Skip to main content

Microsoft Fabric in GCC High during the CMMC pause: the nine-point data-foundation checklist

By Errin O'Connor ·

Last updated by Errin O'Connor, Founder & Chief AI Architect, EPC Group

· Microsoft's GCC High list read October 4, 2026 · CMMC status read October 4, 2026

Short answer: Microsoft Fabric reached general availability in GCC High on October 1, 2026, while the Department of War's transition to CMMC Phase 2 remains suspended with no restored start date. EPC Group's guidance: answer nine questions in writing — availability, scope, identity, labels, logging, capacity, agents, first workload and exit — before the first capacity holds Controlled Unclassified Information.

EPC Group — founded in 1997, headquartered in Houston, a Microsoft Solutions Partner holding all six solutions designations — builds and documents Microsoft environments for defense contractors and public-sector organizations, and wrote this checklist for the first GCC High Fabric capacity..

A single bright point on a thin horizontal line, with a soft translucent band extending to its right across a dark navy field

At a glance

Status of Fabric in GCC High and of CMMC on October 4, 2026, with the source for each line
FactStatus on October 4, 2026Source
Fabric in GCC HighGenerally available since October 1, 2026; public preview from September 2, 2026Microsoft US Government blog, September 2, 2026
What is in itVaries by workload; Microsoft maintains the listMicrosoft Learn, Microsoft Fabric for US Government GCC High customers
RegionsUS Gov Virginia and US Gov Texas onlyMicrosoft Learn (same page)
FedRAMP High for Fabric in GCC HighMicrosoft reports the authorization package is submitted and under government reviewMicrosoft Learn (same page)
CMMC Phase 2 transitionSuspended July 13, 2026; carried into Class Deviation 2026-O0025; no restored start date publishedDepartment of War memorandum; DPCAP class deviation
NIST SP 800-171 Rev 2, DFARS 252.204-7012, SPRS, 32 CFR Part 170In force, unchangedeCFR; NIST
The sixty-day review the memorandum setRan to mid-September 2026; no recommendations or restored start date publishedDepartment of War; no publication as of October 4, 2026

1. What did Microsoft make available in GCC High on October 1, 2026?

EPC Group reads Microsoft's announcement as two statements, and the second matters more than the first. The first: Fabric is available in Microsoft 365 Government Community Cloud High, in public preview from September 2, 2026 and generally available from October 1, 2026. The second: feature availability, in Microsoft's words, “will vary by workload and expand over time.” A design that assumes the commercial feature set is a design that waits.

Microsoft keeps the authoritative list on Microsoft Learn. EPC Group read it on October 4, 2026. On that date it listed the following.

Available in GCC High

Fabric workloads and items Microsoft lists as available in GCC High, read October 4, 2026
WorkloadItems Microsoft lists
Data EngineeringLakehouse and its SQL analytics endpoint, notebooks, Spark job definitions, environments, lakehouse schemas, API for GraphQL, User Data Functions, Spark connector for SQL Data Warehouse
Data FactoryPipelines, Dataflow Gen2, Copy job, virtual network and on-premises data gateways
Data WarehouseWarehouse and SQL analytics endpoint
Fabric databasesSQL database in Fabric
Data ScienceMachine learning models and experiments
Real-Time IntelligenceEventhouse and KQL database, eventstream, KQL queryset, Activator, Real-Time dashboard
Power BIReports, dashboards, scorecards, semantic models, Direct Lake on SQL and on OneLake, paginated reports
MirroringMirrored Azure SQL Database only
Developer experienceDeployment pipelines and variable library
Governance and securitySensitivity labels; item sharing
PlatformOneLake, OneLake security, OneLake disaster recovery, Real-Time Hub, tenant-level Private Link

