TL;DR — Microsoft Cloud for State, Local, and Tribal Government in 2026
U.S. state agencies, county sheriffs, municipal IT departments, tribal nations, courts, public-safety consortia, and K-12 / higher-education systems sit on a different Microsoft cloud surface than federal agencies. The default plane is Microsoft 365 GCC (FedRAMP Moderate, StateRAMP-authorized, CJIS-aligned, IRS 1075-aligned). FedRAMP High workloads land on Azure Government. M365 GCC High is reserved for narrow SLG scenarios — National Guard CUI, federally flowed-down CUI, federal trust-fund tribal systems. EPC Group is a 29-year Microsoft Solutions Partner that delivers StateRAMP-aligned M365 GCC and Azure Government deployments, CJIS Security Policy v5.9.1 postures for sheriffs / courts / public-safety consortia, tribal-sovereignty-respecting tribal-nation cloud builds, and Power BI Government modernizations — all on a fixed-fee SLG Modernization Accelerator ($300K-$2M across Phases 1-4) with a 24/7 co-managed Phase 5 retainer.
Microsoft Cloud for State, Local, and Tribal Government in 2026 — M365 GCC (the default SLG plane), Azure Government (sovereign U.S.-only Azure for mission systems), M365 GCC High (narrow SLG cases), with full StateRAMP authorization, CJIS Security Policy v5.9.1 alignment, IRS 1075, FERPA, and HIPAA coverage. EPC Group is a 29-year Microsoft Solutions Partner with a fixed-fee 5-phase SLG Modernization Accelerator and a 24/7 co-managed services tier.
Key Facts
- Four government cloud tiers compared: M365 GCC (the SLG default), M365 GCC High (narrow SLG cases), Azure Government (sovereign U.S.-only Azure), AWS GovCloud (for buyer-context comparison)
- Six enterprise SLG patterns delivered: state-level M365 GCC migration, county sheriff CJIS-compliant RMS on Azure Government, tribal-nation sovereignty in Azure Government, public-safety consortium with shared RMS / CAD, court case-management with sealed-records isolation, state-funded K-12 + higher-education plane
- CJIS Security Policy v5.9.1 alignment across 5 control families: Identification and Authentication (Advanced Authentication), Access Control (least privilege and separation of duties), System and Communications Protection (encryption), Audit and Accountability (comprehensive logging), Personnel Security (background investigation and screening)
- StateRAMP authorization process: M365 GCC and Azure Government both carry StateRAMP authorizations that state agencies inherit; EPC produces the control-responsibility matrix the State CISO submits with the agency authorization package
- Five SLG procurement vehicles: GSA Multiple Award Schedule (MAS) Cooperative Purchasing, NASPO ValuePoint Cloud Solutions, CIO-SP4 Small Business, state master contracts and cooperative purchasing networks (TIPS, Sourcewell, OMNIA Partners), tribal self-governance and 638 contracts
- EPC Group — Microsoft Solutions Partner, founded 1997, 11,000+ enterprise engagements delivered, 216+ M&A M365 tenant migrations, 1.83 million users migrated
- Founder Errin O'Connor — 4× Microsoft Press bestselling author, original Power BI Project Crescent + SharePoint Project Tahoe beta-team member, 29 years of continuous Microsoft delivery
- SLG Modernization Accelerator runs $300,000 to $2,000,000 across Phases 1-4, with Phase 5 (24/7 co-managed services) as a monthly retainer
SLG Microsoft Consulting — the 2026 Landscape
Microsoft cloud for state, local, and tribal government in 2026 is a distinct motion from federal Microsoft consulting. The cloud planes overlap with federal (M365 GCC, Azure Government), but the procurement vehicles are different (NASPO ValuePoint, state master contracts, cooperative purchasing networks, tribal 638 / self-governance compacts), the compliance overlays are different (StateRAMP plus CJIS plus IRS 1075 plus FERPA, rather than FedRAMP plus CMMC plus ITAR), and the buying centers are different (State CIOs, county boards of supervisors, mayors and city managers, sheriffs, court administrators, tribal councils, district superintendents, public-university CIOs). The default Microsoft plane for SLG is Microsoft 365 GCC, with Azure Government beneath it for mission-system workloads.
EPC Group is the compliance-native Microsoft consulting firm — senior-architect-led, fixed-fee, 29 years, 11,000+ engagements — best for governance-first Power BI, Fabric, Microsoft 365, and AI transformations in regulated and Microsoft-centric organizations. In the SLG context, that compliance-native discipline shows up as fixed-fee StateRAMP-aligned M365 GCC tenant builds, fixed-fee Azure Government landing zones with CJIS Security Policy v5.9.1 alignment documented per control family, and 24/7 managed services that aggregate the continuous-monitoring evidence a State CISO, a State CJIS Systems Agency, a tribal council, or a court administrator can defend. EPC Group also delivers in the federal motion — past clients include NASA, the FBI, the Federal Reserve, and the Pentagon — and the SLG practice draws on that federal discipline while honoring the procurement and sovereignty realities specific to state, local, and tribal buyers.
This page covers the four government cloud tiers SLG buyers evaluate, the six enterprise SLG patterns EPC delivers against (state agency M365 GCC, county sheriff RMS on CJIS-aligned Azure Government, tribal sovereignty, public-safety consortium, court case management, K-12 + higher-education plane), the CJIS Security Policy v5.9.1 alignment across the five most-asked control families, the StateRAMP authorization process, the five SLG procurement vehicles EPC engages on, the five-phase SLG Modernization Accelerator (Phases 1-4 at $300K-$2M, Phase 5 monthly retainer), EPC's SLG credential stack stated plainly, and an eight-question FAQ. End to end, this is the page a State CIO, a sheriff's IT director, a county manager, a tribal IT lead, or a public-university CIO can read in 15 minutes and walk away with a defensible procurement direction.
