Back

Compliance in GCC High, GCC and Microsoft 365 Commercial

Simply having GCC High GCC or Azure Government does not meet any compliance framework all by itself This should go without saying but NO platform ...

6 min read
Published on May 6, 2020
Compliance in GCC High, GCC and Microsoft 365 Commercial

Simply having GCC High, GCC, or Azure Government does not meet any compliance framework all by itself. This should go without saying, but NO platform comes out-of-the-box compliant. No matter which cloud you are in, you must build upon their foundational compliance to your own uses to assure you are meeting your compliance requirements. One of the strongest benefits of GCC, GCC High, and cloud computing in general is the shared responsibility model.

The Shared Responsibility Model for Compliance

As you move further away from on-premises infrastructure, the number of things you need to manage and maintain are greatly reduced. When you move from on-prem to Infrastructure as a Service (IaaS), you stop needing to manage your own virtualization, storage, or networking, As you move through Platform and Software as a Service (PaaS and SaaS), you gradually remove more and more of the infrastructure components you need to configure and maintain. With this comes cost savings, both in hardware and licensing costs, but also you are able to lean on the compliance efforts and certifications of your cloud provider.

One important thing to understand is flow-downs. In many cases, Microsoft meets or exceeds the compliance requirements of frameworks, such as DFARS, in all of their environments and have audit documentation to prove it. This is needed so that Microsoft can provide services to the government. However, in the environments without flow-downs they will not provide you with documentation that YOU meet those frameworks in that environment, meaning you cannot use the shared responsibility model in those clouds. This is important to understand when audit time comes, and you find out that Microsoft will not provide attestation that you are meeting your compliance requirements.

Using Microsoft Compliance Manager’s template for NIST 800-171 in a commercial environment, you get a clear view of the overall impact of this shared responsibility model. When you run this report, you will get a listing of total controls, and how many of those controls are managed by Microsoft and how many must be managed by your organization. Out of 396 controls, 208 are managed by Microsoft, and only 188 must be managed by the customer. All of the controls managed by Microsoft are already documented, with audit references easily accessible. The financial impact of reducing regulatory burden will vary depending on your own organizational readiness and resources, but almost always comes out as a net win for companies who move to an appropriately compliant cloud.

Microsoft Compliance across GCC, GCC High, DOD, and Commercial

CommercialGCCGCC HighDoD
Customer EligibilityAnyFederal, SLG, DIBFederal, DIBDOD ONLY
DC LocationsUS and OCUNUSCONUS OnlyCONUS OnlyCONUS Only
AccreditationFedRAMP ModerateFedRAMP ModerateFedRAMP HighFedRAMP High
HIPAA/HITECHYESNONONO
FBI CJISNOYESNONO
DFARSNOYES (no flow downs)YES (flow downs)YES
ITAR / EARNONOYESYES
CUI / CDINONOYESYES
DOD SRG LevelN/AL2L4L5
NIST 800-171NONOYESYES
NIST 800-53YESYESYESYES
NERC / FERCYESYES
CMMCLevels 1 and 2Levels 1 and 2Levels 3-5Levels 3-5
Customer SupportWorldwide / CommercialWorldwide / CommercialUS Based / Restricted PersonnelUS Based / Restricted Personnel
Directory NetworkAzure CommercialAzure CommercialAzure GovernmentAzure Government

GCC Compliance Frameworks

Understanding why specific cloud environments meet specific compliance frameworks takes a deeper understanding of what those compliance requirements are, and how the various environments are structured. While all of the Microsoft clouds meet FedRAMP moderate, and NIST 800-53, this is because there is a contractual requirement that GCC meets these frameworks, and since GCC is an segregated enclave of Commercial, those frameworks exist there as well. However, there is no contractual requirement in commercial regarding data residency, nor the limitation of screened US personnel to administer the solutions. For most frameworks, the most important consideration is where the infrastructure and directory network exist. Within Commercial and GCC, your Azure Active Directory resides in the commercial Azure environment which is a global infrastructure, and support is delivered by a global workforce.

The Defense Federal Acquisition Regulation Supplement (DFARS) is another interesting case. While Microsoft meets DFARS for GCC, they will not sign a contractual flow-down that lets customers meet DFARS in GCC, nor will they provide any form of demonstration for DFARS . It was not built for Microsoft to provide to government agencies, and thus they must meet it, but it was not built for Microsoft customers to deliver services to government agencies. If you wish to take advantage of the shared responsibility model to demonstrate DFARS compliance to your customers, you will need GCC High.

