The Backup Nobody Checked Against the Boundary 

Every organization we migrate into GCC High already has backups running before we touch the tenant. Almost none of them have confirmed where those backups land. 

That gap isn’t hypothetical. DFARS 252.204-7012 requires covered contractor information systems to implement NIST SP 800-171. Control 3.8.9 states it plainly: protect the confidentiality of backup CUI at storage locations. 

What Control 3.8.9 Requires 

The requirement is narrower than most people assume. It doesn’t say an organization must have a backup. It says that wherever CUI ends up once it’s backed up, that copy’s confidentiality has to be protected the same way the original is, typically through encryption and access control at the storage location itself. 

That distinction matters, because most organizations already pass the easy version of this question. Yes, we have backups. The harder question is where those backups live, and whether anyone has ever checked. 

Where the Backup Actually Lands 

A backup vendor selected for uptime and price, often years before GCC High was even under discussion, doesn’t automatically inherit the boundary a CUI environment now sits inside. 

Microsoft’s own documentation shows the parity gap directly. Azure Backup’s support matrix limits Resource Health monitoring for backup vaults to “all Azure public regions, except Sovereign clouds,” and scopes Zone-Redundant Storage to a named list of regions that includes US Gov Virginia for some workloads and not others. Azure Site Recovery’s overview documentation doesn’t address Azure Government or GCC High support at all. It has to be confirmed separately, service by service. 

None of that means these tools can’t be used inside a compliance boundary. It means the fact that a backup exists, and the fact that it’s a backup built for GCC High, are two different facts. Only one of them satisfies 3.8.9. 

What “Protected” Really Means Once It’s Backed Up 

Confidentiality isn’t a single checkbox. Azure Backup encrypts data at rest by default using platform-managed keys, Microsoft’s own keys, held and rotated on Microsoft’s schedule, not the organization’s. 

An organization can move to customer-managed keys instead, stored in Azure Key Vault or a managed HSM, with its own rotation schedule and its own access control on who can unwrap them. That’s a real control gain. It’s also a one-way door: once customer-managed keys are turned on for a vault, there’s no reverting to the platform-managed default. 

NIST SP 800-171 control 3.13.11 adds a second requirement most teams don’t connect to backups at all: when cryptography protects the confidentiality of CUI, that cryptography has to be FIPS-validated. Microsoft’s own documentation on customer-managed keys for backup vaults doesn’t state a FIPS validation status either way. That’s a detail to confirm against Microsoft’s own FIPS compliance documentation, not assume from the encryption feature description alone. 

The Assumption That Costs the Most 

The organizations we see get this wrong aren’t the ones without backups. They’re the ones whose backup vendor was never re-evaluated after the environment around it became a CUI boundary. 

A Recovery Services vault’s sovereign-cloud footnote will never win an award for compelling reading, but it’s exactly the kind of detail an assessment doesn’t forgive skipping. 

Confirming where a backup lands, and whether that location was ever evaluated against a CUI boundary, is a short conversation. It’s far shorter than the one that happens after an assessor asks the same question and the answer is silence. 

Where Do Your Backups Live, and Has Anyone Checked? 

Commercial vs. GCC vs. GCC High: Which Microsoft Cloud Do You Need? 

Y’all. If I had a dollar every time someone asked me “can’t we just use GCC?” I could retire, buy a boat, and name it Sub-Paragraphs (c) through (g).  (I would not do this, my dad says it’s better to have friends with boats than to own a boat yourself.) 

This question comes up constantly, and it makes sense. Microsoft has a LOT of clouds. The names sound similar, the licensing is confusing, and every MSP in the DIB seems to have a different opinion. The good news is that Richard Wakeman at Microsoft keeps a long, very thorough post called Understanding Compliance Between Commercial, Government, DoD & Secret Offerings. He’s kept it updated for years, and it’s basically the source of truth on this. If you haven’t read it, go bookmark it now. I’ll wait. 

…OK, it’s long. I GOTCHU. Here’s the Maggie version, and we’re skipping the DoD and Secret clouds, because if you need those, you already know. 

The Three Clouds 

Commercial is regular Microsoft 365. It’s global, it gets new features first, and support comes from wherever in the world someone is awake. It’s great for most businesses. It was not built for US government requirements, and it probably doesn’t work for you if you’re reading this. 

GCC (Government Community Cloud) keeps your data stored in the US (data residency) and has screened US persons handling customer content. But it still shares a lot of plumbing with Commercial, including directory and authentication services that can process data outside the US.  It’s built on top of Azure Commercial, which is worldwide. 

GCC High is the sovereign cloud. It’s a separate environment, operated by screened US persons in US locations, and it’s the one where Microsoft commits to keeping data processing in the US and in US hands. That’s data sovereignty, and it’s a whole different thing from residency.  GCC High leverages Azure Government.  This is important. 

