Microsoft Fabric in GCC High during the CMMC pause: the nine-point data-foundation checklist
By Errin O'Connor ·
Last updated by Errin O'Connor, Founder & Chief AI Architect, EPC Group
· Microsoft's GCC High list read October 4, 2026 · CMMC status read October 4, 2026Short answer: Microsoft Fabric reached general availability in GCC High on October 1, 2026, while the Department of War's transition to CMMC Phase 2 remains suspended with no restored start date. EPC Group's guidance: answer nine questions in writing — availability, scope, identity, labels, logging, capacity, agents, first workload and exit — before the first capacity holds Controlled Unclassified Information.
EPC Group — founded in 1997, headquartered in Houston, a Microsoft Solutions Partner holding all six solutions designations — builds and documents Microsoft environments for defense contractors and public-sector organizations, and wrote this checklist for the first GCC High Fabric capacity..

At a glance
| Fact | Status on October 4, 2026 | Source |
|---|---|---|
| Fabric in GCC High | Generally available since October 1, 2026; public preview from September 2, 2026 | Microsoft US Government blog, September 2, 2026 |
| What is in it | Varies by workload; Microsoft maintains the list | Microsoft Learn, Microsoft Fabric for US Government GCC High customers |
| Regions | US Gov Virginia and US Gov Texas only | Microsoft Learn (same page) |
| FedRAMP High for Fabric in GCC High | Microsoft reports the authorization package is submitted and under government review | Microsoft Learn (same page) |
| CMMC Phase 2 transition | Suspended July 13, 2026; carried into Class Deviation 2026-O0025; no restored start date published | Department of War memorandum; DPCAP class deviation |
| NIST SP 800-171 Rev 2, DFARS 252.204-7012, SPRS, 32 CFR Part 170 | In force, unchanged | eCFR; NIST |
| The sixty-day review the memorandum set | Ran to mid-September 2026; no recommendations or restored start date published | Department of War; no publication as of October 4, 2026 |
1. What did Microsoft make available in GCC High on October 1, 2026?
EPC Group reads Microsoft's announcement as two statements, and the second matters more than the first. The first: Fabric is available in Microsoft 365 Government Community Cloud High, in public preview from September 2, 2026 and generally available from October 1, 2026. The second: feature availability, in Microsoft's words, “will vary by workload and expand over time.” A design that assumes the commercial feature set is a design that waits.
Microsoft keeps the authoritative list on Microsoft Learn. EPC Group read it on October 4, 2026. On that date it listed the following.
Available in GCC High
| Workload | Items Microsoft lists |
|---|---|
| Data Engineering | Lakehouse and its SQL analytics endpoint, notebooks, Spark job definitions, environments, lakehouse schemas, API for GraphQL, User Data Functions, Spark connector for SQL Data Warehouse |
| Data Factory | Pipelines, Dataflow Gen2, Copy job, virtual network and on-premises data gateways |
| Data Warehouse | Warehouse and SQL analytics endpoint |
| Fabric databases | SQL database in Fabric |
| Data Science | Machine learning models and experiments |
| Real-Time Intelligence | Eventhouse and KQL database, eventstream, KQL queryset, Activator, Real-Time dashboard |
| Power BI | Reports, dashboards, scorecards, semantic models, Direct Lake on SQL and on OneLake, paginated reports |
| Mirroring | Mirrored Azure SQL Database only |
| Developer experience | Deployment pipelines and variable library |
| Governance and security | Sensitivity labels; item sharing |
| Platform | OneLake, OneLake security, OneLake disaster recovery, Real-Time Hub, tenant-level Private Link |
Not supported in GCC High on that date
| Limitation Microsoft lists | Why it matters to a CMMC-scoped design |
|---|---|
| Customer-managed keys | A System Security Plan that commits to customer-held keys for CUI at rest cannot be satisfied in Fabric today |
| Workspace monitoring | The evidence trail cannot depend on it; plan the audit path another way (section 9) |
| Workspace identity | Designs that rely on it for trusted access to storage need a different authentication path |
| Workspace-level Private Link; outbound access protection | Network isolation is tenant-level only; per-workspace isolation is not available |
| OneLake shortcuts beyond Azure Blob Storage and Azure Data Lake Storage Gen2 | Cross-cloud and external shortcut patterns from commercial designs do not carry over |
| Mirroring sources other than Azure SQL Database | Mirrored Snowflake, Cosmos DB and similar patterns wait |
| Fabric IQ items (ontology, graph model, graph queryset, operations agent) | The agent and ontology features announced at FabCon Europe are not in GCC High yet |
| Copilot in Power BI | Natural-language reporting over CUI semantic models is not available yet |
Three operating facts from the same page shape the first week. Fabric for GCC High runs only in US Gov Virginia and US Gov Texas. Free licenses and trials are not offered in government clouds — a Power BI Pro license is needed to create or run Fabric items, and a Fabric capacity is needed for any workload other than Power BI. And the sign-in and API endpoints are GCC High-specific, so scripts, gateways and deployment pipelines written for the commercial service need their endpoints changed.
