
Compliance
CMMC 2.0 Level 1 / 2 / 3 implementation roadmap for DoD prime + sub contractors using Microsoft 365 GCC High. Control mapping, assessment costs, timelines, and the 14 NIST 800-171 control families.

Updated: April 25, 2026 · By: Errin O'Connor, Founder & Chief AI Architect, EPC Group · Reading time: 21 min
CMMC 2.0 became enforceable for DoD contracts in late 2025. By Q1 2026, every DoD prime and sub handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) needs CMMC certification. EPC Group has supported 18 CMMC L2 implementations. This is the consolidated playbook.
Most DoD contractors target Level 2.
For CMMC L2 with CUI, GCC High is the standard. It is FedRAMP High authorized + ITAR/EAR commitments + DFARS 7012 covered. GCC alone is FedRAMP Moderate; insufficient for most CUI scenarios.
Maps directly to CMMC L2:
EPC Group's CMMC Control Mapping Workbook ties every control to a Microsoft tenant configuration or process artifact.
Identify CUI environment boundary. Most contractors over-scope; we tighten.
Map current state against 110 controls. Output: gap report with severity + remediation cost.
If not already on GCC High, migrate. Plan for 12+ weeks. Includes Exchange, SharePoint, Teams, Intune, Defender, Sentinel.
Configure tenant settings, deploy DLP, implement Insider Risk, deploy Sentinel, train users, document procedures.
Pre-assessment with EPC Group simulating C3PAO process. Output: gap closure list.
Third-party assessor evaluates. Outcome: certified or POA&M with deadlines.
For a mid-size DoD contractor (500-2,500 employees) achieving Level 2:
If you handle FCI: Level 1 minimum. CUI: Level 2. Highest-value CUI: Level 3. Some pure commercial-item contracts are exempt.
FCI = Federal Contract Information (any non-public info from federal contract). CUI = Controlled Unclassified Information (specifically marked under 32 CFR 2002).
For Level 1 only (FCI). For Level 2 (CUI), you need GCC High in most realistic scenarios.
12-18 months total for typical mid-size contractor.
CMMC governs the contractor handling government data. FedRAMP authorizes a cloud service offering. They overlap on ~80% of controls but require separate audits. Contractors using GCC High inherit FedRAMP High; CMMC adds contractor-organization-specific controls.
If the software handles CUI on behalf of a DoD customer, the customer's CMMC scope likely extends. Vendor contracts dictate exact application.
CMMC Third-Party Assessment Organization. Independent assessors authorized by Cyber AB. Contracted by you to perform L2 assessment.
Every 3 years for L2 (with annual self-attestation in between).
Azure Government inherits ~40% of CMMC controls; you implement the rest. GCC High does the same for Microsoft 365 + adds DoD-specific commitments (ITAR, DFARS 7012).
DFARS 7012 flow-down means your DoD subs need CMMC at the appropriate level. Your contracts must include flow-down clauses.
Pursuing CMMC Level 2? EPC Group has supported 18 implementations on GCC High. Schedule a CMMC readiness assessment or explore CMMC compliance services.
Founder & Chief AI Architect
29 years Microsoft consulting experience. 4-time Microsoft Press bestselling author.
View Full ProfileOur team of experts can help you implement enterprise-grade compliance solutions tailored to your organization's needs.