By Michael Branson

Quick answer. As of September 2026, sort by what triggers each rule rather than by what each one requires: CMMC is triggered by a contract clause and by federal contract information or controlled unclassified information landing on your own unclassified system, ITAR is triggered by the data itself being technical data directly related to a defense article on the U.S. Munitions List whether or not a DoD contract exists, FedRAMP is triggered by your firm selling a cloud service to a federal agency rather than buying one, and GCC High is not a regime at all but a Microsoft environment you become eligible to buy once one of the first two puts you there. The contracting officer and the contract clause settle the CMMC question, and your export-control function settles the ITAR question; the Microsoft cloud tier follows from the regime and the data, never the other way round.

The request that reaches IT is almost never the question that has to be answered first, because “do we need GCC High” names a product where the binding fact is a data type and a contract clause. A new award or teaming agreement lands with a DFARS clause nobody in IT has read, engineering calls a set of drawings export controlled, a peer says their prime made them move the whole tenant, and someone senior asks the one-line question anyway. Answering it as asked is the expensive mistake in both directions: under-scope, and export-controlled technical data sits in a tenant that was never built for it; over-scope, and the firm migrates an estate into a restricted environment a narrower reading never required, and absorbs the licensing and feature loss permanently. The sections below sort the four names by what triggers each one and who decides it, then hand each branch to the i3solutions page that already covers what that regime requires, how long it takes, and how an engagement for it is scoped.

Which compliance regime applies to us: CMMC, FedRAMP, GCC High, or ITAR?

Sort by your contract clause and your data type. A DoD contract putting federal contract information (FCI) or controlled unclassified information (CUI) on your own systems triggers CMMC. Technical data for a U.S. Munitions List article triggers ITAR, contract or not. FedRAMP authorization is for firms that sell a cloud service to a federal agency, not for firms that buy one. GCC High is not a regime; it is a Microsoft environment a firm becomes eligible for once CUI Specified such as ITAR data, or a contract clause that names it, is in play.

Name What triggers it Who decides Primary source
CMMC A DoD contract plus FCI or CUI on a contractor information system The DoD program manager or requiring activity, per procurement, when it sets the CMMC Status 32 CFR 170.3(a)(1) and 170.3(d)
ITAR Technical data directly related to the defense articles of a U.S. Munitions List category, with or without a DoD contract The firm’s export-control function 22 CFR 120.10(b), with technical data defined at 22 CFR 120.33(a)(1)
FedRAMP The firm sells a cloud service to a federal agency. A buyer of cloud meets a DFARS flow-down instead: its provider must meet security equivalent to the FedRAMP Moderate baseline The authorizing agency, for a seller; the contractor’s own choice of provider, for a buyer 48 CFR 252.204-7012(b)(2)(ii)(D)
GCC High Not a regime. A Microsoft environment that opens to a firm once CUI Specified such as ITAR technical data, or a contract clause that names it, is in play Microsoft’s eligibility validation Microsoft Learn, Office 365 GCC High and DoD service description, last updated August 3, 2026

Every citation in the table was read at its source on 2026-09-27 (eCFR and Microsoft Learn). The sections below take each branch in turn: CMMC, then ITAR, then FedRAMP, then GCC High, then the case where two regimes apply at once.

Start from your contracts and your data, not from a product

The routing question has two inputs a reader already holds and one they do not. What the contract says, and what the data actually is, are facts the reader can check today. Which regime that combination triggers is the fact this page exists to sort.

The federal definition that anchors the first input is DFARS 252.204-7012’s own definition of covered defense information: information that is “Marked or otherwise identified in the contract, task order, or delivery order and provided to the contractor by or on behalf of DoD in support of the performance of the contract” or “Collected, developed, received, transmitted, used, or stored by or on behalf of the contractor in support of the performance of the contract,” where it meets the standard for federal contract information or controlled unclassified information (48 CFR 252.204-7012, eCFR, read live 2026-09-21). Neither branch asks what product the firm uses. Both ask what the contract says and what the contractor does with the information.