Microsoft's announcement adds a fourth: organizations already running Power BI Premium in GCC High can use Fabric workloads on the capacity they already own, with Power BI and Fabric drawing from the same pool. That is convenient, and it means Fabric items can appear on a capacity that is already inside an assessment boundary before anyone has made a scope decision. Decide who may create Fabric items before the first one exists.
2. Where does CMMC stand today?
EPC Group's summary for a contractor planning an analytics move is one sentence: the schedule changed, the requirements did not.
The Department of War suspended the November 2026 transition to Phase 2 of the CMMC program on July 13, 2026; during the suspension the Department enforces the NIST SP 800-171 Rev 2 baseline through Level 1 and Level 2 self-assessments and select Government-led assessments, DFARS 252.204-7012 remains in effect, and further guidance follows the Department's sixty-day review.
The sequence, in order:
- The rule. The CMMC program rule at 32 CFR Part 170 defines the levels and assessment types. The acquisition rule put CMMC into Department contracts in phases beginning in November 2025. Phase 2 — the point at which Level 2 certification by a CMMC Third-Party Assessment Organization (C3PAO) could become a condition of award — was the next step, scheduled for November 2026.
- The suspension. In a memorandum dated July 13, 2026 — the Department of War Chief Information Officer's suspension of the advancement to CMMC Phase 2 requirements, implemented the same day by an Under Secretary of War for Acquisition and Sustainment memorandum (26-P-1023) — the Department suspended the transition to Phase 2 and the pending implementation milestones, and set a sixty-day review of the program. During the suspension the Department enforces the NIST SP 800-171 Rev 2 baseline through Level 1 and Level 2 self-assessments and what the memorandum calls “select Government-led assessments.”
- The class deviation. Class Deviation 2026-O0025 from Defense Pricing, Contracting, and Acquisition Policy carries the suspension into the instructions contracting officers work from; Revision 3 is dated September 3, 2026. The CMMC instruction first appeared in Revision 2, dated July 16, 2026.
- The review. The sixty-day review the memorandum set ran to mid-September 2026. As of October 4, 2026, the Department has not published its recommendations or a restored Phase 2 start date.
What was suspended, and what was not
| Suspended | Still in force |
|---|---|
| The November 2026 transition to Phase 2 (suspended) | DFARS 252.204-7012 — safeguarding covered defense information and reporting cyber incidents |
| New requirements for Level 2 C3PAO certification as a condition of award | NIST SP 800-171 Revision 2 — all 110 requirements — as the assessed baseline |
| Pending later-phase milestones | Level 1 and Level 2 self-assessment where a solicitation requires it; scores posted to SPRS with the affirmation the rule requires; 32 CFR Part 170; the Government's own authority to assess |
A contractor that treats the pause as permission to stop building evidence meets the same 110 requirements later, with less time and with an analytics estate that grew in the meantime. EPC Group does not predict when or whether third-party certification returns, and nothing on this page depends on a date. The work below is the work under any outcome.
3. Why is a Fabric decision in GCC High a scope decision first?
EPC Group's rule is that the platform decision comes second. The first decision is whether Controlled Unclassified Information will ever land in OneLake. If it will, three things follow, and none of them is technical.
