Every defense contractor running Microsoft 365 asks the same question before spending a dollar on CMMC: do I actually need to migrate to GCC High? And every article they find gives them a version of the same hedge: "you may need GCC High if you handle CUI..."
There is a reason those articles hedge. Almost all of them are written by Microsoft partners who make their margin selling GCC High migrations. Saying "actually, GCC is enough for most contractors" costs those partners a $20-per-user-per-month upgrade and a six-figure migration engagement. So they don't say it, even when it is true.
This guide is written by a vendor that does not sell any Microsoft 365 tenant. We build an on-premises compliance platform. Our answer to "do you need GCC High" does not change our revenue either way, which means we can afford to give you the answer instead of the hedge.
Why this is really a question about email
Most articles frame the GCC High decision as "do I have CUI." That framing hides the real question. The real question is how CUI moves in and out of your business.
Consider what any competent enclave already handles:
- Storing CUI. Files on a hardened workstation, a network share inside a segregated VLAN, an on-premises platform. All routine.
- Processing CUI. CAD work, engineering analysis, documentation authoring, review workflows. All routine.
- Access control. AD/entra ID isolation, RBAC, MFA on the CUI enclave. All routine.
Now consider what an enclave does not handle on its own:
- Sending CUI by email to a customer or prime. The moment a user has to reply to a customer email with a CUI drawing attached, they reach for Outlook, and Outlook lives in your M365 tenant.
- Receiving CUI by email from a customer or prime. The prime sends an RFI with a CUI attachment. That attachment lands in Exchange Online. Exchange Online is your M365 tenant.
- Sharing CUI with external collaborators via Teams or SharePoint. Same story: the sharing infrastructure is M365.
Everything in that second list is transmission, and transmission is what forces the tenant question. If CUI never has to travel through M365, your M365 tenant does not have to be GCC High. If CUI does need to travel through M365, then your tenant does, because the M365 email and collaboration infrastructure is what is now handling CUI at rest and in transit.
This is what purpose-built CUI tools like PreVeil actually solve. They are not primarily CUI storage tools, even though they can store files. They are compliant transmission channels for CUI: an alternate email path that does not touch your M365 tenant. Users get a PreVeil client alongside Outlook. Anything CUI goes through PreVeil. Everything else goes through Outlook. The tenant boundary holds because the transmission channel for CUI is elsewhere.
Decision tree: which tenant do you need?
Answer these questions in order. The first "yes" that applies to your contract determines your minimum tenant.
| Step | Question | If yes |
|---|---|---|
| 1 | Does your contract explicitly require GCC High or a US-person-only Microsoft 365 environment in the SOW, PWS, or a Contract Data Requirements List (CDRL)? | GCC High required. Contract language overrides regulatory floor. Some primes flow this down even when the underlying data would not require it. |
| 2 | Will CUI (any category) be transmitted through Microsoft 365? That means: emailed via Outlook/Exchange Online, shared via Teams or SharePoint with external parties, or otherwise routed through M365 collaboration infrastructure to or from someone outside your enclave. Include ITAR, EAR, CUI//SP-CTI, and any other CUI category. | Your M365 tenant is now handling CUI at rest and in transit. For non-export-controlled CUI, GCC is the minimum. For export-controlled CUI transmitted through M365, GCC High is required. Alternative: route CUI transmission through a separate compliant channel (see Step 3), and this row stops applying. |
| 3 | Will CUI transmission be routed only through a purpose-built secure email and file-sharing channel that lives outside your M365 tenant (PreVeil, Aerofiler/Aeroplicity, Kiteworks, DoD SAFE for one-offs, or an on-premises platform), with M365 documented to never send, receive, or store CUI? | M365 stays out of CUI scope entirely. Both storage and transmission of CUI happen elsewhere. M365 tenant choice reverts to Step 5 (Commercial is likely fine if no CUI is in M365 at all). |
| 4 | Will you store or process CUI in Microsoft 365 (in SharePoint, OneDrive, Teams files) but keep external transmission out of M365 by using a separate secure channel? | GCC minimum for the storage. If any of that stored CUI is export-controlled and M365 is the system of record for it, GCC High is required for the M365 tenant even if transmission happens elsewhere. |
| 5 | Do you have DoD contracts but no CUI actually flows to your organization? (You are a supplier of commercial off-the-shelf items, non-CUI services, or you only see FCI.) | Commercial is sufficient for M365. You are likely at CMMC Level 1 rather than Level 2 for the FCI portion, and DFARS 7012 does not attach. |
| 6 | Do you want to keep the M365 tenant out of your CMMC boundary entirely? | Enclave alternative. Stand up a CUI environment outside Microsoft 365 (purpose-built CUI tool, virtual desktop enclave, hardened workstations, or on-premises platform), leave the rest of the business on Commercial, and document the boundary. |
The step that matters most is Step 3, and it is the step the majority of articles skip. If your export-controlled data lives in a purpose-built CUI tool that carries its own US-person operations, the M365 tenant is not the one enforcing that requirement, so the tenant does not have to be GCC High. Many small ITAR contractors satisfy their obligations with Commercial or GCC plus a dedicated CUI tool, at a fraction of the cost and complexity of a full GCC High migration.