CMMC: what triggers it, and who decides the level

CMMC is a contract-driven regime. Its own applicability rule, 32 CFR 170.3(a)(1), reads: “All DoD contract and subcontract awardees that will process, store, or transmit information, in performance of the DoD contract, that meets the standards for FCI or CUI on contractor information systems” are subject to it (eCFR, read live 2026-09-21). One exclusion narrows it in the other direction: 32 CFR 170.3(b) states plainly, “The requirements of this part do not apply to Federal information systems operated by contractors or subcontractors on behalf of the Government.” So the trigger is the pairing of a DoD contract with federal contract information or controlled unclassified information on the contractor’s own unclassified system, not the existence of a DoD relationship by itself.

Who decides the level is stated in the same part. 32 CFR 170.3(d) reads: “DoD Program Managers or requiring activities are responsible for selecting the CMMC Status that will apply for a particular procurement or contract based upon the type of information, FCI or CUI, that will be processed on, stored on, or transmitted through a contractor information system.” The determination sits with the program manager or requiring activity on the government side, read against the contract, never with a vendor and never with IT.

Once CMMC is in play, the level, the four-phase rollout and the enclave-scoping question are a second decision, and a live i3solutions page already answers it: Which CMMC Level Applies to You, and When Does It Start?

ITAR: the regime that does not wait for a contract

ITAR is the branch most often missed on a routing call, because it is triggered by the data itself and not by a DoD award. A firm with no defense contract at all can hold ITAR-controlled technical data, and a firm deep inside a CMMC scope can hold none.

The trigger is 22 CFR 120.33(a)(1)’s definition of technical data: information “required for the design, development, production, manufacture, assembly, operation, repair, testing, maintenance, or modification of defense articles,” including “information in the form of blueprints, drawings, photographs, plans, instructions, or documentation” (eCFR, read live 2026-09-21). What makes an article a defense article is the U.S. Munitions List, which 22 CFR 120.10(a) describes as the list of “articles, services, and related technical data designated as defense articles or defense services pursuant to sections 38 and 47(7) of the Arms Export Control Act,” published in 22 CFR part 121 (eCFR, read live 2026-09-21). The determiner is the firm’s own export-control function, reading the data against the Munitions List, never IT and never a Microsoft environment.

The regulation also defines a narrow set of activities that are not exports, reexports, retransfers or temporary imports at all, one of which concerns unclassified technical data meeting stated encryption and location conditions (22 CFR 120.54(a)(5)). As served by eCFR on 2026-09-21, that text is unchanged from its 2025 form, but the section carries two live cross-reference notices, to a Federal Register amendment dated August 28, 2026 and a correction dated September 16, 2026, neither of which has yet been folded into the codified text this page read. What that carve-out does and does not cover, and whether any firm’s configuration meets it, is a determination for the firm’s export-control function and counsel, never a reading IT takes from this page, and never a substitute for GCC High that this page proposes for any firm.

FedRAMP: are you selling a cloud service, or buying one?

FedRAMP is the category error that recurs most often on this estate: a firm assumes FedRAMP reaches it because it is a defense contractor, when FedRAMP is a program for cloud service providers, not for the firms that buy from them.

The sentence that actually reaches a contractor who buys cloud sits inside DFARS 252.204-7012(b)(2)(ii)(D), and the duty it creates falls on the contractor’s choice of provider: a contractor using an external cloud service provider for covered defense information “shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline,” with further requirements for cyber incident reporting, malicious software and media preservation carried in the rest of the clause (48 CFR 252.204-7012, eCFR, read live 2026-09-21). That is a flow-down requirement on the cloud provider the contractor selects, not a FedRAMP authorization the contractor itself carries. A firm building and selling its own cloud service to a federal agency is a different case, and needs its own authorization.