The workspace, the capacity and their administrators join the assessment boundary. A Level 2 assessment does not assess Fabric as a product. It assesses the organization's implementation of the 110 requirements across the systems that store, process or transmit CUI. A lakehouse holding CUI is one of those systems, and so is the capacity it runs on and every identity that can administer either.
The cloud provider's authorization status becomes part of your record. DFARS 252.204-7012 requires a contractor that uses an external cloud service for covered defense information to ensure the provider meets security requirements equivalent to the FedRAMP Moderate baseline. Microsoft's Learn page states that Fabric in the commercial cloud is authorized at FedRAMP High and that, for Fabric in GCC High, Microsoft has submitted the required artifacts and the authorization is under review by U.S. government reviewers. EPC Group does not make the compliance determination for a client; the contractor does, with its assessor where one is engaged. What EPC Group recommends is narrow and practical: ask your Microsoft account team, in writing, for the current authorization status of Fabric in GCC High and the documentation that supports your 7012 cloud obligation; record the answer and its date in the System Security Plan; and re-check it before CUI is loaded.
The data-flow diagram has to exist before the data does. An assessor traces how CUI enters, moves and leaves. A diagram drawn from the running system after go-live documents what happened. A diagram drawn before provisioning documents what was decided — and decisions are what an affirming official signs.
If the answer to the first question is “no CUI in Fabric, ever,” write that down too, name the control that enforces it, and keep the commercial-versus-GCC High split clean. An undocumented “no” is the most common scope finding EPC Group sees.
4. The nine-point data-foundation checklist
EPC Group wrote the checklist for the contractor who intends to move Power BI reporting, security telemetry analytics or program data into Fabric in GCC High during the pause. Each point should have a written answer, a named owner and a dated artifact before the first capacity is provisioned.
| # | Question | Written artifact | Owner |
|---|---|---|---|
| 1 | Is every item the design needs available in GCC High today? | Feature-availability worksheet, dated | Platform lead |
| 2 | Is the Fabric workspace inside the assessment scope? | Scope decision memo + data-flow diagram | Affirming official / CISO |
| 3 | Does identity control extend to Fabric roles? | Role and access-review matrix | Identity owner |
| 4 | Are CUI-bearing items labeled, and are the protections confirmed? | Label map + confirmation record | Information-protection owner |
| 5 | Where do Fabric and OneLake audit events land? | Logging entry in the System Security Plan | Security operations |
| 6 | What is the capacity posture? | Capacity posture sheet per capacity | Capacity owner / finance |
| 7 | What may an agent do? | Approved-actions list per agent | Agent owner |
| 8 | Which workload goes first? | First-workload selection memo | Program sponsor |
| 9 | What moves, what retires, what stays? | Commercial-exit plan with dates | Platform lead |
1. Confirm the workload is actually available in GCC High today
List every Fabric item the design depends on — lakehouse, warehouse, eventhouse, pipelines, mirroring source, shortcut target, semantic-model storage mode, any Copilot or agent experience — and check each against Microsoft's GCC High page on the day you decide. Record the page's last-updated date beside each line. On October 4, 2026, the lines most likely to fail were shortcuts to anything other than Azure Blob Storage or ADLS Gen2, mirroring from anything other than Azure SQL Database, Copilot in Power BI, Fabric IQ items, customer-managed keys and workspace monitoring. Done when: every dependency is marked available, substituted, or deferred with a named date to re-check. A design that needs an unavailable feature is a design that waits.
2. Decide whether the Fabric workspace is inside the assessment scope
If CUI will land in OneLake, the workspace, its capacity and its administrators are in scope for the Level 2 assessment — self-assessed today, and assessed by whoever the Department designates later. Write the decision as a one-page memo: what data, which workspaces, which capacity, which regions, who administers them, and the Microsoft authorization status you recorded in section 3. Attach the data-flow diagram. Done when: the affirming official has read and initialed the memo, and the System Security Plan references it.
3. Map identity before data
Fabric in GCC High inherits Microsoft Entra identity. Confirm that conditional access, privileged identity management and the access-review cadence you already run under NIST SP 800-171 extend to four new populations: workspace roles, capacity administrators, the Fabric administrator role, and any service principal or gateway identity a pipeline uses. Every OneLake shortcut is an access path an assessor will trace, so list them. Done when: a role matrix names every identity with Admin, Member or Contributor rights on a CUI workspace and the date of its next review.