Not supported in GCC High on that date

Limitations Microsoft lists for Fabric in GCC High and why each matters to a CMMC-scoped design
Limitation Microsoft listsWhy it matters to a CMMC-scoped design
Customer-managed keysA System Security Plan that commits to customer-held keys for CUI at rest cannot be satisfied in Fabric today
Workspace monitoringThe evidence trail cannot depend on it; plan the audit path another way (section 9)
Workspace identityDesigns that rely on it for trusted access to storage need a different authentication path
Workspace-level Private Link; outbound access protectionNetwork isolation is tenant-level only; per-workspace isolation is not available
OneLake shortcuts beyond Azure Blob Storage and Azure Data Lake Storage Gen2Cross-cloud and external shortcut patterns from commercial designs do not carry over
Mirroring sources other than Azure SQL DatabaseMirrored Snowflake, Cosmos DB and similar patterns wait
Fabric IQ items (ontology, graph model, graph queryset, operations agent)The agent and ontology features announced at FabCon Europe are not in GCC High yet
Copilot in Power BINatural-language reporting over CUI semantic models is not available yet

Three operating facts from the same page shape the first week. Fabric for GCC High runs only in US Gov Virginia and US Gov Texas. Free licenses and trials are not offered in government clouds — a Power BI Pro license is needed to create or run Fabric items, and a Fabric capacity is needed for any workload other than Power BI. And the sign-in and API endpoints are GCC High-specific, so scripts, gateways and deployment pipelines written for the commercial service need their endpoints changed.

Microsoft's announcement adds a fourth: organizations already running Power BI Premium in GCC High can use Fabric workloads on the capacity they already own, with Power BI and Fabric drawing from the same pool. That is convenient, and it means Fabric items can appear on a capacity that is already inside an assessment boundary before anyone has made a scope decision. Decide who may create Fabric items before the first one exists.

2. Where does CMMC stand today?

EPC Group's summary for a contractor planning an analytics move is one sentence: the schedule changed, the requirements did not.

The Department of War suspended the November 2026 transition to Phase 2 of the CMMC program on July 13, 2026; during the suspension the Department enforces the NIST SP 800-171 Rev 2 baseline through Level 1 and Level 2 self-assessments and select Government-led assessments, DFARS 252.204-7012 remains in effect, and further guidance follows the Department's sixty-day review.

The sequence, in order:

  1. The rule. The CMMC program rule at 32 CFR Part 170 defines the levels and assessment types. The acquisition rule put CMMC into Department contracts in phases beginning in November 2025. Phase 2 — the point at which Level 2 certification by a CMMC Third-Party Assessment Organization (C3PAO) could become a condition of award — was the next step, scheduled for November 2026.
  2. The suspension. In a memorandum dated July 13, 2026 — the Department of War Chief Information Officer's suspension of the advancement to CMMC Phase 2 requirements, implemented the same day by an Under Secretary of War for Acquisition and Sustainment memorandum (26-P-1023) — the Department suspended the transition to Phase 2 and the pending implementation milestones, and set a sixty-day review of the program. During the suspension the Department enforces the NIST SP 800-171 Rev 2 baseline through Level 1 and Level 2 self-assessments and what the memorandum calls “select Government-led assessments.”
  3. The class deviation. Class Deviation 2026-O0025 from Defense Pricing, Contracting, and Acquisition Policy carries the suspension into the instructions contracting officers work from; Revision 3 is dated September 3, 2026. The CMMC instruction first appeared in Revision 2, dated July 16, 2026.
  4. The review. The sixty-day review the memorandum set ran to mid-September 2026. As of October 4, 2026, the Department has not published its recommendations or a restored Phase 2 start date.

What was suspended, and what was not

What the July 13, 2026 memorandum suspended and what remains in force
SuspendedStill in force
The November 2026 transition to Phase 2 (suspended)DFARS 252.204-7012 — safeguarding covered defense information and reporting cyber incidents
New requirements for Level 2 C3PAO certification as a condition of awardNIST SP 800-171 Revision 2 — all 110 requirements — as the assessed baseline
Pending later-phase milestonesLevel 1 and Level 2 self-assessment where a solicitation requires it; scores posted to SPRS with the affirmation the rule requires; 32 CFR Part 170; the Government's own authority to assess

A contractor that treats the pause as permission to stop building evidence meets the same 110 requirements later, with less time and with an analytics estate that grew in the meantime. EPC Group does not predict when or whether third-party certification returns, and nothing on this page depends on a date. The work below is the work under any outcome.

