Industries / Defense contractor
CMMC Level 2 on Microsoft 365, without the CUI question every quarter.
DoD prime contractors and subcontractors have a hard deadline in the DFARS 7021 clause: CMMC Level 2 assessment before contract award for anything touching CUI. Identra configures the Microsoft 365 GCC High tenant to the NIST 800-171 Rev 3 controls a C3PAO assesses, documents the System Security Plan, produces the CMMC evidence pack, and stages the tenant so the prime or sub can go into assessment with confidence.
- Regulation
- CMMC 2.0, DFARS 7012, NIST 800-171 Rev 3
- Vertical scope
- DoD prime, subcontractor, defense industrial base
- License footprint
- M365 GCC High (E5 recommended)
- Delivery
- Fixed scope, fixed price
01 / What we configure
Four workstreams for a CMMC Level 2 target.
- 01
CUI enclave and identity
GCC High tenant configured as the CUI enclave. FIPS 140-2 validated authenticators on every account. Conditional Access blocks CUI access from commercial-cloud identities. Entra Cross-Tenant Sync configured for approved commercial-to-GCC-High collaboration where the contract allows.
GCC HighFIPS 140-2Cross-Tenant Sync - 02
NIST 800-171 Rev 3 control coverage
Every 110 800-171 control mapped to a named GCC High tenant setting with evidence. Coverage across AC (access control), AT (awareness), AU (audit), CM (config), IA (identification), IR (incident response), MP (media protection), PE (physical), PS (personnel), RA (risk assessment), SA (system acquisition), SC (system and communications), and SI (system and information integrity) families.
800-171 Rev 3Coverage matrix110 controls - 03
System Security Plan and POAM
SSP drafted to the CMMC Level 2 template using live tenant data. Plan of Action and Milestones tracks any temporary control gaps with owner, date, and closure evidence. Both documents maintained as living records that update from tenant changes, not point-in-time snapshots.
SSPPOAMLiving documents - 04
C3PAO assessment preparation
Trial-run assessment walkthroughs with the tenant admin. Common C3PAO questions on Entra, Defender, and Purview posture in GCC High, with the settings and evidence to answer each. Reduces assessment-cycle back-and-forth and cuts the risk of a POAM item that blocks Level 2 achievement.
C3PAOWalkthroughAssessment prep
02 / What it looks like
Three defense industrial base engagements.
Different tier positions in the DoD supply chain, same CMMC clock.
CIO at a mid-tier defense prime
Situation. Existing commercial-cloud tenant carries a mix of CUI and non-CUI content. Prime programme manager escalated: next contract renewal explicitly requires CMMC Level 2 assessment before Q3 award.
Outcome. CUI enclave stood up in GCC High. Commercial tenant retained for non-CUI operations. Cross-Tenant Sync configured for approved commercial-to-CUI collaboration. C3PAO assessment passed in Q2, ahead of the renewal window.
IT Director at a defense subcontractor
Situation. Prime contractor flowed down a CMMC Level 2 requirement with 90-day notice. Existing M365 GCC tenant configured to CIS benchmark but never assessed against 800-171. No SSP.
Outcome. 60-day sprint mapped the tenant against 800-171 Rev 3, found 22 control gaps, closed 18 in configuration, opened 4 as POAM items. SSP drafted using live tenant data. Prime accepted the SSP and the sub retained the contract.
CISO at a defense-adjacent research organisation
Situation. Research contracts include both CUI and Fundamental Research (which is out of scope for CMMC). Team struggled to isolate CUI workflow from open research collaboration.
Outcome. Information barriers segmented CUI workloads inside the GCC High tenant. Fundamental Research workflows retained on commercial cloud with clear labelling. CMMC Level 2 assessment scoped to the CUI enclave only, reducing assessment surface area and cost.
03 / Frequently asked
What buyers ask first.
- What is CMMC?
- The Cybersecurity Maturity Model Certification is the DoD program to assess and certify the cybersecurity posture of the defense industrial base. CMMC 2.0 has three levels: Level 1 (self-assessment against 15 basic controls), Level 2 (third-party assessment against NIST 800-171 Rev 3), and Level 3 (higher-assurance assessment against 800-171 plus 800-172 enhanced controls). Level 2 applies to any contractor handling CUI. The DFARS 7021 clause makes CMMC assessment a contract award requirement.
- Do we need GCC High for CMMC Level 2?
- GCC High is the default recommendation for CMMC Level 2 tenants because it handles ITAR-scoped data, meets DFARS 7012 flow-down for cloud service provider requirements, and provides the FIPS 140-2 validated crypto without additional configuration. Some subcontractors handling CUI without ITAR content can run in GCC (not High) at lower cost, but the contract clause typically forces the decision. Identra scoping identifies which tenant type your specific contract portfolio requires.
- What is a C3PAO?
- A CMMC Third-Party Assessment Organisation, accredited by the Cyber-AB (the CMMC accreditation body), that performs the independent CMMC Level 2 assessment. The C3PAO produces the assessment report that supports the CMMC certification submitted to the DoD. Identra prepares customers for the C3PAO assessment but does not perform the assessment itself. Same distinction as 3PAO under FedRAMP.
- How does DFARS 7012 relate to CMMC?
- DFARS clause 252.204-7012 (Safeguarding Covered Defense Information) has required NIST 800-171 self-assessment since 2016 and cloud service provider FedRAMP Moderate equivalence since 2017. DFARS 7021 (added 2020, effective in phases) adds the CMMC assessment obligation on top. Contractors with existing 7012 self-assessment often have a partial baseline that reduces CMMC preparation time, but the C3PAO assessment is a fresh third-party review, not a re-badging of the self-assessment.
- How long does a CMMC Level 2 engagement take?
- First-time engagement typically runs 16 to 24 weeks including SSP drafting, control gap remediation, POAM handling, and C3PAO scheduling. Weeks 1 to 4 assess current posture. Weeks 5 to 16 configure controls and draft the SSP. Weeks 17 to 24 walk through with the C3PAO and close any remaining POAM items. Complex tenants or multi-enclave environments can run longer.
04 / Related
Where this fits.
Federal
FedRAMP and GCC High consulting
Government-cloud tenant configuration for federal, StateRAMP, and CMMC workloads.
Framework
NIST 800-53 Rev 5 mapping
Control-by-control mapping of tenant settings; 800-171 subset filter available.
Law enforcement
CJIS compliance
FBI CJIS Security Policy for law enforcement-adjacent defense workloads.