Skip to content
Pro IT NW

Industries / Defense Contractors

GCC High, CMMC, and NIST 800-171.
Built for the obligation the pause didn't lift.

Mid-market defense contractors and DoD suppliers. We assess your CUI exposure, recommend the right tenant (commercial / GCC moderate / GCC High / hybrid enclave), and migrate or harden against NIST 800-171 — without partner-badge incentives bending the recommendation.

CMMC Phase 2 — the milestone scheduled for Nov 10, 2026 — was suspended on July 13, 2026, and Phases 3 and 4 are paused. The audit is paused; the obligation is not. DFARS 252.204-7012 and your NIST 800-171 self-attestation still bind, and with no assessor checking the work, your SPRS score carries more weight, not less.

The Phase 2 suspension

The audit is paused. The obligation is not.

CMMC 2.0's final rule (32 CFR Part 170) was published in October 2024 and phases in over three years. On July 13, 2026 the Department of War suspended Phase 2 — the milestone scheduled for November 10, 2026 — and paused the Phase 3 and Phase 4 milestones behind it. The rule itself was not amended, and the underlying contractual requirements were not withdrawn.

The phased rollout is on hold above Phase 1. The November 10, 2026 Phase 2 milestone is suspended, Phases 3 and 4 are paused, and program offices are barred from designating Level 2 or Level 3 assessments while the suspension stands. Read them as paused, not cancelled — and note that the rule's own phase ladder is what determines what you are still on the hook for today:

Phase 1 — still in force. Per 32 CFR §170.3, DoD "intends to include the requirement for CMMC Statuses of Level 1 (Self) or Level 2 (Self)" as a condition of contract award. This is the self-assessment stage, and nothing about the suspension removes it. If a solicitation asks you for a Level 1 or Level 2 self-assessment and an affirmed SPRS score, that is Phase 1 working as designed.

Phase 2 — suspended. This is the phase that would have added the third party. Section 170.3 says DoD "intends to include the requirement for CMMC Status of Level 2 (C3PAO)… as a condition of contract award," with discretion to defer it to an option period instead. That C3PAO requirement — scheduled for November 10, 2026 — is what the memoranda issued on July 13, 2026 suspended.

Phases 3 and 4 — paused behind it. These layered in Level 2 (C3PAO) and Level 3 (DIBCAC) requirements more broadly. They are in abeyance, not withdrawn.

The distinction between Phase 1 and Phase 2 is the one worth being precise about, because it is the difference between "assess yourself and affirm it" and "pay an assessor." Only the second was suspended. For the memoranda themselves, see our breakdown of the suspension.

There were two memoranda on July 13, 2026, not one: the CIO memo that suspended Phase 2 and established a CMMC Reform Task Force, and a separate implementation memo from the Under Secretary of Defense for Acquisition and Sustainment directing contracting officers on how to handle solicitations and existing contracts. If your contract already carries a clause above Phase 1, that second memo is the one your contracting officer is working from — and it is worth asking whether the clause is being removed by modification or left in place until an option period.

What still binds today: DFARS 252.204-7012, and the NIST 800-171 self-attestation behind your SPRS score. That score is a representation to the government. With the third-party assessment gate removed, nobody is independently checking it before award — which makes an inflated score a larger False Claims Act exposure than it was when a C3PAO was going to catch it.

The practical math has not changed as much as the headline suggests. The lead time on a clean GCC High migration plus L2 readiness for a 100–300-user shop is still 6–12 months, and the reform review that produced this pause is scoped in months. A firm that treats the suspension as permission to stop is betting that the replacement date lands more than a year out. A firm that uses the pause to close its 800-171 gaps is fixing an obligation it already carries.

The framework on this page is for buyers who already know they need to act. The goal is not to convince you the deadline matters — it's to map your environment to the right tenant strategy, the right control framework scope, and a defensible remediation plan.

CMMC levels

L1, L2, L3 — and which one is yours.

Most mid-market defense contractors land at L2. L1 applies if you only handle FCI (no CUI). L3 is reserved for top-tier suppliers on the highest-priority programs.

