Short answer. No. Office 365 is not CMMC compliant, and it cannot be, because CMMC certifies organizations, not products. But the useful answer has two layers, and almost every article collapses them into one. Layer one is the SKU. Office 365 is not Microsoft 365. Microsoft’s own plan table reads “Microsoft 365 E3 (includes Office 365 E3)”: Microsoft 365 is the superset. Office 365 is the productivity layer, Exchange Online, SharePoint Online, OneDrive, Teams and the Office apps. The endpoint and identity layer that carries a large share of the 110 CMMC Level 2 requirements, Microsoft Intune, Microsoft Entra ID P1 or P2 for Conditional Access, and Microsoft Defender for Endpoint, is what the Microsoft 365 bundles add on top. If your tenant is licensed Office 365 E3 or E5 rather than Microsoft 365 E3 or E5, entire requirement families have no enforcement point in your tenant at all, and moving that same Office 365 SKU to GCC High does not create one. Layer two is the environment, and the binding rule there is not CMMC. It is DFARS 252.204-7012.

This page is written for the person who has to defend the answer to a C3PAO assessor. Every requirement number, licensing rule, and clause citation below is sourced to Microsoft’s published service documentation, to the CMMC rule at 32 CFR Part 170, or to the DFARS clause itself.

No product is CMMC compliant, including Office 365

CMMC assesses an Organization Seeking Assessment, not software. A vendor can tell you its product is FedRAMP authorized, or that it runs at a given DoD Impact Level, and that can be true and verifiable. None of it makes the product “CMMC compliant,” and none of it transfers to you.

Microsoft says this itself: “CMMC compliance depends on customer configuration, implementation, and operational controls, as well as the use of qualified assessors and partners. Microsoft cloud services provide capabilities that can help support these requirements.” Note the verb. Microsoft services support requirements. They do not satisfy them.

So the question worth answering is narrower and more useful: which of the 110 CMMC Level 2 requirements can Office 365 actually carry, which can it never carry, and what do I have to buy or build for the rest?

What CMMC Level 2 requires, in the numbering that is actually in force

The CMMC Program rule at 32 CFR Part 170 took effect on December 16, 2024. CMMC Level 2 is the 110 security requirements of NIST SP 800-171 Revision 2, incorporated by reference; 32 CFR 170.14 states that “the security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2.” NIST organizes them into fourteen families.

Two traps, both common in the Office 365 content that currently ranks:

  • Rev 2 governs, even though NIST withdrew it. NIST superseded SP 800-171 Rev 2 with Rev 3 in May 2024. CMMC did not follow. The rule still points at Rev 2, so Rev 2 numbering is what a C3PAO assesses you against.
  • The CMMC 1.0 practice IDs are dead. Numbering like AC.1.001 or SC.3.177, and any reference to “Level 3 with 130 practices,” belongs to the superseded CMMC 1.0 model. The current identifier is domain, level, and NIST requirement, so 3.1.1 is cited as AC.L2-3.1.1.

Scoring: the rule conditions a POA&M on the assessment score divided by the total number of Level 2 requirements being greater than or equal to 0.8, which yields a Conditional CMMC Status, with all NOT MET requirements closed and verified by a POA&M closeout assessment within 180 days. Six requirements are ineligible for a POA&M and must be MET at assessment: AC.L2-3.1.20, AC.L2-3.1.22, CA.L2-3.12.4, PE.L2-3.10.3, PE.L2-3.10.4, and PE.L2-3.10.5.

Layer one: Office 365 is not Microsoft 365, and the gap is exactly where the controls live

This is the layer nobody covers, and it decides the answer before the environment ever comes up. Microsoft’s plan-options table is unambiguous. It lists the enterprise family as “Microsoft 365 E3 (includes Office 365 E3)” and “Microsoft 365 E5 (includes Office 365 E5).” Microsoft 365 contains Office 365. They are not synonyms, and the difference is not cosmetic.

