Short answer. Most defense contractors do not need GCC High in order to pass a CMMC Level 2 assessment. Microsoft’s own guidance is that the need for CMMC certification is not a deciding factor for choosing your cloud environment. What forces GCC High is export controlled data under ITAR or EAR, a DISA Impact Level 4 requirement, DoD controlled unclassified information, or a contract clause that names the environment. If none of those apply to you, GCC is the environment Microsoft calls its hero offering. And Microsoft does not publish a public per user list price for GCC High, so any figure you have been quoted came from a partner price sheet, not from Microsoft.

This page answers the three questions defense and federal buyers actually ask before they commit a tenant: which environment do we need, does CMMC force GCC High, and what does GCC High really cost. Every rule and figure below is sourced to Microsoft’s published licensing and service documentation or to the federal acquisition regulations themselves.

GCC vs GCC High: which Microsoft government cloud does your organization need?

Choose the lowest environment that can legally hold your data, and let the data type decide, not the sales conversation. Microsoft sells four Microsoft 365 environments, and they are not tiers of quality. They are separate accreditation boundaries with different authorizations, different purchase channels and different feature sets.

Decision criterion Commercial GCC GCC High DoD
Who it is for Any organization Government entities and sponsored contractors holding controlled information Contractors holding DoD CUI or ITAR regulated data The Department of Defense
Published authorizations FedRAMP High for services in scope FedRAMP High, DFARS, CJIS, IRS 1075, DISA SRG Level 2 FedRAMP High, ITAR, DFARS, DISA SRG Level 4 controls DISA SRG Level 5
ITAR and export controlled data No No Yes Yes
Federal Contract Information only Sufficient Sufficient More than required More than required
Non export controlled CUI Not appropriate Sufficient in most cases Sufficient More than required
Personnel handling customer data No US citizenship requirement Screened US citizens Screened US citizens, plus OFAC, BIS and DDTC list validation and fingerprint checks Adds Department of Defense IT-2 adjudication
Data storage Not guaranteed inside the United States Continental United States Continental United States Continental United States
Purchase channel Any Enterprise Agreement through an LSP, AOS-G, MPSA, Web Direct, CSP Enterprise Agreement through an LSP, or AOS-G. No Web Direct, no CSP, no MPSA Enterprise Agreement only
Trial available Yes Yes, one month, Office 365 GCC only No No
Eligibility validation required before purchase No Yes Yes Yes

Two lines in that table decide most cases. The first is ITAR. If your technical data is export controlled, GCC is off the table and the conversation is over. The second is the purchase channel. GCC High cannot be bought on a credit card, cannot be bought through a CSP reseller relationship, and has no trial tenant. Microsoft requires an eligibility validation form before the environment is established at all, and licenses are sold only through select partners: licensing solution providers transacting an Enterprise Agreement, or AOS-G partners for organizations under 500 seats.

What accepted data types actually qualify you

Microsoft validates non government organizations against a specific list. Accepted government data types include International Traffic in Arms (ITAR) data, Controlled Unclassified Information, Department of Defense Unclassified Controlled Nuclear Information, Department of Energy UCNI, Criminal Justice Information, and Department of Defense Impact Level data. An international commercial entity can qualify, but regulated data could be required to be purchased through a US subsidiary. Proof of membership in one of those groups is required. Wanting a more secure tenant is not an eligibility category.

There is no Microsoft product called GCC Moderate

GCC Moderate is not a SKU. Microsoft’s four environments are Commercial, GCC, GCC High and DoD. The word Moderate leaks in from a different document: DFARS 252.204-7012 requires that where a contractor uses an external cloud service provider to process, store or transmit covered defense information, that provider must meet security requirements equivalent to the FedRAMP Moderate baseline. Buyers hear FedRAMP Moderate, look at the government cloud that is not GCC High, and fuse the two into GCC Moderate.

The confusion is expensive, because it hides the real fact: GCC does not merely meet FedRAMP Moderate, it is authorized at FedRAMP High. So is Microsoft 365 Commercial for the services in its scope, and so are both Azure and Azure Government. The FedRAMP baseline named in DFARS is a floor that several environments clear. It is not the thing that separates GCC from GCC High. When a contract or a reseller says GCC Moderate, get it in writing whether they mean the GCC environment or simply a FedRAMP Moderate equivalent platform.