Residency vs. Sovereignty (aka the part everyone skims and shouldn’t) 

This is the crux of the whole thing, so I’m giving it its own section. 

  • Data residency = where your data lives 
  • Data sovereignty = who can touch it, where it’s processed, and under whose rules 

GCC gives you residency. GCC High gives you sovereignty. When you’re dealing with export-controlled information (ITAR/EAR) or the more sensitive categories of CUI, residency alone doesn’t cut it. As Richard puts it, CUI effectively requires data sovereignty. (Mic drop, Richard.) 

So what do the regulations say? 

Let’s go through the ones we care about. 

DFARS 252.204-7012: If you handle Covered Defense Information, your cloud provider has to meet FedRAMP Moderate (or equivalent) and flow down the incident reporting, forensics, and media preservation requirements, which is sub-paragraphs (c)–(g). Microsoft does not support DFARS 7012 for Commercial M365 productivity services. GCC and GCC High both do. 

ITAR/EAR: Commercial, no. GCC, no. GCC High, yes. That’s the whole list. GCC High was literally created to give contractors a US commitment for export controls. If you have ITAR data and you’re in GCC, I love you, but we need to talk. 

CUI: Here it gets murky. GCC may be fine for some CUI Basic. But CUI Specified categories like Controlled Technical Information, export-controlled data, and defense-related CUI are where GCC stops being a safe bet. GCC High covers all of it. 

CMMC: For Level 1 (FCI only), any of the three works. For Level 2 and up, where CUI comes in, Microsoft recommends GCC High. GCC is a “caveated yes,” and Commercial isn’t recommended. 

Now, the caveat to the caveat: GCC High isn’t the only road to Level 2. Solutions like PreVeil add an encrypted layer for your CUI (email and files) that sits alongside your existing Microsoft 365, which means you can meet CMMC Level 2 while staying in GCC. For some orgs, especially smaller ones where only a handful of people touch CUI, that can be a smart, cost-effective move. It’s a different architecture with its own tradeoffs, so scope it carefully, but it’s a legit option. 

“But GCC High is expensive and annoying” 

Yes. I’m not going to pretend otherwise. It costs more, some features show up later than in Commercial (because government clouds have to pass compliance gates first), and a few third-party integrations take extra work. 

But here’s the thing: moving between clouds is painful. GCC High is a separate environment, so migrating into it later means real time, real money, and real disruption. If you’re in the DIB and CUI is anywhere in your future, whether that’s a new contract, a new prime, or a new flow-down clause, picking the right cloud now is way cheaper than fixing it in the middle of a CMMC assessment (lol you will not be able to fix it mid-assessment, your assessment is getting paused until you completely redo your CMMC scope). 

And be honest with yourself about what data you have. A lot of companies say “oh, we don’t really have CUI” and then… they do. It’s in an email thread from 2019. It’s in a SharePoint folder named “Misc.” We’ve seen it. Many times. 

The Maggie Cheat Sheet 

If you… You probably need… 
Only handle FCI (CMMC Level 1) Commercial or GCC can work 
Are a federal civilian contractor with CUI Basic GCC 
Have ITAR or EAR data GCC High. Full stop. 
Are a DIB contractor pursuing CMMC Level 2 GCC High (Microsoft’s recommendation), or GCC plus a solution like PreVeil 
Are “not sure” what data you have A scoping conversation before any migration 

Why this matters 

CMMC is here, and “we’ll figure it out later” is no longer a strategy. The cloud you choose becomes the foundation for your whole compliance program. It affects your SSP, your shared responsibility matrix, your assessment scope, and how much of your life you’ll lose explaining your architecture to an assessor. A bad foundation doesn’t get better by adding more policies on top of it. 

Microsoft has been very clear about where it stands. Richard’s post lays it out better than anyone, and I’d encourage every IT lead and compliance owner in the DIB to read the full thing, especially the sections on export controls and CUI. 

And if you read it and your brain feels like soup, that’s normal, and it’s exactly what we do all day at Agile IT. We’ve been moving defense contractors into GCC High for years, and we’re happy to help you figure out which cloud fits your data, your contracts, and your budget. 

LFG. 

Is CMMC Dead?

Is Russia in charge now? What on earth does the DoW mean by “CMMC Phase II is paused”?

July 13, 2026 – a day that will live in infamy

Jk, it won’t really. This is a blip in a program roll out that has had many blips over the years. Some of the blips are really beneficial (removing the delta 20 out of CMMC 1.0, for example). Some are not. None of them will stop what will eventually be the CMMC program in its full (codified, legal) glory.

Jolene

It is important that you all know that yesterday was also Jolene’s birthday.

