Microsoft GCC High CMMC Level 2 Support
On Microsoft GCC High? We map exactly which CMMC Level 2 controls your Entra / Purview / Defender / Sentinel configuration covers, what you still have to configure and evidence, and the artifacts a C3PAO will ask for.
Get a GCC High evidence map →The honest starting point
GCC High is the right environment for many CUI and ITAR workloads — but it does not make you compliant on its own. Under the shared-responsibility model, the platform provides a sovereign foundation; you configure the controls, write the policies, and produce the evidence. The fastest way to know where you stand is to map your tenant against the 110 requirements.
What GCC High helps you cover (with the right config)
- 3.5.3 MFA — Entra Conditional Access + Authentication Methods + PIM for privileged roles (GCC High control page).
- 3.1.1 / 3.1.2 Access control & least privilege — Entra roles, RBAC/PIM eligible-vs-active, access reviews.
- 3.3.1 Audit logging — Purview Audit + Entra logs, retention via Log Analytics / Sentinel (control page).
- 3.14.6 Monitor for attacks — Microsoft Sentinel analytics rules + incidents (control page).
- Malicious code — Defender for Endpoint + Defender for Office 365.
What you still own
- 3.13.11 FIPS-validated cryptography — confirm validated modules/config for CUI protection (control page).
- CUI boundary & scoping — what's in the GCC High enclave vs. elsewhere; this drives most of the effort.
- Policies, procedures, and the human controls the platform can't provide.
- Configuration baselines & enforcement — see 3.4.1 / 3.4.2.
What you get
- A control-by-control map of your GCC High tenant to the 110 NIST 800-171 objectives.
- A gap list with specific configuration and evidence recommendations.
- Your current SPRS score and the deductions driving it.
- The exact evidence artifacts to produce for each control, GCC-High-specific.
- A prioritized remediation plan.
Who this is for
Defense and aerospace contractors and subs on Microsoft GCC High who handle CUI or ITAR data, face the CMMC Level 2 mandate, and want an assessor-grade read on what their tenant covers — and what it doesn't.
Pricing
Scope & Gap Sprint with GCC High evidence mapping — $1,495 (one-time). Ongoing, the $349/mo L2 Core workspace keeps evidence and SPRS current.
Map my GCC High tenant →FAQ
Does GCC High make me CMMC compliant?
No — it's a sovereign environment suited to CUI/ITAR, but compliance is your responsibility. You configure the controls and produce the evidence; we map exactly where the tenant covers you.
Do I actually need GCC High?
Often yes for CUI/ITAR, due to US-person handling and sovereignty. Some orgs meet L2 on other tiers with added controls. It depends on your data and scope, which we assess first.
Related: Google Workspace CMMC · CMMC Level 2 Readiness Assessment · Control evidence library
Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Microsoft, GCC High, Entra, Purview, Defender, and Sentinel are trademarks of Microsoft; Athena is not affiliated with or endorsed by Microsoft.