The Office 365 service family is the productivity and collaboration layer:

Layer What you get Which CMMC Level 2 families it can serve
Office 365 (E1 / E3 / E5) Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, the Office apps, Microsoft Purview information protection and audit (depth varies by tier) Parts of Audit and Accountability (3.3.x), Media Protection for content at rest (3.8.x), System and Communications Protection for CUI in transit and at rest (3.13.x), and email malicious-code protection (3.14.2)
What Microsoft 365 adds on top Microsoft Intune (device management), Microsoft Entra ID P1 or P2 (Conditional Access, MFA enforcement), Microsoft Defender for Endpoint, Windows Enterprise Nearly all of Access Control on endpoints (3.1.x), Configuration Management (3.4.x), Identification and Authentication (3.5.x), removable media control (3.8.7), and endpoint malicious-code protection (3.14.2, 3.14.4)

Microsoft’s own Intune licensing documentation makes the same point from the other direction: organizations get Intune “as part of a Microsoft 365 bundle (such as Microsoft 365 E3, E5, or E7).” It names Microsoft 365 bundles. It does not name Office 365 plans.

The practical consequences are blunt:

  • No Intune means no device compliance policy and no configuration baseline. The Configuration Management family (3.4.1, 3.4.2, 3.4.6, 3.4.7, 3.4.9) has no enforcement point in your tenant. Neither does 3.1.18 on controlling mobile device connection, nor 3.1.19 on encrypting CUI on mobile devices.
  • No Microsoft Entra ID P1 or P2 means no Conditional Access. Conditional Access is what turns a policy into an enforceable access control. Without it, AC.L2-3.1.1 and IA.L2-3.5.3 are assertions, not controls. Microsoft states plainly that features depending on Entra ID P1 or P2 “still require the appropriate license.”
  • No Defender for Endpoint means no endpoint protection story. Microsoft Defender for Office 365 protects mail and collaboration content. It is a different product from Microsoft Defender for Endpoint, which protects the device. Assessors ask about the device.

Check your actual SKU before you do anything else. “We have Office 365 E5, so we have Microsoft’s security stack” is one of the most expensive sentences in this market, and it is wrong. And note the trap that follows from it: buying Office 365 GCC High rather than Microsoft 365 GCC High moves the same incomplete SKU into a government cloud. The environment changes. The missing control planes do not appear.

Layer two: the environment, and what DFARS 252.204-7012 actually says

The clause that binds you is DFARS 252.204-7012, and it is contractual, not technical. Three paragraphs do the work:

  • (b)(2)(ii)(D), the cloud rule. “If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline.” That is the floor your tenant has to clear, and it is the reason the environment question exists at all.
  • (c)(1)(ii), the 72-hour rule. You must “rapidly report cyber incidents to DoD at https://dibnet.dod.mil,” where “rapidly report” is defined as within 72 hours of discovery of any cyber incident.
  • (e), the 90-day rule. On discovering a cyber incident you must “preserve and protect images of all known affected information systems … and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report.”

Read those last two again, because no SKU discharges them. The 72-hour report and the 90-day media preservation are obligations on you. There is no Office 365 licence that files a DIBNet report or holds forensic images for you. This is the part buyers consistently under-scope, and it is why the evidence burden, not the configuration, usually drives the schedule.

The environment decision itself, Commercial versus GCC versus GCC High, turns on your CUI type and your contract clauses, not on CMMC directly. We treat it as its own decision, and it should be settled before any of the design work below: see Microsoft 365 GCC vs GCC High and Does CMMC require GCC High?

What Office 365 can genuinely carry in a CMMC Level 2 boundary

Office 365 is not useless here. It is the enforcement point for a real, if narrow, set of requirements, all of them about content rather than endpoints. The requirement text is NIST’s. The enforcement point and evidence columns are i3Solutions’ implementation mapping, not a Microsoft claim of coverage.