Microsoft 365 tenant comparison for CMMC
Every attribute below is the property of the tenant itself, not your configuration. Your configuration determines whether you pass a CMMC Level 2 assessment; the tenant determines whether you were allowed to store CUI there in the first place.
| Attribute | Commercial | GCC | GCC High | DoD |
|---|---|---|---|---|
| Can store CUI under DFARS 7012 | No | Yes | Yes | Yes (DoD orgs only) |
| FedRAMP authorization | None (commercial) | Moderate | High | DoD IL5 |
| DoD Impact Level | None | IL2 | IL4/IL5 | IL5 |
| ITAR / EAR eligible | No | No | Yes | Yes |
| US-person-only support access | No | No | Yes (screened US citizens) | Yes |
| Physically segregated infrastructure | No | Logically isolated on commercial | Physically separate | Physically separate, DoD-only |
| Available to commercial contractors | Yes | Yes (eligibility screening) | Yes (eligibility screening) | No (DoD organizations only) |
| Approximate E3 pricing (per user/mo) | ~$36 | ~$46 | ~$63 | N/A |
| Third-party integrations | Full ecosystem | Reduced (most enterprise ISVs) | Significantly reduced (federal-focused ISVs only) | Most restricted |
| Ideal for | Contractors with no CUI in scope | CMMC Level 2 without ITAR/EAR | CMMC Level 2 with ITAR, EAR, or CUI//SP-CTI | DoD organizations only |
Pricing is approximate and based on 2026 public list rates for M365 E3 equivalent SKUs; enterprise agreements, government incentives, and add-on services materially change effective cost. Verify current pricing with your Microsoft partner.
What actually forces GCC High
There are exactly two things that force GCC High. Neither is "you handle ITAR data." Both are more specific than that. Every other reason you have heard is either preference, hedge, or a partner selling you the upgrade.
1. Export-controlled technical data living inside your M365 tenant
ITAR (International Traffic in Arms Regulations, 22 CFR 120-130) governs defense articles and defense services on the US Munitions List. EAR (Export Administration Regulations, 15 CFR 730-774) governs dual-use items on the Commerce Control List. Both require that access to controlled technical data be limited to US persons (US citizens, permanent residents, and certain protected individuals). Non-US-person access to that data is a "deemed export" and requires an export license you almost certainly do not have.
Microsoft 365 Commercial and GCC use global support staff who may be non-US persons, so if export-controlled data sits in the tenant, the tenant itself has to enforce US-person-only access. GCC High is the Microsoft answer to that: physically segregated infrastructure staffed exclusively by screened US persons.
The critical qualifier is where the data lives. The US-person requirement follows the export-controlled data, not the organization. If you route that data through a purpose-built CUI tool that enforces its own US-person controls (PreVeil, Aerofiler/Aeroplicity, Kiteworks, or an on-premises CUI platform), and you document that M365 never touches it, then M365 is not in the ITAR/EAR scope. Your tenant choice reverts to whatever your other CUI in M365 requires (GCC for non-export-controlled CUI, Commercial for no CUI at all). See the workaround pattern below.