Holy hell you guys, it’s been a wild 24 hours. The most important thing that happened yesterday, obvs, is that Baby Jolene turned THREE and I am still in shock that she’s not a baby baby anymore. The second most important thing is that DoW issued a press release announcing the immediate suspension of the CMMC Phase II requirements. This is legit insane behavior, but sure, do you, guys.

The link to the press release: Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements > U.S. Department of War > Release | U.S. Department of War

The press release basically says “we can’t let a little thing like paperwork slow us down, we need to do WAR”. It goes on to say that this is being done for small and mid-sized businesses to ensure they can still participate in the space – the SBA had put out a report that compliance with CMMC is forcing innovative companies out of the DIB. This might be true? It’s probably true. Please remember that contractors have been saying they’ve been compliant FOR ALMOST TEN FREAKING YEARS. The thing CMMC is doing is bringing in third-party auditing. The cost of the audit isn’t prohibitive, it’s getting compliant WITH THE THING THEY’VE BEEN LYING ABOUT that’s prohibitive.

Anyway. Yes, we need to be able to move quickly as we respond to threats around the world. Yes, we need to ensure innovators and precision manufacturers and the entire dang supply chain can provide the services and machines the Department needs. And to be fair, it really did seem like SOMETHING was going to break in November 2026 when Phase II rolled out – there are approximately 100 C3PAOs as of this writing, and 200,000 DIB contractors that need to be assessed. That’s a lot of math that doesn’t quite work. That being said… is it the assessment that’s hard? Or is it getting into compliance that’s the ACTUAL brunt of the work? Maybe we have enough assessment orgs but DON’T have enough qualified consultants to help Dibbies get where they need to be.

I’m off track here. Ok, back to what happened yesterday. Press release came out. It’s a short read, go read it. It ends with a link to a new section of the DoW CIO website called Brilliant Basics. We’ll get into that hot mess later.

We also got two memos (cute). One from Kirsten Davies (DoW CIO) and one from Michael Duffey (USD for A&S).

Kirsten Davies said we need to be prepared for war and the current CMMC program doesn’t allow for the rapid scaling of our warfighting capabilities. She is also establishing a CMMC Reform Task Force that will have 60 days to review the program and provide recommendations for a better framework. (lol sure Jan). Listen, the program has ISSUES. But it’s still a whole lot better than what we had before. CMMC-ReformMemo.pdf

Ms. Davies also made a short speech worth listening to, which is posted to the DoW CIO website: CIO – Cybersecurity Maturity Model Certification She’s really on that “this is for the warfighter and the small businesses” line that they’ve got going. Also ended with “peace through technical strength”, so that’s a line we have now.

Michael Duffey basically said the same thing, aligning to Hegseth’s 5 pillars of the Acquisition Transformation Strategy. He also included an attachment that has guidance for Program Managers re: assessments and solicitations. He did explicitly state that the cybersecurity reporting requirements in DFARS 252.204-7012 are still v much alive and well. (good, the DFARS clauses that we think about are a GOOD THING FOR NATIONAL SECURITY) ImplementingSuspensionCMMC-PhaseII.pdf

ALSO yesterday, CMMC disappeared completely for a few hours from the DoW CIO website. It’s back, and it is less: CIO – About CMMC They’ve taken out every mention of what Level 2 (C3PAO) or Level 3 (DIBCAC) assessments might look like. There is an update to the FAQs, but mostly in the “we’re paused in Phase 1” kind of way. These FAQs are important to know, though, so suggest familiarizing yourself: CYBERSECURITY MATURITY MODEL CERTIFICATION Program (CMMC) FREQUENTLY ASKED QUESTIONS

LASTLY (maybe, I’ll probably add to this bc who knows what else will happen): DoW CIO added a new “Brilliant Basics” section to their website. It is… basic. Someone said “what if we took all the meat out of NIST 800-171 and added graphics?” and then put it on an actual Dept website. A fun thing here is that backups are in scope for this Basics thing? Backups are not required in NIST 800-171 (fwiw, back shit up. It’s not that hard and it is wildly important). Brilliant at the Basics

Editorialized

I know I’ve been restrained in my thoughts and feelings, so if you don’t want to hear how I feel, you can stop reading now – you’ve got the gist of what went down yesterday.

THE DFARS IS CORRECT, WE NEED REGULATION ON THE DEFENSE SUPPLY CHAIN. It’s not a coincidence that China produced the J-35 fighter jet after we built the F-35. We KNOW that non-kinetic warfare and industrial espionage are on the rise. The entire war landscape is rapidly changing as our defense contractors build autonomous drones and vessels, AI-powered missiles, and quantum cryptography. If we can’t stay ahead of our enemies, or if we LET OUR DAMN TECHNOLOGY FALL INTO THEIR HANDS, where is our advantage? How are we protecting our troops at home and abroad?

