBuying GCC High for a workload it does not host, or buying IaaS while CUI still sits in ordinary email
3. The exact offeringWhich specific cloud service offering processes, stores, or transmits the information?Full product name, package ID, included services, dependent productsTreating the vendor name or product family as the assessed offering
4. Certification or equivalency evidenceDoes the exact offering's current Marketplace record and package support the Moderate-or-higher requirement — without treating class as an automatic crosswalk — or does it have a complete DoD-equivalency body of evidence?Dated Marketplace record and certification package, or SSP/SAP/SAR/POA&M materials plus assessor standingAccepting "in process," "built on FedRAMP," "FedRAMP-aligned," or self-attestation as proof
5. Customer implementationWhat stays with you — identities, endpoints, connected infrastructure, policies, logging, evidence?Responsibility matrix, SSP, asset inventory, boundary and network diagrams, configuration evidenceAssuming the provider's package transfers compliance to your organization

The nine questions to send your provider

Copy these into an email. Every one of them is answerable in a paragraph by a provider who has done this before, and every one is revealing when a provider stalls.

  1. What is the exact offering name and package ID on the FedRAMP Marketplace for the service that will handle our CUI?
  2. What are its current Phase, Status, Type, Path, and Class as displayed today?
  3. Are you certified, or are you on the DoD equivalency path? If equivalency, who performed the assessment and what is their current FedRAMP Recognized standing?
  4. Will you provide the body of evidence or certification package, and under what terms?
  5. Are there open POA&Ms from your most recent assessment?
  6. Will you contractually commit to DFARS 252.204-7012 paragraphs (c) through (g)?
  7. Where is your customer responsibility matrix, and does it map to NIST SP 800-171 Revision 2?
  8. Is the offering Type Rev5 or 20x, which Consolidated Rules for 2026 apply to its current certification, and what is the provider's published transition roadmap?
  9. Are the exact SKUs we are purchasing inside the certified boundary?

Save a dated artifact

Whatever you learn, capture it: a PDF or screenshot of the Marketplace record, the date you accessed it, the package ID, the version of the responsibility matrix, the quote or contract naming the exact service, and any written clarification the provider gave you.

That folder is worth more at assessment time than any vendor's compliance badge. It shows what was true when you made the decision, what you relied on, and what you later re-verified.


Does a FedRAMP-certified cloud make you CMMC compliant?

No. A certified cloud can supply inherited controls and supporting evidence, but the contractor remains responsible for its own configuration, identities, endpoints, connected infrastructure, policies, documentation, and annual affirmation. Microsoft states that CMMC support depends on customer configuration, implementation, and operational controls — not simply on which service you buy.

This is the section that saves people from the most expensive version of this mistake: buying a premium environment, relaxing, and discovering at assessment that the platform covered a fraction of the work.

Responsibility area — What may be inherited from the cloud — What you still have to prove
Responsibility areaWhat may be inherited from the cloudWhat you still have to prove
Physical and data-center protectionsProvider facilities and underlying infrastructure controlsThat the offering and boundary you documented are the ones you actually use
IdentitySome platform identity capabilitiesAccount lifecycle, privilege design, MFA configuration, administrator practice, and evidence of all four
Data protectionPlatform encryption and storage capabilitiesClassification, approved locations, sharing rules, labeling, and actual observed data flow
LoggingPlatform logging capabilityCorrect configuration, retention, review cadence, alerting, and use during incidents
EndpointsEssentially nothing from buying SaaSDevice inventory, hardening, access control, malware protection, local-storage restrictions
Incident responseProvider processes inside its own boundaryYour reporting decisions, escalation, preservation, and coordination
DocumentationThe responsibility matrix and provider packageYour SSP, boundary definition, asset list, policies, procedures, and proof of implementation
Connected infrastructureNo automatic exclusionConnected on-premises systems remain in scope under § 170.19

What an assessor will not accept

We've heard every one of these. None of them is evidence:

  • "We bought GCC High."
  • "Microsoft handles that."
  • "Our MSP said we're compliant."
  • "It's FedRAMP, so it's covered."
  • "CUI probably doesn't go there."
  • "We'll document it later."

Each of those is a sentence. An assessment runs on artifacts.

