The pattern shows up on the second call, not the first. A defense contractor architected its SharePoint estate for CMMC Level 2, cleanly: a CUI site collection, sensitivity labels, Conditional Access, a documented boundary. Then a prime flowed down a Level 3 requirement on a follow-on award, and the assessor conversation moved from “do you have the control” to “show me the evidence for each requirement objective, per asset, and hash the artifact so we can prove it was not altered.” The controls existed. The information architecture could not produce evidence at that grain, because it was designed to pass a Level 2 self-assessment rather than to survive a DIBCAC certification assessment. Nothing was broken. It was built one tier below the question it was about to be asked.
Who builds SharePoint solutions that meet CMMC Level 3 requirements?
Three kinds of firm: a large federal systems integrator, a CMMC-focused security consultancy, or a Microsoft delivery firm with a compliance practice. Whichever of the three you shortlist, require two things in writing before you sign. First, delivery evidence against named control families in NIST SP 800-171 and a GCC High tenant boundary, because 32 CFR 170.14(c)(3) makes Level 2 identical to NIST SP 800-171 R2 and 170.18(a) makes a Final Level 2 (C3PAO) status a prerequisite to a Level 3 assessment. Second, a written method for producing evidence per requirement objective. Discount any builder claiming Level 3 certification past performance, and take the Level 2 and NIST SP 800-171 artifact set as the evidence standard instead. Under 32 CFR 170.18(c)(6)(ii) an external service provider’s services are assessed inside your assessment, so the builder’s documentation discipline becomes your findings.
1. What Level 3 actually adds over Level 2, from the rule itself
Level 3 is not a stricter reading of Level 2. It is a different requirement set, layered on top, assessed by a different party. The four facts that change the architecture, all from 32 CFR Part 170:
- The requirement source changes. Section 170.14(c)(3) states that “The security requirements in CMMC Level 2 are identical to the requirements in NIST SP 800-171 R2.” Section 170.14(c)(4) states that “The security requirements in CMMC Level 3 are selected from NIST SP 800-172 Feb2021, and where applicable, Organization-Defined Parameters (ODPs) are assigned.” Table 1 to 170.14(c)(4) lists 24 selected requirements with DoD parameters filled in.
- The assessor changes. Level 2 certification is a C3PAO assessment. Per 170.18(a)(1) the Level 3 certification assessment “will be performed by DCMA DIBCAC ( www.dcma.mil/DIBCAC ) on behalf of the DoD”. Level 2 is a gate: “A CMMC Status of Final Level 2 (C3PAO) for information systems within the Level 3 CMMC Assessment Scope is a prerequisite to undergo a Level 3 certification assessment.”
- The cadence doubles. The Level 3 certification assessment “must be performed every three years for all information systems within the Level 3 CMMC Assessment Scope”. Because Level 2 compliance is a prerequisite, “a Level 2 (C3PAO) certification assessment must also be conducted every three years to maintain CMMC Level 3 (DIBCAC) status”. Recertification pulls a new Level 2 assessment with it.
- The evidence becomes a hashed artifact set. The eMASS submission includes a “Result for each security requirement objective” and a “List of the artifact names, the return value of the hashing algorithm, and the hashing algorithm used.” To show artifacts have not been altered, “the OSC must hash the artifact files using a NIST-approved hashing algorithm.”
Two of the 24 requirements land on the SharePoint boundary directly (32 CFR 170.14(c)(4), Table 1, items (i) and (ii)). AC.L3-3.1.2e requires you to “Restrict access to systems and system components to only those information resources that are owned, provisioned, or issued by the organization.” AC.L3-3.1.3e requires you to “Employ secure information transfer solutions to control information flows between security domains on connected systems.” Several more reach the estate indirectly, and section 2 maps them.
The current program state matters and is easy to get wrong. The DoD CIO CMMC program page, read 2026-08-19, states that “On July 13, 2026, the Department of War announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which was originally scheduled for November 10, 2026. All Phase I self-assessment requirements remain firmly in place.” The About CMMC page adds that “CMMC implementation is paused in Phase 1” and that during this period “the DoW will enforce cybersecurity compliance with NIST 800-171 Rev 2 through self-assessments and select government-led assessments”. It also states that the action “does not eliminate the requirement for companies to protect information in accordance with DFARS clause 252.204-7012”. So the Level 3 requirement text is codified and stable, the contractual trigger for Phase II is suspended pending review, and the 800-171 obligation is untouched. Design for the codified requirement, schedule the certification against the program state.