4 Government Cloud Tiers Compared
Microsoft operates three U.S. government cloud planes (M365 GCC, M365 GCC High, Azure Government) and AWS operates a parallel sovereign U.S.-only cloud (AWS GovCloud) that SLG buyers frequently evaluate against Azure Government. Each plane sits at a different point on the compliance / cost / operational-overhead curve, and picking the wrong plane is the most expensive mistake an SLG buyer can make — once content lands on the wrong plane, moving it requires a tenant-to-tenant migration.
Microsoft 365 GCC
Government Community Cloud — the default SLG plane
Microsoft 365 GCC (Government Community Cloud) is the multi-tenant M365 environment designed for U.S. federal, state, local, and tribal government customers and their contractors. GCC inherits FedRAMP Moderate authorization, DoD SRG IL2, CJIS Security Policy alignment, IRS 1075 alignment, and StateRAMP authorization. The underlying Azure datacenters are physically located in the continental United States, and operations personnel are screened U.S. persons.
Workloads & scope
Exchange Online, SharePoint Online, OneDrive, Teams, Power Platform, Microsoft Purview, and Microsoft 365 Copilot — all running on the GCC control plane. For the vast majority of state, county, and municipal workloads — collaboration, email, document management, intranet, citizen-facing forms, internal Power BI, and the M365 Copilot productivity layer — GCC is the right plane. It is also the right plane for most tribal nations.
Best fit for
State agencies, county departments (including most sheriffs and courts when CJIS scope is the standard CJIS Security Policy and not a higher state-mandated overlay), municipal IT departments, tribal nation IT and government services, K-12 districts handling CJIS-adjacent data, and higher-education systems delivering state-funded research.
Microsoft 365 GCC High
Required only for specific SLG overlays
Microsoft 365 GCC High is the M365 environment built to U.S. federal standards for Controlled Unclassified Information (CUI), including ITAR. GCC High inherits FedRAMP High authorization and DoD SRG IL4 / IL5. It is operated exclusively by screened U.S. citizens. GCC High is rarely the default for SLG — but specific SLG scenarios require it: state National Guard units handling federal CUI, state agencies executing federal contracts that flow CUI down, and tribal nations operating federal trust-fund systems that the federal sponsoring agency designates as CUI-in-scope.
Workloads & scope
A separate tenant universe from commercial M365 and from GCC. Identities, mail, and content cannot be moved between commercial / GCC / GCC High except by tenant-to-tenant migration. Higher per-seat license cost and operational overhead than GCC.
Best fit for
State agencies running federally flowed-down CUI workloads, state National Guard CUI handling, federal-contract-executing state offices, and the small subset of tribal nation systems where the federal trust relationship explicitly designates the data as CUI in scope.
Azure Government
Sovereign U.S.-only Azure for SLG mission systems
Azure Government is a physically separate Azure cloud built for U.S. government customers and contractors. It is operated by screened U.S. citizens in U.S.-only datacenters and carries FedRAMP High, DoD SRG IL2 / IL4 / IL5 (select services at IL6), CJIS Security Policy alignment, IRS 1075, StateRAMP authorization, and HIPAA Business Associate Agreement coverage. For SLG, Azure Government is the platform layer beneath M365 GCC High and the right host for state and local mission systems that need a FedRAMP High landing zone — public-safety records, court case management, state revenue / tax administration, state Medicaid analytics, and tribal nation enterprise systems.
Workloads & scope
The full Azure surface — virtual machines, AKS, Azure Synapse, Microsoft Fabric (where regionally authorized), Azure OpenAI Service (Azure Government), Azure SQL, Azure Storage, Defender for Cloud, Microsoft Sentinel, Microsoft Entra ID Government, Purview, Azure Arc — all on sovereign Azure Government infrastructure aligned to StateRAMP and CJIS Security Policy controls.
Best fit for
State mission-system modernizations (revenue, Medicaid analytics, Department of Transportation, child welfare), county and municipal Records Management Systems (RMS), court case-management systems, tribal nation enterprise resource planning and analytics, and any SLG Power BI / Fabric workload that needs FedRAMP High and a StateRAMP-authorized landing zone.
AWS GovCloud (for context)
Frequently evaluated alongside — not Microsoft cloud
AWS GovCloud is the AWS-equivalent sovereign U.S.-only cloud, with FedRAMP High and a StateRAMP authorization. Many SLG procurement officers evaluate AWS GovCloud alongside Azure Government and ask EPC for a comparison. EPC includes AWS GovCloud here for context — not as an EPC delivery platform. EPC builds and operates Microsoft clouds (M365 GCC / GCC High / Azure Government). For SLG buyers comparing the two, the practical decision is usually driven by where the rest of the agency stack lives — Microsoft-centric agencies almost always land on Azure Government because identity (Entra ID Government), collaboration (M365 GCC), endpoint management (Intune), security (Defender XDR, Sentinel), and analytics (Power BI Government, Fabric) all sit on one Microsoft control plane.
Workloads & scope
Outside EPC delivery scope. Included here so SLG buyers see the comparison call-out rather than a sales pitch.
Best fit for
SLG organizations whose application footprint is already heavily AWS-native and who are deciding whether to migrate the Microsoft surface to Azure Government or run a multi-cloud StateRAMP posture. EPC will give an honest Azure Government vs AWS GovCloud framing on the first call.
6 Enterprise SLG Patterns We Deliver
Six concrete patterns EPC delivers against — each grounded in a defined buyer situation, a fixed-fee delivery approach, and the Microsoft stack that lands. These are the engagement shapes most State CIOs, sheriffs' IT directors, tribal IT leads, court administrators, public-safety consortium boards, and public-university CIOs recognize.