CMMC ID NIST SP 800-171 Rev 2 requirement Office 365 enforcement point Evidence a C3PAO accepts
AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems) SharePoint and OneDrive permissions, Teams membership, external sharing policy. Note: the device half of this requirement needs Entra ID Conditional Access, which Office 365 alone does not include Permission and sharing-policy exports, site inheritance report
AC.L2-3.1.2 Limit system access to the types of transactions and functions that authorized users are permitted to execute SharePoint permission levels, sensitivity labels, Purview DLP policy actions Permission-level definitions, DLP policy export with per-rule actions
AU.L2-3.3.1 Create and retain system audit logs and records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful or unauthorized system activity Microsoft Purview Audit. Retention depth is a licensing question, not a switch Audit configuration, retention policy, sample searchable log export
AU.L2-3.3.2 Ensure that the actions of individual system users can be uniquely traced to those users, so they can be held accountable for their actions Unified audit log with per-user attribution; no shared or generic accounts in the CUI boundary Audit log sample showing per-user attribution, shared-account exception register
MP.L2-3.8.7 Control the use of removable media on system components Not achievable in Office 365. This is an endpoint control requiring Intune device configuration or Defender device control None available from Office 365
SC.L2-3.13.8 Implement cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission unless otherwise protected by alternative physical safeguards TLS enforcement on Exchange Online mail flow, Purview Message Encryption, sensitivity-label encryption Connector and TLS configuration, label encryption settings
SC.L2-3.13.11 Employ FIPS-validated cryptography when used to protect the confidentiality of CUI Depends on the environment and endpoint configuration; Office 365 alone does not let you assert this end to end Environment attestation plus endpoint FIPS configuration evidence
SC.L2-3.13.16 Protect the confidentiality of CUI at rest SharePoint, OneDrive and Exchange encryption at rest, sensitivity labels with encryption Label policy export, encryption configuration
SI.L2-3.14.2 Provide protection from malicious code at designated locations within organizational systems Microsoft Defender for Office 365 covers the mail and collaboration designated locations. It does not cover the endpoint Defender for Office 365 policy export. Endpoint coverage requires Defender for Endpoint

Look at the shape of that table. Office 365 covers content: what is stored, what is shared, what is logged, what is encrypted. It covers almost nothing about the machine the CUI is opened on. In a CMMC Level 2 assessment, the machine is at least half the conversation.

The three architectures that actually pass

There are only three honest ways to hold CUI in a Microsoft estate. Pick deliberately.

  1. Microsoft 365 GCC High, full stack. The default when your CUI is export-controlled under ITAR or EAR, when a DoD Impact Level 4 requirement applies, or when a contract clause names the environment. Buy the Microsoft 365 bundle, not the Office 365 one, or you have solved the environment and left the control planes behind.
  2. Microsoft 365 GCC, with the compensating controls documented. Viable for a lot of non-export-controlled CUI. The burden shifts to your System Security Plan: you have to write down why GCC clears the (b)(2)(ii)(D) bar for your data and be ready to defend it.
  3. Commercial Microsoft 365 plus a FedRAMP-authorized CUI enclave. This is the overlay pattern, where an encrypted email-and-file product handles every CUI flow and Commercial Microsoft 365 handles everything else.

Be clear-eyed about what option three is. The overlay pattern works by routing CUI around Office 365, not through it. It shrinks your assessment boundary by taking Office 365 out of the CUI path. That can be a legitimate and cost-effective architecture, and for a small contractor with narrow CUI flows it often is. But notice what it concedes: a vendor selling you an enclave because “Microsoft 365 Commercial does not meet CMMC or DFARS requirements” has answered the question in this page’s title, and answered it no. Their own architecture is the proof. Buy it with your eyes open, and understand that your users now live in two systems, that the boundary between them is the thing an assessor will probe hardest, and that every CUI flow which leaks back into Office 365 is a finding.

