CMMC 2.0NIST 800-171DFARS 7012ITAR

Government Contractors

Microsoft 365 for GovCon. CMMC-Ready Configuration.

CMMC 2.0 Level 2 requires compliance with 110 NIST 800-171 practices — a substantial number of which map directly to Microsoft 365 configuration. We know which controls apply to M365, how to implement them, and how to produce the evidence documentation your C3PAO assessor needs to see.

The Regulatory Reality

The Compliance Requirements That Apply to Your M365 Environment

CMMC 2.0 Level 2

CMMC 2.0 Level 2 aligns to NIST SP 800-171 Rev 2 (110 practices across 14 domains). Defense contractors handling CUI must achieve Level 2 certification by their DIBCAC or C3PAO.

  • 14 practice domains — Access Control, Identification & Authentication, System & Comms Protection, and more
  • M365 is in scope for the majority of applicable practices in a modern GovCon environment
  • Third Party Assessment Organization (C3PAO) assessment required for most Level 2 contractors
  • Plan of Action & Milestones (POA&M) required for any practices not yet implemented
NIST SP 800-171 Rev 2

The foundational control set behind CMMC 2.0 Level 2. 110 security requirements across 14 families — implemented through M365 configuration, policy documentation, and operational procedures.

  • Access Control (AC): 22 requirements — Entra ID, Conditional Access, PIM
  • Identification & Authentication (IA): 11 requirements — MFA, password policies, identifier management
  • Audit and Accountability (AU): 9 requirements — audit log configuration, retention, review
  • System and Communications Protection (SC): 16 requirements — encryption, network controls
DFARS 252.204-7012

DFARS 7012 requires adequate security for covered defense information (CDI) and CUI, and mandates use of cloud services that meet FedRAMP Moderate or equivalent — which affects your choice of M365 cloud environment.

  • Microsoft 365 GCC meets DFARS 7012 adequacy requirements for most CUI scenarios
  • GCC High is required for specific CUI categories (ITAR, certain FOUO) and controlled environments
  • Microsoft's M365 Government cloud products have FedRAMP High authorization
  • Breach reporting obligations to DoD Cyber Crime Center (DC3) within 72 hours

What We Configure

Industry-Specific Microsoft 365 Configuration

Every Microsoft 365 product we configure maps to the specific compliance controls your industry requires.

Microsoft 365 GCC / GCC High

Cloud Environment Selection and Migration

The GCC vs. GCC High decision has significant cost and capability implications. We assess your CUI categories, contract requirements, and ITAR obligations to recommend the correct environment — and migrate your existing commercial M365 tenant if you're moving up-tier.

Microsoft Entra ID

CUI Boundary Access Controls

Conditional Access policies restricting CUI access to compliant, Entra ID-joined devices. Named location policies preventing CUI access from unapproved networks. Phishing-resistant MFA (FIDO2 or CBA) for users handling CUI — a CMMC Level 2 requirement.

Microsoft Teams

External Access Controls for CUI

Teams external access and guest policies configured to prevent accidental CUI exposure to external parties. Teams channel governance for CUI-containing projects, with membership controls and external sharing restrictions aligned to your CUI handling requirements.

SharePoint Online

CUI Information Architecture

CUI boundary enforcement in SharePoint — dedicated site collections for CUI with restricted permission models, sensitivity labels, DLP policies detecting CUI indicators, and external sharing locked down to prevent unauthorized CUI disclosure.

Microsoft Purview

CUI Detection and Sensitivity Labeling

Sensitivity labels configured for CUI categories (CUI Basic, CUI Specified) with automatic labeling policies detecting CUI indicators in email, documents, and Teams messages. DLP policies enforcing CUI handling controls at the data layer.

Powered by TenantForge

TenantForge maps your M365 configuration to CMMC 2.0 Level 2 practices and NIST 800-171 controls — showing compliance status for each applicable practice, evidence of configuration, and gaps requiring remediation. We use it to run the initial assessment and to generate the System Security Plan (SSP) entries for M365-applicable controls.

FAQ

Common Questions

What is the difference between GCC and GCC High for a government contractor?
Microsoft 365 GCC is a FedRAMP Moderate-authorized environment appropriate for most CUI scenarios. GCC High is a FedRAMP High-authorized environment required for ITAR-controlled data, certain Export Administration Regulation (EAR) scenarios, and organizations with specific DoD contract requirements specifying GCC High. GCC High has a higher cost and a smaller feature parity gap with commercial M365. We assess your contract requirements and CUI categories to determine which environment is appropriate for your organization.
How many NIST 800-171 controls map to Microsoft 365 configuration?
Approximately 60–70 of the 110 NIST 800-171 practices have a direct M365 configuration component — depending on how you scope the assessment. The remaining practices involve physical security, personnel management, incident response procedures, and other non-M365 controls. We focus on the M365 scope specifically and map each applicable practice to the precise configuration required.
Can you help us write the System Security Plan (SSP) for our M365 environment?
Yes. We write SSP entries for every NIST 800-171 practice that M365 addresses — documenting what control is in place, what the specific M365 configuration is, and how it satisfies the practice requirement. The SSP documentation we produce is designed for C3PAO assessor review and follows the format expected in CMMC assessment contexts.
We're currently on commercial Microsoft 365. Do we need to migrate to GCC?
It depends on your contract requirements and CUI categories. DFARS 7012 requires adequate security, and for many contractors, GCC is the minimum that satisfies adequacy. If you're handling information that is specifically subject to ITAR or certain FOUO markings, GCC High may be required. We assess your specific situation before recommending a migration path — GCC migration is a significant project that we plan and execute carefully.
How long does CMMC 2.0 Level 2 preparation take for the M365 environment?
A full CMMC 2.0 Level 2 preparation engagement for an M365 environment typically runs 8–16 weeks, depending on the starting compliance posture, environment complexity (number of users, sites, applications), and your team's responsiveness for testing and approval. We start with a structured gap assessment, produce a prioritized remediation plan, and execute in documented phases with progress tracking against each practice.

Get Your CMMC 2.0 M365 Readiness Assessment.

Start with a free M365 assessment. We'll identify every gap that matters for your industry and build a remediation roadmap your team can act on.

No commitment required · 5-day turnaround