On this page
What the government actually requires for cloud
The rule is narrower and more precise than a lot of marketing pages make it sound. When a cloud service provider stores, processes, or transmits CUI for the assessed environment, the offering must meet the FedRAMP Moderate baseline or the official equivalent path described by DoD.
That is the requirement to anchor on. The content should not jump straight to a blanket statement that every contractor must move to one particular Microsoft tenant or one specific vendor stack.
Encrypted CUI in the cloud
DoD’s January 2026 FAQ answers one of the most important edge cases directly. A non-FedRAMP Moderate cloud service offering may not store encrypted CUI unless it meets FedRAMP Moderate equivalency. The same FAQ also says encrypted CUI remains CUI until it is formally decontrolled.
Together, those answers eliminate a common shortcut. You cannot take CUI, encrypt it, put it somewhere that does not meet the required cloud baseline, and then claim the problem disappeared.
MSPs, MSSPs, ESPs, and CSPs
A provider can sit in different roles depending on what it is doing. If the service is a cloud offering storing, processing, or transmitting CUI, it is a cloud-service question. If the provider is not a cloud offering but provides IT or cybersecurity services tied to in-scope systems or security protection data, it can become an external service provider question.
The January 2026 FAQ says an MSP that is not itself a cloud offering does not need its own CMMC assessment or certification just to support you. If the MSP or MSSP provides security protection services or managed administration for systems inside the boundary, that relationship still needs to be documented and treated within your scope as appropriate.
So do you need GCC High?
Not automatically. There is no official government statement saying every defense contractor needs GCC High. The real decision point is whether your architecture for handling CUI in Microsoft 365 or connected services can satisfy the current requirements, responsibilities, and scope boundaries.
Many contractors do choose GCC High, a dedicated enclave, or another contained architecture because it can simplify governance and reduce ambiguity. But that is an architecture conclusion, not a universal rule written by the government.
What buyers need from architecture guidance
- A decision process based on actual CUI workflows rather than generic fear.
- A clear map of which cloud offerings store, process, or transmit CUI.
- A responsibility model showing what the provider covers versus what the contractor must still implement.
- A scope design that fits the business, including enclave options where justified.
- Migration and evidence planning that lines up with the SSP and assessment process.
Frequently asked questions
Does a cloud service storing CUI need FedRAMP Moderate?
Yes. If the cloud service offering stores, processes, or transmits CUI for the assessed environment, it must meet the FedRAMP Moderate baseline or the official equivalent path.
Can a non-FedRAMP Moderate cloud store encrypted CUI?
No. DoD’s January 2026 FAQ says that is not allowed unless the service meets FedRAMP Moderate equivalency.
Does encrypted CUI stop being CUI?
No. The official FAQ says encrypted CUI remains CUI until it is formally decontrolled.
Does our MSP need its own CMMC certification?
If the MSP is not a cloud service offering, it does not need its own CMMC assessment or certification just to support you. If its managed services or assets protect in-scope systems or security protection data used to meet requirements, that relationship still needs to be documented and treated within your scope as appropriate.
What is an ESP in CMMC?
An external service provider is an external party providing IT or cybersecurity services whose services or assets process, store, or transmit CUI or security protection data, or provide security protection capabilities used to meet requirements.
What is the difference between a CSP and an ESP?
A CSP question centers on a cloud offering storing, processing, or transmitting CUI. An ESP question centers on an external IT or cybersecurity provider whose services or assets support the in-scope environment or required security protection capabilities.
Do all contractors need GCC High?
No. The government does not publish a blanket requirement that every contractor needs GCC High. The right architecture depends on scope, workflows, and how CUI is handled.
Why do so many companies still move to GCC High or enclaves?
Because a contained environment can simplify governance, reduce the boundary, and make evidence easier to manage. That is a practical architecture choice, not a universal government mandate.
Related articles
Official sources reviewed
Contract language, current regulations, and official CMMC program guidance control.
Want help turning this into a real readiness plan?
Velocity CMMC can scope the environment, map CUI flows, organize the documentation package, support remediation, and help your team prepare for the right assessment path without pretending to be the certifier.