You've resolved the cloud question. Now find out what's still sitting on your side of the line.

Our CMMC Readiness Checklist is a 32-point self-check mapped to the 14 NIST SP 800-171 Revision 2 control families — scoping and CUI inventory, SSP and POA&M baseline, SPRS posting, and an assessment-type decision tree. It is emailed as a printable PDF; the weekly briefing option is separate and unchecked by default. It's the fastest way to see what a certified cloud did not solve for you.

Get the CMMC Readiness Checklist →

Free. Do not upload contracts, CUI, system diagrams, or incident details through any form.


What are the real tradeoffs of GCC High?

GCC High provides a more isolated government-cloud boundary for qualifying CUI workflows, and that boundary creates genuine operational friction. Microsoft's current Office 365 GCC High and DoD service description documents restricted external sharing, feature differences from commercial Microsoft 365, and a customer-support channel that sits outside the service's accreditation boundary.

We're not here to talk anyone out of GCC High. We're here to make sure nobody discovers these after the purchase order.

External sharing is intentionally constrained. Native sharing in SharePoint and OneDrive is limited to other GCC High organizations. If you collaborate daily with primes, subs, or customers who aren't in GCC High, test that workflow before you migrate, not after.

The support channel sits outside the accreditation boundary. Microsoft advises customers not to share controlled, sensitive, or confidential information with support personnel until they've confirmed the agent is authorized to receive it. This is the most underrated line in the entire service description. Your incident-response procedure needs a rule about it, and your assessor may ask.

Feature parity differs from commercial. Telephony is delivered through Direct Routing rather than commercial calling plans. Some integrations require government-cloud-specific endpoints or are unavailable, and GCC High pairs with Microsoft Entra ID in Azure Government. Verify every dependency against the current government-cloud feature matrix.

The migration is a tenant-to-tenant project, not a license flip. Microsoft advises allocating at least three months for the migration phase. Plan to rebuild or revalidate identity, conditional access, device management, integrations, and endpoint settings instead of assuming they carry over untouched.

None of that makes GCC High a bad product. It makes it a specific product. The stricter boundary only creates value when it matches your actual data and workflow — which is the entire argument of this page, stated one more way.

For licensing, migration sequencing, and total-cost reality, we keep that on dedicated pages: GCC High for CMMC and the Microsoft 365 GCC High migration guide.


What are the alternatives to GCC High?

A contractor may use any cloud architecture that clears the applicable regulatory, contractual, data, and workload requirements. Realistic alternatives include a FedRAMP Certified SaaS offering whose exact package and evidence support the Moderate-or-higher requirement, a secure transfer service, a managed CUI enclave, government-cloud infrastructure such as Azure Government or AWS GovCloud, or an on-premises environment — each of which shifts the boundary, the evidence, and the customer responsibility burden.

Path — Strongest use case — Main advantage — Main risk — Where to read more
PathStrongest use caseMain advantageMain riskWhere to read more
Microsoft 365 GCC (MSO365MT)Non-export-controlled CUI in a familiar Microsoft environmentLower cost and closer to commercial day-to-day useTreating the Class C label as automatic approval; failing to confirm the exact packageGCC High for CMMC
Microsoft 365 GCC HighBroad Microsoft 365 CUI collaboration with export-control or contract overlaysMicrosoft-stated IL4 and ITAR support, with a less ambiguous High-labeled recordCost, sharing friction, and support-boundary rulesGCC High migration
Managed CUI enclaveA small population touches CUIConfines the premium environment to in-scope users and can shrink the assessment boundaryBoundary leakage; running two environments badlyEnclave vs. enterprise compliance · Enclave cost
Government IaaS/PaaSCUI lives in applications, databases, VMs, or engineering workloadsArchitectural flexibilityHeavy customer configuration and operations burdenAzure Government · AWS GovCloud
On-premisesAn existing controlled environment and a capable internal teamDirect controlHighest direct operational and evidence burden; connected services still in scopeCMMC scoping guide

The scope-reduction lever most contractors underuse: if CUI genuinely touches six people and two workflows, a contained enclave can be dramatically cheaper than migrating an entire company. The catch is that the boundary has to be real. No forwarding CUI to ordinary commercial Outlook. No quietly uploading a drawing to out-of-boundary SharePoint. No cached copies on unmanaged laptops. An enclave that leaks is worse than no enclave, because you paid for a boundary you can't defend.


