Skip to main content

CMMC Level 2 Gap Assessment and Microsoft 365 GCC High Migration for Defense Contractors

Last updated by Errin O'Connor, Founder & Chief AI Architect, EPC Group

EPC Group's CMMC Level 2 gap assessment scores a defense contractor's environment against the 110 NIST SP 800-171 requirements in three weeks — evidence seen and missing for each, the DoD-methodology score, the SSP findings, an ordered POA&M, a written GCC High fit decision and a roadmap to a C3PAO assessment — delivered by US persons under a written contractual term. Phase 2 of the CMMC acquisition rollout is dated November 10, 2026, when the Level 2 third-party certification may be required on awards involving CUI. Contractors past that date get remediation sprints and, where needed, the Microsoft 365 GCC High migration as fixed-fee engagements scoped from the gap register; a monthly managed-compliance cadence keeps the controls passing afterwards. Fixed fee, quoted after a scoping call; no rate card.

Key Facts

  • CMMC Level 2 is the 110 security requirements of NIST SP 800-171, assessed by a C3PAO on a three-year cycle for contracts that involve controlled unclassified information.
  • Phase 2 of the CMMC acquisition rollout is dated November 10, 2026 — the Level 2 C3PAO certification may appear as a condition of award from that date.
  • The gap assessment runs three weeks and returns the gap register, SSP findings, an ordered POA&M, the GCC High fit decision, the readiness roadmap and an executive readout.
  • US-persons delivery is a written contractual term of the statement of work, not a verbal assurance.
  • Missed November 10? The order does not change — assess, remediate, certify — remediation sprints and the GCC High migration are scoped from the gap register.
  • Managed compliance runs monthly (monitoring, evidence, POA&M), quarterly (tabletop, access review, SSP check) and annually (affirmation, SPRS, pre-assessment).
  • Fixed fee, quoted within 48 hours of a scoping call; Microsoft licensing is a Microsoft cost at list pricing; EPC Group publishes no rate card.

Phase 2 is dated November 10, 2026

The CMMC acquisition rule took effect in November 2025 and phases the requirement into contracts over three years. In Phase 1 a contractor handling controlled unclassified information could satisfy Level 2 with a self-assessment posted to SPRS and an affirmation from a senior official. Phase 2 is dated November 10, 2026: from that date the Department may require the Level 2 certification assessed by a C3PAO as a condition of award on applicable solicitations and contracts, and primes are already writing it into flow-downs ahead of the date.

A C3PAO scores the 110 requirements of NIST SP 800-171 against your system security plan and the evidence you can produce. A conditional certificate is possible with a POA&M, but the open items have to close within 180 days and the requirements that cannot be deferred have to be in place on the day. The gap between what most contractors' SSPs say and what their tenants do is what the gap assessment measures.

The seven areas the assessment scores

1

Access control, identification and authentication

Who can reach CUI and how they prove it: Entra ID Conditional Access, MFA on every account including privileged and service accounts, session and device controls, the separation of duties the 800-171 families expect.

2

Audit, accountability and incident response

What is logged, for how long, who reviews it and how a CUI incident is detected, contained and reported within the DFARS 252.204-7012 72-hour window — Purview Audit, Defender and Sentinel as they are actually configured.

3

Configuration and system integrity

Intune baselines, patch cadence, endpoint protection, allow-listing, the change process, and the flaw-remediation evidence an assessor asks to see.

4

Media, physical and personnel protection

Where CUI lands beyond the tenant — removable media, printers, home offices, subcontractors — and the screening, training and off-boarding records that go with it.

5

Risk, security assessment and system protection

The risk assessment on file, the last self-assessment and its SPRS score, boundary and encryption controls, and whether the information system boundary described in the SSP matches the tenant that exists.

6

The system security plan and the POA&M

Whether the SSP describes each of the 110 requirements as implemented, and whether every gap has an owner, a date and a closure plan a C3PAO would accept — the two documents an assessment is scored against.

7

Cloud fit: commercial, GCC or GCC High

Whether the workloads that hold CUI, export-controlled or ITAR data sit in a Microsoft cloud that supports the DFARS 7012 flow-down and the data-handling commitments your contracts require — and what a GCC High migration would move, keep and retire.

The six deliverables

  1. 1

    The 110-requirement gap register

    Every NIST SP 800-171 requirement marked implemented, partially implemented or not implemented, with the evidence seen, the evidence missing and the scoring under the DoD assessment methodology — the same view a C3PAO builds.

  2. 2

    SSP findings and rewrite plan

    Where the system security plan is silent, wrong or describes a system that no longer exists, and the corrected statements for each affected requirement.

  3. 3

    The POA&M, ordered

    Each open item with an owner, a target date, the technical change behind it and its effect on the score — sequenced so the items that block certification close first and the 180-day POA&M closeout after a conditional certificate stays reachable.

  4. 4

    GCC High fit decision

    A written recommendation — stay, move to GCC, or move to GCC High — with the workloads, identities and data that would move, the licensing path, and the order of a migration if one is needed.

  5. 5

    Assessment-readiness roadmap

    The remediation waves, the evidence-collection plan, the affirmation the senior official will sign, and the date by which a C3PAO engagement can be scheduled with confidence.

  6. 6

    Executive readout

    One session with the accountable executive and the contracts lead: where you stand against Phase 2, what it costs in time and effort to close, and what to tell the prime.