2. Explicit contract requirement
Some primes and program offices write GCC High into the SOW or a Contract Data Requirements List regardless of what the underlying data classification requires. This is common on programs where the prime standardized on GCC High and wants uniform sub-tier environments. It is contract language, not regulation, but it binds you the same way.
Read your contract before deciding. Search for "GCC High," "US persons only," "sovereign cloud," and any Data Rights or Export Control clauses. If those requirements appear in the contract, no amount of technical parsing gets you out of the GCC High requirement. Even the workaround pattern below does not override contract language.
When GCC (not GCC High) is enough
Microsoft 365 GCC is FedRAMP Moderate authorized. FedRAMP Moderate is the exact baseline DFARS 252.204-7012 calls out as the required standard for cloud services handling CUI. That is the entire regulatory hurdle for cloud storage of CUI under DFARS 7012. GCC clears it.
GCC is the right choice when all of the following are true:
- You handle CUI (so Commercial is not an option).
- None of your CUI carries ITAR or EAR export-control markings.
- No CUI//SP-CTI (Controlled Technical Information) is in scope, or the CTI you handle does not include export-controlled technical data.
- Your contract does not explicitly require GCC High or a US-person-only environment.
- You want to remain in the Microsoft 365 ecosystem rather than moving CUI to a separate enclave.
This describes a large share of small defense contractors: cleared shops doing manufacturing, IT services, professional services, sustainment work, or supplying non-export-controlled parts to primes. If that is you, GCC gives you a compliant answer for roughly a third less licensing cost than GCC High, without the migration complexity or the reduced third-party integration surface.
GCC eligibility is screened. You need a US-based organization supporting a US federal, state, or local government mission, or a contractor delivering to one. Applying takes a few weeks. Once approved, migration from Commercial to GCC is technically similar to any other Microsoft 365 tenant migration, without the export-control screening overhead of GCC High.
When Microsoft 365 Commercial is fine
Not every DoD contractor handles CUI. If your organization sees only Federal Contract Information (FCI), the broader class of contract-related information that is not marked CUI, you are at CMMC Level 1, not Level 2, and DFARS 7012 does not apply to your Microsoft 365 tenant.
Commercial is the right choice when:
- You have DoD contracts but the work does not generate or receive CUI (typical for suppliers of commercial off-the-shelf items, general services, or logistics).
- You are subject to CMMC Level 1 (15 basic safeguarding requirements from FAR 52.204-21), which does not carry the FedRAMP Moderate cloud requirement.
- You have documented and enforced a boundary that keeps CUI out of Microsoft 365 entirely. For example, CUI is handled only in a separate enclave, and email addresses tied to CUI programs are not on the M365 tenant.
The workaround pattern: keep CUI transmission out of M365
This is the pattern most articles do not explain. It is legitimate, widely deployed across the DIB, and can eliminate the need for a GCC High migration for a large share of contractors who think they need one.
The pattern in one sentence: route CUI transmission (specifically email and external file sharing) through a purpose-built secure channel that does not touch your M365 tenant, keep CUI storage and processing in your enclave, and document the boundary so M365 is provably outside CUI scope.
The reason this works is the reason spelled out in the section above: an enclave already handles CUI storage and processing without difficulty. What forces the M365 tenant question is transmission, specifically email. Take email out of M365 for CUI, and the M365 tenant is no longer handling CUI at all.
How it works
- Stand up a purpose-built secure email and file-sharing channel that carries its own FedRAMP-authorized deployment and, if you handle export-controlled data, its own US-person operations. Common options are named below.
- Route all CUI email through that channel. Inbound RFIs from the prime, outbound deliverables to the customer, engineer-to-engineer file exchanges. Nothing that is CUI goes through Outlook, Exchange Online, external Teams shares, or SharePoint external sharing.
- Store and process CUI wherever your enclave lives (on-premises platform, hardened workstation VLAN, virtual desktop enclave). That side does not need to be M365 at all.
- Configure and document the M365 boundary. DLP rules blocking CUI patterns from leaving the M365 tenant, mail-flow rules on senders known to transmit CUI, user training on which channel to use, and periodic evidence collection showing the separation held.
- Choose your M365 tenant based on whatever CUI (if any) is still in scope for M365. If none, Commercial is fine. If non-export-controlled CUI is stored in M365 SharePoint or OneDrive but transmission happens elsewhere, GCC is the minimum for that storage.