4. Label the items that will hold CUI, and confirm the protections before relying on them
Microsoft lists sensitivity labels as available for Fabric in GCC High. Apply Microsoft Purview sensitivity labels to the lakehouses, warehouses and semantic models that will hold CUI, and decide in writing whether downstream inheritance is expected. Data loss prevention policies for Fabric items, and other Purview controls you may use in the commercial cloud, are not on Microsoft's GCC High list as read on October 4, 2026 — confirm each with Microsoft before your System Security Plan claims it. Done when: a label map shows item, label, owner and the date each protection was confirmed.
5. Route Fabric and OneLake audit events into the evidence trail
The audit and accountability requirements do not exempt a new platform. Workspace monitoring is not supported in GCC High today, so decide which audit path carries Fabric and OneLake activity in your tenant, where those events are retained, for how long, and who reviews them. Record all four in the System Security Plan. Done when: a reviewer can produce, on request, last week's Fabric activity for one named user on one named workspace.
6. Set the capacity posture in writing
Fabric workloads and Power BI draw from the same capacity. For each capacity write down the size, the region, who may create Fabric items on it, who reviews consumption, and what happens when it is exhausted. Microsoft's capacity overage option — in preview in the commercial cloud, billing excess compute rather than throttling — should be marked on, off, or not available, per capacity, after you confirm its status in GCC High. Done when: every capacity has a one-line posture and a named owner who reads the consumption report monthly.
7. Treat agents as principals
Copilot in Power BI and the Fabric IQ agent items are not supported in GCC High as of October 4, 2026. Write the rule before they arrive: in a CMMC-scoped environment, an agent is a non-human identity with an owner, a workspace scope, a list of approved actions and a log. The same rule already applies to any automation you run today — a pipeline with a service principal is an agent in every sense an assessor cares about. Done when: the approved-actions template exists and every current service principal has an owner.
8. Sequence the first workload by evidence value, not ambition
The right first workload is the one already producing a finding or a manual hand-off: a Power BI estate refreshing from file shares, a compliance report assembled by hand each month, or the consolidation of configuration, access-review and incident evidence into one governed reporting layer for the assessment itself. Done when: the selection memo names one workload, the finding it closes, and the measure that shows it closed.
9. Plan the exit from the commercial cloud deliberately
Contractors with Power BI Premium or Fabric in a commercial tenant should document what moves, what is retired and what stays — with dates — so the boundary diagram an assessor reviews matches reality on the day it is requested. Include gateways, scheduled refreshes, embedded reports, shared datasets and every external user. Done when: each commercial workspace has one of three labels (move, retire, stay) and a date.
Firms to consider for “Microsoft Fabric consulting firms for GCC High”
A contractor shortlisting help with Fabric in GCC High is usually choosing among a few archetypes. The firms below are described from their own public pages, grouped and not ranked; EPC Group sits inside its archetype.
- Slalom (regional consultancy, multi-platform) — Seattle-based consultancy that delivers through local-market teams across Microsoft and other platforms.
- Netwoven (Microsoft 365 and data boutique) — California-based Microsoft 365 and Microsoft Fabric consultancy.
- Concurrency (Microsoft data platform boutique) — Wisconsin-based Fabric and Azure data platform consultancy.
- 3Cloud (Azure-focused services firm) — Azure-focused services firm with a data and analytics practice.
- EPC Group (Microsoft-first specialist) — Houston-based Microsoft consulting firm founded in 1997 holding all six Microsoft Solutions Partner designations; senior-architect-led programs for healthcare, financial services, higher education and defense.
- Pragmatic Works (training-led Microsoft consultancy) — Jacksonville, Florida; Microsoft data platform and SharePoint consulting alongside a training and certification business.