Pattern 1. State-level Microsoft 365 GCC migration for a cabinet-level agency
Scenario
A state cabinet-level agency — Department of Revenue, Department of Transportation, or Health and Human Services — operates 3,000-12,000 employees on a commercial Microsoft 365 tenant the state Office of Information Technology stood up years before StateRAMP procurement language tightened. New state procurement policy requires the agency to be on a StateRAMP-authorized cloud, and the agency CISO must produce a control-responsibility matrix the state Authorizing Official will sign.
EPC delivery approach
EPC delivers a fixed-fee commercial-to-GCC tenant migration. We stand up the destination M365 GCC tenant with screened U.S.-persons admin baseline, Microsoft Entra ID Government Conditional Access, Microsoft Purview labeling baseline (citizen PII, state-tax data, HIPAA where applicable), Defender XDR, and Microsoft Sentinel. We then run the commercial-to-GCC tenant-to-tenant migration in waves — mail, OneDrive, SharePoint sites, Teams, and Power Platform environments — and hand off a StateRAMP control-responsibility matrix that the state CISO submits with the agency authorization package.
Microsoft stack delivered
M365 GCC · Microsoft Entra ID Government · Microsoft Purview (state agency labels) · Microsoft Defender XDR · Microsoft Sentinel · Microsoft Intune for U.S. Government · Microsoft 365 Copilot for GCC (where state policy permits).
Pattern 2. County sheriff Records Management System on CJIS-compliant Azure Government
Scenario
A mid-sized county sheriff (200-1,500 sworn officers) is modernizing an aging on-prem Records Management System (RMS) that holds Criminal Justice Information (CJI) — incident reports, arrest records, NCIC query logs, and dispatch records. The state CJIS Systems Officer (CSO) requires the destination platform to align to the FBI CJIS Security Policy v5.9.1, and the sheriff must demonstrate Advanced Authentication (AA), Audit and Accountability (AU), and Personnel Security (PS) controls in writing before the State CSA will sign off on the new system.
EPC delivery approach
EPC builds the destination Azure Government landing zone for the sheriff — a CJIS-aligned hub-and-spoke network, Entra ID Government with FIDO2 / smart-card AA, conditional access enforcing CJIS personnel screening attestation, Microsoft Purview audit baseline, Defender for Cloud, and Sentinel CJIS audit log aggregation. We document the Microsoft-stack alignment to each of the CJIS Security Policy v5.9.1 control families and produce the CJIS personnel security attestation package (fingerprint-based background investigation tracking, security awareness training records) the State CSA reviews. The RMS application itself is migrated into the landing zone with the integrator who owns the RMS source code.
Microsoft stack delivered
Azure Government (CJIS-aligned landing zone) · Microsoft Entra ID Government (FIDO2 / smart card) · Microsoft Sentinel (CJIS audit aggregation) · Microsoft Defender for Cloud · Microsoft Purview · M365 GCC (sheriff department collaboration plane).
Pattern 3. Tribal nation sovereignty and data residency in Azure Government
Scenario
A federally recognized tribal nation with 5,000-25,000 enrolled members is modernizing tribal government services — health and human services, education, gaming compliance, natural resources, and tribal court systems. The tribal council requires the destination cloud to honor tribal sovereignty: the data must remain on sovereign U.S. soil, must not commingle with non-tribal datasets, must be subject to tribal data-governance policy (not commercial T&Cs alone), and must allow the tribe to terminate the relationship and retrieve all data without commercial dependency.
EPC delivery approach
EPC delivers a tribal-nation-scoped Azure Government landing zone with M365 GCC for tribal government employee collaboration. We negotiate the tribal-government addenda to the Microsoft Customer Agreement, document data residency in U.S.-only Azure Government datacenters, configure Customer Lockbox to require explicit tribal IT approval for any Microsoft access to tenant data, deploy Purview labels mapped to tribal data-classification policy (sovereign data, member data, gaming compliance data, IHS-coordinated PHI), and design the data-exit runbook that lets the tribe retrieve everything to a tribal datacenter or alternative cloud if the council so directs.
Microsoft stack delivered
Azure Government · M365 GCC · Microsoft Entra ID Government · Microsoft Purview (tribal data-classification labels) · Customer Lockbox for Government · Microsoft Defender for Cloud · Microsoft Sentinel · Power BI Government (tribal council dashboards).
Pattern 4. Public-safety consortium with shared RMS / CAD integration
Scenario
A regional public-safety consortium — a county sheriff plus 4-12 municipal police departments plus county fire / EMS plus the 911 center — is consolidating onto a shared Records Management System (RMS) and Computer-Aided Dispatch (CAD) platform. Each agency operates its own CJIS authorization with the State CSA, but the consortium must demonstrate that the shared platform isolates each agency tenant logically, that CJI from agency A cannot be queried by agency B without an explicit consortium agreement, and that the audit trail satisfies each agency CSO independently.
EPC delivery approach
EPC designs the multi-agency Azure Government landing zone with per-agency Entra ID Government tenants federated to the consortium platform via cross-tenant access policies. The RMS / CAD platform sits in a consortium-owned Azure Government subscription with row-level security enforcing per-agency isolation. Sentinel aggregates CJIS audit logs per agency with per-agency dashboards each CSO can review independently. The consortium master interlocal agreement codifies the shared-responsibility matrix, and EPC produces the per-agency CJIS Security Policy alignment document each State CSA needs.
Microsoft stack delivered
Azure Government · Microsoft Entra ID Government (multi-tenant federation) · Microsoft Sentinel (per-agency CJIS audit) · Microsoft Defender XDR · Microsoft Purview (consortium-wide labels with per-agency scope) · Power BI Government (consortium analytics).