Do you need GCC High for CMMC, or is GCC Moderate enough?

CMMC by itself does not require GCC High. Microsoft is explicit: both Azure and Azure Government can help you meet CMMC obligations, you can obtain CMMC certification for solutions deployed to either environment, and the need for CMMC certification is not a deciding factor for choosing your cloud environment. CMMC is an assessment of your implementation of NIST SP 800-171 practices. It is not applicable directly to cloud services, which is why no cloud platform carries a CMMC certification of its own.

That is the opposite of what most of the market tells defense contractors, so here is the reasoning laid out. DFARS 252.204-7012 sets the cloud service provider bar at FedRAMP Moderate equivalency. GCC clears it at FedRAMP High. NIST SP 800-171 is a subset of the NIST SP 800-53 controls already assessed under FedRAMP, so a FedRAMP High baseline addresses and exceeds the 800-171 requirements. The platform is not what fails an assessment. Configuration discipline and audit evidence are.

The four things that do force GCC High

  1. Export controlled data. ITAR or EAR regulated technical data. GCC High supports ITAR. GCC does not.
  2. A DISA Impact Level requirement. GCC is authorized at DISA SRG Level 2. GCC High can demonstrate equivalency to Impact Level 4. The DoD environment is authorized at Level 5. If your contract requires IL4, GCC cannot get you there.
  3. DoD controlled unclassified information. Microsoft’s own positioning is that GCC remains the offering for every customer that does not hold FedRAMP High or DoD CUI.
  4. A contract clause that names the environment. Some primes and some programs specify GCC High in the flow down. That is a contractual obligation, and no amount of technical equivalence argument overrides it. Read the clause.

What does not get you GCC High

  • Upgrading a Commercial tenant to E5. Licensing tier and accreditation boundary are unrelated.
  • Applying Microsoft Purview sensitivity labels to CUI in a Commercial tenant. Labeling changes handling, not the authorization of the environment holding the data.
  • A reseller who says they will make your tenant compliant. GCC High requires Microsoft eligibility validation before the environment exists.
  • An Azure Government subscription on its own. Azure Government and Microsoft 365 GCC High are separate purchases in separate service families.
  • A Plan of Action and Milestones. A POA&M manages a gap. It does not create an authorization.

How much does Microsoft 365 GCC High cost, including licensing and migration?

Microsoft does not publish a public per user list price for Microsoft 365 GCC High, and we are not going to invent one. GCC High is available through Volume Licensing only, after eligibility validation, which means your real rate comes off a licensing solution provider price sheet under an Enterprise Agreement, or from an AOS-G partner if you are under 500 seats. There is no Web Direct price to look up, because there is no Web Direct channel for GCC High.

What Microsoft does publish is the price movement, and it is worth knowing before you sign. Effective July 1, 2026, Microsoft raised the government suites:

Suite Environments Increase effective July 1, 2026 Commercial anchor SKU
Microsoft 365 G3 GCC, GCC High, DoD 8 percent Microsoft 365 E3, $36.00 to $39.00 per user per month
Microsoft 365 G5 GCC, GCC High, DoD 5 percent Microsoft 365 E5, $57.00 to $60.00 per user per month
Office 365 G3 GCC 13 percent Office 365 E3, $23.00 to $26.00 per user per month
Office 365 G5 GCC 8 percent Office 365 E5, $38.00 to $41.00 per user per month

Note what that table shows and what it does not. Microsoft published percentage increases for the government SKUs and dollar figures only for the commercial anchors. The government columns carry percentage correlations to commercial rates rather than discrete dollar amounts. Anyone quoting you a precise GCC High list price per user per month is quoting a partner price sheet, and you should ask to see it.

The cost structure, which is the part nobody itemizes

Licensing is the line item you will be shown. It is rarely the line item that decides the program.