Purpose-built CUI transmission channels commonly used in this pattern
The tools below are best understood as compliant email and file-transfer channels that run in parallel to your M365 tenant. Users get the purpose-built tool alongside Outlook. Anything CUI goes through the purpose-built tool; everything else stays in M365. That is how the pattern keeps CUI transmission out of the M365 tenant.
| Tool | Transmission model | How it satisfies compliance |
|---|---|---|
| PreVeil | End-to-end encrypted email and file sharing that runs alongside Outlook. Users have a PreVeil client for CUI messages; Outlook handles everything else. CUI email never traverses Exchange Online. | FedRAMP High authorized government edition, US-person-only operations, and an encryption model that keeps Microsoft (or any other cloud provider) outside the trust boundary. Widely used specifically to avoid GCC High migrations. |
| Aerofiler / Aeroplicity | Compliance-focused document and email platform for defense contractors, providing a separate compliant channel for CUI transmission. | US-person operations and compliance-mode configurations that align with ITAR/EAR transmission requirements outside of M365. |
| Kiteworks | Enterprise secure file-transfer and email content platform with private-cloud and FedRAMP-authorized deployments. Handles the CUI transmission channel while M365 handles unrelated communications. | Isolated deployment model with US-person operations and tenant-level control that keeps CUI transmission out of the M365 environment. |
| DoD SAFE | DoD's own secure file transfer service, useful for one-off CUI file exchanges when a full-time channel is not needed. | Operated by DoD, no vendor tenant in the trust boundary at all. Not suitable as a primary channel (retention and workflow limitations), but a legitimate fallback and evidence that transmission does not have to touch M365. |
| Air-gapped on-premises platform | Compliance platform running on hardware inside your facility, handling both CUI storage and (via its own communications module or via SFTP/managed file transfer) CUI transmission. | CUI data and CUI transmission both stay on your network. No cloud vendor is in the trust boundary at all. This is 1TEN's model. |
Done right, this pattern is not a compromise. It is often the most sensible architecture for a small contractor whose export-controlled work is a well-defined slice of the business. The alternative, migrating the entire company to GCC High for the sake of a handful of ITAR-controlled workflows, is often the more expensive and less flexible answer. Discuss the pattern with your Registered Practitioner and export-control counsel before committing to either path.
Other alternatives to GCC High
Beyond the workaround pattern above, contractors evaluating GCC High should also consider these full-tenant alternatives.
CUI enclave outside Microsoft 365
Stand up a bounded environment (a virtual desktop enclave, a hardened physical workstation environment, or a small on-premises platform) that is the only place CUI ever renders. Keep the rest of the business on Commercial. Only the enclave is in CMMC scope. This works well when CUI touches a small slice of your business (a specific program, a specific team, a specific set of drawings) rather than being pervasive.
Full details are in the CMMC Enclave Strategy guide.
On-premises or air-gapped platforms
If your objection to GCC High is fundamentally about not wanting CUI in any cloud tenant (boundary complexity, sovereignty concerns, or a preference for physical control), an on-premises platform keeps CUI on hardware you own and operate. This is 1TEN's model. It removes the cloud vendor from your assessment boundary entirely, at the cost of running hardware in your own facility.
AWS GovCloud (US)
AWS GovCloud is the equivalent conversation on the AWS side: two regions (GovCloud West and East) with US-person-only operations, FedRAMP High authorization, and ITAR eligibility. For contractors already invested in AWS rather than Microsoft, GovCloud is the analogous choice to GCC High. The decision framework is the same. Export-controlled data or contract language forces GovCloud; otherwise standard AWS commercial regions with a properly bounded CUI workload may satisfy DFARS 7012.
Google Workspace Assured Controls
Google offers Workspace configurations aimed at CJIS and defense customers. Adoption in the DIB is materially smaller than either Microsoft or AWS, and third-party CMMC tooling around the Google stack is thinner. Viable but the smallest of the three ecosystems.
Why some contractors are moving away from GCC High
GCC High solves the export-control problem. It also introduces problems of its own that contractors do not always price into the migration decision. A minority (but a growing one) is now moving CUI out of GCC High into enclave or on-premises architectures, keeping the rest of the business on Commercial.