We already saw what happened when self-assessment and self-attestation were the standard. DIB contractors blatantly disregarded the entire framework that was designed specifically to keep the information that they are handling safe. And they LIED ABOUT IT. There are lives at stake when we don’t adequately protect our information. Our technical prowess means nothing if we let it fall into a rival power’s hands. And we KNOW that without third-party accountability, the cybersecurity measures that we have determined are vital DO NOT TAKE PLACE.

We need to keep America, and Americans, safe. That includes safeguarding information across the defense industrial base.

CMMC is taking a beat, as is 100% normal when a new CIO comes in. It is not over, not by a long shot. And all the contractors breathing a sigh of relief about spending time & money on compliance are flat out WRONG and the DoJ is looking forward to having a word with them.

The requirements haven’t changed. They honestly haven’t really changed since Dec 31, 2017. It is BEYOND time for defense contractors to GET THEIR SHIT TOGETHER.

And you guys, Agile IT legit knows how to help. We know this stuff. So LFG.

CMMC Quick(ish) Reference Guide 

Y’all, I have spent TIME wrapping my head around CMMC and let me tell ya – it is a LOT. I’m not an expert by any means (if that’s what you’re looking for, go talk to my man Mike Shughrue), but I’ve been able to learn a bit and thought it might be helpful to have some consolidated info. Are you new to Agile IT? Are you new to CMMC? Are you just trying to remember how to find the results of the DoD’s audit of ISOO? I GOTCHU. Sit down, buckle up, and get ready to get PUMPED on CMMC. 

Let’s start with what it is, right? 

That seems like a good place to start. CMMC is the Cybersecurity Maturity Model Certification. Katie Arrington calls it The CMMC. The rest of us just call it CMMC. CMMC has a pretty bitchin mission statement: 

  1. Safeguard sensitive information to enable and protect the warfighter 
  1. Enforce DIB cybersecurity standards to meet evolving threats 
  1. Ensure accountability while minimizing barriers to compliance with DoD requirements 
  1. Perpetuate a collaborative culture of cybersecurity and cyber resilience 
  1. Maintain public trust through high professional and ethical standards 

(Heads up we love an acronym around here. I’ll stick a reference down at the bottom. For now, know that DIB = Defense Industrial Base) 

Now we do timeline! This baby has been 15 years in the making. 

2010, November:  Once upon a time, President Obama was like “I’m sick of all these different markings for our information. FOUO? How about GTFO? We’re standardizing and calling all controlled unclassified information exactly that. We can shorten it to CUI. People will love this.” Executive Order 13556 — Controlled Unclassified Information | whitehouse.gov 

2015, June:  NIST says something like “ok we’ve had the CUI marker for a while now. But how do we protect it? Where are the standards?” It was a good question, and luckily, NIST is the institute that can help with stuff like that. They release NIST SP 800-171: “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations”. Note that this is specific to Industry, since our Fed homies are already aligned to NIST 800-53. NIST SP 800-171 is a derivative of that publication, comprised of 110 security requirements. We’ll get into version history, assessment objectives, and class deviations a bit later. SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations | CSRC 

2016, October:  The DoD takes things into their own hands. No one is enforcing the protection of CUI, and national security is at stake. We MUST ask the defense supply chain to shore up cybersecurity. DFARS clause 252.204-7012 goes into the FAR. This clause starts hitting contracts the DoD is sending out, and says “We’re giving you CUI. You’re creating CUI. You had better be protecting that CUI by implementing the 110 security requirements in NIST SP 800-171. You have until December 31st, 2017 to be 100% in compliance. P.S. if you have a cyber incident, you have to tell us within 72 hours AND you have to flow down this requirement to any of your subcontractors that are going to be storing, processing, or transmitting CUI”. 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting. | Acquisition.GOV 

2017 – 2019:  DIB contractors did not do the thing that they very explicitly said they were doing. 

2019, July:  The DoD’s Office of Inspector General releases a report after an audit of DIB adherence to NIST 800-171. Their findings? It ain’t happening. Turns out self-attestation isn’t a great way to get organizations into compliance. The results are pretty damning, and pretty frustrating for folks that care about safeguarding our national interests. Audit of Protection of DoD Controlled Unclassified Information on Contractor-Owned Networks and Systems DODIG-2019-105 > Department of Defense > DoD OIG Reports 

2020, January:  CMMC 1.0 is released. It’s not being enforced, but the model now exists and this is cool. Again, only going to be applicable to DIB, but it is a START at keeping our stuff safe from foreign adversaries. There are five levels, it’s not super well defined, it’s definitely too complex, but again – it’s a start. This is v cool. Things are supposed to go rapidly and we think we’re going to see CMMC requirements in contracts by like, the end of 2020. 