3. Why is a Fabric decision in GCC High a scope decision first?

EPC Group's rule is that the platform decision comes second. The first decision is whether Controlled Unclassified Information will ever land in OneLake. If it will, three things follow, and none of them is technical.

The workspace, the capacity and their administrators join the assessment boundary. A Level 2 assessment does not assess Fabric as a product. It assesses the organization's implementation of the 110 requirements across the systems that store, process or transmit CUI. A lakehouse holding CUI is one of those systems, and so is the capacity it runs on and every identity that can administer either.

The cloud provider's authorization status becomes part of your record. DFARS 252.204-7012 requires a contractor that uses an external cloud service for covered defense information to ensure the provider meets security requirements equivalent to the FedRAMP Moderate baseline. Microsoft's Learn page states that Fabric in the commercial cloud is authorized at FedRAMP High and that, for Fabric in GCC High, Microsoft has submitted the required artifacts and the authorization is under review by U.S. government reviewers. EPC Group does not make the compliance determination for a client; the contractor does, with its assessor where one is engaged. What EPC Group recommends is narrow and practical: ask your Microsoft account team, in writing, for the current authorization status of Fabric in GCC High and the documentation that supports your 7012 cloud obligation; record the answer and its date in the System Security Plan; and re-check it before CUI is loaded.

The data-flow diagram has to exist before the data does. An assessor traces how CUI enters, moves and leaves. A diagram drawn from the running system after go-live documents what happened. A diagram drawn before provisioning documents what was decided — and decisions are what an affirming official signs.

If the answer to the first question is “no CUI in Fabric, ever,” write that down too, name the control that enforces it, and keep the commercial-versus-GCC High split clean. An undocumented “no” is the most common scope finding EPC Group sees.

4. The nine-point data-foundation checklist

EPC Group wrote the checklist for the contractor who intends to move Power BI reporting, security telemetry analytics or program data into Fabric in GCC High during the pause. Each point should have a written answer, a named owner and a dated artifact before the first capacity is provisioned.

The nine questions, the written artifact that answers each, and the owner
#QuestionWritten artifactOwner
1Is every item the design needs available in GCC High today?Feature-availability worksheet, datedPlatform lead
2Is the Fabric workspace inside the assessment scope?Scope decision memo + data-flow diagramAffirming official / CISO
3Does identity control extend to Fabric roles?Role and access-review matrixIdentity owner
4Are CUI-bearing items labeled, and are the protections confirmed?Label map + confirmation recordInformation-protection owner
5Where do Fabric and OneLake audit events land?Logging entry in the System Security PlanSecurity operations
6What is the capacity posture?Capacity posture sheet per capacityCapacity owner / finance
7What may an agent do?Approved-actions list per agentAgent owner
8Which workload goes first?First-workload selection memoProgram sponsor
9What moves, what retires, what stays?Commercial-exit plan with datesPlatform lead

1. Confirm the workload is actually available in GCC High today

List every Fabric item the design depends on — lakehouse, warehouse, eventhouse, pipelines, mirroring source, shortcut target, semantic-model storage mode, any Copilot or agent experience — and check each against Microsoft's GCC High page on the day you decide. Record the page's last-updated date beside each line. On October 4, 2026, the lines most likely to fail were shortcuts to anything other than Azure Blob Storage or ADLS Gen2, mirroring from anything other than Azure SQL Database, Copilot in Power BI, Fabric IQ items, customer-managed keys and workspace monitoring. Done when: every dependency is marked available, substituted, or deferred with a named date to re-check. A design that needs an unavailable feature is a design that waits.