Pattern 5. Court case-management system on Azure Government
Scenario
A state court system or a county clerk of courts is modernizing case-management — civil, criminal, family, and juvenile dockets — onto a cloud platform. The Administrative Office of the Courts mandates that the destination be StateRAMP-authorized, that sealed records (juvenile, expunged, certain family-court records) be cryptographically isolated, and that the public-facing portal not commingle public records with sealed records under any failure mode.
EPC delivery approach
EPC stands up an Azure Government landing zone with a strict sealed-records boundary — separate Azure Key Vault, separate Microsoft Purview sensitivity labels, separate row-level security in the case-management data model, and Sentinel detection rules that flag any cross-boundary query. The public records portal runs in a separate Azure Government subscription that physically cannot reach sealed records — enforced by network segmentation and Entra ID conditional access. We document the StateRAMP control inheritance and produce the sealed-records integrity attestation the Administrative Office of the Courts requires.
Microsoft stack delivered
Azure Government · Microsoft Entra ID Government · Microsoft Purview (sealed-records labels with strict isolation) · Azure Key Vault Managed HSM · Microsoft Sentinel (cross-boundary query detection) · Microsoft Defender for Cloud · Power BI Government (court dashboards).
Pattern 6. State-funded K-12 and higher-education plane
Scenario
A state Department of Education or a public university system needs to modernize the K-12 + higher-education Microsoft surface — student-information-system integration, statewide single sign-on, FERPA-aligned data handling, statewide Power BI dashboards for the legislature, and AI-assisted instruction (Microsoft 365 Copilot for Education) for participating districts. The State Auditor requires that any cloud carrying student PII be StateRAMP-authorized and that FERPA controls be documented at the platform level.
EPC delivery approach
EPC delivers an M365 GCC tenant for state education staff (StateRAMP-authorized) alongside a dedicated education tenant (commercial or A5-equivalent, depending on state policy) for district staff and students. Entra ID Government federates the state plane with the district plane; Purview labels enforce FERPA-aligned handling on the student-data surface; Power BI Government delivers the legislative dashboards on the Azure Government plane. M365 Copilot for Education is deployed only in districts where the school board has adopted the AI-use policy, with content sensitivity labels enforcing the no-train-on-student-data posture.
Microsoft stack delivered
M365 GCC (state plane) · Microsoft Entra ID Government · Microsoft Purview (FERPA-aligned labels) · Microsoft Sentinel · Power BI Government (legislative dashboards) · M365 Copilot for Education (district plane) · Azure Government (data warehouse + AI workloads).
CJIS Security Policy v5.9.1 Alignment — 5 Control Families
The FBI CJIS Security Policy v5.9.1 (and successor versions) governs the handling of Criminal Justice Information (CJI) in every state, county sheriff, municipal police department, court system, and public-safety consortium that touches NCIC or state CJI systems. The State CJIS Systems Officer (CSO) and State CJIS Systems Agency (CSA) review the agency's CJIS posture against the Security Policy before signing off on any new cloud system. Below are the five control families EPC's SLG practice maps the Microsoft stack to most often — each anchored to the specific Microsoft technology that delivers the control.
Identification and Authentication (IA) — Advanced Authentication
CJIS Security Policy v5.9.1 requires Advanced Authentication (AA) for access to Criminal Justice Information (CJI) from any environment that is not physically inside an agency-controlled secure facility. AA must satisfy NIST SP 800-63B Authenticator Assurance Level (AAL) 2 or higher.
EPC's Microsoft-stack delivery anchor
Microsoft Entra ID Government delivers AAL2 / AAL3 Advanced Authentication via FIDO2 security keys, Windows Hello for Business with TPM-bound credentials, smart-card / PIV authentication, and certificate-based authentication. EPC configures Entra ID conditional access policies to enforce AA on every CJI-system entry point and documents the configuration in the CJIS audit package.
Access Control (AC) — Least Privilege and Separation of Duties
CJIS requires that access to CJI be limited to authorized personnel, that role-based access control (RBAC) be enforced, and that administrative duties be separated from operational user duties on CJI systems.
EPC's Microsoft-stack delivery anchor
EPC implements Microsoft Entra ID Privileged Identity Management (PIM) for time-bound role activation, RBAC role assignments mapped to CJIS personnel screening status, separation of duties between Global Administrator / Privileged Role Administrator / agency CJIS Systems Officer, and Just-in-Time elevation requiring justification logged to the CJIS audit trail.
System and Communications Protection (SC) — Encryption
CJIS requires that CJI be encrypted in transit (TLS 1.2 minimum, FIPS 140-2 / 140-3 validated cryptographic modules) and at rest (FIPS-validated cryptographic modules, key management documented). For CJI traversing public networks, FIPS-validated VPN or equivalent is required.
EPC's Microsoft-stack delivery anchor
Azure Government and M365 GCC use FIPS 140-2 / 140-3 validated cryptographic modules by default. EPC enforces TLS 1.2 minimum across all CJI-bearing endpoints, deploys Azure Key Vault Managed HSM (FIPS 140-2 Level 3) for tenant-managed keys where the State CSA requires customer-managed encryption, and documents the cryptographic module validation references in the CJIS package.
Audit and Accountability (AU) — Comprehensive Logging
CJIS requires comprehensive audit logging of all access to CJI, all administrative actions on CJI systems, all queries to NCIC / state CJI systems, and the ability to reconstruct the exact sequence of events for any CJI incident. Audit logs must be retained for a minimum of 365 days.
