CMMC and GCC for Microsoft 365: how the pieces fit

Defense and government work runs on different Microsoft clouds and answers to different rules. This page explains CMMC, the Microsoft 365 Government environments (GCC, GCC High, and DoD), and how they tie together, so you can see the landscape clearly.

Where to go next: the CMMC 2.0 guide for the levels, the 14 domains and which tenant settings become evidence · Senserva Federal Watch for the live federal wire and the BOD 22-01 deadlines · Senserva for CMMC for what the audit returns today · CISA SCuBA for the federal civilian baseline.

What is live, and what is not. Senserva Federal Watch is live in beta: it is email alerts and a federal wire, not a tenant scan. The Senserva audit runs against commercial Microsoft 365, Intune, Defender, Entra ID and Purview, and produces the configuration evidence behind many NIST SP 800-171 control families today. Senserva does not yet support Microsoft 365 Government (GCC, GCC High, or DoD), and provides no CMMC assessment and no Federal authorization. This page is a primer on the landscape, not a statement of Government cloud coverage.

What CMMC is

The Cybersecurity Maturity Model Certification (CMMC) is the US Department of Defense program that verifies defense contractors protect sensitive information. It applies across the Defense Industrial Base (DIB), and the level required depends on the data you handle.

Level What it covers
Level 1 (Foundational)The 15 basic safeguarding requirements for Federal Contract Information (FCI), from FAR 52.204-21. Self-assessed annually and affirmed in SPRS by a company official.
Level 2 (Advanced)Protection of Controlled Unclassified Information (CUI): the 110 security requirements of NIST SP 800-171 across 14 domains. Where most defense contractors land, assessed every three years, by an accredited C3PAO for most CUI contracts. Limited POA&M items must close within 180 days.
Level 3 (Expert)Level 2 plus selected enhanced requirements from NIST SP 800-172, aimed at advanced persistent threats on the highest-risk programs. Assessed by the government (DIBCAC).

In short: FCI points you toward Level 1, CUI toward Level 2 and its NIST SP 800-171 control set, and the most sensitive work toward Level 3. The data you hold drives the level you need. CMMC is now phasing into Department of Defense contracts, so the level appears in the contract and an assessor asks for evidence rather than intentions. The CMMC 2.0 guide walks the 14 domains and names which Microsoft 365, Intune and Defender settings become that evidence.

The Microsoft 365 Government clouds

Microsoft runs separate government clouds so regulated data stays in the right boundary. Choosing the right one is a prerequisite for meeting CUI and DoD obligations.

GCC
Government Community Cloud, for state, local, and many federal needs. US-based, with controls beyond commercial, but not designed for the strictest CUI or ITAR cases.
GCC High
Built to support CUI, DFARS, and ITAR, with screened US-person operations and FedRAMP High alignment. The common target for CMMC Level 2 in the defense base.
DoD
The Department of Defense cloud, for DoD mission owners and the most sensitive impact levels.

Microsoft also publishes which services and certifications apply in each environment, and a shared-responsibility model: Microsoft secures the platform, and the customer is responsible for how identity, devices, data, and access are configured on top of it.

How it ties together

CMMC says what you must protect and to what standard. The Microsoft 365 Government clouds give you a boundary built for that data. The tenant configuration on top, identity, Conditional Access, device compliance in Intune, Defender, and Purview information protection, is where most of the NIST SP 800-171 control families are actually satisfied or missed.

  • Pick the cloud that matches your data: FCI may fit GCC, CUI and ITAR generally point to GCC High.
  • Map your CMMC level to the NIST control set: Level 2 to 800-171, Level 3 adds 800-172.
  • Configure and prove the technical controls in the tenant, then keep evidence that they stay in place.

Where Senserva is, and where it is headed

Live now, in beta: Senserva Federal Watch. The federal wire, the CMMC rule-making lane pulled from the Federal Register and acquisition.gov, the BOD 22-01 remediation dates from the CISA Known Exploited Vulnerabilities catalog, and those deadlines by email. Free to join, one email address.

Live now, on commercial tenants: deep Microsoft 365, Intune, Defender, Entra ID, and Purview analysis: ranked findings, automated and validated approve-before-apply remediation, and Senserva Trustworthy AI that keeps every answer grounded and every change reviewed. Access Control, Identification and Authentication, Audit and Accountability, and Configuration Management already produce dated evidence an assessor recognises; the CMMC 2.0 guide marks which of the 14 domains those are.

Not yet: Government cloud tenants. When GCC and GCC High access is in place, the plan is to bring that same depth there, with the configuration evidence and remediation mapped to the NIST SP 800-171 and 800-172 control families behind CMMC. The per-practice CMMC mapping is being built now. Senserva for CMMC is where that lands, and where you can ask to be told when it does.

Nothing here is a claim of CMMC certification, Federal authorization, or Government cloud coverage. Federal Watch is an alerting service, not an assessment.

AI governance belongs in the Federal conversation

As AI and Copilot enter government and defense work, AI governance becomes part of the same compliance picture. The standards below are the most relevant to Federal and regulated programs, and Senserva already audits the Microsoft AI surface they care about: agent identities, the permissions agents inherit, and high-risk Graph scopes. That coverage is available on commercial Microsoft 365 today and is part of the same roadmap toward Government cloud support.

NIST AI RMF
The US framework (Govern, Map, Measure, Manage). The natural AI companion to NIST 800-171 and 800-172 thinking.
ISO/IEC 42001
The international AI management system standard. A structured way to govern AI risk, impact, and lifecycle.
Microsoft AI security
What Senserva audits today: Copilot and AI agent identities, inherited permissions, and high-risk Graph scopes.

See the full AI Governance coverage for how these map to Senserva.

Talk to us about Federal

If CMMC and GCC are on your roadmap, tell us. Joining Senserva Federal Watch above is the fastest way to hear it first, and it is how the federal deadlines reach you in the meantime. The pages below are the rest of the federal set.

Talk to us about Federal Senserva Federal Watch Senserva for CMMC CMMC 2.0 guide CISA SCuBA Compliance frameworks Security checks catalog

Explore the AI Enhanced suite

Agentic AI for Microsoft 365 security, end to end. Each piece works with the AI of your choice.

Works with any AIChatGPT, Claude, Gemini, Copilot, or a local model, with a built-in prompt builder. Claude & MCPRun Microsoft 365 security agentically from Claude through the Senserva MCP. AI security reportsSix AI-enhanced report types generated from one scan. AI remediationValidated, approve-before-apply fixes for every finding. AI complianceMap and close gaps against CISA SCuBA, MCSB, and more.

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.

Senserva Federal

Senserva Federal Watch is in beta. The federal wire and the deadlines.