2. The SharePoint and GCC High decisions the Level 3 requirement set reaches
Most of the 24 Level 3 requirements are not SharePoint controls. They are enterprise controls that your SharePoint design either supports or quietly defeats. The ones that change a build:
- Device trust becomes a hard gate, not a policy preference (AC.L3-3.1.2e). Restricting access to organization-owned or issued resources means Conditional Access requiring a compliant or hybrid-joined device for SharePoint and OneDrive. It also means SharePoint’s own unmanaged-device access control set to block or browser-only for the CUI sites. Two settings, one gate. A design that assumes contractor-owned laptops reach a CUI library through a browser session will not survive this requirement.
- Cross-boundary sharing becomes a mechanism, not a setting (AC.L3-3.1.3e). A secure information transfer solution between security domains is the honest name for the commercial-tenant-to-GCC-High problem. Native cross-tenant SharePoint sharing is not that mechanism. You need a defined transfer path with logging on both sides, and the collaboration model has to be designed around it, because engineering teams will otherwise route around it with email.
- The solution inventory becomes an authoritative source (CM.L3-3.4.1e and CM.L3-3.4.3e). These require an “authoritative source and repository” for approved and implemented system components, plus “automated discovery and management tools to maintain an up-to-date, complete, accurate, and readily available inventory of system components.” Translated to a SharePoint estate: a governed provisioning catalog, a tracked inventory of site templates, SPFx packages, Power Platform solutions, and third-party add-ins in the CUI scope, generated automatically. A spreadsheet maintained by one architect is the finding.
- The enclave decision becomes an isolation control (SC.L3-3.13.4e). The requirement permits “physical isolation techniques or logical isolation techniques or both” in organizational systems and system components. That is where the separate-tenant versus separate-site-collection argument gets resolved on evidence rather than preference. Preference loses. Logical isolation is allowed, so a well-labeled site collection with its own Conditional Access, DLP, and sharing posture can carry the argument, provided the boundary is documented and testable.
- Your design rationale becomes SSP text (RA.L3-3.11.4e). The requirement is to “Document or reference in the system security plan the security solution selected, the rationale for the security solution, and the risk determination.” A SharePoint architecture with no written rationale for each choice is not a documentation gap at Level 3. It is a missed requirement. It is the thing a builder most often leaves behind unfinished.
- Test and lab environments come into scope (SI.L3-3.14.3e). Specialized assets “including IoT, IIoT, OT, GFE, Restricted Information Systems, and test equipment” must be in scope or segregated into purpose-specific networks. Every SharePoint programme has a dev or UAT tenant holding a copy of a production library. That copy either carries the CUI posture or it gets segregated and proven separate.
- Custom code enters the penetration test (CA.L3-3.12.1e). Annual penetration testing “or when significant security changes are made to the system” now covers your SPFx web parts, your Power Platform connectors, and any custom API in the boundary. Build them expecting to be tested, and budget the remediation window.
- The cloud service baseline is explicit, and your on-premises footprint follows it in (170.18(c)(5)). The OSC “may utilize a CSP product or service offering that meets the FedRAMP Moderate (or higher) baseline.” Use of a CSP “does not relieve an OSC of its obligation to implement the 24 Level 3 security requirements”. Inheritance is not exemption. Where requirements are inherited you must produce a “Customer Implementation Summary/Customer Responsibility Matrix (CIS/CRM) and associated Body of Evidence (BOE).” Per 170.18(c)(5)(iii), “the OSC’s on-premises infrastructure connecting to the CSP’s product or service offering is part of the CMMC Assessment Scope.” A hybrid SharePoint Server farm feeding the cloud estate is in scope, not adjacent to it.
3. Information architecture and audit-trail design that can evidence a control
The estate that fails here usually passes every control test first. It has the labels, the Conditional Access rules and the documented boundary, and it still cannot produce a result per requirement objective without a manual reconstruction. The requirement that reshapes information architecture is not a control at all. It is the submission format: a result for each security requirement objective, with hashed artifacts. That forces four design decisions upstream of any site build.
- Classify at the item, not the folder. Sensitivity labels with auto-labeling on the CUI categories you actually hold, plus a managed metadata column carrying the CUI category and the contract it arrived under. The test is whether a single query can enumerate every CUI item in the boundary and return which requirement objective covers it. Folder-tree permissioning cannot answer that question, and folder trees are what legacy estates are made of.
- Design permissions to be describable in one page. Container-level labels on sites and Teams, permissions through Entra groups only, no broken inheritance below the library, no “Everyone except external users” anywhere in the boundary, external sharing off at tenant level with per-site exceptions logged and reviewed. The reason is evidentiary rather than aesthetic. An assessor reads your access model as a claim and then samples it.
