Do I have to move to GCC High?
Sometimes, yes.
GCC High is a Microsoft government tenant. It's one place to hold CUI — not the only one, and not what the clause names. DFARS 252.204-7012 requires a FedRAMP Moderate cloud and the 800-171 controls. A FedRAMP-authorized cloud you already run can satisfy that directly. Some firms genuinely need GCC High. Saying so is what makes the rest true.
AWS GovCloud, Azure Government, and Google Assured Workloads are FedRAMP-authorized. Build the CUI boundary there and the cloud requirement is met — no migration to Microsoft required.
A cloud that's merely "equivalent" makes you demonstrate the full FedRAMP Moderate baseline with no gaps. That's a high bar — and the reason authorization matters more than marketing.
Three drivers, in order.
If you hold ITAR technical data, US-person access controls tighten the shortlist. This is the strongest case for GCC High — and even then, not the only path.
If CUI lives mostly in email and collaboration, a Microsoft government tenant is one answer. If it lives in your workloads and data, the boundary belongs in your cloud.
Already on AWS or Google Cloud in production? A parallel Microsoft estate doubles what you operate. The authorized boundary can sit where your workloads are.
Three ways to hold CUI.
| FedRAMP-authorized cloud AWS / Azure Gov / Google | Microsoft GCC High M365 government tenant | "Equivalent" cloud Not on the Marketplace | |
|---|---|---|---|
| FedRAMP status | Authorized (High) | Authorized (High) | 3PAO-validated equivalence |
| Satisfies DFARS 7012 for CUI | Directly | Directly | Prove 100%, 0 POA&Ms |
| ITAR / export-controlled fit | Yes, with US-person controls | Strong, purpose-built | Case by case |
| Leave your current cloud? | No — build where you are | Yes — new estate | Depends |