FedRAMP’s own public register is the FedRAMP Marketplace, which the program describes, as served on 2026-09-21, as “a searchable database of FedRAMP certified cloud services, authorizing agencies, and FedRAMP recognized assessors,” under a “Consolidated Rules for 2026” ruleset (fedramp.gov, read live 2026-09-21). For a contractor building an application on an authorized platform, exactly what is inherited from that platform and what is not is a separate, already-answered question: Is FedRAMP High Required to Build Government Contractor Applications?

GCC High is a consequence, not a regime

GCC High is the word buyers reach for first, and it is the one name on this page that names no regulation at all. Microsoft’s own service description states the reason the environment exists: “To meet the unique and evolving requirements of the United States Department of Defense, as well as contractors holding or processing DoD controlled unclassified information (CUI) or subject to International Traffic in Arms Regulations (ITAR), Microsoft offers GCC High and DoD environments,” available through a process Microsoft describes plainly: “interested organizations go through a validation process to ensure eligibility before an environment is established” (Microsoft Learn, GCC High and DoD service description, read live 2026-09-21). GCC High does not trigger itself. CMMC’s CUI trigger or ITAR’s technical-data trigger triggers it, and the environment is what a firm becomes eligible to buy once one of those two puts it there.

Once a firm knows CUI is in play but has not yet worked out which Microsoft 365 environment that calls for, the choice among GCC, GCC High and commercial Microsoft 365 is a separate, already-answered comparison: GCC vs GCC High vs Commercial Microsoft 365 for CUI: An Evaluation Matrix Whether CMMC itself requires GCC High, specifically, is the single most consequential branch of that question and it is answered in full on its own page: Does CMMC Require GCC High? What the Rule Actually Requires for Defense Contractors And because an environment is not the same thing as a certification, whether a given Microsoft 365 SKU can pass a CMMC boundary at all is answered separately too: Office 365 and CMMC requirements For the firm that has already reached a GCC High decision and needs the migration itself scoped and evaluated, that is its own engagement: GCC High and Sensitive Data Protection: Migration Consulting for Defense Contractors

Two regimes at once, and what that does not mean

A firm can be inside CMMC and ITAR at the same time, because the two triggers are independent of each other. A contract clause and a CUI type can put a firm inside CMMC while none of its data is ITAR-controlled technical data; a firm with no DoD contract at all can hold ITAR-controlled technical data on a commercial program. Neither trigger resolves the other, and a firm that has answered one has not thereby answered the second. Nothing in this page resolves what a specific combination means for a specific reader; that reading is the export-control function’s and the contracting officer’s, together, against the reader’s own contract and own data.

Honest counter-case: when this framework gives you the wrong answer

This framework describes triggers and determiners. It does not override four things that outrank it in a specific case.

A prime’s flow-down can impose a posture stricter than the regulation requires of the subcontractor, and the contract wins over the general rule stated here. A firm that already holds a determination from its own contracting officer or export-control function does not re-derive that determination from a web page; the standing determination governs. A narrow enclave can make the whole routing question smaller than a firm assumes, because scoping CMMC to an enclave rather than the whole organization is itself a decision with its own rules, covered in full on the CMMC timeline page linked above. And where the data classification itself is contested, whether a given drawing or dataset is technical data on the Munitions List, no framework on a website resolves that; the determination is a legal one, made by the firm’s export-control function and counsel.

How i3solutions approaches the routing decision

This page sets out a framework for making this decision. i3solutions engages its Federal Compliance Assessment when the scope spans a FedRAMP Moderate or FedRAMP High boundary, or when the client operates in a GCC High tenant. Getting the sort right before spending against it is the actual decision this page exists to support. i3solutions advises clients on federal compliance posture as its own assessment rather than as a restatement of Microsoft’s documentation, including whether SharePoint Online meets NIST 800-53, whether Azure Government is required under the DoD Cloud Computing SRG, and whether a CMMC gap assessment is needed to bid. That advisory work is the same judgment this page walks through: read the contract, read the data, and settle which regime is actually in play before any Microsoft cloud tier is chosen.

