Managed Microsoft 365 GCC High · For the defense industrial base

Your CMMC-ready enclave —
built, migrated, and managed.

Handling CUI or ITAR-controlled data on a DoD contract means meeting DFARS 252.204-7012 and, increasingly, CMMC Level 2. Optimal stands up your Microsoft 365 GCC High environment, migrates your people and data into it, engineers the NIST SP 800-171 controls, and runs it for you — so compliance becomes a capability you operate, not a fire drill before every award.

Build / Migrate / Engineer controls / Manage

Led by a former C3PAO lead assessor — TS/SCI · CISSP · CCSP · CCP · U.S. Air Force Security Forces. The person your assessor will meet →

Not sure yet? Do I actually need GCC High? Get the 2-minute answer →

SDVOSB-certified CUI & ITAR-ready GCC High G5 licensing included
Why GCC High

Commercial Microsoft 365 wasn't built for defense data. GCC High was.

Four things drive a defense contractor into GCC High. If any of them are in your contracts, the environment isn't optional.

CUI

Controlled Unclassified Information

CUI carries handling requirements your prime and the DoD will hold you to. GCC High is built to store and process it inside a US-sovereign boundary — not bolted onto commercial email.

ITAR / EAR

Export-controlled technical data

Export-controlled data must stay with US persons on US soil. GCC High provides screened US-person support and US data residency — the access control ITAR and EAR expect.

DFARS 7012

The clause already in your contracts

DFARS 252.204-7012 requires NIST SP 800-171 safeguarding and rapid incident reporting. GCC High is the environment engineered to meet the clause you already signed.

CMMC L2

The assessment that's coming

CMMC is phasing into DoD solicitations now. Level 2 means a third-party assessment against 800-171 — and an enclave built for those controls is how you pass it the first time.

The delivery model

Your tenant. Your data. Our management.

Some vendors sell a hosted enclave — their infrastructure, their tenant, your CUI living inside a boundary they own. We don't. Optimal stands up a GCC High tenant registered to your company and runs it for you.

01

You own the tenant

The GCC High subscription is registered to your company. Entra ID, the data, the keys, the audit logs — all yours. If you replace us, you keep the environment and everything in it. There is nothing of ours to migrate out of.

02

We run the operations

Identity and device policy, patching, monitoring, configuration-drift control, security operations, incident response, and help desk for your cleared users — inside your boundary, on your side of the line.

03

Licensed to your actual CUI footprint

Only the people who touch CUI need a GCC High seat. Engineering and contracts move in; the rest of the business can stay on commercial Microsoft 365 with the boundary enforced between them. Scoping that footprint is where most of the cost control lives.

How we scope it: we review your contracts and your CUI footprint and tell you what you actually need — including when a smaller scope is enough. We won't quote a company-wide migration for a problem that lives in one department.

The managed service

One partner, from first tenant to steady state.

Other shops migrate your email and hand you the keys. Optimal builds the enclave, moves you in, engineers the controls, and keeps running it — the whole lifecycle, on one contract.

01

Design & build the enclave

A compliant Microsoft 365 GCC High tenant, hardened to a CUI-ready baseline from day one.

  • GCC High tenant provisioning and hardening
  • Entra ID, Conditional Access, MFA, device compliance
  • Microsoft Defender and Purview (DLP, sensitivity labels, audit)
  • Baseline mapped to NIST SP 800-171 from the start
02

Migrate without spillage

Your people and data moved into the boundary cleanly — no CUI left where it shouldn't be.

  • Email, OneDrive, SharePoint, Teams, and identities
  • From Commercial Microsoft 365 or GCC into GCC High
  • Data classification and spillage controls in flight
  • Coexistence during cutover, minimal downtime
03

Engineer & document the controls

The 800-171 control set implemented, documented, and ready to be assessed.

  • All 110 NIST SP 800-171 controls implemented
  • System Security Plan (SSP) authored and maintained
  • POA&M for any residual gaps, tracked to closure
  • Evidence organized for a C3PAO Level 2 assessment
04

Manage & sustain

The ongoing operations that keep the enclave compliant long after go-live.

  • Day-to-day administration and user lifecycle
  • Patching, monitoring, and configuration-drift control
  • Security operations and incident-response support
  • Help desk for your cleared users

GCC High G5 licensing and provisioning included — we source and stand up your licenses and tenant, so there's no separate reseller to chase.

What it costs

Three lines, and we name all three before you sign.

Nobody should have to reverse-engineer a GCC High quote. A managed environment costs money in three places — the project that builds it, the operations that run it, and the Microsoft licensing underneath both.

01

Build & migration

A fixed-scope project: tenant provisioning, the CUI-ready hardening baseline, the 800-171 control implementation, and the migration itself. Priced on user count, data volume, and what you are moving from — Commercial, GCC, or nothing yet.

