2-minute answer

Do you actually
need GCC High?

Five questions. No form, no gate, and an honest answer if the answer is no — these are the same questions we would ask on a scoping call, so you may as well have them first.

  1. 01

    Does DFARS 252.204-7012 appear in any contract or flow-down you've signed?

    If yesThen you have already agreed to safeguard covered defense information to NIST SP 800-171 and to report incidents within 72 hours. This is the single strongest signal.

    If noCheck the subcontract flow-downs, not just the prime award. The clause usually arrives through a prime's terms rather than directly.

  2. 02

    Do you receive, create, or store Controlled Unclassified Information?

    If yesDrawings, specifications, test data, program schedules, and anything marked CUI or CDI. If it lives in email or a shared drive today, it lives outside a boundary built to hold it.

    If noBe careful here. Most contractors who say no are thinking of markings; CUI is defined by category, and plenty of it arrives unmarked from a prime.

  3. 03

    Do you handle ITAR or EAR export-controlled technical data?

    If yesExport-controlled technical data has to stay with US persons on US soil. That is an access-control requirement your commercial tenant cannot meet — support staff location alone can put you out of compliance.

    If noIf you make, design, or test anything on the US Munitions List, verify with your export-control officer before answering no.

  4. 04

    Is CMMC Level 2 in a solicitation you intend to bid?

    If yesLevel 2 is assessed against all 110 NIST SP 800-171 controls by an accredited third party. Building the environment after you win is the expensive order to do it in.

    If noCheck the pipeline, not just the current backlog. The requirement is phasing into DoD solicitations now, and the lead time on an environment is measured in months.

  5. 05

    Is your SPRS score self-attested against an environment you can actually evidence?

    If yesGood — that is the position you want to be in when an assessor asks for evidence rather than for a score.

    If noA score submitted against controls nobody implemented is the most common finding we see, and it is the one with the most exposure attached to it.

What your answers mean

The honest read.

Yes to 1, 2, or 3
You almost certainly need GCC High. Export-controlled data and a signed DFARS clause are not requirements you can engineer around inside commercial Microsoft 365, and a prime will eventually ask you to prove where the data lives.
Yes to 4 only
You need a plan, and probably an environment, before you bid. Whether that means a full move or a scoped set of seats depends on how much of your business actually touches CUI.
No across the board
You may not need GCC High at all. Commercial Microsoft 365 or GCC with the right controls is sometimes enough, and we will tell you that rather than sell you a larger environment than your contracts require.

Whatever the answer, no environment makes you compliant on its own. CMMC Level 2 is a third-party assessment against the 110 NIST SP 800-171 controls, performed independently by an accredited C3PAO. Optimal engineers the environment and prepares the evidence — we prepare, we don't grade.

Answered yes
more than once?

Bring us the clauses and we'll scope it — how much of your business actually needs to move, what it costs, and what the alternative looks like if a smaller scope covers your obligations.