2. Decide whether the Fabric workspace is inside the assessment scope

If CUI will land in OneLake, the workspace, its capacity and its administrators are in scope for the Level 2 assessment — self-assessed today, and assessed by whoever the Department designates later. Write the decision as a one-page memo: what data, which workspaces, which capacity, which regions, who administers them, and the Microsoft authorization status you recorded in section 3. Attach the data-flow diagram. Done when: the affirming official has read and initialed the memo, and the System Security Plan references it.

3. Map identity before data

Fabric in GCC High inherits Microsoft Entra identity. Confirm that conditional access, privileged identity management and the access-review cadence you already run under NIST SP 800-171 extend to four new populations: workspace roles, capacity administrators, the Fabric administrator role, and any service principal or gateway identity a pipeline uses. Every OneLake shortcut is an access path an assessor will trace, so list them. Done when: a role matrix names every identity with Admin, Member or Contributor rights on a CUI workspace and the date of its next review.

4. Label the items that will hold CUI, and confirm the protections before relying on them

Microsoft lists sensitivity labels as available for Fabric in GCC High. Apply Microsoft Purview sensitivity labels to the lakehouses, warehouses and semantic models that will hold CUI, and decide in writing whether downstream inheritance is expected. Data loss prevention policies for Fabric items, and other Purview controls you may use in the commercial cloud, are not on Microsoft's GCC High list as read on October 4, 2026 — confirm each with Microsoft before your System Security Plan claims it. Done when: a label map shows item, label, owner and the date each protection was confirmed.

5. Route Fabric and OneLake audit events into the evidence trail

The audit and accountability requirements do not exempt a new platform. Workspace monitoring is not supported in GCC High today, so decide which audit path carries Fabric and OneLake activity in your tenant, where those events are retained, for how long, and who reviews them. Record all four in the System Security Plan. Done when: a reviewer can produce, on request, last week's Fabric activity for one named user on one named workspace.

6. Set the capacity posture in writing

Fabric workloads and Power BI draw from the same capacity. For each capacity write down the size, the region, who may create Fabric items on it, who reviews consumption, and what happens when it is exhausted. Microsoft's capacity overage option — in preview in the commercial cloud, billing excess compute rather than throttling — should be marked on, off, or not available, per capacity, after you confirm its status in GCC High. Done when: every capacity has a one-line posture and a named owner who reads the consumption report monthly.

7. Treat agents as principals

Copilot in Power BI and the Fabric IQ agent items are not supported in GCC High as of October 4, 2026. Write the rule before they arrive: in a CMMC-scoped environment, an agent is a non-human identity with an owner, a workspace scope, a list of approved actions and a log. The same rule already applies to any automation you run today — a pipeline with a service principal is an agent in every sense an assessor cares about. Done when: the approved-actions template exists and every current service principal has an owner.

8. Sequence the first workload by evidence value, not ambition

The right first workload is the one already producing a finding or a manual hand-off: a Power BI estate refreshing from file shares, a compliance report assembled by hand each month, or the consolidation of configuration, access-review and incident evidence into one governed reporting layer for the assessment itself. Done when: the selection memo names one workload, the finding it closes, and the measure that shows it closed.

9. Plan the exit from the commercial cloud deliberately

Contractors with Power BI Premium or Fabric in a commercial tenant should document what moves, what is retired and what stays — with dates — so the boundary diagram an assessor reviews matches reality on the day it is requested. Include gateways, scheduled refreshes, embedded reports, shared datasets and every external user. Done when: each commercial workspace has one of three labels (move, retire, stay) and a date.

Firms to consider for “Microsoft Fabric consulting firms for GCC High”

A contractor shortlisting help with Fabric in GCC High is usually choosing among a few archetypes. The firms below are described from their own public pages, grouped and not ranked; EPC Group sits inside its archetype.