EPC's Microsoft-stack delivery anchor
EPC aggregates Microsoft Purview Audit (Premium), Microsoft Entra ID sign-in and audit logs, Microsoft Defender XDR alerts, and application-level CJI access logs into Microsoft Sentinel with a 365-day minimum retention (typically configured for the 7-year retention many state CSAs prefer). Sentinel workbooks deliver CJIS audit views per agency, and detection rules flag CJI-system anomalies the CJIS Systems Officer reviews weekly.
Personnel Security (PS) — Background Investigation and Screening
CJIS requires that all personnel with unescorted access to CJI undergo a fingerprint-based background investigation, that the screening be documented and tracked, and that personnel security training be delivered before access is granted and annually thereafter.
EPC's Microsoft-stack delivery anchor
Microsoft 365 GCC and Azure Government are operated by screened U.S. persons — Microsoft contractually attests to the personnel screening of platform operations staff. EPC documents the inheritance of Microsoft's personnel screening attestation, tracks agency-side personnel screening status in a CJIS personnel matrix, and delivers the annual CJIS Security Awareness Training package (mapped to the CJIS Security Policy training requirements) for agency employees.
The StateRAMP Authorization Process
StateRAMP — the State Risk and Authorization Management Program — is the state, local, and education (SLED) parallel to FedRAMP. The StateRAMP Program Management Office governs the program; cloud service offerings (CSOs) earn StateRAMP authorizations at Low, Moderate, or High impact levels modeled on the NIST SP 800-53 control catalog and the FedRAMP baselines. SLG agencies inherit the StateRAMP-authorized CSO's controls and document the agency-implemented controls in a control-responsibility matrix the State CISO or Authorizing Official signs off on.
For Microsoft cloud, both Microsoft 365 GCC and Azure Government carry StateRAMP authorizations. SLG agencies on those planes inherit the StateRAMP control baseline directly from Microsoft; the agency's job is to document the agency-implemented controls (identity policy, conditional access posture, data-classification labels, audit-log retention, personnel screening tracking, incident response procedures) and to maintain continuous monitoring evidence for the agency boundary.
EPC's StateRAMP rollout work for SLG clients follows a documented sequence: (1) Phase 1 Readiness Assessment identifies the agency-boundary controls and inherits the Microsoft StateRAMP baseline; (2) Phase 2 M365 GCC tenant build implements agency-side controls aligned to StateRAMP Moderate (or High, where the agency mission warrants); (3) Phase 3 Azure Government landing zone aligns mission systems to StateRAMP Moderate or High; (4) the StateRAMP control-responsibility matrix is delivered as a contractual artifact the State CISO uses for continuous monitoring; (5) Phase 5 managed services aggregates the continuous-monitoring evidence (Sentinel queries, Defender XDR alerts, Purview audit, Entra ID sign-in logs) on the cadence the State CISO requires.
Honest framing: StateRAMP authorization is granted to cloud service offerings — not to consulting firms. EPC is a StateRAMP-aligned consultancy: EPC delivers Microsoft cloud implementations mapped to the StateRAMP control catalog and produces the documentation an SLG agency needs to defend its authorization. EPC does not hold a StateRAMP authorization in its own right; no consulting firm does.
5 SLG Procurement Vehicles We Engage On
SLG procurement runs on a different set of vehicles than federal procurement. The five most-used vehicles for Microsoft cloud in the SLG space — and how EPC engages on each — are listed below. EPC will identify the specific vehicle that fits your acquisition strategy on the first call.
GSA Multiple Award Schedule (MAS)
The General Services Administration Multiple Award Schedule — formerly Schedule 70 for IT — is the most-used federal contract vehicle and is widely accessible to state, local, tribal, and education buyers under the GSA Cooperative Purchasing Program.
EPC engagement model
EPC engages on MAS-vehicle task orders both directly and as a subcontractor through prime contractors holding MAS schedules. EPC will identify whether MAS Cooperative Purchasing fits your SLG acquisition strategy on the first call.
NASPO ValuePoint
NASPO ValuePoint is the National Association of State Procurement Officials cooperative purchasing program. NASPO contracts are pre-negotiated by lead states and made available to all participating states, local governments, and authorized public entities. The NASPO ValuePoint Cloud Solutions contract is the most-used SLG vehicle for Microsoft cloud.
EPC engagement model
Most state Microsoft cloud procurements for SLG run on NASPO ValuePoint or on a state-specific master contract negotiated against NASPO terms. EPC delivers under NASPO-vehicle subcontracts where the prime is the contracting entity with the state.
CIO-SP4 Small Business (CIO-SP4 SB)
NITAAC CIO-SP4 is the federal government-wide acquisition contract for IT services. The CIO-SP4 Small Business set-aside provides a fast acquisition path for federal agencies — and many state and local governments piggyback federal task orders that include SLG scope.
EPC engagement model
EPC engages on CIO-SP4 SB task orders through prime contractors. Federal-to-SLG flow-down work — federal grant-funded state programs, federal trust-fund tribal systems — sometimes runs on CIO-SP4 SB with SLG end-customers.
State Master Contracts and Cooperative Purchasing Networks
Many states run their own master IT contracts (Texas DIR, California CMAS, Florida State Term Contracts, New York OGS, and others). Regional cooperative purchasing networks (TIPS, Sourcewell, OMNIA Partners) provide access to pre-negotiated SLG pricing.
EPC engagement model
EPC will name which specific state master contract or cooperative vehicle fits your SLG acquisition on the first call. EPC engages both directly under cooperative vehicles where eligible and as a subcontractor to primes holding the relevant master contracts.
Tribal Self-Governance and 638 Contracts
Federally recognized tribes can contract directly under Indian Self-Determination and Education Assistance Act (Public Law 93-638) authority, and many tribes operate enterprise IT under self-governance compacts that consolidate federal program funding.