The common reasons:
- Third-party integration gaps. Many enterprise ISVs (project management, CAD collaboration, accounting, HR) either do not offer GCC High connectors or offer them at higher tiers with delayed feature parity. Users end up with two workflows: one in GCC High for CUI, one in Commercial for everything else.
- Feature-parity lag. New Microsoft 365 features typically ship in Commercial first, then GCC, then GCC High, sometimes with multi-quarter lag. Copilot rollout followed this pattern.
- Boundary sprawl. The whole GCC High tenant is in CMMC scope. If your CUI touches a small share of the business but the tenant hosts everyone, everyone is in scope. Enclave architectures shrink that.
- Cost. Licensing plus migration plus reduced ISV options plus operational overhead often runs $30,000 to $75,000 per year higher than commercial equivalents for a 25-user tenant. That is real money for a small contractor.
- Lock-in. Migrating out of GCC High is materially harder than migrating in. Contractors that jumped early sometimes want a smaller cloud footprint later and find the exit path more expensive than they expected.
None of this makes GCC High wrong. For ITAR contractors, it is the right answer. It does mean the "GCC High or nothing" framing that dominated 2020-2024 no longer fits every contractor.
Decision checklist
Before signing anything, work through this list. If your answers change during the exercise, you have discovered your real tenant requirement.
| Question | Where to find the answer |
|---|---|
| What CUI categories does my contract actually invoke? | Contract clauses, Program Protection Plan, CUI Registry (NARA) |
| Is any of my CUI ITAR-controlled or EAR-controlled? | Export control classification (ECCN), contract markings, empowered official review |
| Does the SOW or PWS mention GCC High or US-person-only? | Contract text; search for "US person," "sovereign," "GCC High," "export" |
| What percentage of my headcount actually touches CUI? | Data-flow inventory; if the answer is under 20%, evaluate enclave |
| What does my current tenant cost, and what would GCC or GCC High cost end-to-end? | Microsoft partner quote including migration services, not just licensing |
| What third-party tools would I lose or need to replace? | Software inventory checked against ISV availability in target tenant |
| How does the tenant choice affect my CMMC assessment boundary? | Discussion with your Registered Practitioner before signing anything |
If you cannot answer these confidently, the answer is not "migrate to GCC High now." The answer is "answer these first, then decide." A wrong tenant choice is expensive to reverse.
What the tenant choice does not solve
Choosing the right tenant is table stakes. It gets you to a compliant foundation. It does not, by itself, get you to CMMC Level 2 certification.
Regardless of which tenant you land on, you still have to implement all 110 NIST SP 800-171 controls in that environment, generate a substantive SSP that maps to your actual configuration, track a SPRS score, manage a POA&M for any deficiencies, run an internal assessment, and be prepared for a C3PAO third-party assessment. The tenant provides a compliant substrate. Your configuration and documentation do the rest.
See the CMMC Shared Responsibility Matrix guide for what Microsoft is actually responsible for in each tenant versus what stays on you.
Frequently asked questions
Not automatically. CMMC Level 2 itself does not require GCC High. GCC High is forced only when export-controlled data (ITAR, EAR, CUI//SP-CTI) will be stored, processed, or transmitted inside your Microsoft 365 tenant, or when your contract explicitly requires it. Contractors with export-controlled data can often avoid GCC High entirely by handling that data in a purpose-built CUI tool (PreVeil, Aerofiler/Aeroplicity, Kiteworks, or an on-premises platform) that enforces its own US-person controls, keeping M365 out of ITAR/EAR scope. Contractors handling non-export-controlled CUI can satisfy CMMC using Microsoft 365 GCC at lower cost.
No. DFARS 252.204-7012 requires that cloud services storing CUI meet FedRAMP Moderate baseline or equivalent. Microsoft 365 GCC meets FedRAMP Moderate. Microsoft 365 GCC High exceeds it (FedRAMP High plus DoD Impact Level 4). The DFARS clause itself is agnostic between the two. GCC High is required only when other overlays apply, most commonly ITAR export control.