02

Managed operations

The monthly fee for running it: administration, patching, monitoring, drift control, security operations, help desk, and keeping your SSP and evidence current between assessments.

03

Microsoft licensing

GCC High G3 or G5, per user per month, on Microsoft's price list. We source and provision it so there is no separate reseller to chase — and only the seats inside your CUI footprint need it.

Microsoft raised GCC High list pricing in July 2026 — roughly 8% on G3 and 5% on G5 — so a budget written before that needs revisiting. Licensing is the line that moves without us; scoping the CUI footprint tightly is the control you have over it. Ask for the numbers on the scoping call and we'll quote all three against your actual user count.

CMMC Level 2 · NIST SP 800-171

Built for the 110 controls — and the assessment that checks them.

CMMC Level 2 assesses your program against the 14 families and 110 controls of NIST SP 800-171. We implement them in the enclave, document them in your SSP, track residual gaps in a POA&M, and hand your assessor an environment that's ready to be graded.

Access ControlAwareness & TrainingAudit & AccountabilityConfiguration ManagementIdentification & AuthenticationIncident ResponseMaintenanceMedia ProtectionPersonnel SecurityPhysical ProtectionRisk AssessmentSecurity AssessmentSystem & Communications ProtectionSystem & Information Integrity

Where we draw the line: Optimal builds and prepares the environment and gets you assessment-ready. The certified CMMC assessment is performed independently by an accredited C3PAO — we don't assess our own work, and we won't tell you you're compliant. We'll tell you you're ready.

External Service Provider

Your assessor will ask who owns which control.

Bringing in a managed provider doesn't move your obligation — it splits it. Under 32 CFR 170 the relationship has to be documented in your System Security Plan, and an assessor will expect a Customer Responsibility Matrix showing which controls the provider operates and which stay with you. An ESP that can't produce one is a finding waiting to happen.

Every managed engagement ships with a Shared Responsibility Matrix: all 110 NIST SP 800-171 controls, each marked Optimal-owned, client-owned, or shared, with the evidence artifact that proves it. It's maintained as the environment changes — not written once at go-live and left to drift out of date before your assessment.

The matrix is written for your assessor, not for us. Optimal engineers the environment and prepares the evidence; the certified CMMC assessment is performed independently by an accredited C3PAO. We prepare, we don't grade.

Included in the managed service

Vulnerability management that produces evidence, not a backlog.

800-171 expects you to inventory what you run, find the flaws in it, and show that you remediated the ones that mattered. Most contractors answer that with a scanner report nobody can act on. Your enclave runs NINELINE — Optimal’s reference implementation of AI-native supply-chain security, deployed inside your boundary.

It runs inside the boundary — your tenant, your infrastructure, air-gap capable. That is the difference between this and a SaaS scanner: the bill of materials for a defense program’s codebase is itself sensitive, and most tooling that analyzes it requires you to ship it to somebody else’s cloud. A migration-only MSP doesn’t offer this at all. See how NINELINE works →

The difference

The GCC High partner that also gives you AI.

Most GCC High shops migrate your mailboxes and disappear. Optimal's other half is AI security — so once the enclave is standing, we stand up governed access to the frontier models authorized for your sovereign cloud: Azure OpenAI in Azure Government, and Microsoft 365 Copilot as it reaches GCC High.

One authenticated gateway, fail-closed guardrails, default-deny egress, and an audit trail — the same open-source Zero Trust pattern we publish. Your cleared teams get real AI on mission work, governed and logged, inside the boundary. See the architecture →

Who it's for

Built for the defense industrial base.

Primes and subcontractors, manufacturers, aerospace and defense, and R&D shops — anyone with CUI or ITAR obligations flowing down from a prime. Especially the small and mid-size contractors who can't staff a full compliance and IT security team, and can't afford to lose an award over it.

SDVOSB — Service-Disabled Veteran-Owned Small Business, SBA VetCert certified

Optimal, LLC is an SBA-certified Service-Disabled Veteran-Owned Small Business — teaming- and set-aside-friendly for your subcontracting goals.

FAQ

GCC High & CMMC, answered.

What is Microsoft 365 GCC High?

Microsoft 365 GCC High is a dedicated, US-sovereign deployment of Microsoft 365 that runs in Microsoft's Azure Government cloud. It is physically and logically separated from the commercial and standard-government (GCC) environments, keeps data in the continental US, and is supported only by screened US persons. It exists so defense contractors can handle CUI, ITAR, and export-controlled data under DFARS and CMMC.

What's the difference between GCC and GCC High?