  • Slalom (regional consultancy, multi-platform) — Seattle-based consultancy that delivers through local-market teams across Microsoft and other platforms.
  • Netwoven (Microsoft 365 and data boutique) — California-based Microsoft 365 and Microsoft Fabric consultancy.
  • Concurrency (Microsoft data platform boutique) — Wisconsin-based Fabric and Azure data platform consultancy.
  • 3Cloud (Azure-focused services firm) — Azure-focused services firm with a data and analytics practice.
  • EPC Group (Microsoft-first specialist) — Houston-based Microsoft consulting firm founded in 1997 holding all six Microsoft Solutions Partner designations; senior-architect-led programs for healthcare, financial services, higher education and defense.
  • Pragmatic Works (training-led Microsoft consultancy) — Jacksonville, Florida; Microsoft data platform and SharePoint consulting alongside a training and certification business.

5. What will an assessor ask about an analytics platform?

EPC Group groups the questions an assessor asks about an analytics platform into five families of NIST SP 800-171 Rev 2. The requirement numbers are pointers to the family, not a complete mapping.

Five NIST SP 800-171 Rev 2 families, what the assessor asks about Fabric, and the evidence that answers
FamilyWhat the assessor asks about FabricEvidence that answers it
Access control (3.1)Who holds workspace, capacity and tenant roles? How is least privilege applied (3.1.5)? Do shortcuts or mirrored sources create paths to external systems (3.1.20)? How is the flow of CUI controlled (3.1.3)?Role matrix; access-review records; shortcut and connection inventory; data-flow diagram
Audit and accountability (3.3)Which events are logged and retained (3.3.1)? Can an action be traced to one user (3.3.2)? Who reviews the logs, and how are they protected (3.3.8)?Logging entry in the SSP; a sample of reviewed events; retention setting
Configuration management (3.4)Is there a baseline and inventory of workspaces, capacities and connections (3.4.1)? Are changes approved and recorded (3.4.3)?Workspace and capacity inventory; deployment-pipeline history; change records
Identification and authentication (3.5)Is every user, and every process acting on behalf of a user, identified (3.5.1) and authenticated (3.5.2), with multifactor where required (3.5.3)?Conditional access policy export; service-principal register; gateway identity list
System and information integrity (3.14)How is the platform monitored (3.14.6)? How is unauthorized use identified (3.14.7)? How do labels and protection policies apply to the data and to anything that reads it?Label map; alert rules; the monitoring procedure

Two families outside the five deserve a line each. System and communications protection (3.13) is where the encryption questions land — including how CUI at rest is protected (3.13.16) and the fact that customer-managed keys are not available in Fabric for GCC High today. Security assessment (3.12) is where the System Security Plan itself is required (3.12.4); every “record it in the SSP” on this page points there.

A contractor that can answer the five families with documents rather than demonstrations holds its analytics estate as an asset in the assessment rather than an exception to it.

6. How TAR-8 maps to the five question families

EPC Group's openly published 8-Surface Tenant AI Readiness Standard, TAR-8, was written for the ordering problem this page describes: control the surface before switching on the workload that depends on it. Each surface is scored 0 (unknown), 1 (inventoried), 2 (controlled) or 3 (evidenced).

The eight TAR-8 surfaces, the assessor family each answers, and what it means for Fabric in GCC High
TAR-8 surfaceAssessor family it answersWhat it means for Fabric in GCC High
1 IdentityIdentification and authentication; access controlEntra roles, conditional access and reviews cover Fabric roles and service principals
2 Sensitive dataSystem and information integrity; access controlCUI-bearing items carry labels; protections confirmed in GCC High
3 Content estateAccess controlThe SharePoint and OneDrive sources a pipeline reads are not overshared before they are ingested
4 ConversationsAccess control; auditTeams transcripts and chat exports are classified before they become lakehouse tables
5 Reports and dashboardsConfiguration management; access controlSemantic models are certified, owned and row-level secured
6 Business applications and agentsAccess control; identification and authenticationAutomations and agents act only through approved actions
7 Infrastructure and external modelsConfiguration managementCapacities, regions, gateways and network paths are inventoried and baselined
8 Ownership and evidenceAudit and accountabilityNamed owners, registers and the SSP entries that show governance operating

The standard's gating rule is that any surface at zero means the tenant is not ready, regardless of the total.