5. What will an assessor ask about an analytics platform?
EPC Group groups the questions an assessor asks about an analytics platform into five families of NIST SP 800-171 Rev 2. The requirement numbers are pointers to the family, not a complete mapping.
| Family | What the assessor asks about Fabric | Evidence that answers it |
|---|---|---|
| Access control (3.1) | Who holds workspace, capacity and tenant roles? How is least privilege applied (3.1.5)? Do shortcuts or mirrored sources create paths to external systems (3.1.20)? How is the flow of CUI controlled (3.1.3)? | Role matrix; access-review records; shortcut and connection inventory; data-flow diagram |
| Audit and accountability (3.3) | Which events are logged and retained (3.3.1)? Can an action be traced to one user (3.3.2)? Who reviews the logs, and how are they protected (3.3.8)? | Logging entry in the SSP; a sample of reviewed events; retention setting |
| Configuration management (3.4) | Is there a baseline and inventory of workspaces, capacities and connections (3.4.1)? Are changes approved and recorded (3.4.3)? | Workspace and capacity inventory; deployment-pipeline history; change records |
| Identification and authentication (3.5) | Is every user, and every process acting on behalf of a user, identified (3.5.1) and authenticated (3.5.2), with multifactor where required (3.5.3)? | Conditional access policy export; service-principal register; gateway identity list |
| System and information integrity (3.14) | How is the platform monitored (3.14.6)? How is unauthorized use identified (3.14.7)? How do labels and protection policies apply to the data and to anything that reads it? | Label map; alert rules; the monitoring procedure |
Two families outside the five deserve a line each. System and communications protection (3.13) is where the encryption questions land — including how CUI at rest is protected (3.13.16) and the fact that customer-managed keys are not available in Fabric for GCC High today. Security assessment (3.12) is where the System Security Plan itself is required (3.12.4); every “record it in the SSP” on this page points there.
A contractor that can answer the five families with documents rather than demonstrations holds its analytics estate as an asset in the assessment rather than an exception to it.
6. How TAR-8 maps to the five question families
EPC Group's openly published 8-Surface Tenant AI Readiness Standard, TAR-8, was written for the ordering problem this page describes: control the surface before switching on the workload that depends on it. Each surface is scored 0 (unknown), 1 (inventoried), 2 (controlled) or 3 (evidenced).
| TAR-8 surface | Assessor family it answers | What it means for Fabric in GCC High |
|---|---|---|
| 1 Identity | Identification and authentication; access control | Entra roles, conditional access and reviews cover Fabric roles and service principals |
| 2 Sensitive data | System and information integrity; access control | CUI-bearing items carry labels; protections confirmed in GCC High |
| 3 Content estate | Access control | The SharePoint and OneDrive sources a pipeline reads are not overshared before they are ingested |
| 4 Conversations | Access control; audit | Teams transcripts and chat exports are classified before they become lakehouse tables |
| 5 Reports and dashboards | Configuration management; access control | Semantic models are certified, owned and row-level secured |
| 6 Business applications and agents | Access control; identification and authentication | Automations and agents act only through approved actions |
| 7 Infrastructure and external models | Configuration management | Capacities, regions, gateways and network paths are inventoried and baselined |
| 8 Ownership and evidence | Audit and accountability | Named owners, registers and the SSP entries that show governance operating |
The standard's gating rule is that any surface at zero means the tenant is not ready, regardless of the total.
The standard is public at /insights/microsoft-365-tenant-ai-readiness-8-surface-standard, and EPC Group delivers it as a fixed-scope readiness assessment.
7. Identity: map it before the data
EPC Group starts every GCC High Fabric design with a role matrix, because identity is the control every other control depends on.
- Workspace roles. Admin, Member, Contributor and Viewer. Admin and Member can change access; treat both as privileged.
- Capacity administrators. They can assign workspaces to a capacity and change its settings. Usually too many people hold this.
- The Fabric administrator role. Tenant-wide settings, including who may create Fabric items. Put it under privileged identity management with time-bound activation.
- Service principals and gateway identities. Every pipeline, dataflow and scheduled refresh runs as something. Name it, own it, review it. Workspace identity is not available in GCC High today, so these identities will be service principals, gateway credentials or user credentials — the last is the one to eliminate.
- OneLake shortcuts. Limited in GCC High to Azure Blob Storage and ADLS Gen2. Each shortcut is a standing connection to another storage account: record the target, the credential and the owner.