Microsoft 365 GCC is FedRAMP Moderate authorized, uses commercial Microsoft infrastructure logically isolated for government customers, and can store CUI under DFARS 7012. Microsoft 365 GCC High is FedRAMP High and DoD IL4 authorized, runs on physically segregated infrastructure, and enforces US-person-only support access. GCC High is required when CUI includes ITAR or EAR technical data. GCC is sufficient for CUI that does not carry export control.
No. Microsoft 365 Commercial is not FedRAMP Moderate authorized and does not meet DFARS 252.204-7012 requirements for cloud services storing CUI. Storing CUI in a Commercial tenant is a compliance violation and, under the DOJ Civil Cyber-Fraud Initiative, a potential False Claims Act exposure. Commercial is fine for contractors who have DoD contracts but do not receive or generate CUI.
In most cases, no. If your CUI is not export-controlled (no ITAR/EAR markings, no CUI//SP-CTI category), Microsoft 365 GCC satisfies DFARS 7012 and supports CMMC Level 2 compliance without the additional cost and complexity of GCC High. Verify the specific CUI categories in your contract and Program Protection Plan with your contracting officer before finalizing tenant selection.
Not compliantly. Emailing CUI through Microsoft 365 Commercial violates DFARS 252.204-7012 because Commercial is not FedRAMP Moderate authorized. Emailing CUI through GCC is technically permitted for non-export-controlled CUI, since GCC meets FedRAMP Moderate. Emailing export-controlled CUI (ITAR, EAR, CUI//SP-CTI) requires GCC High or an equivalent US-person-controlled channel. The most common workaround for contractors on Commercial or GCC is to route CUI email through a purpose-built secure email channel (PreVeil, Aerofiler/Aeroplicity, Kiteworks) that lives outside the M365 tenant. Users get the purpose-built client alongside Outlook; anything CUI goes through the purpose-built channel; everything else stays in M365.
Yes, in many cases. The US-person-only access requirement under ITAR and EAR follows the export-controlled data, not the organization or the M365 tenant. If you route that data through a purpose-built CUI collaboration tool that enforces its own US-person controls (PreVeil, Aerofiler/Aeroplicity, Kiteworks, or an on-premises platform), and you document that Microsoft 365 never touches the export-controlled data, then M365 is not in the ITAR/EAR scope. Your M365 tenant choice reverts to whatever your other CUI requires: GCC for non-export-controlled CUI, Commercial if no CUI is in M365 at all. This pattern is widely deployed and can eliminate a GCC High migration for a large share of contractors who think they need one. Exception: if your contract explicitly requires GCC High, contract language overrides this pattern.
The CMMC Level 2 assessment itself does not require GCC High. The assessment evaluates your implementation of all 110 NIST SP 800-171 requirements. What the tenant choice affects is whether your Microsoft 365 environment can host CUI at all under DFARS 7012, and whether it can host export-controlled data under ITAR or EAR. Choose the tenant based on those regulatory obligations, then assess against CMMC Level 2 in either environment.
Approximate per-user monthly pricing as of 2026, before enterprise agreements: Microsoft 365 E3 Commercial runs around $36; equivalent GCC around $46; equivalent GCC High around $63. E5 tiers add roughly $20-30 per user per month on top. Beyond licensing, GCC High carries migration cost (weeks to months of professional services), reduced third-party integration availability, and higher operational overhead. Total cost of ownership for a 25-user tenant typically runs $30,000 to $75,000 per year higher than commercial equivalents.
Four main alternatives. First, Microsoft 365 GCC when CUI is not export-controlled. It meets DFARS 7012 at lower cost and complexity than GCC High. Second, the workaround pattern: keep export-controlled data out of Microsoft 365 entirely by using a purpose-built CUI tool (PreVeil, Aerofiler/Aeroplicity, Kiteworks) that carries its own US-person operations, then M365 stays on Commercial or GCC based on whatever other CUI is in scope. Third, a full CUI enclave outside M365 using a hardened virtual desktop or physical workstation environment for the slice of the business that handles CUI. Fourth, on-premises or air-gapped platforms that keep CUI out of any cloud tenant. The right choice depends on how much of your business actually touches CUI, whether that CUI is export-controlled, and your appetite for cloud-boundary complexity.