2020, March:  you remember. This kind of derails… gestures broadly at everything 

2020, June:  Pilot program begins. Gradual implementation, DoD is ready and willing to work with Industry to make this happen. 

2021, March:  Industry feedback comes in. “This is expensive. This is complex. This is time consuming.” DoD graciously takes this into consideration (and I do legit mean graciously, since contractors are currently complaining about something that they have said they were doing for three entire years now). 

2021, November:  CMMC 2.0 is here! Kinda. Like the program gets unveiled (now with three levels and much more clarity) but it’s still not in the federal register. DoD and Industry collab on program implementation, develop a phased roll out, all the good stuff that’s needed to turn this into a working model for us all. 

2024, December:  OK NOW IT’S REALLY ACTUALLY HERE. Kinda. CFR Title 32 part 170 goes into effect, firmly establishing the CMMC program. It’s official, it’s real, it’s in the federal register. This is VERY exciting. Much hubbub ensues. There is now a real, defined framework and program for ensuring Industry compliance with NIST 800-171. BUT WAIT. There are two rules in play, and 32 is only one of them. It establishes the program, it does not incorporate CMMC into contracts. Federal Register :: Cybersecurity Maturity Model Certification (CMMC) Program 

2025, November:  OK THIS TIME I MEAN IT, IT IS HERE LFG. CFR Title 48 parts 204, 212, 217, and 252 enter the federal register on the Marine Corps’ 250th birthday. This is it, this is the Final Rule that means CMMC is beginning its phased roll out and there ain’t no turnin back now. This rule amends the DFARS to incorporate contractual requirements for DoD contractors. So what Industry sees in their contracts is DFARS clause 252.204-7021. What makes that possible is the publication of Title 48 in the federal register. 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements. | Acquisition.GOV and Federal Register :: Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041) 

July 13, 2026:  lol jk, self-assessment is fine again. Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements > U.S. Department of War > Release | U.S. Department of War 

Reference Docs 

I spend a lot of time going back to what other folks have written. I’ve got these all bookmarked, but to save you the trouble, I thought I’d go ahead and make ya a little URL library for what I’ve got saved and why. 

Part One: Source Documentation 

This is stuff that’s been put out by Fed or the CyberAB (performing a no-cost contract with the DoD to oversee the CMMC program). When it comes down to “truth”, this is where we go. Everything else comes from experience, opinion, and speculation. FWIW, the only CyberAB doc is the CAP. Everything else (including scoping and assessment guides) comes straight from DoD. 

Rules, regulations, and publications 

  1. 32 CFR (part 170, the part about CMMC): eCFR :: 32 CFR Part 170 — Cybersecurity Maturity Model Certification (CMMC) Program 
  1. Why this matters: It’s literally THE rule. 
  1. Like 48 matters too (bc that’s where it says “you gotta put this in contracts”), but 32 gives the nitty gritty on how the program is meant to work, who the players are in the program, and what it takes to pass assessment. We also refer to “32 CFR” a lot, but the thing we actually care about is “32 CFR part 170”. We don’t need to refer to part 170 every time we discuss, but it’s important that we keep it in the back of our heads. 
  1. 32 CFR (part 2002, the part about CUI): eCFR :: 32 CFR Part 2002 — Controlled Unclassified Information (CUI) 
  1. You want the definitions for CUI, CUI Specified, and CUI Basic? This is where you go. This is the actual establishment of the Executive CUI program. 
  1. 48 CFR: Federal Register :: Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041) 
  1. Why this matters: This baby puts the whole dang thing into effect. Contractors don’t care about 48 CFR, they care about the fact that 48 CFR put DFARS 7021 into place. 
  1. DFARS 7012: 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting. | Acquisition.GOV 
  1. Why this matters: Contractors already see this in their contracts with DoD and Primes. You know the False Claims Act? It comes up when Industry does NOT meet the security requirements in NIST 800-171. Again, Industry has been told to be compliant with NIST 800-171 since DECEMBER 31st of FREAKING 2017. Yeah, if you get slapped with a False Claims Act, it sucks, but it shouldn’t be unexpected. 
  1. DFARS 7021: 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements. | Acquisition.GOV 
  1. Why this matters: Ta-da! CMMC requirements are IN contracts, and you must meet compliance at the time of contract award. 