- External and guest users. Decide whether any exist on a CUI workspace. The usual right answer is none.
Then extend what already runs: conditional access policies should cover the Fabric and Power BI service; access reviews should include workspace membership on the cadence your SSP already states; and joiner-mover-leaver processes should remove workspace roles, not just licenses.
8. Information protection: labels first, then confirm the rest
EPC Group's order of operations is label, then verify, then rely.
Label. Decide which sensitivity label means CUI in your tenant and apply it to each lakehouse, warehouse and semantic model that will hold CUI before data is loaded. Decide whether reports and exports built on those items are expected to inherit the label, and test that they do. Microsoft's reference is Information protection in Microsoft Fabric.
Verify. For each further protection you intend to cite — data loss prevention on Fabric items, protection-policy enforcement, restrictions on export — confirm with Microsoft that it operates in GCC High. Microsoft's list as read on October 4, 2026 names sensitivity labels and item sharing under governance and security, and OneLake security under platform functionality. Anything beyond that list is an assumption until confirmed.
Rely. Only confirmed protections go into the System Security Plan. A control described in the SSP that does not operate in your environment is worse than a gap: it is a statement an affirming official signed.
OneLake security — the ability to define who can read which folders and tables in OneLake itself — is listed by Microsoft as matching the commercial service. Where it is used, document the roles the same way as workspace roles. Row-level and object-level security in semantic models remain the control for what a report reader sees; certify the models that carry them. EPC Group's method for that is in semantic-model certification for AI grounding.
9. Logging: where the evidence trail lands
EPC Group asks four questions about logging, and the answers go into the System Security Plan as one paragraph.
- Which audit path carries Fabric and OneLake activity in this tenant? Workspace monitoring is not supported in GCC High today. Confirm with Microsoft which audit log and which administrative interfaces expose Fabric and Power BI activity in your GCC High tenant, and whether OneLake data-access events are included; Microsoft's commercial reference is Track user activities in Microsoft Fabric.
- Where do the events land? If you run a security information and event management platform inside the boundary, decide whether Fabric activity is forwarded to it. If the events stay in the Microsoft audit log, say so.
- How long are they retained? State the retention period and where it is configured. The period should match what the SSP already commits to for other in-scope systems.
- Who reviews them, how often, and what do they look for? Name the role. List the events that matter: role changes on CUI workspaces, new shortcuts and connections, exports and downloads, capacity setting changes, and sharing of labeled items.
Run the test in checklist point 5 before go-live: one named user, one named workspace, last week's activity, produced on request. If that takes more than an hour, the evidence trail is not operating yet.
10. Capacity and agents as governed principals
EPC Group treats a capacity and an agent the same way: each is a principal with an owner, a limit and a log.
Capacity. In GCC High there is no trial, so the first capacity is a purchase or an existing Power BI Premium capacity. Write one posture line per capacity: size and region (US Gov Virginia or US Gov Texas); which workspaces are assigned; who may create Fabric items; who reads consumption and when; what happens at exhaustion. Fabric smooths and then throttles work when a capacity is over-consumed; a throttled capacity delays the compliance report along with everything else, so the evidence workloads deserve their own headroom or their own capacity. Confirm with Microsoft whether the Capacity Metrics app and the capacity overage option are available in your GCC High tenant before the posture line refers to either. EPC Group's sizing method is in Fabric capacity FinOps and right-sizing, and the Premium-to-Fabric transition is covered in the capacity runbook.
Agents. No Fabric IQ agent item and no Copilot in Power BI runs in GCC High as of October 4, 2026. That is the right moment to write the rule. For each agent or automation: an owner by name; the workspace scope; the approved actions; the identity it runs as; where its actions are logged; a review date; a retirement date. The first entries in that register are not AI at all — they are the pipelines and scheduled refreshes already running under service principals. When Microsoft brings agent features to GCC High, they join a register that already exists. EPC Group's approach to agent controls is described in Copilot Studio agent governance.
