CUI Compliant
0 NIST 800-171 gaps detected. FedRAMP authorized at High impact level. Approved for CUI handling in DoD environments.
SharePoint GCC High
by Microsoft
FedRAMP Status
FedRAMP Authorized
Impact Level
High
Category
File Sharing
Authorized: December 26, 2024
Overview
SharePoint GCC High provides document management, file sharing, and intranet capabilities on dedicated government infrastructure. It is FedRAMP High authorized and supports CUI and ITAR file sharing.
CUI Risk Assessment
FedRAMP authorized at High impact level. Approved for CUI handling in DoD environments.
Deployment & Architecture
Deployment Model: Government Cloud (FedRAMP boundary)
SharePoint GCC High operates within a FedRAMP-authorized boundary. CUI can be processed within the authorization scope, but contractors must verify their specific use case falls within the system's security boundary as documented in the SSP.
Configuration Checklist
- 1ISSO shall provision SharePoint GCC High tenant and configure tenant-level external sharing restrictions to block anonymous and guest access per NIST 800-171 AC-3 requirements.
- 2System administrator shall implement conditional access policies requiring MFA for all SharePoint GCC High access and document configuration in the SSP Section 10.
- 3ISSO shall configure DLP policies to detect and prevent sharing of CUI markings including FOUO, ITAR, and proprietary technical data per DFARS 252.204-7012 requirements.
- 4System administrator shall establish site collection structure aligned with contract data segregation requirements and document access control matrices in authorization boundary diagrams.
- 5Legal team shall review and approve SharePoint governance policies ensuring compliance with ITAR technical data handling requirements under DFARS 252.204-7021.
- 6ISSO shall configure audit logging to capture file access, sharing attempts, and administrative actions with 180-day retention per NIST 800-171 AU-6 requirements.
- 7System administrator shall implement automated retention policies for contract-specific CUI data and document disposal procedures in the SSP.
- 8Training coordinator shall deliver SharePoint CUI handling training to all users and maintain completion records for CMMC Level 2 assessment evidence.
Other FedRAMP Authorized File Sharing Tools
Related Compliance Assessments
Frequently Asked Questions
Is SharePoint GCC High FedRAMP authorized?
Yes. SharePoint GCC High is FedRAMP High authorized as part of the Microsoft 365 GCC High environment.
Can I use SharePoint GCC High with CUI?
Yes. SharePoint GCC High is approved for CUI and ITAR file sharing and document management in defense contractor environments.
Run a Full Tech Stack Audit
Check all your enterprise tools at once with our free CUI Compliance Auditor.
Launch CUI AuditorGet a defensible CUI architecture
This SharePoint GCC High CUI review flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.
Schedule architecture reviewRelated: how much CMMC certification costs — DoD’s own priced figures