  • Suite licensing. G3 or G5 per user per month, on an Enterprise Agreement or AOS-G paper, at a rate you negotiate rather than look up.
  • Eligibility and validation. An intake form, proof of your accepted data type, and elapsed calendar time before the environment is provisioned at all. This is a schedule cost, not an invoice cost, and it lands before anything else can start.
  • Tenant build. A new tenant, new identity architecture, conditional access, device compliance, DLP, and the CUI boundary itself. GCC High supports federated multifactor authentication using PIV and CAC cards, which is capability you may need to build rather than inherit.
  • Cross cloud migration. Mailboxes, SharePoint sites, OneDrive content, Teams, and endpoint management move across a cloud boundary. Microsoft states that cross tenant OneDrive migration is not supported for Government Cloud users including GCC, GCC High and DoD, and that Power Platform tenant to tenant moves between GCC and public clouds are not supported in either direction. Third party migration tooling and a longer coexistence window are the consequence.
  • Feature loss you have to design around. Real, documented, and often discovered late. See the next section.
  • Third party tools inside the CUI boundary. Every non Microsoft tool touching CUI has to be assessed too. That is scope, and scope is cost.
  • Ongoing evidence production. A CMMC Level 2 assessment is an evidence exercise. The artifacts do not generate themselves.
  • No rehearsal environment. Microsoft offers no trial of GCC High or DoD. There is a one month trial of Office 365 GCC and nothing equivalent above it. You cannot pilot GCC High before you buy it.

How does Microsoft 365 GCC High compliance differ from Microsoft 365 Commercial?

The difference is not the feature list. It is the compliance boundary, and four things move. Commercial and GCC High run the same productivity apps; what changes is who may operate the environment, what data it is permitted to hold, which authorizations it carries, and what your contract makes you responsible for.

  • Who operates it. Microsoft 365 Commercial support personnel are not restricted to screened US persons. GCC High runs in a segregated US government environment operated by screened US persons. If your data is export controlled, that single fact is usually the whole decision, because ITAR restricts access by foreign persons regardless of how well the data is encrypted.
  • What data it may hold. Commercial is appropriate for Federal Contract Information and for CUI only in narrow, well argued cases. GCC High is the environment Microsoft positions for export controlled CUI under ITAR or EAR, for DoD CUI, and for contracts that name DISA Impact Level 4.
  • Which authorizations it carries. The comparison table above sets these out per environment. The one that governs is DISA Impact Level 4, which Commercial does not carry.
  • What you still owe either way. This is the part buyers miss. DFARS 252.204-7012(b)(2)(ii)(D) requires any external cloud service provider that stores, processes or transmits covered defense information to meet security requirements “equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline.” Paragraph (c)(1)(ii) requires you to report a cyber incident to DoD at https://dibnet.dod.mil within 72 hours of discovery, and paragraph (e) requires you to preserve images of affected systems for at least 90 days. No tenant discharges those three obligations. They are yours in Commercial and they are still yours in GCC High.

Two corrections worth making explicitly, because both cost money. CMMC does not require GCC High. The rule names no cloud environment, and a great many contractors handling non export controlled CUI meet CMMC Level 2 in GCC. And Microsoft publishes no public per user list price for GCC High. It carries a licensing premium over Commercial and is sold through Microsoft agreements and authorized partners, so any per user figure or premium percentage you have been quoted came from a partner price sheet, not from Microsoft. Treat published “GCC High costs X percent more” claims as unsourced.

One more trap that is specific to the SKU rather than the environment: buying Office 365 GCC High rather than Microsoft 365 GCC High moves an incomplete SKU into a government cloud. Office 365 has no Microsoft Intune, no Microsoft Entra ID P1 or P2 for Conditional Access, and no Microsoft Defender for Endpoint, so several CMMC requirement families would still have no enforcement point in your tenant. See Is Office 365 CMMC compliant? for that distinction, and Is Microsoft Intune CMMC compliant? for what changes on the endpoint side in GCC High.

What you actually give up when you move to GCC High

These are documented Microsoft feature differences, not opinions, and they change how people work on day one:

  • External sharing narrows sharply. Users in GCC High can share only with other organizations in GCC High.
  • Non GCC High email addresses on user profiles are not supported. Alert emails will not be delivered to them.
  • File requests are not available in Office 365 Government.
  • Phone System and Audio Conferencing are delivered via Direct Routing in GCC High and DoD. PSTN Calling and PSTN Conferencing are not available.
  • Exchange Online Unified Messaging integration with an on premises IP-PBX is not supported.
  • Viva Engage for enterprise is not available in GCC High or DoD.
  • Microsoft support is outside the accreditation boundary. Microsoft’s guidance is not to share controlled, sensitive or confidential information with customer support personnel, and states that GCC High and DoD support does not provide FedRAMP, DoD SRG, ITAR, IRS 1075 or CJIS data handling compliance assurances. Your support process needs a rule for that, in writing.

