Controlled Unclassified Information
CUI carries handling requirements your prime and the DoD will hold you to. GCC High is built to store and process it inside a US-sovereign boundary — not bolted onto commercial email.
Handling CUI or ITAR-controlled data on a DoD contract means meeting DFARS 252.204-7012 and, increasingly, CMMC Level 2. Optimal stands up your Microsoft 365 GCC High environment, migrates your people and data into it, engineers the NIST SP 800-171 controls, and runs it for you — so compliance becomes a capability you operate, not a fire drill before every award.
Build / Migrate / Engineer controls / Manage
Led by a former C3PAO lead assessor — TS/SCI · CISSP · CCSP · CCP · U.S. Air Force Security Forces. The person your assessor will meet →
Not sure yet? Do I actually need GCC High? Get the 2-minute answer →
Four things drive a defense contractor into GCC High. If any of them are in your contracts, the environment isn't optional.
CUI carries handling requirements your prime and the DoD will hold you to. GCC High is built to store and process it inside a US-sovereign boundary — not bolted onto commercial email.
Export-controlled data must stay with US persons on US soil. GCC High provides screened US-person support and US data residency — the access control ITAR and EAR expect.
DFARS 252.204-7012 requires NIST SP 800-171 safeguarding and rapid incident reporting. GCC High is the environment engineered to meet the clause you already signed.
CMMC is phasing into DoD solicitations now. Level 2 means a third-party assessment against 800-171 — and an enclave built for those controls is how you pass it the first time.
Some vendors sell a hosted enclave — their infrastructure, their tenant, your CUI living inside a boundary they own. We don't. Optimal stands up a GCC High tenant registered to your company and runs it for you.
The GCC High subscription is registered to your company. Entra ID, the data, the keys, the audit logs — all yours. If you replace us, you keep the environment and everything in it. There is nothing of ours to migrate out of.
Identity and device policy, patching, monitoring, configuration-drift control, security operations, incident response, and help desk for your cleared users — inside your boundary, on your side of the line.
Only the people who touch CUI need a GCC High seat. Engineering and contracts move in; the rest of the business can stay on commercial Microsoft 365 with the boundary enforced between them. Scoping that footprint is where most of the cost control lives.
How we scope it: we review your contracts and your CUI footprint and tell you what you actually need — including when a smaller scope is enough. We won't quote a company-wide migration for a problem that lives in one department.
Other shops migrate your email and hand you the keys. Optimal builds the enclave, moves you in, engineers the controls, and keeps running it — the whole lifecycle, on one contract.
A compliant Microsoft 365 GCC High tenant, hardened to a CUI-ready baseline from day one.
Your people and data moved into the boundary cleanly — no CUI left where it shouldn't be.
The 800-171 control set implemented, documented, and ready to be assessed.
The ongoing operations that keep the enclave compliant long after go-live.
GCC High G5 licensing and provisioning included — we source and stand up your licenses and tenant, so there's no separate reseller to chase.
Nobody should have to reverse-engineer a GCC High quote. A managed environment costs money in three places — the project that builds it, the operations that run it, and the Microsoft licensing underneath both.
A fixed-scope project: tenant provisioning, the CUI-ready hardening baseline, the 800-171 control implementation, and the migration itself. Priced on user count, data volume, and what you are moving from — Commercial, GCC, or nothing yet.
The monthly fee for running it: administration, patching, monitoring, drift control, security operations, help desk, and keeping your SSP and evidence current between assessments.
GCC High G3 or G5, per user per month, on Microsoft's price list. We source and provision it so there is no separate reseller to chase — and only the seats inside your CUI footprint need it.
Microsoft raised GCC High list pricing in July 2026 — roughly 8% on G3 and 5% on G5 — so a budget written before that needs revisiting. Licensing is the line that moves without us; scoping the CUI footprint tightly is the control you have over it. Ask for the numbers on the scoping call and we'll quote all three against your actual user count.
