Controlled Unclassified Information
CUI carries handling requirements your prime and the DoD will hold you to. GCC High is built to store and process it inside a US-sovereign boundary — not bolted onto commercial email.
Handling CUI or ITAR-controlled data on a DoD contract means meeting DFARS 252.204-7012 and, increasingly, CMMC Level 2. Optimal stands up your Microsoft 365 GCC High environment, migrates your people and data into it, engineers the NIST SP 800-171 controls, and runs it for you — so compliance becomes a capability you operate, not a fire drill before every award.
Build / Migrate / Engineer controls / Manage
Four things drive a defense contractor into GCC High. If any of them are in your contracts, the environment isn't optional.
CUI carries handling requirements your prime and the DoD will hold you to. GCC High is built to store and process it inside a US-sovereign boundary — not bolted onto commercial email.
Export-controlled data must stay with US persons on US soil. GCC High provides screened US-person support and US data residency — the access control ITAR and EAR expect.
DFARS 252.204-7012 requires NIST SP 800-171 safeguarding and rapid incident reporting. GCC High is the environment engineered to meet the clause you already signed.
CMMC is phasing into DoD solicitations now. Level 2 means a third-party assessment against 800-171 — and an enclave built for those controls is how you pass it the first time.
Other shops migrate your email and hand you the keys. Optimal builds the enclave, moves you in, engineers the controls, and keeps running it — the whole lifecycle, on one contract.
A compliant Microsoft 365 GCC High tenant, hardened to a CUI-ready baseline from day one.
Your people and data moved into the boundary cleanly — no CUI left where it shouldn't be.
The 800-171 control set implemented, documented, and ready to be assessed.
The ongoing operations that keep the enclave compliant long after go-live.
GCC High G5 licensing and provisioning included — we source and stand up your licenses and tenant, so there's no separate reseller to chase.
CMMC Level 2 assesses your program against the 14 families and 110 controls of NIST SP 800-171. We implement them in the enclave, document them in your SSP, track residual gaps in a POA&M, and hand your assessor an environment that's ready to be graded.
Where we draw the line: Optimal builds and prepares the environment and gets you assessment-ready. The certified CMMC assessment is performed independently by an accredited C3PAO — we don't assess our own work, and we won't tell you you're compliant. We'll tell you you're ready.
Most GCC High shops migrate your mailboxes and disappear. Optimal's other half is AI security — so once the enclave is standing, we stand up governed access to the frontier models authorized for your sovereign cloud: Azure OpenAI in Azure Government, and Microsoft 365 Copilot as it reaches GCC High.
One authenticated gateway, fail-closed guardrails, default-deny egress, and an audit trail — the same open-source Zero Trust pattern we publish. Your cleared teams get real AI on mission work, governed and logged, inside the boundary. See the architecture →
Primes and subcontractors, manufacturers, aerospace and defense, and R&D shops — anyone with CUI or ITAR obligations flowing down from a prime. Especially the small and mid-size contractors who can't staff a full compliance and IT security team, and can't afford to lose an award over it.
Microsoft 365 GCC High is a dedicated, US-sovereign deployment of Microsoft 365 that runs in Microsoft's Azure Government cloud. It is physically and logically separated from the commercial and standard-government (GCC) environments, keeps data in the continental US, and is supported only by screened US persons. It exists so defense contractors can handle CUI, ITAR, and export-controlled data under DFARS and CMMC.
GCC (Government Community Cloud) runs on commercial infrastructure with some government features and is fine for many state, local, and federal-civilian needs. GCC High runs in Azure Government with stricter personnel screening, US-person support, and data-residency controls, and is the environment recommended — and often required — for CUI and ITAR-regulated defense data. If ITAR or DFARS/CMMC is in your contract, GCC High is usually the answer.
If your DoD contracts flow down DFARS 252.204-7012, involve CUI, or touch ITAR/export-controlled technical data, you almost certainly need GCC High. If you're unsure, we'll review your contract clauses and data types and tell you honestly — sometimes GCC or Commercial with the right controls is enough, and we'll say so rather than sell you a bigger environment than you need.
No environment makes you compliant on its own. CMMC Level 2 is a third-party assessment against the 110 NIST SP 800-171 controls. What GCC High gives you is a foundation built for those controls. Optimal implements and documents the control set inside your enclave (SSP and POA&M), collects the evidence, and gets you assessment-ready — but the certified assessment is performed independently by an accredited C3PAO. We prepare the environment; we don't grade our own work.
Most migrations run four to eight weeks, depending on user count, the volume and sensitivity of the data, and your source environment. We scope it precisely up front and run the cutover with coexistence so your team keeps working through the transition.
Yes, increasingly. Azure OpenAI is available in Azure Government today, and Microsoft 365 Copilot is rolling out to GCC High. Optimal stands up governed access to whatever AI is authorized for your environment — behind an authenticated gateway with fail-closed guardrails and an audit trail — so your cleared users get AI on mission work without data leaving the boundary. That governed-AI layer is what sets us apart from a migration-only shop.
Yes. We source and provision your Microsoft 365 GCC High G5 licensing and stand up the tenant, so you don't have to manage a separate licensing relationship on top of everything else.
Yes — that's the point. After go-live we run day-to-day administration, patching, monitoring, user lifecycle, security operations, and help desk, and we keep your SSP and evidence current so you stay assessment-ready between contracts and re-assessments.
Tell us the contracts you're chasing, the data you handle, and where you are today — Commercial, GCC, or nothing yet. We'll scope the migration, the controls, and the managed service, and give you a straight answer on GCC High.
Book a scoping call →