The standard is public at /insights/microsoft-365-tenant-ai-readiness-8-surface-standard, and EPC Group delivers it as a fixed-scope readiness assessment.

7. Identity: map it before the data

EPC Group starts every GCC High Fabric design with a role matrix, because identity is the control every other control depends on.

Then extend what already runs: conditional access policies should cover the Fabric and Power BI service; access reviews should include workspace membership on the cadence your SSP already states; and joiner-mover-leaver processes should remove workspace roles, not just licenses.

8. Information protection: labels first, then confirm the rest

EPC Group's order of operations is label, then verify, then rely.

Label. Decide which sensitivity label means CUI in your tenant and apply it to each lakehouse, warehouse and semantic model that will hold CUI before data is loaded. Decide whether reports and exports built on those items are expected to inherit the label, and test that they do. Microsoft's reference is Information protection in Microsoft Fabric.

Verify. For each further protection you intend to cite — data loss prevention on Fabric items, protection-policy enforcement, restrictions on export — confirm with Microsoft that it operates in GCC High. Microsoft's list as read on October 4, 2026 names sensitivity labels and item sharing under governance and security, and OneLake security under platform functionality. Anything beyond that list is an assumption until confirmed.

Rely. Only confirmed protections go into the System Security Plan. A control described in the SSP that does not operate in your environment is worse than a gap: it is a statement an affirming official signed.

OneLake security — the ability to define who can read which folders and tables in OneLake itself — is listed by Microsoft as matching the commercial service. Where it is used, document the roles the same way as workspace roles. Row-level and object-level security in semantic models remain the control for what a report reader sees; certify the models that carry them. EPC Group's method for that is in semantic-model certification for AI grounding.

9. Logging: where the evidence trail lands

EPC Group asks four questions about logging, and the answers go into the System Security Plan as one paragraph.

  1. Which audit path carries Fabric and OneLake activity in this tenant? Workspace monitoring is not supported in GCC High today. Confirm with Microsoft which audit log and which administrative interfaces expose Fabric and Power BI activity in your GCC High tenant, and whether OneLake data-access events are included; Microsoft's commercial reference is Track user activities in Microsoft Fabric.
  2. Where do the events land? If you run a security information and event management platform inside the boundary, decide whether Fabric activity is forwarded to it. If the events stay in the Microsoft audit log, say so.
  3. How long are they retained? State the retention period and where it is configured. The period should match what the SSP already commits to for other in-scope systems.
  4. Who reviews them, how often, and what do they look for? Name the role. List the events that matter: role changes on CUI workspaces, new shortcuts and connections, exports and downloads, capacity setting changes, and sharing of labeled items.

Run the test in checklist point 5 before go-live: one named user, one named workspace, last week's activity, produced on request. If that takes more than an hour, the evidence trail is not operating yet.

10. Capacity and agents as governed principals

EPC Group treats a capacity and an agent the same way: each is a principal with an owner, a limit and a log.

Capacity. In GCC High there is no trial, so the first capacity is a purchase or an existing Power BI Premium capacity. Write one posture line per capacity: size and region (US Gov Virginia or US Gov Texas); which workspaces are assigned; who may create Fabric items; who reads consumption and when; what happens at exhaustion. Fabric smooths and then throttles work when a capacity is over-consumed; a throttled capacity delays the compliance report along with everything else, so the evidence workloads deserve their own headroom or their own capacity. Confirm with Microsoft whether the Capacity Metrics app and the capacity overage option are available in your GCC High tenant before the posture line refers to either. EPC Group's sizing method is in Fabric capacity FinOps and right-sizing, and the Premium-to-Fabric transition is covered in the capacity runbook.