EPC engagement model
EPC engages on 638 / self-governance tribal contracts both directly with tribal IT departments and through prime contractors. Tribal sovereignty obligations are honored in every engagement — data residency, sovereign data governance, and the exit-runbook discipline described in the use cases above.
EPC's SLG Modernization Accelerator — 5 Phases ($300K-$2M)
SLG acquisition prefers fixed-fee, milestone-priced engagements with defined deliverables. The EPC SLG Modernization Accelerator runs in five phases — Phases 1-4 are fixed-fee deliverable steps totaling $300,000 to $2,000,000 across the engagement, and Phase 5 is a monthly co-managed-services retainer. Each phase produces a contractually reusable artifact the State CIO, county manager, sheriff, court administrator, tribal council, or public-university CIO can hand to the next phase or to the State CISO for continuous monitoring.
Phase 1 — SLG Microsoft Readiness Assessment
3-4 weeks · fixed-fee
Outcome
A complete readiness package — current-state inventory across commercial / GCC / GCC High / Azure Government, compliance-gap analysis mapped to StateRAMP, CJIS Security Policy v5.9.1, IRS 1075 (where applicable), FERPA (for education clients), HIPAA (where applicable), target-state architecture diagrams, a costed multi-year roadmap, and the procurement language for the SOW. The output is contractually reusable in the agency / consortium / tribal authorization package.
Commercial model
Fixed-fee, scoped on the first 30-minute call. Delivered by a senior SLG architect, no offshore handoff. Output is the procurement-ready deliverable an agency CIO, consortium board, or tribal council can use to issue the next phase.
Phase 2 — M365 GCC Tenant Build and Migration
90-180 days
Outcome
Full M365 GCC tenant build and migration from the current state — screened U.S.-persons admin baseline, Microsoft Entra ID Government Conditional Access, Microsoft Purview labeling baseline (citizen PII, tax data, criminal justice information, PHI, FERPA-protected student data — whichever applies), Defender XDR, Microsoft Sentinel SIEM integration, and tenant-to-tenant migration of mailboxes, SharePoint sites, Teams, OneDrive, and Power Platform environments. Designed for 200-15,000 seat agency / consortium / tribal footprints.
Commercial model
Fixed-fee per seat-band. Includes documentation, runbooks, StateRAMP control-responsibility matrix, 30 days of hypercare, and optional Microsoft Sentinel managed SOC handoff at end of engagement.
Phase 3 — Azure Government Landing Zone and Mission Systems
120-240 days
Outcome
Azure Government landing zone build aligned to StateRAMP and CJIS Security Policy v5.9.1 — hub-and-spoke network, Entra ID Government integration, Microsoft Purview, Defender for Cloud, Microsoft Sentinel, Azure Key Vault Managed HSM where customer-managed encryption is required, and the migration of one to three SLG mission systems (RMS, court case management, revenue / tax administration, Medicaid analytics, tribal ERP, public-safety CAD, court records) onto the landing zone.
Commercial model
Fixed-fee per landing-zone scope and mission system. Includes the StateRAMP control-responsibility matrix, CJIS Security Policy alignment package (where applicable), and the runbook handoff. Mission-system migration is priced per system; EPC partners with the application integrator that owns the source code where appropriate.
Phase 4 — Power BI Government and Microsoft Fabric Modernization
90-180 days
Outcome
Power BI Government and Microsoft Fabric (where regionally authorized on Azure Government) build — tenant build, OneLake lakehouse, semantic-model layer, row-level security mapped to agency / consortium role taxonomy, and migration of the legacy reporting estate (SSRS, Excel, Tableau, Qlik) onto Power BI Government. Includes the legislative / council / tribal-leadership executive dashboards and the data-quality and lineage layer.
Commercial model
Fixed-fee per report-band. Includes the legislative dashboard set, the data-warehouse modernization, and the StateRAMP / FedRAMP control mapping for the analytics platform. Optional retainer for ongoing Power BI / Fabric center-of-excellence operation.
Phase 5 — 24/7 Co-Managed SLG Microsoft Services
Monthly retainer
Outcome
A 24/7 senior-architect-escalated managed service for the M365 GCC / Azure Government estate — tenant operations, Sentinel SOC monitoring, Defender XDR response, Purview label lifecycle, Entra ID Conditional Access maintenance, StateRAMP continuous-monitoring evidence collection, CJIS audit-package quarterly refresh, and CMMC / NIST 800-171 evidence aggregation (where applicable). Senior architect on the bridge for any Severity 1.
Commercial model
Monthly retainer scoped to seat count and platform surface. Defined SLOs, monthly executive review, and quarterly compliance posture report to the agency CISO, the State CSA where CJIS applies, and the tribal council where tribal sovereignty applies. The five-phase SLG Modernization Accelerator runs $300K to $2M across Phases 1-4 depending on scope; Phase 5 is monthly retainer.
EPC's SLG Credential Stack
SLG buyers need to verify a consultancy's credentials before issuing a task order or signing an NASPO subcontract. Below is EPC Group's SLG credential stack — stated plainly, with the appropriate honest framing around what consultancies can and cannot hold (FedRAMP and StateRAMP authorizations go to cloud service offerings, not to consulting firms).
Firm profile & past performance
- Named federal past performance: NASA, the FBI, the Federal Reserve, and the Pentagon (public references)
- SLG portfolio: state agencies, county sheriffs, municipal IT departments, tribal nations, public-safety consortia, K-12 districts, and higher-education systems — specific named SLG references released under NDA after a Phase 1 fit-call
- Microsoft partner status: Microsoft Solutions Partner holding all six current Solutions Partner Designations
- Continuous Microsoft tenure: 29 years — founded 1997, one of the longest continuously operating Microsoft Solutions Partners in the U.S.