Missed November 10? Remediation and the GCC High migration

The order of work does not change after the date — assess, remediate, certify — but the sequencing with your contracts team does, because the prime or the contracting officer may already be asking for the certificate. EPC Group runs the remediation as fixed-fee sprints scoped from the gap register: the Conditional Access and MFA baseline, the Purview labels and DLP for CUI, the Intune baselines and patch evidence, the logging and incident-response runbook against the 72-hour clock, and the SSP rewritten to describe the system that exists.

Where the fit decision calls for it, the Microsoft 365 GCC High migration moves the CUI workloads, identities and mail first, so the assessment boundary is clean and the rest of the estate can follow on its own schedule. The migration is scoped from the same register — what moves, what stays in commercial, what retires — and delivered by US persons under the same written term.

Managed compliance — the cadence after certification

Monthly

Control monitoring against the 110 requirements, evidence refresh for the items that age (access reviews, patch reports, log reviews), POA&M status with owners, a written summary for the compliance file.

Quarterly

A tabletop exercise against the 7012 incident-reporting clock, a Conditional Access and privileged-access review, a check of the SSP against the tenant as it stands.

Annually

The affirmation package for the senior official, the self-assessment and SPRS update where the contract calls for one, and the readiness check ahead of the triennial C3PAO assessment.

A monthly retainer scoped to the tenant and the number of systems in the boundary; described here without figures.

Participants, duration, prerequisites

From your side

A named sponsor, the contracts lead, the tenant administrators, and the owners of the systems that touch CUI.

Duration

Three weeks for a single tenant and boundary; scoped up front where several tenants, sites or classified-adjacent systems are in play. Weekly working sessions in weeks one and two, the readout in week three.

Prerequisites

Read access to the Microsoft 365 and Azure admin portals, Purview, Defender and Intune; the current SSP, POA&M and last self-assessment; the system inventory; the list of awards carrying the 7012 and CMMC clauses.

Why EPC Group

Frequently Asked Questions

What does the CMMC Level 2 gap assessment deliver?

A three-week, fixed-fee engagement in which EPC Group assesses your environment against the 110 NIST SP 800-171 requirements that make up CMMC Level 2 — access control through system and communications protection — with the evidence seen and missing for each, the score under the DoD assessment methodology, the system security plan findings, an ordered POA&M, a written GCC High fit decision and a roadmap to a C3PAO assessment. One senior architect leads it from scoping to readout.

Why does November 10, 2026 matter?

The CMMC acquisition rule took effect in November 2025 with a phased rollout. Phase 2 is dated November 10, 2026: from that date the Department may include the Level 2 third-party (C3PAO) certification requirement in applicable solicitations and contracts that involve controlled unclassified information, where Phase 1 allowed a self-assessment. A contractor that has not closed its gaps and scheduled its C3PAO by then is exposed on every affected award and option.

Missed November 10? What then?

The order of work does not change: gap assessment, remediation, then the C3PAO. What changes is the urgency and the sequencing with your contracts team, because the prime or the contracting officer may already be asking for the certificate. EPC Group runs the remediation sprints and, where the fit decision calls for it, the Microsoft 365 GCC High migration as fixed-fee engagements scoped from the gap register — the migration moving the CUI workloads, identities and mail first so the assessment boundary is clean.

Do we need Microsoft 365 GCC High?

Not always. GCC High is the Microsoft cloud built for contractors handling CUI, ITAR and export-controlled data under the DFARS 7012 flow-down, with the data-handling and personnel commitments those contracts require. Many Level 2 contractors can meet the 110 requirements in commercial or GCC tenants when their data and contracts allow it; others cannot. The fit decision in the assessment answers this for your contracts and your data, in writing, before anyone buys licenses.

What does "US-persons delivery, contracted in writing" mean?

That the statement of work names US persons as the only people who access your environment and your CUI during the engagement, and says so as a contractual term — not a verbal assurance. It is the same standard your DFARS flow-downs impose on you, applied to your consultant.

How is the work priced?

The gap assessment is a fixed fee, quoted within 48 hours of a scoping call that confirms the number of tenants, sites and systems in the assessment boundary; remediation sprints and the GCC High migration are fixed fees scoped from the gap register. EPC Group publishes no rate card. Microsoft licensing — GCC High, Azure Government, Defender, Purview — is a Microsoft cost at Microsoft list pricing, separate from the services.

What is the managed-compliance cadence?

After certification the controls have to keep passing. The monthly cadence covers control monitoring, evidence refresh and POA&M tracking with a written summary for the compliance file; quarterly a tabletop exercise, an access review and an SSP check; annually the affirmation package, the self-assessment or SPRS update and the readiness check before the triennial C3PAO assessment. It is a monthly retainer scoped to the tenant, described here without figures.

Who takes part, and what do you need from us?

A named sponsor; the contracts lead who knows which awards carry the 7012 and CMMC clauses; the tenant administrators; read access to the Microsoft 365 and Azure admin portals, Purview, Defender and Intune; the current SSP, POA&M and last self-assessment; and the inventory of systems that touch CUI. Weekly working sessions in weeks one and two, the readout in week three.

How does AI governance fit a CUI environment?

Copilot, Copilot Studio agents and third-party AI tools reach whatever the tenant lets them reach; in a CUI environment that is an assessment finding waiting to happen. The gap assessment records where AI tools sit against the boundary; EPC Group's virtual Chief AI Officer service carries the AI governance program forward for contractors that need an accountable owner for it.

Related EPC Group services and references

Book the scoping call

Thirty minutes: your contracts, your tenant, your boundary. The fixed fee follows within 48 hours.

AI assistant — not human