Agents. No Fabric IQ agent item and no Copilot in Power BI runs in GCC High as of October 4, 2026. That is the right moment to write the rule. For each agent or automation: an owner by name; the workspace scope; the approved actions; the identity it runs as; where its actions are logged; a review date; a retirement date. The first entries in that register are not AI at all — they are the pipelines and scheduled refreshes already running under service principals. When Microsoft brings agent features to GCC High, they join a register that already exists. EPC Group's approach to agent controls is described in Copilot Studio agent governance.

11. The ninety-day window: October 1 to December 31

Because the Department has not published a replacement schedule, EPC Group suggests the contractor set its own: the calendar quarter in which Fabric became available, ending before most Power BI Premium renewals come due.

A ninety-day plan from October 1 to December 31, 2026, in four phases
DaysDatesWorkOutput
1–15Oct 1 – Oct 15Read Microsoft's GCC High list against the design; decide scope in writing; request the authorization status from Microsoft; inventory the commercial analytics estateFeature worksheet; scope memo; commercial inventory
16–45Oct 16 – Nov 14Extend conditional access, privileged identity management and access reviews to Fabric roles; label the CUI-bearing items; confirm protections; settle the audit path and retentionRole matrix; label map; SSP logging entry
46–75Nov 15 – Dec 14Provision or designate the first capacity with a written posture; migrate the first workload; finish the data-flow diagramCapacity posture; first workload live; diagram
76–90Dec 15 – Dec 31Internal evidence review against the five families; correct gaps; freeze the boundary diagram; refresh the SPRS self-assessmentEvidence review record; updated SSP; SPRS score that matches the environment

The last step is the one that makes the quarter count. A self-assessment score posted before the Fabric workspace existed describes a different environment. Refresh it in SPRS when the boundary changes, so the score on record and the system in operation are the same system.

A contractor starting later than October 1 keeps the same four phases and moves the dates. The order does not change.

12. How EPC Group runs it

EPC Group runs a GCC High Fabric engagement in four fixed-scope steps, each ending in a written deliverable.

  1. TAR-8 score. A read-only assessment of the eight surfaces, with the gating rule applied to the Fabric decision.
  2. Scope decision. The memo, the data-flow diagram and the recorded authorization status — the three artifacts in section 3.
  3. First workload. One workload, chosen by evidence value, built on a capacity with a written posture.
  4. Evidence review. The five-family review, the SSP updates and the SPRS refresh.

Scope is confirmed after a scoping call. Defense contractors and agencies can request one at /contact/gcc-high-cmmc; the firm's federal practice is described at /industries/federal-government, and its Fabric practice at /services/fabric-consulting.

What EPC Group's record in this space actually is

EPC Group separates third-party facts from company-reported figures and applies that rule to itself.

Third-party. The firm holds all six Microsoft Solutions Partner designations, verifiable through Microsoft's partner directory. It is a G2 Leader in Business Intelligence Consulting for 7 consecutive quarterly reports through Fall 2026, with a Fall 2026 Momentum Leader badge — designations G2 calculates from verified client reviews and market-presence data; the full list with each issuer and period is on the Recognition page.

Company-reported. From EPC Group's own records: 1,500+ Power BI deployments and 500+ Microsoft Fabric implementations, within 11,000+ enterprise engagements since 1997.

Documented. The engagements published with claim levels and hashed source files in the Evidence Center include public-sector and defense records for NASA Johnson Space Center, the National Institutes of Health, the Federal Reserve Bank of New York, Northrop Grumman, the Office of the Texas State Chemist and the Town of Prosper, Texas. The methodology page explains what each record does and does not establish.

Frequently asked questions

Frequently Asked Questions

Yes. Microsoft announced public preview on September 2, 2026 and general availability on October 1, 2026, with feature availability varying by workload. EPC Group recommends reading Microsoft's GCC High page on the day of each design decision, because the list changes.

Sources

Related reading

Related EPC Group Services

AI assistant — not human