Scoping and assessment 

  1. CMMC Scoping Guide for Level 2: CMMC Scoping Guide Level 2 
  1. Why this matters: When you’re establishing boundaries, this is your bible. You want to keep your CMMC scope as small as possible, and this doc will help you do that. 
  1. CMMC Assessment Guide for Level 2: CMMC Assessment Guide Level 2 
  1. Why this matters: As you prep for either self-assessment or assessment by a C3PAO, you want to be damn sure that you’ve crossed your Ts and dotted your Is. This is THE thing that will help. Heads up that there are scoping guides and assessment guides for Levels 1 and 3 as well, but since we deal mostly with folks looking to get Level 2, that’s what I’m sticking in here. 
  1. CMMC Assessment Process (CAP): CMMC Assessment Process v2.0.pdf 
  1. Why this matters: This is a huge piece of what CCPs and CCAs get grilled on when taking their tests. This is what your clients want to know as they get ready to go into Assessment. 

Memos and class deviations 

  1. Determining CMMC level: Implementing the Cybersecurity Maturity Model Certification Program: Guidance for Determining Appropriate CMMC Compliance Assessment Levels and Process for Waiving CMMC Assessment Requirements 
  1. Listen, it’s ok to not just accept markings or determinations. It’s ok to ask questions. You can save yourself and your subcontractors a lot of headaches if you make sure that what you’re getting is appropriately marked. 
  1. ODPs for Rev 3: Department of Defense Organization-Defined Parameters for National Institute of Standards and Technology Special Publication 800-171 Revision 3 
  1. We’re not on NIST SP 800-171 rev 3 yet (we’re still working off of rev 2). BUT it’s def coming, probably in the next year and a half or so. Preparing now just makes sense. An ODP is an Organizationally Defined Parameter, and in our case, the “organization” is DoD. They get to say (for example) what kind of audit logs we need to keep. This memo highlights alla that. 
  1. Sticking with NIST 800-171 R2: MEMORANDUM FOR 
  1. Speaking of R2, there was confusion there for a while if we should be on R2 or R3. This class deviation clears it up for us. 

Additional resources 

  1. NARA CUI Registry: CUI Registry | National Archives 
  1. Yeah, DoD has their own registry. But NARA’s is the official, real, legit, one. The Organizational Index Groupings that we pay attention to are Defense and Export Control. 
  1. CMMC FAQs: CYBERSECURITY MATURITY MODEL CERTIFICATION Program FREQUENTLY ASKED QUESTIONS 
  1. When DoD puts out a list of FAQs, mind their answers. 
  1. PPT from DoD on technical application: Topics For CIO Summit: External Service Providers (ESPs), Asset Categories, SPA/SPD, and VDI 
  1. This is helpful if (when) you want to get deep into asset types and applicability for security requirements. It’s also got some info on VDI that’s gonna be nice to have on hand. 
  1. DoDI 5200.48: DoDI 5200.48, “Controlled Unclassified Information (CUI),” Effective March 6, 2020 
  1. Obama’s EO said “make me a CUI program”. 32 CFR 2002 said “cool, here’s your CUI program”. DoDI 5200.48 said “nice, here’s instruction for DoD on how to adopt the CUI program”. 

Part Deux: Reference Material 

So like YES always go back to our source material, BUT there are a whole lot of really smart people out there (Amira Armond is a personal hero of mine, for example). Below are some of my go-tos. 

  1. This blog from Richard Wakeman: Understanding Compliance Between Commercial, Government, DoD & Secret Offerings – July 2025 Update | Microsoft Community Hub 
  1. It’s an intense read, but it is the best thing I’ve found to talk customers through “do I need GCC or GCC High”. 
  1. Reference architectures for DIB: Microsoft-Reference-Identity-Architectures-ND-ISAC-MSCloud-Whitepaper.pdf 
  1. Comes complete with pretty pictures so we don’t have to start from scratch! 
  1. Speaking of reference architectures: KRA-Datasheet.pdf 
  1. Have I mentioned my love for Amira Armond? I stand by it.  She is a brilliant OG and everyone should listen to her. The KRA is WILDLY helpful in that it’s designed around GCC High. Use this for scoping. 
  1. Technical reference guide from Microsoft: Download Microsoft Technical Reference Guide for CMMC 2.0 from Official Microsoft Download Center 
  1. It’s a doozy, but where NIST 800-171 says “achieve this”, this doc says “and here’s how”. 

Part Trois: Catch-Alls 

Helpful catch-alls. Like bookmark these and know these and love these. 

  1. CMMC Wiki: CMMC Toolkit Wiki 
  1. Has everything. I mean EVERYTHING. I mostly use this for CCP exam practice. 
  1. DoD CUI Program: DoD CUI Program 

OKKKKKKKKKKKKKKKKKKKKKKKK I am le tired and legit, you need to go read this source documentation. Let’s consider this a work in progress? 

