Government Contractors
Microsoft 365 for GovCon. CMMC-Ready Configuration.
CMMC 2.0 Level 2 requires compliance with 110 NIST 800-171 practices — a substantial number of which map directly to Microsoft 365 configuration. We know which controls apply to M365, how to implement them, and how to produce the evidence documentation your C3PAO assessor needs to see.
The Regulatory Reality
The Compliance Requirements That Apply to Your M365 Environment
CMMC 2.0 Level 2 aligns to NIST SP 800-171 Rev 2 (110 practices across 14 domains). Defense contractors handling CUI must achieve Level 2 certification by their DIBCAC or C3PAO.
- 14 practice domains — Access Control, Identification & Authentication, System & Comms Protection, and more
- M365 is in scope for the majority of applicable practices in a modern GovCon environment
- Third Party Assessment Organization (C3PAO) assessment required for most Level 2 contractors
- Plan of Action & Milestones (POA&M) required for any practices not yet implemented
The foundational control set behind CMMC 2.0 Level 2. 110 security requirements across 14 families — implemented through M365 configuration, policy documentation, and operational procedures.
- Access Control (AC): 22 requirements — Entra ID, Conditional Access, PIM
- Identification & Authentication (IA): 11 requirements — MFA, password policies, identifier management
- Audit and Accountability (AU): 9 requirements — audit log configuration, retention, review
- System and Communications Protection (SC): 16 requirements — encryption, network controls
DFARS 7012 requires adequate security for covered defense information (CDI) and CUI, and mandates use of cloud services that meet FedRAMP Moderate or equivalent — which affects your choice of M365 cloud environment.
- Microsoft 365 GCC meets DFARS 7012 adequacy requirements for most CUI scenarios
- GCC High is required for specific CUI categories (ITAR, certain FOUO) and controlled environments
- Microsoft's M365 Government cloud products have FedRAMP High authorization
- Breach reporting obligations to DoD Cyber Crime Center (DC3) within 72 hours
What We Configure
Industry-Specific Microsoft 365 Configuration
Every Microsoft 365 product we configure maps to the specific compliance controls your industry requires.
Cloud Environment Selection and Migration
The GCC vs. GCC High decision has significant cost and capability implications. We assess your CUI categories, contract requirements, and ITAR obligations to recommend the correct environment — and migrate your existing commercial M365 tenant if you're moving up-tier.
CUI Boundary Access Controls
Conditional Access policies restricting CUI access to compliant, Entra ID-joined devices. Named location policies preventing CUI access from unapproved networks. Phishing-resistant MFA (FIDO2 or CBA) for users handling CUI — a CMMC Level 2 requirement.
External Access Controls for CUI
Teams external access and guest policies configured to prevent accidental CUI exposure to external parties. Teams channel governance for CUI-containing projects, with membership controls and external sharing restrictions aligned to your CUI handling requirements.
CUI Information Architecture
CUI boundary enforcement in SharePoint — dedicated site collections for CUI with restricted permission models, sensitivity labels, DLP policies detecting CUI indicators, and external sharing locked down to prevent unauthorized CUI disclosure.
CUI Detection and Sensitivity Labeling
Sensitivity labels configured for CUI categories (CUI Basic, CUI Specified) with automatic labeling policies detecting CUI indicators in email, documents, and Teams messages. DLP policies enforcing CUI handling controls at the data layer.
Powered by TenantForge
TenantForge maps your M365 configuration to CMMC 2.0 Level 2 practices and NIST 800-171 controls — showing compliance status for each applicable practice, evidence of configuration, and gaps requiring remediation. We use it to run the initial assessment and to generate the System Security Plan (SSP) entries for M365-applicable controls.
FAQ