11. The ninety-day window: October 1 to December 31
Because the Department has not published a replacement schedule, EPC Group suggests the contractor set its own: the calendar quarter in which Fabric became available, ending before most Power BI Premium renewals come due.
| Days | Dates | Work | Output |
|---|---|---|---|
| 1–15 | Oct 1 – Oct 15 | Read Microsoft's GCC High list against the design; decide scope in writing; request the authorization status from Microsoft; inventory the commercial analytics estate | Feature worksheet; scope memo; commercial inventory |
| 16–45 | Oct 16 – Nov 14 | Extend conditional access, privileged identity management and access reviews to Fabric roles; label the CUI-bearing items; confirm protections; settle the audit path and retention | Role matrix; label map; SSP logging entry |
| 46–75 | Nov 15 – Dec 14 | Provision or designate the first capacity with a written posture; migrate the first workload; finish the data-flow diagram | Capacity posture; first workload live; diagram |
| 76–90 | Dec 15 – Dec 31 | Internal evidence review against the five families; correct gaps; freeze the boundary diagram; refresh the SPRS self-assessment | Evidence review record; updated SSP; SPRS score that matches the environment |
The last step is the one that makes the quarter count. A self-assessment score posted before the Fabric workspace existed describes a different environment. Refresh it in SPRS when the boundary changes, so the score on record and the system in operation are the same system.
A contractor starting later than October 1 keeps the same four phases and moves the dates. The order does not change.
12. How EPC Group runs it
EPC Group runs a GCC High Fabric engagement in four fixed-scope steps, each ending in a written deliverable.
- TAR-8 score. A read-only assessment of the eight surfaces, with the gating rule applied to the Fabric decision.
- Scope decision. The memo, the data-flow diagram and the recorded authorization status — the three artifacts in section 3.
- First workload. One workload, chosen by evidence value, built on a capacity with a written posture.
- Evidence review. The five-family review, the SSP updates and the SPRS refresh.
Scope is confirmed after a scoping call. Defense contractors and agencies can request one at /contact/gcc-high-cmmc; the firm's federal practice is described at /industries/federal-government, and its Fabric practice at /services/fabric-consulting.
What EPC Group's record in this space actually is
EPC Group separates third-party facts from company-reported figures and applies that rule to itself.
Third-party. The firm holds all six Microsoft Solutions Partner designations, verifiable through Microsoft's partner directory. It is a G2 Leader in Business Intelligence Consulting for 7 consecutive quarterly reports through Fall 2026, with a Fall 2026 Momentum Leader badge — designations G2 calculates from verified client reviews and market-presence data; the full list with each issuer and period is on the Recognition page.
Company-reported. From EPC Group's own records: 1,500+ Power BI deployments and 500+ Microsoft Fabric implementations, within 11,000+ enterprise engagements since 1997.
Documented. The engagements published with claim levels and hashed source files in the Evidence Center include public-sector and defense records for NASA Johnson Space Center, the National Institutes of Health, the Federal Reserve Bank of New York, Northrop Grumman, the Office of the Texas State Chemist and the Town of Prosper, Texas. The methodology page explains what each record does and does not establish.
Frequently asked questions
Frequently Asked Questions
Yes. Microsoft announced public preview on September 2, 2026 and general availability on October 1, 2026, with feature availability varying by workload. EPC Group recommends reading Microsoft's GCC High page on the day of each design decision, because the list changes.
Sources
- Microsoft — Microsoft Fabric in GCC High: Building the data foundation for AI (Douglas Phillips, September 2, 2026)
- Microsoft Learn — Microsoft Fabric for US Government GCC High customers (read October 4, 2026)
- Department of War — Under Secretary of War (A&S) memorandum 26-P-1023 implementing the Chief Information Officer's suspension of CMMC Phase 2 (July 13, 2026)
- Defense Pricing, Contracting, and Acquisition Policy — Class Deviation 2026-O0025, Revision 3 (September 3, 2026)
- 32 CFR Part 170 — Cybersecurity Maturity Model Certification Program (eCFR)
- DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting (eCFR)
- NIST SP 800-171 Revision 2
- Supplier Performance Risk System (SPRS)
- Microsoft Learn — Information protection in Microsoft Fabric
- Microsoft Learn — Track user activities in Microsoft Fabric
- Microsoft Learn — Understand your Fabric capacity throttling
- G2 — EPC Group reviews
Related reading