Level Applies to Controls Assessment Typical audience
Level 1 FCI only 17 practices Annual self-assessment Subcontractors handling Federal Contract Information without CUI
Level 2 CUI 110 NIST SP 800-171 controls Self or C3PAO third-party (program-dependent, eventually C3PAO for all) Most mid-market defense contractors and prime suppliers
Level 3 CUI on highest-priority programs 110 + ~24 NIST 800-172 enhanced practices Government-led (DIBCAC) Top-tier defense suppliers and DIB-priority programs

Tenant decision

Commercial / GCC / GCC High / hybrid.

The tenant decision drives the entire migration. Wrong tenant choice in either direction is expensive: GCC High you didn't need (over-licensed, feature-limited) or commercial when you needed GCC High (compliance failure, contract risk).

M365 Commercial

Fits when

FCI-only contractors. CUI-free environments. Self-attesting Level 1 customers.

Breaks when

Any CUI that triggers ITAR / EAR. Any contract that requires GCC High flow-down. Any prime that requires GCC High.

GCC (Moderate)

Fits when

CUI-handling contractors whose CUI does not include ITAR-controlled items. Some federal civilian work.

Breaks when

ITAR-controlled CUI. Non-US-citizen administrative access. EAR-restricted technology data.

GCC High

Fits when

ITAR-controlled CUI. EAR-restricted data. Primes that require GCC High flow-down. The conservative answer when classification is ambiguous.

Breaks when

Cost-sensitive shops with no actual ITAR/EAR exposure. Customers that need full Microsoft 365 feature parity (some commercial features lag in GCC High).

Hybrid (commercial + GCC High enclave)

Fits when

Larger orgs where most of the business is non-CUI but a specific division or program handles CUI. Keeps cost down on the non-CUI side.

Breaks when

Operational complexity is high — two tenants, two sets of identity, two licensing models, careful data-flow controls. Not a fit for shops without dedicated IT capacity.

The control framework

NIST SP 800-171 — 14 control families.

The 110 controls in 800-171 organize into 14 families. The implementation work in M365 is uneven — some families are 90% configuration (Access Control, Audit, I&A); some are 90% process and documentation (Awareness, Personnel, Risk Assessment). 800-172 (24 enhanced practices for L3) adds 'advanced persistent threat' protections on top.

3.1

Access Control

Conditional Access, MFA enforcement, privileged-access model, role separation

3.2

Awareness & Training

Documented role-based training cadence, evidence retention

3.3

Audit & Accountability

Tenant audit logging, Sentinel ingestion, retention policy alignment

3.4

Configuration Management

Baseline configuration documentation, change management evidence

3.5

Identification & Authentication

Phishing-resistant MFA (FIDO2 / hardware tokens for privileged accounts)

3.6

Incident Response

IR plan, tabletop exercises, evidence of dry runs

3.7

Maintenance

Maintenance logging, remote-maintenance controls, patch management evidence

3.8

Media Protection

Removable-media controls, sanitization documentation

3.9

Personnel Security

Background screening evidence for CUI access, separation procedures

3.10

Physical Protection

Facility access controls, visitor logs (mostly out-of-scope for cloud, in-scope for any on-prem)

3.11

Risk Assessment

Vulnerability scanning evidence, risk-register maintenance

3.12

Security Assessment

Self-assessment, POAM (Plan of Actions and Milestones)

3.13

System & Comm Protection

Encryption-at-rest and in-transit, FIPS 140-2 modules where required, network segmentation

3.14

System & Information Integrity

Defender / EDR coverage, vulnerability remediation cycle, monitoring

Where this work lands

Environment shapes we work in.

Not a client list — the shapes these environments take, and what the work is in each. We're under NDA on most of it.

Precision-machining defense supplier

Commercial → GCC High migration. ITAR-tagged file shares, CUI scoped to engineering and quality.

Aerospace components supplier

GCC High migration + CMMC L2 readiness. Hardware MFA tokens, accounting integration, file-share dual-track.

Systems integrator (defense + federal civilian)

Hybrid tenant strategy. Federal civilian work in GCC moderate, defense CUI work in a GCC High enclave. POAM-driven remediation.

Engineering firm, FCI-only

Stayed on M365 commercial. CMMC L1 self-assessment readiness — Conditional Access, audit logging, baseline hardening.

Why labor-only matters in govcon

No license overselling. No partner-badge bias on the tenant decision.