What changes between now and 2027?

FedRAMP is mid-transition from its legacy Rev5 approach to FedRAMP 20x. Every package in our verified ledger is currently Type Rev5: four are certified and one is in process. FedRAMP's published dates put mandatory adoption of the Consolidated Rules for 2026 at January 1, 2027, and the end of applications for new Rev5 certifications at June 11, 2027.

Here's the calendar, straight from FedRAMP's own timeline:

Date — Milestone
DateMilestone
July 4, 2026Optional early adoption of the Consolidated Rules for 2026 begins
July 6, 2026Initial Implementation Marketplace listings open
July 28, 2026FedRAMP Ready goes legacy; no new submissions accepted
August 3, 2026FedRAMP 20x Class A certification pipeline opens
August 10, 2026Temporary Rev5 Program certification pipelines open for Class B and C
August 31, 2026FedRAMP 20x Class B and C pipeline opens
January 1, 2027Consolidated Rules for 2026 take mandatory effect, subject to their stated applicability dates
June 11, 2027FedRAMP stops accepting applications for new Rev5 certifications

Why a DIB contractor should care: FedRAMP's rules and labels are changing inside current contract periods. That does not create an automatic 20x migration deadline for the five packages above. It creates two sensible questions for the next vendor review — which Consolidated Rules for 2026 apply to the current certification, and what is the provider's published Rev5/20x roadmap? June 11, 2027 is the cutoff for new Rev5 certification applications, not a universal deadline for already-certified Rev5 offerings.

And the CMMC side of the calendar

The original final-rule schedule ran Phase 1 from November 10, 2025 through November 9, 2026, with Phase 2 scheduled to begin November 10, 2026. The Department suspended the Phase II transition on July 13, 2026, and its current CMMC page says the program is paused in Phase 1 with no replacement Phase II date announced. Level 1 (Self) and Level 2 (Self) requirements remain in place where included, results and affirmations continue through SPRS, and DFARS 252.204-7012 safeguarding duties remain in force where the clause applies. We track the current state on our CMMC Phase II update.

The suspension does not change the DFARS cloud requirement analyzed on this page. DFARS 252.204-7012 predates CMMC and remains in force where the clause appears in the contract. The honest urgency is not a guessed replacement milestone — it is your solicitation date, your prime's flow-down deadline, and how long a tenant migration actually takes.


Which provider category should help — and when?

If your question is "does my cloud qualify and how do I prove it," that is a readiness, architecture, and documentation problem. The categories that fit are an RPO/RP, a CMMC-focused MSP or MSSP, a CUI enclave provider, or a GRC platform as a supporting layer. It is not an assessment question yet. A C3PAO may offer other services as a Type C body, but it cannot assess an organization within three years of providing consulting, implementation, or product sales/services to that organization, and it cannot advise the organization during the certification assessment.

If your situation is… — Start with this category — What to verify before you engage
If your situation is…Start with this categoryWhat to verify before you engage
"We don't know whether our cloud qualifies."RPO / RP (Registered Provider Organization / Registered Practitioner) or a vCISOCyber AB Marketplace status, scoping methodology, CUI-flow experience, and that they are readiness support — not the assessor for this engagement
"We need to migrate or stand up the environment."CMMC-focused MSP / MSSP or an authorized government-cloud implementation partnerAuthorization to sell and provision, migration track record, responsibility-matrix and SSP support, ongoing managed-compliance capability
"We want to contain CUI instead of migrating everyone."CUI enclave / secure-collaboration providerHow the boundary is technically enforced, the status of the exact cloud offering, and evidence supporting the proposed scope
"We need evidence workflow and SSP/POA&M tracking."GRC platformThat it is a supporting layer, not a CMMC guarantee; accurate NIST SP 800-171 Revision 2 mapping; exportable assessor-ready evidence
"We're remediated and ready for a formal Level 2 assessment."Authorized C3PAOCurrent Cyber AB Marketplace status and no disqualifying consulting, implementation, or product-sales/services engagement with your organization during the prior three years

Why you won't find a "best provider" list on this page

We could have put ten company names in a table here. We didn't, for a specific reason: this page answers a regulatory and verification question, and naming providers would not make the answer more correct. Dedicated provider guides can evaluate named companies. This page routes the decision by category. When we name providers, the page should disclose category, status check, services reviewed, compensation relationship, evaluation depth, and a last-verified date.