Notes to self on stuff I still wanna tell you about: NARA and ISOO. CyberAB and CAICO. CMMC L1 vs L2. Ethics for the ecosystem. Tailoring for 171 from 53. Hashing guidance for assessment evidence. Specialized assets. 

THERE’S SO DANG MUCH but again…

GCC High Migration Failures: What Goes Wrong and When 

When the boundary gets defined last and the environment gets locked in first, that’s what makes the failure expensive. 

GCC High migrations that fail didn’t break on a technical error; they broke on order. The CUI boundary got defined after the environment was already chosen, and every architectural decision after that had to justify a scope nobody had written down. 

Every migration proposal gets reviewed for technical risk: identity federation, mail flow cutover, data loss during transfer. Sequencing risk doesn’t show up on that list. 

It surfaces later, the first time an assessor or a prime’s security questionnaire asks a scoping question the organization can’t answer cleanly. By then the tenant, the licensing tier, and the identity structure are already built around whatever assumptions filled the gap where a documented boundary should have been. 

The Sequence That Holds Up 

Boundary, then environment, then architecture, then migration. That’s the order, and it rarely runs that way. 

Most engagements arrive with environment and licensing already selected, sometimes with a signed purchase order, and architecture and identity governance still undefined. Boundary shows up last, forced out by that same scoping question when it finally lands. 

Scope authority traces to the designating agency under 32 CFR Part 2002, not to whichever prime is easiest to ask. A boundary built on internal assumptions instead of what the designating agency and the contract’s own CUI markings require won’t hold up to that question. 

Once environment is chosen first, everything downstream becomes a retrofit. Retrofitted architecture still counts as architecture, but now it has to justify a boundary after the fact instead of enforcing one that already existed. An assessor reading the timeline sees the licensing agreement dated before the scoping memo and draws the obvious conclusion. 

Not every CUI boundary needs GCC High. Some need GCC. Some, depending on ITAR exposure and data residency requirements, need Azure Government layered underneath. 

Skipping the boundary work means guessing at that tier instead of deriving it from the data. The guess runs in both directions: an organization that overbuys carries licensing cost for controls it never needed to evidence, and one that underbuys ends up in an environment that can’t carry what its own boundary requires. 

Why Environment Gets Chosen First 

The reversal is rarely bad judgment. It’s a mismatch of timelines. A prime’s flow-down requirement comes with a contract deadline, and a Microsoft partner’s proposal comes with a licensing cost and a start date. 

A boundary exercise done properly takes longer than either party wants to wait: interviewing the people who handle CUI, tracing where it flows in practice, reconciling that against the CUI Registry and the contract’s own marking requirements. 

Environment gets picked on the timeline with a deadline attached. Boundary work gets scheduled for after go-live, where it competes with every other post-migration priority and usually loses. That’s what happens when the wrong calendar governs the decision, not a failure of the people running the migration. 

The Reform Task Force’s public comment period on its reform RFI closed August 14, with recommendations expected roughly sixty days after the July 13 suspension. (DoW RFI, via SBA Office of Advocacy) That review adds one more calendar pulling attention toward what CMMC becomes next, and away from the boundary work an organization owes itself regardless of where it lands. 

Where Each Stage Breaks 

Tenant configuration and identity governance get locked in before the boundary exists. That’s an irreversible decision: expensive and disruptive to unwind once users, mailboxes, and conditional access policies depend on it. 

A contractor that stands up one GCC High tenant for the whole organization, because that was the simplest licensing conversation, has made a scoping decision without calling it one. If the boundary later turns out to be a segment of the business rather than the whole thing, nobody goes back and fixes the tenant. 

Splitting a tenant after two thousand mailboxes and a year of conditional access policies are built on top means re-provisioning identities, cutting over mail flow, and reassigning licenses, done while the business keeps running. Microsoft’s own tenant-to-tenant migration guidance treats that as a full project: identity remapping, license reassignment, and mail routing sequencing, the same categories of work as the original migration. 

Licensing gets chosen the same way, ahead of knowing which controls it has to evidence. A GCC High or Azure Government license satisfies the hosting and data residency requirement in DFARS 252.204-7012. NIST SP 800-171 compliance is a separate, ongoing requirement the license doesn’t cover by itself. 

Which SKU, which add-ons, which retention settings, all of it depends on which of the 110 controls the environment has to carry evidence for: audit log retention, access control enforcement, media protection. Pick the tier first and the gap surfaces at the next add-on purchase, or worse, mid-assessment, as a change order instead of a line item. 

Migration gets executed before conditional access and audit logging are architected, not deployed. A conditional access policy that was never mapped to a control, or logging that’s switched on but not retained on a schedule, is deployed and nothing more. 

Move live CUI into that environment before the gap closes, and the organization is protecting data inside a structure it can’t yet describe on paper. That gap doesn’t surface during the migration. It surfaces the first time someone outside the organization asks to see the policy in writing. 