Once the regime is sorted, the implementation conversation for CMMC, HIPAA, SOC 2 or NIST inside Microsoft 365 is its own engagement, covered here: Microsoft 365 Compliance Consulting: CMMC, HIPAA, SOC 2, and NIST for Regulated Enterprises And the wider governance model this routing decision sits inside is described on the pillar page: Embedding Governance into How the Enterprise Operates and Scales

If you want your own contracts and your own data read against this framework before the next Microsoft cloud tier decision gets made, the conversation starts here.

Contact a senior architect

Frequently Asked Questions

Does being a DoD contractor mean we need FedRAMP?

No. FedRAMP authorization is for firms that sell a cloud service to a federal agency. A contractor that buys cloud for covered defense information must instead require its provider to meet security equivalent to the FedRAMP Moderate baseline, under DFARS 252.204-7012(b)(2)(ii)(D). That duty lands on the chosen provider, and it gives the contractor no FedRAMP authorization of its own.

Can ITAR apply to us without a DoD contract?

Yes. The trigger is the data, not a contract: technical data directly related to the defense articles of a U.S. Munitions List category (22 CFR 120.10(b)), with technical data defined at 22 CFR 120.33(a)(1). No DoD contract is needed, and the export-control function of the firm makes the determination.

Who decides which CMMC level applies to us?

The CMMC Status for a procurement is set by the DoD program manager or requiring activity, based on whether FCI or CUI will sit on a contractor information system (32 CFR 170.3(d)). The level is read from the contract, never chosen by IT or a vendor. What each level asks for, and when it starts, is covered on the CMMC level page linked in the CMMC section above.

Is GCC High a compliance requirement?

No. GCC High is a Microsoft environment, not a regulation. Microsoft offers it to DoD contractors that handle CUI or are subject to ITAR, once they pass an eligibility validation by Microsoft. Whether CMMC on its own calls for GCC High is a separate question with its own page, linked in the GCC High section above.

Can CMMC and ITAR both apply to us at once?

Yes. The triggers are independent: CMMC turns on a DoD contract clause with FCI or CUI on your system, and ITAR turns on your data being technical data directly related to the defense articles of a U.S. Munitions List category (22 CFR 120.10(b)). Answering one never answers the other: the DoD program manager or requiring activity settles CMMC and the export-control function settles ITAR, separately.

Does i3solutions issue an ATO or certify our compliance?

No. i3solutions holds no authorization of its own and issues no ATO. i3solutions delivers a proprietary Federal Compliance Assessment as its own named deliverable, engaged when the scope spans a FedRAMP Moderate or FedRAMP High boundary or a GCC High tenant, and plans and runs GCC High migrations for regulated defense organizations.

Key Takeaways

  • CMMC is triggered by a DoD contract clause combined with federal contract information or controlled unclassified information on the contractor’s own unclassified system (32 CFR 170.3(a)(1)); the DoD program manager or requiring activity selects the CMMC Status (32 CFR 170.3(d)).
  • ITAR is triggered by the data itself, technical data directly related to a U.S. Munitions List defense article (22 CFR 120.33(a)(1), 120.10(b)), independent of whether any DoD contract exists; the firm’s export-control function determines it.
  • FedRAMP reaches a firm that sells a cloud service to a federal agency. A firm that buys cloud instead is reached by a different, narrower flow-down requirement inside DFARS 252.204-7012(b)(2)(ii)(D).
  • GCC High is a Microsoft environment a firm becomes eligible for once CMMC’s CUI trigger or ITAR’s technical-data trigger applies; it is a consequence of one of the first two triggers, not a regime with a trigger of its own.
  • A firm can be inside CMMC and ITAR at the same time, because the two triggers are independent; resolving one does not resolve the other.