If you're the wrong reader for this page, here's where to go instead. If you already have a signed contract naming GCC High and export-controlled data, you don't have a decision — you have a migration project; start at our GCC High migration guide. If your real question is whether to contain CUI rather than migrate it, start at enclave vs. enterprise compliance. If you're not sure whether you need a self-assessment or a certification assessment at all, start at self-assessment vs. C3PAO. For the broader handoff, use CMMC provider categories or Who to Hire First. We'd rather lose the click than waste your afternoon.

The independence rule, briefly

Under the Cyber AB's January 2026 C3PAO Accreditation Requirements, a C3PAO may not conduct a Level 2 certification assessment of an organization within three years of providing consulting, implementation, or product sales/services to that organization. During the assessment, the C3PAO and its affiliated personnel may not provide advice, implementation assistance, or recommendations. If a firm offers to fix your cloud and then certify it, ask for the engagement dates and conflict analysis in writing. Verify the assessor's current status directly on the Cyber AB Marketplace before you contract.

You know what the rule requires. The next question is who helps you prove it.

Tell us your required level, your FCI/CUI scope, your current cloud environment, your assessment type, and your timeline. We'll map you to the provider category that fits — readiness, managed compliance, GRC, or enclave — so you're comparing scoped quotes instead of guesses.

Get matched with source-checked provider options →

Do not submit CUI, drawings, export-controlled content, contract numbers, or system diagrams. This intake is for provider-category routing only.

Disclosure: The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. We may receive compensation for qualified introductions, sponsorships, or partner referrals when disclosed. Compensation does not control our regulatory analysis, provider-category recommendations, or Cyber AB status verification. We are not affiliated with the Cyber AB, the Department of Defense, DCMA DIBCAC, NIST, Microsoft, Amazon, GSA, or any U.S. government agency. Matching is not an endorsement, a certification guarantee, or legal advice.


What we actually verified for this page

On August 24, 2026, The Defense Compliance Report Editorial Team read the operative cloud provisions of 32 CFR Part 170, DFARS 252.204-7012/-7019/-7020/-7021, the controlling NIST publications, the DoD CIO equivalency memorandum, the Cyber AB's current C3PAO accreditation requirements, FedRAMP's Consolidated Rules for 2026, and five live Marketplace product records. Editorial conclusions were built from that source chain rather than from vendor summaries.

What we checked — What it supports — Verified
What we checkedWhat it supportsVerified
32 CFR §§ 170.16–170.17The two cloud doors for Level 2, the identical Moderate-or-higher floor, self-assessment upload and affirmation mechanics, and connected on-premises scopeAug. 24, 2026
32 CFR § 170.18Level 3 cloud language, 24 enhanced requirements, and CRM/body-of-evidence duties for inherited requirementsAug. 24, 2026
CMMC Final Rule, Federal RegisterWhy NIST SP 800-171 Revision 2 — not Revision 3 — remains the controlling CMMC edition unless DoD amends the ruleAug. 24, 2026
DFARS 252.204-7012The FedRAMP Moderate-equivalence requirement and paragraphs (c) through (g)Aug. 24, 2026
DFARS 252.204-7019, 252.204-7020, and 252.204-7021Current-assessment/SPRS checks, Government assessment access and flow-down, and the contract's CMMC-status/affirmation dutiesAug. 24, 2026
NIST SP 800-171 Revision 2 and NIST SP 800-172Publication dates and current NIST status, separated from the editions incorporated into the CMMC ruleAug. 24, 2026
Cyber AB R2002, January 2026C3PAO independence, the three-year consulting/implementation/product-services restriction, no advice during assessment, and no certification guaranteesAug. 24, 2026
FedRAMP Definitions"FedRAMP Certified" satisfies the legal concept of authorization; Certification Profile terminology; current assessor terminologyAug. 24, 2026
FedRAMP Certification ClassesClasses indicate assurance rather than security and are not one-for-one impact-level replacementsAug. 24, 2026
FedRAMP Important DatesThe 2026–2027 adoption and Rev5 application calendarAug. 24, 2026
MSO365MTMicrosoft 365 GCC — Certified, Class C (Moderate), 98 authorizationsAug. 24, 2026
MSO365MTASecond GCC package under the same name — Class D, FedRAMP In Process as of 7/20/2026, zero authorizationsAug. 24, 2026
FR1824057433Microsoft 365 GCC High — Certified, Class D (High), certified since 12/26/2024Aug. 24, 2026
F1603087869Azure Government — Certified, Class D (High), Path JAB, 69 authorizationsAug. 24, 2026
F1603047866AWS GovCloud — Certified, Class D (High), Path JAB, 83 authorizationsAug. 24, 2026
DoD CIO FedRAMP Moderate Equivalency memorandum (Dec. 21, 2023)The 100% baseline, third-party assessment, body-of-evidence, closed-assessment-finding, annual-assessment, contractor-validation, and already-authorized carve-out requirementsAug. 24, 2026
Current DoD CMMC statusThe July 13, 2026 Phase II suspension and continuation of Phase I self-assessment requirementsAug. 24, 2026