- Total enterprise engagements: 11,000+ delivered
- M&A M365 tenant migrations: 216+ (1.83 million users) — includes both private-sector and SLG engagements
- Microsoft Fabric implementations: 500+
- Power BI implementations: 1,500+
SLG-relevant credentials
- StateRAMP-aligned delivery methodology: documented control-responsibility matrix template the State CISO uses for continuous monitoring
- FedRAMP-aligned delivery methodology: Authorization Boundary Diagram, Control Implementation Summary (CIS) workbook, and Continuous Monitoring (ConMon) plan — reusable across engagements
- CJIS Security Policy v5.9.1 alignment practice: Microsoft-stack alignment across IA / AC / SC / AU / PS control families, packaged for State CJIS Systems Officer review
- Microsoft Press authorship: 4× Microsoft Press bestselling author (Power BI, SharePoint Foundation 2010, SharePoint 2013 Field Guide, WSS 3.0) — Errin O'Connor
- Microsoft beta-team participation: original SharePoint "Project Tahoe" beta team + original Power BI "Project Crescent" beta team — nearly three decades of Microsoft delivery context
- Compliance coverage span: HIPAA, SOC 2, FedRAMP, FINRA, CMMC, GxP — plus the SLG overlays (StateRAMP, CJIS, IRS 1075, FERPA) delivered across regulated SLG deployments
- Honest framing: EPC is a FedRAMP-aligned and StateRAMP-aligned consultancy. Neither program issues authorizations to consulting firms — only to cloud service offerings — so no consultancy is literally "FedRAMP-authorized" or "StateRAMP-authorized"
Contract vehicles & staffing posture: EPC engages on SLG contracts both directly under cooperative purchasing vehicles where eligible and as a subcontractor through prime contractors holding NASPO ValuePoint, GSA Multiple Award Schedule (Cooperative Purchasing), state master contracts (Texas DIR, California CMAS, Florida State Term Contracts, New York OGS), and regional cooperative networks (TIPS, Sourcewell, OMNIA Partners). EPC does not represent itself as holding 8(a) small-business status in its own right. For engagements requiring specific personnel security clearances or CJIS personnel screening, EPC documents the staffing posture per engagement. Specific contract-vehicle access is confirmed per-opportunity; ask on the first call which vehicle fits your acquisition strategy.
Frequently Asked Questions
What is the difference between StateRAMP and FedRAMP?
StateRAMP and FedRAMP are parallel programs. FedRAMP — the Federal Risk and Authorization Management Program — is the U.S. federal cloud security authorization program; it grants Moderate and High authorizations to cloud service offerings consumed by federal agencies. StateRAMP — the State Risk and Authorization Management Program — is the equivalent program for state, local, and education (SLED) governments, modeled directly on FedRAMP and using the same NIST SP 800-53 control catalog. The two programs share most of the technical content. The practical differences: StateRAMP is governed by a nonprofit member organization (the StateRAMP Program Management Office) and is procured by SLED entities, while FedRAMP is governed by the federal Joint Authorization Board and procured by federal agencies. Many cloud service offerings — including Microsoft 365 GCC and Azure Government — hold both authorizations. EPC Group delivers StateRAMP-aligned and FedRAMP-aligned Microsoft cloud deployments; the control work overlaps heavily. EPC is a FedRAMP-aligned consultancy and a StateRAMP-aligned consultancy — neither program grants authorization to consulting firms, only to cloud service offerings.
How does EPC support CJIS Security Policy v5.9.1 posture for sheriffs, courts, and public-safety consortia?
CJIS Security Policy v5.9.1 (and successor versions) governs how Criminal Justice Information (CJI) is handled in cloud and on-premises systems. EPC delivers CJIS-aligned Microsoft cloud postures for sheriffs, police departments, court systems, and public-safety consortia. The work covers Advanced Authentication (Microsoft Entra ID Government with FIDO2, Windows Hello for Business, smart-card / PIV), Access Control with separation of duties (Entra ID Privileged Identity Management with time-bound activation), encryption in transit and at rest (FIPS 140-2 / 140-3 validated modules, TLS 1.2 minimum, Azure Key Vault Managed HSM where customer-managed keys are required), comprehensive Audit and Accountability (Microsoft Sentinel with 365-day-minimum retention, frequently configured for 7-year retention), and Personnel Security (Microsoft's screened-U.S.-persons attestation plus agency-side fingerprint-based background investigation tracking). EPC documents each control family's alignment in a CJIS package the State CJIS Systems Officer (CSO) and State CJIS Systems Agency (CSA) review.
Can EPC support a tribal nation that needs sovereign data residency and the right to exit?
Yes. EPC delivers tribal-nation Microsoft cloud engagements that explicitly honor tribal sovereignty. The work includes a tribal-government addendum to the Microsoft Customer Agreement, U.S.-only Azure Government datacenter residency with Microsoft's contractual attestation of personnel screening, Customer Lockbox for Government requiring explicit tribal IT approval for any Microsoft access to tenant data, Purview sensitivity labels mapped to the tribe's own data-classification taxonomy (sovereign data, member data, gaming compliance data, IHS-coordinated PHI, federal trust-fund data), and a documented data-exit runbook that lets the tribe retrieve all data to a tribal datacenter or alternative cloud if the council so directs. EPC does not characterize tribal-nation engagements as "government" engagements without the tribal council's explicit framing — sovereign tribal nations choose how their cloud relationship is described, and EPC follows that lead.
How does EPC integrate with a public-safety Records Management System (RMS) on Azure Government?