The Office 365 evidence a C3PAO assessor asks for

An assessor is not impressed that you own Office 365. Per requirement, they want the policy, the scope, and the proof it is in effect:

  1. The policy export, showing actual setting values, not a screenshot of a blade.
  2. The scope, showing the policy applies to the sites, mailboxes and groups that constitute your CUI boundary and nothing outside it.
  3. The state report, showing the configuration is live, plus the exceptions and what you do about them.
  4. The boundary diagram, showing where CUI is allowed to live and, critically, where it is not.

Microsoft Purview Compliance Manager ships a CMMC v2 Level 2 assessment template; use it as the scaffold for improvement actions and the evidence register, but do not mistake its score for an assessment result. It measures the actions you have recorded, not the ones a C3PAO will accept.

The failure mode i3Solutions sees most often on the Office 365 side is a CUI boundary that is drawn on a slide but not in the tenant: a SharePoint site marked as the CUI enclave, with inheritance still intact from a parent site, external sharing still enabled at the tenant level, and a Teams channel quietly writing to a different site. That is one finding on the diagram and three in the tenant.

How i3Solutions scopes Office 365 inside a CUI boundary

i3Solutions plans and runs governed Microsoft 365 and Azure work for compliance-bound organizations, and maintains dedicated compliance specialists who understand CMMC, HIPAA, SOC 2, and financial services regulations within Microsoft environments, providing audit trail documentation and access control frameworks that reduce audit preparation time by 60 percent.

Two patterns from our delivery work shape how we scope this. First, under DFARS 252.204-7012 cybersecurity incident reporting, the artifact set expands roughly 30 percent versus commercial scope, so the evidence burden, not the configuration, drives the schedule. Second, regulated-industry SharePoint modernization carries roughly 25 to 35 percent cost overhead versus commercial work for equivalent scope, driven by control mappings, audit-trail discipline, and zero-downtime cutover patterns. Anyone quoting you a commercial SharePoint number for a CUI boundary has not scoped the compliance work.

We do this at scale. i3Solutions runs a governed Power Platform for a federal defense agency supporting roughly 10,000 personnel across about 180 locations, which works because it is governed, not despite it, and has unified identity and automated provisioning across systems for 125,000 users by treating the interfaces as owned, governed contracts.

On cost: a CMMC Level 2 implementation for a defense contractor with a defined CUI boundary typically ranges from $45,000 to $75,000, covering the Compliance Manager baseline assessment, Conditional Access redesign, DLP policy build and testing, Purview Audit Premium configuration, and post-implementation documentation. Where SharePoint customizations come with you, full migration project cost for defense contractors with SharePoint customizations and CMMC compliance scope typically lands in the $100,000 to $300,000 range.

Microsoft does not publish a public per-user list price for GCC High. It carries a licensing premium over Commercial Microsoft 365 and is sold through Microsoft agreements and authorized partners, so any per-user GCC High figure you have been quoted came from a partner price sheet, not from Microsoft. Commercial pricing is public: Microsoft 365 E3 lists at $39.00 per user per month on an annual commitment.

If you are building the internal case before committing, start with the boundary, not the licence: our CMMC technology readiness assessment establishes the CUI boundary, tests what an assessor will actually test, and produces the evidence register your committee needs to approve the spend. You can also hire senior Microsoft architects who run CMMC readiness.

Related reading from i3Solutions

Frequently asked questions

Is Office 365 CMMC compliant?

No. CMMC certifies organizations, not products, so no software can be CMMC compliant. Beyond that, Office 365 is only part of the stack: Microsoft’s plan table reads “Microsoft 365 E3 (includes Office 365 E3),” meaning Microsoft 365 is the superset. Office 365 gives you Exchange Online, SharePoint Online, OneDrive and Teams, and it can carry content-side requirements such as AU.L2-3.3.1 on audit logs and SC.L2-3.13.16 on protecting CUI at rest. It does not include Microsoft Intune, Microsoft Entra ID P1 or P2 for Conditional Access, or Microsoft Defender for Endpoint, so the Configuration Management family and most endpoint access control have no enforcement point in an Office 365 tenant.