The pattern underneath all three is acceleration without alignment: the migration moves at the calendar’s pace, the governance work that makes the environment defensible moves at whatever pace is left over, usually nobody’s. The data arrives before the paperwork does, and once it’s there, the paperwork is describing a decision that already happened instead of one still open for review. 

What a Microsoft Partner Should Be Asked Before the Agreement Is Signed 

The sequencing problem usually surfaces first in the sales conversation, because that conversation runs on the licensing timeline, not the boundary timeline. A partner can describe what GCC High includes. Whether that matches the organization’s actual CUI boundary is a different question, and it’s the organization’s to ask. 

Worth asking before signature: which control families the proposed tenant configuration is meant to evidence, not just support. Whether the structure assumes one enterprise-wide boundary or a narrower enclave, and which one matches the boundary work already done. Whether conditional access and logging get built to a documented set of controls or shipped as a default to adjust later. 

A partner who can’t answer against a boundary document, because none exists yet, has confirmed the sequence is running environment-first. 

None of this is a criticism of the partner. A licensing conversation is structured to answer licensing questions, and a good one says so directly rather than improvising an answer to a scoping question that belongs to the organization. The problem is that conversation happening as the first decision instead of the third. 

What It Costs to Reorder After the Fact 

Reordering after go-live means reopening tenant architecture that live users already depend on, and remapping a control set onto a license that may not carry what the boundary needs. Microsoft’s own migration guidance treats a tenant restructuring as a full project on the same scale as the original migration: identity remapping, mail flow cutover, and license reassignment, done while the business keeps running. 

The organizations that avoid this can say, before the migration starts, which decision got locked in first and whether it was made against a documented boundary or a licensing conversation. 

The exposure isn’t limited to a future assessment. An inaccurate SPRS score is a representation the government can already act on under the False Claims Act. In September 2025, the Department of Justice settled with Georgia Tech Research Corporation for $875,000 over cybersecurity compliance claims that didn’t match the environment they described. That exposure exists independent of whether CMMC Phase II ever returns in its original form. 

Three Questions a Working Tenant Doesn’t Answer 

A tenant that’s live, populated, and functioning proves the migration succeeded. Whether the boundary was ever written down, whether the license maps to what it needs to evidence, and whether conditional access and logging were architected rather than switched on are three separate questions a working environment can’t answer by itself. 

GCC High and “compliant with NIST SP 800-171” get treated as the same fact more often than not. GCC High satisfies a hosting and data residency requirement. Whether the organization’s controls hold up under NIST SP 800-171 is a separate, ongoing question the environment can’t answer by itself. 

The CMMC Phase II suspension doesn’t change any of it. Phase I self-assessment, DFARS 252.204-7012 safeguarding, SPRS reporting, and annual affirmation are still active regardless of where the reform review lands. Reading the pause as room to slow down the boundary work runs the wrong direction. 

The next irreversible step in most of these environments is the identity and tenant decision that has to hold for years, not the migration itself. Before that locks in, the question that matters is which order the decisions arrived in, and whether that order would hold up if someone asked to see it. 

Compliance is an operating state, not a milestone. A new contract, a new CUI category, or a business unit added to scope reopens the same sequencing question. 

Our GCC High licensing guidance walks through how tier selection maps to control evidence. 

Which order were your decisions made in? 

GCC High Migration FAQs 

Draft. Marketing lead to approve or answer. Substantively unchanged except where noted below. 

What’s the right order of decisions in a GCC High migration? 

Boundary, then environment, then architecture, then migration. Document what CUI the organization handles before selecting GCC High, GCC, or Azure Government, build identity governance and audit logging to enforce that boundary, then migrate. 

Why is identity governance considered an “irreversible” decision in a migration? 

Once tenant structure and conditional access policies have live users and mailboxes built on top of them, changing that structure means redoing identity, mail routing, and licensing work, the same categories of work as the original migration. 

Does being in GCC High automatically mean CUI is handled compliantly? 

No. GCC High satisfies a hosting and data residency requirement under DFARS 252.204-7012. Whether the organization’s controls meet NIST SP 800-171 is a separate, ongoing question the environment doesn’t answer on its own. 

What should a contractor ask a Microsoft partner before signing a GCC High agreement? 

Which control families the configuration is built to evidence, whether tenant structure matches a documented boundary or assumes one, and whether conditional access and logging are built to specific controls or left at default. 

What does it cost to fix a migration that was sequenced in the wrong order? 

Reopening tenant architecture and remapping controls after go-live means redoing identity, mail routing, and licensing work while the business keeps running, the same categories of work as the original migration. The exact cost varies by engagement; the direction doesn’t.