What we could not verify, and are not claiming

  • We did not find published guidance reconciling the 2026 FedRAMP labels with the wording in 32 CFR Part 170. We searched DoD, CMMC PMO, Cyber AB, and FedRAMP sources. We're reporting a gap in the public record, not asserting that no such guidance exists anywhere.
  • We are not stating why Microsoft holds two GCC packages under one name. We're reporting what the Marketplace displays and what it means for your evidence file.
  • We did not independently verify any vendor's marketing claims about impact-level support, ITAR suitability, or assessment outcomes. Where we repeat one, we attribute it.
  • We are not determining any individual contractor's required CMMC level, export-control obligation, or ITAR applicability. Those come from your contract, your data, and qualified counsel.
  • We do not claim any control-count figure for the FedRAMP Moderate baseline. Published sources disagree on the number; we cite the baseline as FedRAMP publishes it rather than repeat a figure we haven't confirmed at the source.

Who wrote this and why: The Defense Compliance Report Editorial Team, an independent trade publication on CMMC 2.0 and DIB compliance. This is editorial research, not formally reviewed by a CMMC Subject Matter Advisor. We built it because "FedRAMP vs GCC High" is a question with a cheap correct answer and an expensive wrong one, and because the 2026 Marketplace changes made a previously simple lookup genuinely confusing. See our Methodology, Editorial Standards, Editorial Review Process, and Corrections policy — if you find an error on this page, tell us and we'll fix it and date the fix.

Confirm scope and applicability for your contracts with a CMMC Registered Practitioner, a qualified federal-contracts attorney, or qualified export-control counsel where applicable before making compliance decisions.


FedRAMP vs GCC High: frequently asked questions

Is FedRAMP the same thing as GCC High?

No. FedRAMP is a governmentwide program that assesses and certifies cloud service offerings and publishes the results on a public Marketplace. Microsoft 365 GCC High is one cloud service offering that holds a FedRAMP certification. One is the evaluation program; the other is a product it evaluated.

Does CMMC require FedRAMP High?

No. Under 32 CFR § 170.16 and § 170.17, a cloud service offering handling CUI must be FedRAMP Authorized at the Moderate baseline or higher per the FedRAMP Marketplace, or meet equivalent security requirements in accordance with DoD policy. DFARS 252.204-7012 names the Moderate baseline, not the High baseline. Do not convert that into a Class C-equals-Moderate shortcut; FedRAMP says the 2026 Certification Classes are not one-for-one impact-level replacements.

Is GCC High FedRAMP certified?

Yes. As of August 24, 2026, the FedRAMP Marketplace lists Microsoft 365 Government Community Cloud-High, package FR1824057433, as FedRAMP Certified, Class D (High), in Ongoing Certification, certified since December 26, 2024. Verify the live record before relying on it in an evidence file.

Is Microsoft 365 GCC FedRAMP Moderate?

