[ultimate_heading main_heading=”Do I Need GCC High To Comply With CMMC?” main_heading_color=”#000000″ sub_heading_color=”#777777″ spacer=”line_only” spacer_position=”bottom” line_height=”3″ line_color=”#ffb931″ main_heading_margin=”margin-bottom:20px;” sub_heading_margin=”margin-top:20px;margin-bottom:30px;” line_width=”104″ spacer_margin=”margin-top:30px;margin-bottom:35px;” main_heading_font_family=”font_family:Poppins|font_call:Poppins|variant:500″ main_heading_style=”font-weight:500;” main_heading_font_size=”desktop:30px;” main_heading_line_height=”desktop:40px;” sub_heading_font_family=”font_family:Poppins|font_call:Poppins|variant:300″ sub_heading_style=”font-weight:300;” sub_heading_font_size=”desktop:18px;” sub_heading_line_height=”desktop:30px;”]For DoD contractors, complying with Cybersecurity Maturity Model Certification (CMMC) standards is crucial. So it comes as no surprise that this is one of the most common questions about GCC High.[/ultimate_heading]
[ultimate_heading main_heading_color=”#000000″ sub_heading_color=”#777777″ spacer=”line_only” spacer_position=”bottom” line_height=”3″ line_color=”#ffb931″ main_heading_margin=”margin-bottom:20px;” sub_heading_margin=”margin-top:20px;margin-bottom:30px;” line_width=”104″ spacer_margin=”margin-top:30px;margin-bottom:35px;” main_heading_font_family=”font_family:Poppins|font_call:Poppins|variant:500″ main_heading_style=”font-weight:500;” main_heading_font_size=”desktop:30px;” main_heading_line_height=”desktop:40px;” sub_heading_font_family=”font_family:Poppins|font_call:Poppins|variant:300″ sub_heading_style=”font-weight:300;” sub_heading_font_size=”desktop:18px;” sub_heading_line_height=”desktop:30px;”]The table below summarizes the key differences between the commercial version of Microsoft Office 365, Microsoft Office 365 GCC, Microsoft Office 365 GCC High, and Microsoft Office 365 DoD:[/ultimate_heading]
|
Microsoft 365
“Commercial” |
Microsoft 365 US
Government (GCC) |
Microsoft 365
Government (GCC High) |
Microsoft 365
Government (DoD) |
Customer eligibility |
Any customer |
“Federal, SLG, Tribes,
Eligible Contractors
(DIB, FFRDC, UARC)” |
“Federal,
Eligible Contractors
(DIB, FFRDC, UARC)” |
DoD only |
Data center locations |
US & OCONUS |
CONUS Only |
CONUS Only |
CONUS Only |
FedRAMP 1 |
High |
High |
High |
High |
DFARS 252.204-7012 |
No |
Yes |
Yes |
Yes |
FCI+ CMMC L1 |
Yes |
Yes |
Yes |
Yes |
CUI/CDI CMMC L2-3 |
No |
Yes^ |
Yes |
Yes |
ITAR/EAR |
No |
No |
Yes |
Yes |
DoD CC SRG Level 2 |
N/A |
IL2 |
IL4 |
IL5 |
NIST SP 800-53/171 3 |
Yes |
Yes |
Yes |
Yes |
CJIS Agreement |
No |
State |
Federal |
No |
NERC/FERC |
No |
Yes^ |
Yes |
Yes |
Customer Support |
Worlwide/Commercial personnel |
U.S-based/Restricted personnel |
Directory/Network |
Azure “Commercial” |
Azure Government |
|
U.S. SOVEREIGN CLOUD |
1 Equivalency Supports accreditation at noted impact level
2 Equivalency PA issued for DoD only
3 Organizational Defined Values (ODV’s) will vary
^ CUI Specified (e.g. ITAR Nuclear, etc.) not suitable REQS US Sovereignty
SOURCE: Understanding Compliance Between Commercial, Government and DoD Offerings – March 2022 Update