- Treat the audit log as a retained artifact, not telemetry. Purview Audit at the tier that gives you the retention you need, audit retention policies scoped per workload, and an export path that produces a file you can hash. Since the eMASS submission carries artifact names with hash values, your evidence pipeline has to produce immutable files on a schedule, not screenshots taken during assessment week.
- Make the evidence package a deliverable of the build. One folder per requirement objective, each holding the artifact, the generating query or script, the date, and the hash. Built during the project this costs a few hours per sprint. Reconstructed later, it is the most expensive item in a certification budget, because the people who made the decisions have moved on and the rationale was never written down.
i3solutions runs migrations against named control families across CMMC, HIPAA, SOC 2, and NIST 800-171, producing artifacts auditors can review. That is the method this section describes, stated at the tier it has actually been delivered.
4. Migration sequencing for a CUI enclave
Sequence matters more than tooling, because two of the steps are irreversible in practice. Content moved into an enclave before it was classified stays there, and permissions replicated during a migration become the baseline nobody revisits.
- Inventory and categorize before you scope. CMMC scoping is asset-based. You cannot draw a boundary around content you have not categorized, and the DoW CUI Registry is the authority for which categories you hold.
- Decide the tenant boundary on the export-control question, not the price. If the estate holds ITAR or export-controlled technical data, that decision is largely made for you. If it does not, a commercial tenant with a rigorous overlay is a legitimate answer and a cheaper one.
- Stand up labels, DLP, and Conditional Access before content arrives. Labeling on ingest is one pass. Labeling after the fact is a remediation project with a discovery phase.
- Remediate permissions in the source, then move. Broken inheritance, orphaned groups, and stale guest access all migrate faithfully. Fix them where the business owners still remember why they exist.
- Move by business function in waves, with a read-only source period. Each wave produces its own evidence set. Keep the source readable and frozen for a defined window, then decommission on a date rather than on sentiment.
- Write the SSP sections as the waves land. Each architectural decision gets its rationale and risk determination recorded while it is fresh, which is exactly what RA.L3-3.11.4e asks for.
- Sequence the assessments in the order the rule requires. Final Level 2 (C3PAO) on the systems in the Level 3 scope first, then the DIBCAC Level 3 assessment. And note the scope constraint in 170.18(c)(1)(i): “The CMMC Assessment Scope for the Level 3 certification assessment must be equal to, or a subset of, the CMMC Assessment Scope associated with the OSC’s Final Level 2 (C3PAO).” A Level 3 scope drawn wider than the Level 2 scope is a restart, not a variance.
On cost, i3solutions publishes attested bands for the work that sits underneath a Level 3 ambition. A CMMC Level 2 implementation for a defense contractor with a defined CUI boundary typically ranges from $45,000 to $75,000, covering the Compliance Manager baseline assessment, Conditional Access redesign, DLP policy build and testing, Purview Audit Premium configuration, and post-implementation documentation. Full migration project cost for defense contractors with SharePoint customizations and CMMC compliance scope typically lands in the $100,000 to $300,000 range. For the GCC High move considered on its own, the attested band reads: “Implementation costs for a GCC High migration typically range from $75,000-$150,000 for this organization size, including data migration and compliance configuration.” That band travels with the organization size it was scoped against, so read it as an order of magnitude for planning rather than as a quote. None of these three bands price a Level 3 certification assessment, which is a DIBCAC engagement rather than an implementation.
5. How to vet a builder, and what an honest builder can claim
The vetting question that separates candidates fastest is not about certifications. It is about what happens to their work inside your assessment.
- Ask the external service provider question first. Under 170.18(c)(6)(ii), for an ESP that is not a CSP, “The ESP services used to meet OSC requirements are assessed within the scope of the OSC’s assessment against all Level 2 and Level 3 security requirements.” Your builder’s practices are inside your assessment. Ask for their service description and their customer responsibility matrix as a procurement artifact, not as a courtesy.
- Ask what they hand you per requirement objective. A builder who has done this work will describe a folder structure and a hashing step without being prompted. A builder who has not will describe a report.
- Ask which control families they have built against, and make them state the tier. “We do CMMC” is not an answer. “We have implemented these families of NIST SP 800-171 R2, in these environments, and here is the artifact set” is one.
- Ask who writes the SSP language. If the answer is “your compliance team, from our documentation,” find out what that documentation looks like before signing. Rationale and risk determination are requirements, and translating an architect’s intent into SSP prose after the fact is the most reliably underestimated task in this kind of programme.
- Discount any claim of Level 3 certification past performance. Level 3 status is achieved by an OSC on its own information systems, not by a builder on a client’s behalf, and the certification path runs through DIBCAC. With Phase II suspended and implementation paused in Phase 1, a vendor marketing broad Level 3 delivery experience is describing something the program has not yet issued at volume. What is verifiable today is Level 2 and NIST SP 800-171 delivery, GCC High tenant work, and a documented control-family method. Ask for that, and treat a firm that offers you more than the program can support as a firm that will also overstate your readiness.