RMS source-code ownership almost always sits with a specialist public-safety integrator (Tyler Technologies, Motorola Solutions, Mark43, Caliber Public Safety, Niche Technology, and others). EPC does not own RMS source code. EPC builds the destination Azure Government landing zone — CJIS-aligned network, Entra ID Government with Advanced Authentication, Sentinel CJIS audit aggregation, Defender for Cloud — and partners with the RMS integrator to migrate the application into the landing zone. The shared-responsibility split is documented in the engagement: EPC owns the landing zone, identity, audit, and Microsoft-stack security; the RMS integrator owns the application; the agency owns CJI handling policy and personnel screening. This split is the only honest way to deliver RMS on Azure Government — any consultancy claiming to own both the landing zone and the RMS source code is either an RMS vendor in disguise or is misrepresenting scope.
M365 GCC or M365 Commercial — which one does a state agency actually need?
For most state, local, and tribal government workloads, the right plane is Microsoft 365 GCC, not commercial M365. GCC inherits FedRAMP Moderate, DoD SRG IL2, CJIS Security Policy alignment, IRS 1075 alignment, and StateRAMP authorization — the regulatory baseline most SLG procurement officers now require. Commercial M365 does not carry StateRAMP authorization, and many state procurement policies as of 2026 explicitly require StateRAMP-authorized cloud. The exceptions are narrow: education tenants for student-facing workloads sometimes run on the commercial education plane (A3 / A5 for Education) because the FERPA control posture is delivered through the education-specific agreements rather than through GCC. For agency staff handling state-tax data, criminal justice information, citizen PII, or federal flow-down data, GCC is the right plane. EPC will identify the specific workloads that belong on commercial, GCC, and GCC High during the Phase 1 Readiness Assessment.
How much does the SLG Modernization Accelerator cost?
The EPC SLG Modernization Accelerator runs $300,000 to $2,000,000 across Phases 1-4, with Phase 5 as a separate monthly retainer. Phase 1 (Readiness Assessment, 3-4 weeks) is the smallest fixed-fee step and is procurement-ready output. Phase 2 (M365 GCC tenant build and migration, 90-180 days) typically lands in the $250K-$700K range for 500-5,000 seat agencies. Phase 3 (Azure Government landing zone plus one to three mission systems, 120-240 days) typically lands in the $400K-$900K range depending on landing-zone scope and the number of mission systems migrated. Phase 4 (Power BI Government / Fabric modernization, 90-180 days) typically lands in the $200K-$500K range depending on the legacy reporting estate size. Phase 5 (24/7 co-managed services) is monthly retainer scoped to seat count and platform surface. Microsoft licensing (GCC seats, Azure Government consumption, Sentinel ingest, Defender) is separate and scopes per Microsoft's government price list. EPC delivers on a fixed-fee basis with the costed Statement of Work after Phase 1 — no time-and-materials surprises.
What past performance does EPC have with state, local, and tribal government?
EPC Group has delivered Microsoft engagements with named federal references — NASA, the FBI, the Federal Reserve, and the Pentagon — plus a broader SLG portfolio that includes state agencies, county sheriffs, municipal IT departments, tribal nations, public-safety consortia, K-12 districts, and higher-education systems. The firm's 29-year history (founded 1997) and 11,000+ enterprise engagements include extensive SLG delivery; 216+ M&A M365 tenant migrations and 1.83 million users migrated includes both private-sector and SLG engagements. Specific named SLG references and case-study packages are released under NDA after a Phase 1 fit-call — many state, sheriff, court, and tribal engagements have public-information restrictions that prevent disclosure on a public website. The CEO and founder, Errin O'Connor, is a 4× Microsoft Press bestselling author (Power BI, SharePoint Foundation 2010, SharePoint 2013 Field Guide, WSS 3.0) and an original beta-team member of Microsoft's Project Tahoe (SharePoint) and Project Crescent (Power BI).
Does EPC hold the clearances and certifications SLG buyers ask about?
EPC is honest about credential framing — overstating clearance or certification is unhelpful to SLG buyers. EPC is a Microsoft Solutions Partner holding all six current Solutions Partner Designations. EPC is FedRAMP-aligned and StateRAMP-aligned (neither program issues authorizations to consulting firms — only to cloud service offerings, so no consultancy is literally "FedRAMP-authorized" or "StateRAMP-authorized"). EPC personnel hold individual industry certifications appropriate to engagement scope (Microsoft Certified: Azure Solutions Architect Expert, Microsoft Certified: Security Operations Analyst Associate, Microsoft Certified: Identity and Access Administrator Associate, CISSP, and others). For engagements requiring personnel security clearances or specific CJIS personnel screening, EPC documents the staffing posture per engagement and partners with cleared-prime contractors where the engagement scope so requires. EPC does not represent itself as holding 8(a) small-business status in its own right; 8(a) work is delivered through prime-contractor partnerships.
Related Government & Microsoft Cloud Resources
- Microsoft Cloud Orchestrator — the cross-cloud decision hub
- Federal Microsoft Consulting — FedRAMP, CMMC 2.0, GCC + GCC High (2026)
- Microsoft 365 GCC High and DoD Migration Consulting (2026)
- Microsoft 365 Consulting Services
- Azure Consulting Services
- Standards Alignment — EPC's Compliance Posture
- Microsoft Government Cloud — Service Overview
Talk to an SLG Microsoft Architect
A 60-minute call with a senior SLG architect — no sales lead. We will give you an honest scope-fit assessment against StateRAMP, CJIS Security Policy v5.9.1, M365 GCC, Azure Government, and your specific procurement vehicle (NASPO ValuePoint, state master contract, cooperative purchasing, or tribal 638). If a different firm is a better fit for your acquisition strategy, we will say so.
Errin O'Connor · Founder & CEO · Microsoft Solutions Partner · 4× Microsoft Press bestselling author · Houston, TX