CMMC Level 2 assesses your program against the 14 families and 110 controls of NIST SP 800-171. We implement them in the enclave, document them in your SSP, track residual gaps in a POA&M, and hand your assessor an environment that's ready to be graded.
Where we draw the line: Optimal builds and prepares the environment and gets you assessment-ready. The certified CMMC assessment is performed independently by an accredited C3PAO — we don't assess our own work, and we won't tell you you're compliant. We'll tell you you're ready.
Bringing in a managed provider doesn't move your obligation — it splits it. Under 32 CFR 170 the relationship has to be documented in your System Security Plan, and an assessor will expect a Customer Responsibility Matrix showing which controls the provider operates and which stay with you. An ESP that can't produce one is a finding waiting to happen.
Every managed engagement ships with a Shared Responsibility Matrix: all 110 NIST SP 800-171 controls, each marked Optimal-owned, client-owned, or shared, with the evidence artifact that proves it. It's maintained as the environment changes — not written once at go-live and left to drift out of date before your assessment.
The matrix is written for your assessor, not for us. Optimal engineers the environment and prepares the evidence; the certified CMMC assessment is performed independently by an accredited C3PAO. We prepare, we don't grade.
800-171 expects you to inventory what you run, find the flaws in it, and show that you remediated the ones that mattered. Most contractors answer that with a scanner report nobody can act on. Your enclave runs NINELINE — Optimal’s reference implementation of AI-native supply-chain security, deployed inside your boundary.
An authoritative bill of materials for the software you build and run, differenced on every change, with new dependencies narrated in mission terms as they land.
A frontier model reads the actual codebase — grepping, opening files, tracing call chains — to decide whether a vulnerable path is reachable from an entry point. In the reference scan that took 874 raw findings down to the 18 that required action.
Known-exploited status and exploitation probability fused with the reachability verdict, so the queue is ordered by what an adversary can actually use — not by CVSS score.
Asset inventory, flaw remediation, and risk-assessment artifacts your assessor can read directly — and the continuous-monitoring posture a continuous-ATO program expects.
It runs inside the boundary — your tenant, your infrastructure, air-gap capable. That is the difference between this and a SaaS scanner: the bill of materials for a defense program’s codebase is itself sensitive, and most tooling that analyzes it requires you to ship it to somebody else’s cloud. A migration-only MSP doesn’t offer this at all. See how NINELINE works →
Most GCC High shops migrate your mailboxes and disappear. Optimal's other half is AI security — so once the enclave is standing, we stand up governed access to the frontier models authorized for your sovereign cloud: Azure OpenAI in Azure Government, and Microsoft 365 Copilot as it reaches GCC High.
One authenticated gateway, fail-closed guardrails, default-deny egress, and an audit trail — the same open-source Zero Trust pattern we publish. Your cleared teams get real AI on mission work, governed and logged, inside the boundary. See the architecture →
Primes and subcontractors, manufacturers, aerospace and defense, and R&D shops — anyone with CUI or ITAR obligations flowing down from a prime. Especially the small and mid-size contractors who can't staff a full compliance and IT security team, and can't afford to lose an award over it.
Microsoft 365 GCC High is a dedicated, US-sovereign deployment of Microsoft 365 that runs in Microsoft's Azure Government cloud. It is physically and logically separated from the commercial and standard-government (GCC) environments, keeps data in the continental US, and is supported only by screened US persons. It exists so defense contractors can handle CUI, ITAR, and export-controlled data under DFARS and CMMC.
GCC (Government Community Cloud) runs on commercial infrastructure with some government features and is fine for many state, local, and federal-civilian needs. GCC High runs in Azure Government with stricter personnel screening, US-person support, and data-residency controls, and is the environment recommended — and often required — for CUI and ITAR-regulated defense data. If ITAR or DFARS/CMMC is in your contract, GCC High is usually the answer.