Where i3solutions sits, stated at its actual tier
i3solutions does not hold a CMMC Level 3 certification and does not claim Level 3 past performance. Our attested delivery evidence is at the Level 2, NIST SP 800-171, and GCC High tier, which is the foundation a Level 3 scope is built on and the prerequisite the rule names.
i3solutions has delivered enterprise SharePoint consulting for defense contractors and a federal research agency. Our teams maintain dedicated compliance specialists who understand CMMC, HIPAA, SOC 2, and financial services regulations within Microsoft environments, providing audit trail documentation and access control frameworks that reduce audit preparation time by 60%. On the platform side, the GCC High and CUI enclave work described above is the same work priced in the bands in section 4.
If your requirement is a Level 3 certification assessment, your counterparties are DIBCAC for the assessment and a C3PAO for the Level 2 prerequisite. What a delivery firm contributes is the architecture, the migration, and the evidence set the assessment reads. That is the scope we take.
Frequently asked questions
Does i3solutions have CMMC Level 3 experience?
No, and no builder should tell you otherwise without naming a specific DIBCAC-assessed environment. i3solutions has delivered enterprise SharePoint consulting for defense contractors and a federal research agency. Separately, i3solutions runs migrations against named control families across CMMC, HIPAA, SOC 2, and NIST 800-171, producing artifacts auditors can review. We manage GCC High migrations end-to-end: from eligibility validation and licensing coordination with your AOS-G supplier through identity architecture, data migration, security baseline configuration, and post-migration governance. i3Solutions plans and runs these migrations for regulated defense organizations, structuring each phase around the compliance evidence assessors expect. i3solutions has deployed Power BI inside a GCC High tenant and inside Azure Government for a federal customer. i3solutions maps your Microsoft environment against CMMC Level 2 (110 controls), HIPAA administrative safeguards, and SOC 2 access control frameworks, producing audit-ready documentation that satisfies assessors, not just internal IT teams. That is the tier the rule makes a prerequisite for Level 3, so it is the relevant experience, but it is Level 2 experience and we state it that way.
Do I need GCC High for CMMC Level 3?
Not automatically. 32 CFR 170.18(c)(5) requires a cloud service offering meeting “the FedRAMP Moderate (or higher) baseline,” or security requirements equivalent to it in accordance with DoD policy. GCC High is the usual answer when ITAR or export-controlled technical data is in the boundary. Where it is not, a commercial tenant with a documented overlay can meet the baseline requirement, and the decision should be made on the data you hold rather than on the level number.
Can we go straight to Level 3 and skip the Level 2 certification?
No. Section 170.18(a) makes a CMMC Status of Final Level 2 (C3PAO) on the systems in the Level 3 scope a prerequisite, and the Level 3 scope must be equal to or a subset of that Level 2 scope. Level 2 also has to be reassessed every three years to keep Level 3 status current.
Does the Phase II suspension mean we can stop working on this?
No. The DoD CIO CMMC program page, read 2026-08-19, states that “All Phase I self-assessment requirements remain firmly in place”. The About CMMC page, read the same day, states that “the DoW will enforce cybersecurity compliance with NIST 800-171 Rev 2 through self-assessments and select government-led assessments”, and that the action “does not eliminate the requirement for companies to protect information in accordance with DFARS clause 252.204-7012”. The Level 2 work is unchanged. What has moved is the contractual trigger for the higher-tier certifications.
Will our SharePoint customizations be in the Level 3 assessment scope?
If they process, store, or transmit CUI, yes, and so will the environments that hold copies of them. CM.L3-3.4.1e and CM.L3-3.4.3e require an authoritative, automatically maintained inventory of system components, CA.L3-3.12.1e brings them into annual penetration testing, and SI.L3-3.14.3e pulls test equipment into scope unless it is segregated and proven separate. Inventory the custom surface early. It is usually larger than the architecture diagram suggests.
The two decisions this comes down to, and what settles them
Most people reading this are deciding two things at once: whether their current SharePoint estate can carry a Level 3 scope, and whether the firm they already use can build to that standard. Both are answerable in one session with the right inputs. Bring the asset inventory if you have one, the tenant topology, the CUI categories in play, and the contract language that raised the question. Thirty minutes is enough to tell you whether you are looking at a documentation gap, an information architecture rebuild, or a tenant boundary decision, and those three have very different costs.
You will get a straight read either way, including the read that your Level 2 posture is sound and the Level 3 question is premature given the program pause. That answer is free and it is often the correct one.