GCC (Government Community Cloud) runs on commercial infrastructure with some government features and is fine for many state, local, and federal-civilian needs. GCC High runs in Azure Government with stricter personnel screening, US-person support, and data-residency controls, and is the environment recommended — and often required — for CUI and ITAR-regulated defense data. If ITAR or DFARS/CMMC is in your contract, GCC High is usually the answer.

Do I actually need GCC High?

If your DoD contracts flow down DFARS 252.204-7012, involve CUI, or touch ITAR/export-controlled technical data, you almost certainly need GCC High. If you're unsure, we'll review your contract clauses and data types and tell you honestly — sometimes GCC or Commercial with the right controls is enough, and we'll say so rather than sell you a bigger environment than you need.

Does moving to GCC High make me CMMC compliant?

No environment makes you compliant on its own. CMMC Level 2 is a third-party assessment against the 110 NIST SP 800-171 controls. What GCC High gives you is a foundation built for those controls. Optimal implements and documents the control set inside your enclave (SSP and POA&M), collects the evidence, and gets you assessment-ready — but the certified assessment is performed independently by an accredited C3PAO. We prepare the environment; we don't grade our own work.

How long does a GCC High migration take?

Most migrations run four to eight weeks, depending on user count, the volume and sensitivity of the data, and your source environment. We scope it precisely up front and run the cutover with coexistence so your team keeps working through the transition.

Can I use Copilot or AI inside GCC High?

Yes, increasingly. Azure OpenAI is available in Azure Government today, and Microsoft 365 Copilot is rolling out to GCC High. Optimal stands up governed access to whatever AI is authorized for your environment — behind an authenticated gateway with fail-closed guardrails and an audit trail — so your cleared users get AI on mission work without data leaving the boundary. That governed-AI layer is what sets us apart from a migration-only shop.

Is this a hosted enclave?

No. Some vendors sell a hosted enclave — their infrastructure, their tenant, your CUI living inside a boundary they own. Optimal stands up a Microsoft 365 GCC High tenant registered to your company and manages it for you. The distinction matters when things change: a tenant you own scales with your headcount, holds your data under your keys and your audit logs, and stays yours if you replace us. With a hosted enclave, leaving the provider means moving your CUI out of someone else's environment — and losing access to it is their decision, not yours.

Do I need GCC High licenses for everyone in my company?

Usually not. Only the users who actually handle CUI or export-controlled technical data need to be inside the GCC High boundary. In most contractors that is engineering, contracts, and program management — not the whole company. The rest can stay on commercial Microsoft 365 with the boundary enforced between the two. We scope your CUI footprint first and license to it, because that is where most of the cost is decided.

What does a managed GCC High enclave cost?

It prices as three lines. First, a fixed-scope build and migration project, driven by user count, data volume, and what you are migrating from. Second, a monthly per-user fee for managed operations — administration, patching, monitoring, security operations, help desk, and keeping your SSP and evidence current. Third, Microsoft licensing, which is a per-seat cost on Microsoft's price list. We scope the CUI footprint and quote all three before you sign, and if a smaller scope covers your obligations we will tell you that instead.

What does GCC High licensing cost per user?

GCC High licensing is per user per month, on Microsoft's published price list, and the tier you need — G3 or G5 — depends on which security and compliance capabilities your control set relies on. Microsoft raised GCC High list pricing in July 2026, roughly 8% on G3 and 5% on G5, so budgets written before that need revisiting. Licensing is the line that moves without us; scoping the CUI footprint tightly is the control you have over it. We source and provision the licenses as part of the engagement.

How does Optimal work as an External Service Provider (ESP)?

Bringing in a managed provider does not move your obligation — it splits it. Under 32 CFR 170 the relationship has to be documented in your System Security Plan, and an assessor will expect a Customer Responsibility Matrix showing which controls the provider operates and which stay with you. Every managed engagement ships with a Shared Responsibility Matrix covering all 110 NIST SP 800-171 controls, each marked Optimal-owned, client-owned, or shared, with the evidence artifact that proves it — maintained as the environment changes rather than written once at go-live. Optimal prepares the environment and the evidence; the certified assessment is performed independently by an accredited C3PAO.

Do you provide the GCC High licenses?

Yes. We source and provision your Microsoft 365 GCC High G5 licensing and stand up the tenant, so you don't have to manage a separate licensing relationship on top of everything else.

Do you manage the environment after migration?

Yes — that's the point. After go-live we run day-to-day administration, patching, monitoring, user lifecycle, security operations, and help desk, and we keep your SSP and evidence current so you stay assessment-ready between contracts and re-assessments.

Let's stand up
your enclave.

Tell us the contracts you're chasing, the data you handle, and where you are today — Commercial, GCC, or nothing yet. We'll scope the migration, the controls, and the managed service, and give you a straight answer on GCC High.

Book a scoping call →