If your DoD contracts flow down DFARS 252.204-7012, involve CUI, or touch ITAR/export-controlled technical data, you almost certainly need GCC High. If you're unsure, we'll review your contract clauses and data types and tell you honestly — sometimes GCC or Commercial with the right controls is enough, and we'll say so rather than sell you a bigger environment than you need.
No environment makes you compliant on its own. CMMC Level 2 is a third-party assessment against the 110 NIST SP 800-171 controls. What GCC High gives you is a foundation built for those controls. Optimal implements and documents the control set inside your enclave (SSP and POA&M), collects the evidence, and gets you assessment-ready — but the certified assessment is performed independently by an accredited C3PAO. We prepare the environment; we don't grade our own work.
Most migrations run four to eight weeks, depending on user count, the volume and sensitivity of the data, and your source environment. We scope it precisely up front and run the cutover with coexistence so your team keeps working through the transition.
Yes, increasingly. Azure OpenAI is available in Azure Government today, and Microsoft 365 Copilot is rolling out to GCC High. Optimal stands up governed access to whatever AI is authorized for your environment — behind an authenticated gateway with fail-closed guardrails and an audit trail — so your cleared users get AI on mission work without data leaving the boundary. That governed-AI layer is what sets us apart from a migration-only shop.
No. Some vendors sell a hosted enclave — their infrastructure, their tenant, your CUI living inside a boundary they own. Optimal stands up a Microsoft 365 GCC High tenant registered to your company and manages it for you. The distinction matters when things change: a tenant you own scales with your headcount, holds your data under your keys and your audit logs, and stays yours if you replace us. With a hosted enclave, leaving the provider means moving your CUI out of someone else's environment — and losing access to it is their decision, not yours.
Usually not. Only the users who actually handle CUI or export-controlled technical data need to be inside the GCC High boundary. In most contractors that is engineering, contracts, and program management — not the whole company. The rest can stay on commercial Microsoft 365 with the boundary enforced between the two. We scope your CUI footprint first and license to it, because that is where most of the cost is decided.
It prices as three lines. First, a fixed-scope build and migration project, driven by user count, data volume, and what you are migrating from. Second, a monthly per-user fee for managed operations — administration, patching, monitoring, security operations, help desk, and keeping your SSP and evidence current. Third, Microsoft licensing, which is a per-seat cost on Microsoft's price list. We scope the CUI footprint and quote all three before you sign, and if a smaller scope covers your obligations we will tell you that instead.
GCC High licensing is per user per month, on Microsoft's published price list, and the tier you need — G3 or G5 — depends on which security and compliance capabilities your control set relies on. Microsoft raised GCC High list pricing in July 2026, roughly 8% on G3 and 5% on G5, so budgets written before that need revisiting. Licensing is the line that moves without us; scoping the CUI footprint tightly is the control you have over it. We source and provision the licenses as part of the engagement.
Bringing in a managed provider does not move your obligation — it splits it. Under 32 CFR 170 the relationship has to be documented in your System Security Plan, and an assessor will expect a Customer Responsibility Matrix showing which controls the provider operates and which stay with you. Every managed engagement ships with a Shared Responsibility Matrix covering all 110 NIST SP 800-171 controls, each marked Optimal-owned, client-owned, or shared, with the evidence artifact that proves it — maintained as the environment changes rather than written once at go-live. Optimal prepares the environment and the evidence; the certified assessment is performed independently by an accredited C3PAO.
Yes. We source and provision your Microsoft 365 GCC High G5 licensing and stand up the tenant, so you don't have to manage a separate licensing relationship on top of everything else.
Yes — that's the point. After go-live we run day-to-day administration, patching, monitoring, user lifecycle, security operations, and help desk, and we keep your SSP and evidence current so you stay assessment-ready between contracts and re-assessments.
Tell us the contracts you're chasing, the data you handle, and where you are today — Commercial, GCC, or nothing yet. We'll scope the migration, the controls, and the managed service, and give you a straight answer on GCC High.
Book a scoping call →