The certified GCC package, MSO365MT, is listed as FedRAMP Certified, Class C (Moderate), with 98 authorizations as of August 24, 2026. A second package under the identical product name, MSO365MTA, shows Class D (High) with a status of FedRAMP In Process as of July 20, 2026 and no certification date. Always cite the package ID, not the product name, and do not treat Class C as a one-for-one legal substitute for the rule's Moderate-baseline wording.

What does "FedRAMP Certified" mean if the CMMC rule says "FedRAMP Authorized"?

FedRAMP's 2026 definitions state that FedRAMP Certified is the status of a cloud service offering that has received FedRAMP Certification and meets the legal requirement to be FedRAMP authorized. FedRAMP uses "Certified" as the current program term for offerings that satisfy the statutory concept of authorization. The label changed; the legal meaning did not.

What is a FedRAMP Certification Class?

A Certification Class is one of four categories, A through D, describing the depth and frequency of assurance information a cloud service provider commits to supplying through FedRAMP. FedRAMP states that classes indicate the level of assurance provided, not the level of security or protection provided, and that class does not correspond directly to a FIPS 199 impact level.

Is FedRAMP equivalency as good as FedRAMP certification?

They satisfy the same regulatory door but they are not the same thing, and equivalency carries a heavier evidence burden. The DoD CIO memorandum of December 21, 2023 requires 100% compliance with the FedRAMP Moderate baseline, assessment by a FedRAMP-recognized third-party assessor, closure of findings from that assessment, a complete body of evidence, and annual reassessment — and it places validation duties on the contractor.

Does CMMC use NIST SP 800-171 Revision 3?

No. NIST has published Revision 3 and withdrawn the standalone Revision 2 page, but the current CMMC rule incorporates NIST SP 800-171 Revision 2. DoD expressly rejected an automatic move to whichever NIST revision is current. Revision 3 does not become the CMMC assessment standard unless DoD amends the rule.

Does a FedRAMP-certified cloud make us CMMC compliant?

No. A certified cloud can supply inherited controls and supporting documentation, but your configuration, identities, endpoints, connected on-premises infrastructure, policies, SSP, POA&M closeout, external service provider scoping, and annual affirmation in SPRS remain yours to implement and prove.

Does ITAR require GCC High?

ITAR is a separate legal regime from CMMC and does not name any commercial product. Microsoft states that properly configured GCC High supports ITAR and DoD Impact Level 4 requirements. Whether your data is export-controlled, and what handling that triggers, is a determination to confirm with qualified export-control or federal-contracts counsel.

Is GCC High for classified information?

No. CMMC and this comparison concern unclassified environments handling FCI and CUI. Classified systems operate under entirely different authorization and handling regimes and are outside the scope of 32 CFR Part 170.

Does the CMMC Phase II suspension change our cloud obligations?

No. The Department suspended the Phase II transition on July 13, 2026, which changes the CMMC implementation schedule. DFARS 252.204-7012 and its FedRAMP Moderate baseline requirement are separate obligations that apply wherever the clause appears in your contract, and they remain in force.

How do we prove our cloud's FedRAMP status to an assessor?

Capture a dated record of the exact offering's Marketplace page showing the package ID, phase, status, class, type, and path; keep the certification package or equivalency body of evidence, the provider's customer responsibility matrix, and the service description; document the DFARS 252.204-7012 paragraph (c)–(g) commitment; and reference the evidence in your System Security Plan. Date every artifact, because Marketplace statuses change.


Your next step

You don't need to become a FedRAMP expert. You need four things, in this order: the exact package ID for the cloud that touches your CUI, a dated record of its status, a written answer on DFARS 252.204-7012 paragraphs (c) through (g), and a clear-eyed view of everything still sitting on your side of the responsibility matrix.

Do those four and the GCC High question tends to answer itself.

Need help deciding what type of CMMC provider you need? Tell us your level, scope, and timeline, and we'll match you with source-checked CMMC provider options.

Find My CMMC Path → · Get the CMMC Readiness Checklist →

Do not submit CUI, drawings, export-controlled content, contract numbers, system diagrams, or sensitive incident details through any form on this site. Provider matching may generate referral or lead-routing compensation, disclosed at the point of recommendation.


Related guides

The Defense Compliance Report is an independent trade publication on CMMC 2.0 and DIB compliance. Content is educational and is not legal, contractual, export-control, or compliance advice.