How the CMMC timeline changes the decision

The CMMC Program rule sits at 32 CFR part 170. The acquisition side is DFARS clause 252.204-7021, which became effective on November 10, 2025, and phases in across a three year period running through November 9, 2028. The clause requires a contractor to have and maintain the requisite CMMC level for the life of the contract.

The practical consequence for the environment decision: your certification level is set by the solicitation, and the assessment is of your system, not of Microsoft’s. Moving to GCC High when your data does not require it enlarges the boundary you have to assess, lengthens the migration, and removes capability from your users, without changing the level you have to certify at. Moving too late, when a contract does require it, is worse. Read the clause in the solicitation, classify your data honestly, then pick the environment.

How i3Solutions approaches this decision

i3Solutions has spent three decades building Microsoft platforms for defense industrial base and federal organizations operating under DFARS 252.204-7012 flow downs, NIST SP 800-171 obligations and export control rules. Our position on this question is deliberately unfashionable: we start by trying to keep you out of GCC High, because the cheapest compliant environment is the one that holds your data legally with the fewest capabilities removed from your users.

That means classifying the data first, reading the actual contract clauses second, and only then scoping a tenant. When GCC High is genuinely required, we treat the move as a cross cloud rebuild with a coexistence plan, an evidence plan, and a named owner for every artifact a C3PAO assessor will ask for.

Related reading from i3Solutions

Frequently asked questions

How does Microsoft 365 GCC High compliance differ from Microsoft 365 Commercial?

The difference is the compliance boundary, not the feature list. Microsoft 365 Commercial support personnel are not restricted to screened US persons, and Commercial does not carry the DISA Impact Level 4 authorization or the ITAR handling commitments that export controlled data requires. GCC High runs in a segregated US government environment operated by screened US persons, and it is what Microsoft positions for export controlled CUI under ITAR or EAR, for DoD CUI, and for contracts naming DISA Impact Level 4. What does not change is your own obligation: DFARS 252.204-7012(b)(2)(ii)(D) requires your cloud provider to meet security requirements equivalent to the FedRAMP Moderate baseline, and paragraphs (c) and (e) put the 72 hour DIBNet report and the 90 day media preservation duty on you in either tenant. CMMC itself names no environment, so many contractors handling non export controlled CUI meet Level 2 in GCC. Microsoft publishes no public per user list price for GCC High.

GCC vs GCC High: which Microsoft government cloud does our organization need?

Pick the lowest environment that legally holds your data. Microsoft 365 Commercial is appropriate only when you handle Federal Contract Information and no CUI. GCC is the right answer for most defense contractors handling non export controlled CUI: it carries FedRAMP High, DFARS, CJIS, IRS 1075 and DISA SRG Impact Level 2, and Microsoft calls GCC the hero offering for every customer that does not hold FedRAMP High or DoD controlled unclassified information. GCC High is required when your data is export controlled under ITAR or EAR, when a contract requires DISA SRG Impact Level 4, or when a clause names the environment. The DoD environment is reserved for the Department of Defense itself and is authorized at DISA SRG Impact Level 5. The working rule i3Solutions applies is to keep you out of GCC High unless one of those triggers is real, because every step up removes capability from your users and enlarges the boundary a C3PAO assessor has to examine.

Do we need GCC High for CMMC, or is GCC Moderate enough?

CMMC by itself does not require GCC High. Microsoft states that the need for CMMC certification is not a deciding factor for choosing your cloud environment, and that a contractor using an external cloud service provider to process, store or transmit covered defense information must ensure that provider meets security requirements equivalent to the FedRAMP Moderate baseline. Both Microsoft 365 Commercial and GCC exceed that bar, and Azure and Azure Government both hold FedRAMP High. So the FedRAMP baseline is not the discriminator. What forces GCC High is export controlled data under ITAR or EAR, a DISA SRG Impact Level 4 or 5 requirement, DoD controlled unclassified information, or a contract clause that names the environment. There is no Microsoft SKU called GCC Moderate. The word Moderate comes from the FedRAMP baseline named in DFARS 252.204-7012, not from a product name.

