CUI Compliant

0 NIST 800-171 gaps detected. FedRAMP authorized at High impact level. Approved for CUI handling in DoD environments.

Office Suite

Microsoft 365 Office GCC High

by Microsoft

FedRAMP AuthorizedHigh Impact

FedRAMP Status

FedRAMP Authorized

Impact Level

High

Category

Office Suite

Authorized: December 26, 2024

Overview

Microsoft 365 GCC High includes Word, Excel, PowerPoint, and other Office apps on government infrastructure. It is FedRAMP High authorized for creating and editing CUI documents in defense environments.

CUI Risk Assessment

FedRAMP authorized at High impact level. Approved for CUI handling in DoD environments.

Deployment & Architecture

Deployment Model: Government Cloud (FedRAMP boundary)

Microsoft 365 Office GCC High operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.

Configuration Checklist

  1. 1ISSO must update the System Security Plan (SSP) to reflect Microsoft 365 GCC High as an authorized system component within the CUI processing boundary per NIST 800-171 requirement.
  2. 2System administrator shall configure Azure Information Protection labels aligned with DoD CUI marking requirements and ensure automatic labeling policies prevent unmarked CUI documents.
  3. 3ISSO must establish data loss prevention (DLP) policies preventing CUI sharing outside GCC High tenant boundaries, addressing NIST 800-171 SC-7 boundary protection controls.
  4. 4System administrator shall implement conditional access policies requiring device compliance and MFA for all CUI access, satisfying CMMC Level 2 identification and authentication requirements.
  5. 5Contracts officer must verify all GCC High user licenses comply with DFARS 252.204-7012 requirements for CUI handling system authorization.
  6. 6ISSO shall document GCC High tenant configuration in authorization boundary diagrams, specifically noting data flow restrictions and FedRAMP boundary containment.
  7. 7System administrator must disable external sharing capabilities for SharePoint sites containing CUI, ensuring compliance with NIST 800-171 AC-3 access enforcement.
  8. 8ISSO must create POA&M entries for any GCC High configuration gaps identified during initial deployment, with remediation timelines per NIST 800-171 requirements.
  9. 9Legal team shall review Microsoft GCC High Business Associate Agreement for DFARS 252.204-7021 compliance regarding third-party CUI handling.
  10. 10System administrator must configure audit logging for all CUI document access within Office applications, supporting NIST 800-171 AU audit family requirements.

Other FedRAMP Authorized Office Suite Tools

Frequently Asked Questions

Is Microsoft 365 Office GCC High FedRAMP authorized?

Yes. Microsoft 365 GCC High including all Office applications is FedRAMP High authorized and hosted on Azure Government.

Can I use Microsoft 365 GCC High Office apps with CUI?

Yes. The GCC High Office suite is approved for creating, editing, and storing CUI documents in defense contractor environments.

Run a Full Tech Stack Audit

Check all your enterprise tools at once with our free CUI Compliance Auditor.

Launch CUI Auditor

Get a defensible CUI architecture

This Microsoft 365 Office GCC High CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures