Updated September 30, 2026
Your IT provider quoted "GCC High for CMMC" for all 30 people, with a migration project, a three-year managed-services contract, and a number with a comma in it. Half the people on the list sweep chips and drive the forklift.
CMMC does not require GCC High. It requires that any cloud service holding your controlled drawings meet a government security standard called FedRAMP Moderate, or prove it's equivalent. GCC High is one way to meet that. For most shops the right answer is GCC High for only the people who handle drawings, or no GCC High at all.
A few terms first. CUI (controlled unclassified information) is the sensitive technical data the government marks for protection; in a machine shop it's the drawings and models. FedRAMP is the government's security approval program for cloud services. GCC High is a separate, walled-off copy of Microsoft 365 run by screened US staff, built for defense contractors. Tenant is Microsoft's word for your company's own Microsoft 365 account.
Myth: "CMMC requires GCC High." No CMMC rule names a Microsoft product. The contract clause behind CMMC, DFARS 252.204-7012, says a cloud service holding CUI must meet the FedRAMP Moderate baseline or its equivalent, and must follow the clause's incident-reporting terms (DFARS 252.204-7012, paragraph (b)(2)(ii)(D)). Microsoft's own blog says defense CUI categories are "not appropriate for storage within GCC" (Microsoft). That is advice about where drawings go inside Microsoft 365, not a rule that they must live there.
An assessor on r/CMMC was asked the biggest single mistake he'd seen. His answer: "Uplift everyone to GCCH when they did not need it." (r/CMMC)
Start with a headcount, not a license
Before anyone quotes anything, get two numbers. The first is how many people open a controlled drawing in a normal month. Walk it: who receives the prints, who quotes from them, who programs, who inspects, who runs quality. In a 30-person shop it's usually 4 to 10 names. The floor works from printed travelers and programs, handled separately (the drawing's path through the shop).
The second is volume, and how drawings arrive. One shop on r/CMMC put it this way: "We get like 6 links to CUI files a year." Another: "We do get prints via email." If you're not sure which of your prints count as CUI, sort that first (is this drawing CUI?).
The four routes, in the order we'd consider them
1. GCC High for the drawing handlers only
This is the usual answer for a shop that gets prints weekly and works on them in Outlook, SharePoint, and Teams. The drawing handlers get accounts in a new GCC High tenant; everyone else stays where they are. The industry calls this an enclave.
The license to ask for is Microsoft 365 Business Premium for GCC High. Microsoft launched it on November 3, 2025 for small organizations (Microsoft). The cap is 300 employees for defense contractors, per authorized seller Summit 7 (Summit 7); Microsoft's announcement said 500.
Microsoft doesn't publish the price. Secureframe, an authorized reseller, lists a planning price of $35.80 per user per month for Business Premium for GCC High, unchanged by the July 1, 2026 increase, plus $24.40 for the Defender and Purview add-ons most shops need for CMMC (Secureframe, reseller pricing). Those are one reseller's numbers; get a written quote.
For a 30-person shop:
| Seats | Base license ($35.80) | With add-ons ($60.20) |
|---|---|---|
| 8 drawing handlers | $3,437 a year | $5,779 a year |
| All 30 employees | $12,888 a year | $21,672 a year |
That's about $16,000 a year in licenses alone, before migration labor, before 22 more laptops to manage and 22 more people to train, and before the rest of what CMMC costs a shop.
Two buying rules catch people. You must pass Microsoft's eligibility check first, with proof you hold CUI or ITAR data, and there are no GCC High trials (Microsoft: how to buy). And under 500 seats, only partners on Microsoft's AOS-G list can sell it. AOS-G is Microsoft's program for authorized government resellers. If your current provider isn't on that list, it can't sell you GCC High, whatever the quote says.
2. Keep drawings out of Microsoft 365 entirely
If a few people handle a modest number of prints, leave everyone in regular Microsoft 365 and put the drawings in a secure file-sharing service that meets the same FedRAMP Moderate standard. Two names come up constantly, and they qualify differently:
- Kiteworks. Its Federal Cloud has been FedRAMP Authorized at Moderate since June 2017 (FedRAMP Marketplace: Kiteworks Federal Cloud).
- PreVeil. It is not listed on the FedRAMP Marketplace. PreVeil claims FedRAMP Moderate equivalency instead: an independent assessor tested it against the full Moderate baseline, and DoD's assessment team reviewed the evidence (PreVeil). Equivalency is a legitimate route under the clause, but DoD's December 2023 memo puts the burden on you to hold the vendor's evidence (DoD equivalency memo). Ask for it before you sign (what "equivalent" means).
Be honest about CAD work before you pick this route. A secure file service stores and sends files well, but programmers open drawings in SolidWorks, Mastercam, and inspection software on their own PCs. PreVeil's own guide for CAD users says its service can't host a PDM database (the system that tracks parts, assemblies, and revisions), and that SolidWorks writes scratch copies to the computer's temp folder, so every CAD workstation needs full-disk encryption anyway (PreVeil CAD guide). A 20-person toolmaker on r/CMMC was told by a second IT firm that its PreVeil setup leaned too hard on employees saving files in the right place (r/CMMC). This route works when files flow in and out. It gets leaky when people edit in place all day.
On every route, the PCs that open drawings are in scope, held to all 110 security requirements. No cloud choice changes that.
3. Work only in the prime's portal
If customers deliver drawings through their own portal and you only view them, you may not need a new cloud at all. This is the cheapest route, and the most misunderstood.
The rule keeps a computer out of scope only when it reaches CUI through a virtual desktop that sends nothing but keyboard, video, and mouse (32 CFR 170.19). A web portal that opens the PDF in your browser has put the drawing on your PC. That PC is processing CUI and is in scope. Once someone downloads the file, wherever it lands is in scope too.
So the portal route means one or two managed, encrypted PCs are the only machines that open the portal, nobody downloads to a shared drive, and printouts follow your paper rules. For six packages a year, that holds up fine.
4. The whole company in GCC High
If nearly everyone quotes, programs, inspects, or plans from drawings, or ITAR data is all over the floor, one GCC High tenant beats an enclave people keep leaking out of. If your prime wrote GCC High into your subcontract, buy it and stop debating. Enclave or whole company →
The decision rule
This is the rule we'd use: the cheapest route that holds up in front of an assessor.
| Who handles drawings | How drawings arrive | Our call |
|---|---|---|
| 1–2 people, view only | A customer portal, a handful of packages a year | Portal only, on one or two managed PCs. No new cloud. |
| 1–5 people | By link or email, up to a few packages a month, little editing | A FedRAMP-authorized or equivalent file service. Keep your Microsoft 365. |
| 3–25 people | By email, weekly or daily, edited in Office and CAD | GCC High Business Premium for those people only. |
| Most of the company, or ITAR everywhere | Constantly | The whole company in GCC High. |
Two overrides beat the table: a subcontract that names GCC High, and export-controlled drawings (ITAR or EAR) you plan to keep in Microsoft 365. Both send you to GCC High. Commercial vs. GCC vs. GCC High →
Prints that arrive by email
You can't stop a buyer from emailing a drawing. You can decide where it should land.
Pick one controlled place for prints: a GCC High mailbox or your secure file service. Send each customer a one-line note: "Please send controlled drawings only to drawings@[your controlled domain] or through [service name]." Keep the replies. Then block forwarding out of the controlled mailbox, so nobody sends a print to a regular inbox to work on it.
When a controlled print lands in regular Outlook anyway, and it will, handle it the same way every time: move it to the controlled place, delete it from the regular mailbox, have your IT person purge it from the mailbox's recoverable items, and write down the date, sender, and what you did. Cold RFQs with obviously controlled drawings get the same handling (quoting controlled drawings).
Finding a reseller who will sell you eight
Microsoft's buying rules set no seat minimum under 500 seats. Planet Technologies, an AOS-G partner, says it sells to organizations from "a startup with three users" up (Planet Technologies). Partners set their own terms, though. One shop on r/CMMC found a reseller "who could sell us 8… most wouldn't do less than 50" (r/CMMC). ECF Data, another AOS-G partner, says many partners require a managed-services contract of $10,000 or more as a condition of selling licenses (ECF Data).
Take Microsoft's AOS-G list and email four partners on it. Ask these, in writing:
- Are you an AOS-G partner for GCC High, on Microsoft's current list?
- Will you sell us [number] seats of Business Premium for GCC High, with no seat minimum?
- Can we buy licenses without a managed-services contract? If not, what is the contract's minimum term and price?
- What is the per-seat price for the license and for the Defender and Purview add-ons, on what term, and can we reduce seats mid-term?
- Who does the migration, with what tool, and is it priced per mailbox or per gigabyte?
- Will you give us a written list of which security requirements you handle and which stay with us?
A partner that answers with a single bundled number and no license line is telling you something.
What the move involves, and how long
GCC High is a new tenant in a separate cloud. Your email domain can be verified in only one Microsoft tenant at a time (Microsoft Entra), so an enclave usually gets its own domain or subdomain, and the drawing handlers get a second account. Their mail, files, and Teams channels for controlled work get copied across. Their laptops get enrolled in the new tenant's device management.
Microsoft says to allow at least three months for the migration phase (Microsoft and CMMC). One small shop that did its own migration advised others to "extend the time you anticipate by triple," after moving about half a million files by hand (r/CMMC). Plan four to six months from the first reseller email to the day the last controlled drawing leaves your old mailbox. Move only controlled work, not ten years of everyone's mail.
Whichever route you choose, write it down in one paragraph for your security plan: who handles drawings, where they live, which service holds them, and that service's FedRAMP basis. Garde1 records each cloud service's FedRAMP basis, a Marketplace listing or a body of evidence for "equivalent," and flags it when that evidence goes stale or is missing.