How much does Microsoft 365 GCC High cost, including licensing and migration?

Microsoft does not publish a public per user list price for Microsoft 365 GCC High. GCC High is sold only through Volume Licensing, so your actual rate comes off a licensing solution provider price sheet under an Enterprise Agreement, or from an AOS-G partner if you are under 500 seats. Microsoft does publish the price movement: effective July 1, 2026, Microsoft 365 G3 rose 8 percent and Microsoft 365 G5 rose 5 percent across GCC, GCC High and DoD alike, against commercial anchors of Microsoft 365 E3 moving from $36.00 to $39.00 per user per month and Microsoft 365 E5 moving from $57.00 to $60.00 per user per month. Migration cost is driven by the fact that GCC High is a separate tenant, not a setting on your existing one, so the work is a cross cloud tenant to tenant migration with no in place upgrade path and no trial tenant to rehearse in. Before you price the tenant, price the alternative: an environment your contracts do not actually require is the most expensive line in the program, and that is the first thing i3Solutions tries to talk a client out of.

Is GCC Moderate a real Microsoft product?

No. Microsoft sells four Microsoft 365 environments: Commercial, GCC, GCC High and DoD. Buyers say GCC Moderate because DFARS 252.204-7012 requires a cloud service provider to meet security requirements equivalent to the FedRAMP Moderate baseline, and the word attaches itself to the government cloud that is not GCC High. When a contract or a reseller says GCC Moderate, confirm in writing whether they mean the GCC environment or simply a FedRAMP Moderate equivalent platform, because those are different statements with different consequences.

Can we upgrade our existing Microsoft 365 Commercial tenant to GCC High in place?

No. GCC High is a separate environment established only after Microsoft validates your eligibility, and it is physically and virtually segmented from Commercial. Moving means standing up a new tenant and migrating identities, mailboxes, sites, files, Teams and endpoint management across a cloud boundary. That is system integration and data management work: identity mapping, content migration, and re-pointing every integration across a compliance boundary. Several of the tools you would reach for do not cross that boundary: Microsoft states that cross tenant OneDrive migration is not supported for Government Cloud users including GCC, GCC High and DoD, and that Power Platform tenant to tenant moves between GCC and public clouds are not supported in either direction. Plan the migration as a rebuild with data movement, not as an upgrade.

Sources

Every rule and figure on this page is drawn from primary documentation: Microsoft 365 Government how to buy (eligibility, validation, sales channels, LSP and AOS-G partner lists, trials, environment commitments), Office 365 GCC High and DoD service description (background screening, feature differences, support boundary), Microsoft Azure CMMC compliance documentation (FedRAMP Moderate equivalency, NIST SP 800-171 relationship, environment choice), the Microsoft 365 packaging and pricing updates effective July 1, 2026, the DFARS clause at 252.204-7012, the CMMC Program rule at 32 CFR part 170, and the DFARS clause at 252.204-7021 effective November 10, 2025.

Get the clause read before you buy the tenant

If you are being told you need GCC High, the next artifact you need is not a quote. It is a CUI data classification and a clause review: an inventory of what your organization actually holds, mapped against the DFARS and CMMC language in your live solicitations and prime flow downs, with a written recommendation of Commercial, GCC or GCC High and the reason for it.

That is a document your committee can approve against, and it is cheaper than the wrong tenant. It is also the artifact that tells you whether the migration on your roadmap has to happen at all. Bring your solicitations and your prime flow downs, and we will read them with you before anyone signs a licensing agreement.

Start with the i3Solutions senior Microsoft architects who run CMMC readiness, or request a CUI classification and clause review before you commit budget to an environment.

Michael Branson, Founder/COO, i3Solutions

About the Author

Michael Branson, Founder / COO, i3Solutions. LinkedIn

Michael Branson co-founded i3Solutions 30 years ago and brings executive, operational, and technical perspective to organizations working in complex, secure, and regulated environments. His work focuses on governance, compliance, secure operating models, and the operational discipline required to turn technology investments into practical business systems.