Most GCC High migrations are sold by firms that earn margin on the licenses. That's not inherently wrong — but the tenant decision is the highest-leverage decision in the project. Asking a license-resale firm whether you need GCC High is asking the wrong person. We don't carry that incentive.

We've moved customers to GCC High and we've kept customers off GCC High when their data classification didn't actually require it. Both are correct calls in the right context. The wrong incentives push every customer toward the higher SKU regardless. Labor-only is the alignment.

Licensing flows through your existing Microsoft contracting — CSP, EA, MCA-E, or Microsoft Direct. We do the engineering work. The license invoices come from someone else. That separation is the point.

FAQ

Common questions from defense buyers.

What does CMMC Phase 2 (Nov 10, 2026) actually require?

As of July 13, 2026, nothing — it is suspended. A Department of War memo suspended CMMC Phase 2, the milestone scheduled for November 10, 2026, and paused the Phase 3 and Phase 4 milestones behind it. Program offices are barred from designating Level 2 and Level 3 assessments during the suspension. What did not change is the part that matters most: DFARS 252.204-7012 still binds, and your NIST 800-171 self-attestation — the SPRS score you submit — is still a live contractual obligation. With no third-party assessor reviewing the evidence, an inflated SPRS score is a larger False Claims Act exposure than it was before, not a smaller one. The reform review's public RFI closed on August 14, 2026, and as of August 18, 2026 no results had been published. The CMMC Reform Task Force was given 60 days from the July 13 action — pointing to roughly mid-September 2026 — but no due date is printed in either memo; treat any replacement date as unset until the department publishes one.

Do we have to move to GCC High?

Not always. GCC High is required when you handle CUI that falls under ITAR, certain export-controlled categories, or when your prime requires it contractually. For some FCI-only contractors and some CUI-handling firms whose data does not trigger ITAR / EAR, M365 commercial with appropriate hardening can support CMMC L2 — but the bar is high and the audit trail is tighter. We assess the data classification first, then recommend the tenant. The wrong answer (GCC High you didn't need, or commercial when you needed GCC High) is costly in opposite directions.

What about CMMC Level 1 vs Level 2 vs Level 3?

Level 1 (17 practices) applies to contractors handling FCI only — no CUI. Self-assessment annually. Level 2 (110 NIST 800-171 controls) applies to contractors handling CUI. Self-assessment for some contracts, third-party (C3PAO) assessment for others, eventually for all CUI contracts. Level 3 (110 + ~24 NIST 800-172 enhanced practices) applies to the highest-priority programs — DIB-Top, certain prime suppliers. Government-led assessment. The vast majority of mid-market defense contractors are L2.

How long does GCC High migration take for a 100–300-user shop?

Typical: 12–18 weeks for a 100-user shop, 16–22 weeks for 300 users. Drivers: tenant provisioning timeline (Microsoft has its own SLAs in GCC High that aren't in commercial), ITAR/EAR personnel screening, file-share migration with PHI-equivalent CUI tagging, on-prem AD-to-Entra hybrid, and the standard tenant-to-tenant migration carve-outs. The hardest part is rarely technical — it's the governance work around what's actually CUI vs FCI vs neither.

Are you a Microsoft GCC High partner?

We're labor-only. We don't carry a partner badge for GCC High and we don't resell GCC High licensing. The licensing flows through your existing Microsoft contracting (CSP, EA, MCA-E) or Microsoft Direct. We engineer the migration and the configuration. No license-overselling incentive on our side — including no incentive to push a customer toward GCC High when GCC moderate or commercial would actually meet their CMMC requirement.

Our prime is asking for CMMC compliance now. Does the suspension change that?

No — and this is now the common case. Many primes flow CMMC requirements down in their own contracts independently of the federal phasing, because they want assessed suppliers in their pipeline before they need them. A suspended federal milestone does not rewrite a contract you have already signed with a prime. The work is the same regardless of what triggered it. We assess your current state against 800-171, deliver a gap remediation plan, and either remediate ourselves or hand the plan to your internal team. We don't do the C3PAO assessment ourselves — that's a separate firm — but we get you ready for one.

Using the CMMC pause, or waiting it out?

Tell us your seat count, your prime, and your CUI exposure. We'll come back with a tenant recommendation and remediation timeline.