Compliance Frameworks Achievable in GCC

GCC High Compliance Frameworks

As we have explained, GCC High is, in essence, a copy of the DOD environment. As we explained in our overview of the services this is the level where you get ONLY US Based, screened personnel working in the data centers and your infrastructure and directory services ONLY exist in the continental United States facilities. This allows GCC High to meet the more stringent requirements of the Defense Industrial Base. At this level Microsoft WILL provide needed flow downs, and has both audit documentation and a contractual obligation to provide a compliant environment.

Compliance frameworks achievable in GCC High

What about CUI?

If you have contractual obligations to handle CUI, you hopefully have other requirements in your contract that will clarify this for you. There are over 20 different types of CUI, and each of them have their own requirements for safeguarding. Mention of CUI in a contract is enough to get Category 3 validation from Microsoft which will get you into GCC High and our official guidance is that you should err on the side of caution and use GCC High rather than GCC. If you believe that you can meet your contractual obligations without GCC High, we strongly suggest that you have this conversation with your contract liaison to clarify what requirements you must meet. With the upcoming addition of CMMC language in DOD contracts, we hope this will be further clarified.

Meeting Your DOD Compliance Requirements

Agile IT is at the top of only 8 AOS-G partners capable of licensing, implementing, migrating and managing GCC High for Microsoft Customers. With 14 years as a Microsoft Partner, Over 16 Gold competencies, and a team of former military, government, and state department employees and contractors, we understand the importance of meeting your contractual compliance obligations. To find out more about moving to GCC or GCC High contact us today. Additionally, if you need assistance reaching CMMC or NIST 800-171 compliance, AgileAdvisor provides cloud compliance services for Microsoft 365.

This post has matured and its content may no longer be relevant beyond historical reference. To see the most current information on a given topic, click on the associated category or tag.

Related Posts

CMMC Documentation Requirements: Avoid Assessment Failure

GIGO: Garbage In, Garbage Out: Why Documentation Can Make or Break Your CMMC Success

Strong documentation is critical to CMMC success. Learn the key evidence assessors expect and how to avoid common documentation failures.

Jul 24, 2025
5 min read
Fast-Track CMMC Certification for Urgent Contracts

How to Fast-Track CMMC Certification for Urgent Contracts with AgileThrive JumpStart

Need urgent CMMC certification? AgileThrive JumpStart accelerates compliance for DoD contractors with fast-track assessments, gap analysis, and rapid audit readiness.

Jul 21, 2025
5 min read
Defending Against Email Compromise

Defending Against Email Compromise: Safeguarding Accounting & Procurement

Discover how to defend accounting and procurement teams from email compromise in the Defense Industrial Base. Learn CMMC-aligned best practices using Microsoft 365.

Jul 15, 2025
4 min read
Technical vs. Process Controls in CMMC Compliance

Understanding Technical vs. Process Controls for CMMC Compliance

Understand the difference between technical and process controls in CMMC compliance. Learn how both work together to protect FCI and CUI data effectively.

Jul 14, 2025
4 min read
20 Essential Questions to Ask a Managed Service Provider

Top Questions to Ask Your Managed Service Provider (MSP)

Looking for a new MSP? Stay ahead with the top questions to ask—from security and scalability to pricing and offboarding. Vet your provider with confidence.

Jul 12, 2025
5 min read
Overview of CMMC 2.0 and Its Levels: DoD Compliance Guide

CMMC 2.0 Explained: Levels, Compliance Requirements, and Key Changes

CMMC 2.0 simplifies cybersecurity requirements for DoD contractors. Explore an overview of its levels, key changes from CMMC 1.0, and what each level means for compliance.

Jul 11, 2025
6 min read

Ready to Secure and Defend Your Data
So Your Business Can Thrive?

Fill out the form to see how we can protect your data and help your business grow.

Loading...
Secure. Defend. Thrive.

Let's start a conversation

Discover more about Agile IT's range of services by reaching out.

Don't want to wait for us to get back to you?

Schedule a Free Consultation

Location

Agile IT Headquarters
4660 La Jolla Village Drive #100
San Diego, CA 92122

Secure. Defend. Thrive.

Don't want to wait for us to get back to you?

Discover more about Agile IT's range of services by reaching out

Schedule a Free Consultation