What is the difference between Office 365 and Microsoft 365 for CMMC?

Microsoft 365 contains Office 365 and adds the control planes CMMC leans on. Microsoft’s plan-options table lists the enterprise family as “Microsoft 365 E3 (includes Office 365 E3)” and “Microsoft 365 E5 (includes Office 365 E5).” The additions that matter are Microsoft Intune for device management and configuration baselines, Microsoft Entra ID P1 or P2 for Conditional Access and MFA enforcement, and Microsoft Defender for Endpoint. Microsoft’s Intune licensing documentation says organizations get Intune “as part of a Microsoft 365 bundle,” and it names Microsoft 365 plans, not Office 365 plans.

Can Office 365 Commercial store CUI?

Treat that as a contractual question, not a product one. DFARS 252.204-7012(b)(2)(ii)(D) requires that any external cloud service provider used to store, process or transmit covered defense information “meets security requirements equivalent to those established by the Government for the FedRAMP Moderate baseline,” and paragraphs (c) and (e) put the 72-hour DIBNet reporting duty and the 90-day media preservation duty on you regardless of environment. Your CUI type and your contract clauses decide the environment. Many contractors who assume they need GCC High do not, and some who assume Commercial is fine are wrong.

Is Office 365 GCC High CMMC compliant?

No, for the same reason: no product is. And there is a specific trap here. Buying Office 365 GCC High rather than Microsoft 365 GCC High moves the same incomplete SKU into a government cloud. The environment changes; the missing control planes do not appear. If you are migrating for CMMC, confirm you are buying the Microsoft 365 bundle.

Which CMMC Level 2 requirements can Office 365 satisfy?

Content-side ones. Office 365 is a genuine enforcement point for parts of Audit and Accountability (AU.L2-3.3.1, AU.L2-3.3.2 via Microsoft Purview Audit), protecting CUI in transit and at rest (SC.L2-3.13.8, SC.L2-3.13.16), collaboration-layer access control (AC.L2-3.1.1, AC.L2-3.1.2 via SharePoint and Teams permissions and sensitivity labels), and malicious-code protection for mail and collaboration (SI.L2-3.14.2 via Defender for Office 365). It cannot carry removable-media control (MP.L2-3.8.7), the Configuration Management family, or endpoint protection, all of which are device controls.

Do I need PreVeil or a similar enclave to be CMMC compliant on Office 365?

Not necessarily, and it is worth understanding what that pattern does. An encrypted enclave overlay achieves compliance by routing CUI around Office 365 rather than through it, shrinking your assessment boundary by taking Office 365 out of the CUI path. For a small contractor with narrow CUI flows that can be legitimate and cost-effective. It is not the only option: Microsoft 365 GCC High and Microsoft 365 GCC with documented compensating controls are the other two. The trade you are making is a second system for your users and a boundary an assessor will probe hard, because any CUI that leaks back into Office 365 is a finding.

Who helps defense contractors scope Office 365 inside a CUI boundary?

i3Solutions plans and runs governed Microsoft 365 and Azure work for compliance-bound organizations, with dedicated compliance specialists covering CMMC within Microsoft environments. A CMMC Level 2 implementation for a defense contractor with a defined CUI boundary typically ranges from $45,000 to $75,000. Where SharePoint customizations are in scope, full migration project cost for defense contractors with SharePoint customizations and CMMC compliance scope typically lands in the $100,000 to $300,000 range.

Michael Branson, Founder/COO, i3Solutions

About the Author

Michael Branson, Founder / COO, i3Solutions. LinkedIn

Michael Branson co-founded i3Solutions 30 years ago and brings executive, operational, and technical perspective to organizations working in secure and compliance-bound environments, including CMMC-scoped and defense supply-chain programs.