Skip to main content
Greypike's CMMC Knowledge Base

If you cannot find information about a compliance topic, please contact us for free support.

< All Topics
Print

CUI in Commercial Microsoft 365: What to Do Now

Somebody worked out that you have CUI in commercial Microsoft 365, sitting alongside the payroll spreadsheets and the shop calendar. It is the most common finding in the small defense supply base, and it happens for an entirely rational reason: you bought business software to run a business, and controlled information arrived later without anyone renegotiating where it would live.

The instinct at this point is to call Microsoft and ask to move everything. Resist that for a week. The expensive version of this project moves your whole company. The sensible version moves the data. Which one you end up with is decided in the next few days, not in the migration. This article sits under Something Just Happened and You Need CMMC: A Triage Guide.

What the clause actually demands of a cloud service

DFARS 252.204-7012 says that if you use an external cloud service provider to store, process or transmit covered defense information, that provider must meet security requirements equivalent to the FedRAMP Moderate baseline, and must satisfy the incident reporting, media preservation, malicious software submission, forensic access and damage assessment obligations in paragraphs (c) through (g) of the clause.

The clause in full is covered in What DFARS 252.204-7012 Requires, in Plain English. Read that second half again, because it is the part that gets skipped. Equivalency to a security baseline is a technical claim. The obligations in (c) through (g) are contractual commitments, and they mean the provider has to preserve images and media for at least 90 days after an incident and provide the government access for forensic analysis. Those are commitments a provider either makes to you in writing or does not.

Two other requirements sit alongside it. NIST SP 800-171 requires FIPS validated cryptography to protect controlled information, and FIPS 140-2 certificates move to historical status on September 21, 2026, so a certificate number you were quoted two years ago deserves rechecking. And if any of your data is export controlled under ITAR or EAR, access is restricted to United States persons, which is a personnel and data residency question rather than an encryption question.

Find the CUI in commercial Microsoft 365 before you choose a destination

Nobody can scope a migration they have not measured. Spend two days on this and the rest of the project gets smaller.

  • Mail. Search for the customer domains that send you technical packages, and for the marking text itself. Attachments in mailboxes are where most of it lives, and mailboxes are the hardest place to clean up later.
  • Files. SharePoint, OneDrive and any mapped file server. Look for drawing numbers, specification numbers and the folder that engineering actually uses rather than the one on the network diagram.
  • Chat. Teams messages and channel files. People paste drawings into chat and nobody remembers doing it.
  • Endpoints. Engineering laptops and the machine that drives the CMM. Local copies are common and they are inside your boundary whether you like it or not.
  • Elsewhere. Personal cloud accounts, USB drives, the ERP system, printed drawings on the floor, and the quoting mailbox that three people share.

Write down what you find and who put it there. That inventory becomes the first section of your System Security Plan, so the work is not wasted even if the migration decision changes. If a delivery date is already committed, 90 days to get compliant covers what fits around a migration.

Four honest paths out, and what each one costs

PathFits whenPractical costWatch out for
Move the whole tenant to a government community cloud offering Most of your business is defense, and controlled information touches most departments Highest. Per user licensing goes up and the migration runs three to six months Feature differences and third party integrations that do not exist in the government environments. Inventory your add ins first.
Keep the commercial tenant and stand up a separate compliant enclave for controlled work Defense is a minority of revenue and only a handful of people touch controlled information Moderate. You license only the users who need it Discipline. The enclave only works if data genuinely stays inside it, which is a process problem more than a technology problem.
Stay commercial and document equivalency plus the paragraph (c) through (g) commitments You have written confirmation from the provider covering both halves of the clause, and no export controlled data Lowest in cash, highest in documentation and in risk if the confirmation does not hold up Marketing pages are not commitments. What matters is what appears in your licensing terms, and whether export controlled data is present.
Get out of scope You can genuinely stop receiving controlled information and still do the work Sometimes near zero Requires your customer’s cooperation and a written change to how they send you data. Worth asking. Rarely asked.

The differences between the two government environments are laid out in Microsoft 365 GCC vs GCC High for CMMC, and the choice between them is worth making before you sign anything.

Two notes that save arguments later. The government community environments are not interchangeable with each other, and the one appropriate for export controlled data is not the same as the general government offering. Confirm which one your data requires before you sign, in writing, from Microsoft or your licensing partner. And be aware that some smaller providers advertise government tenants they resell without the corresponding contractual commitments, so read the actual terms.

Sequence the work so you are not exposed in the middle

The riskiest period in this project is the six weeks when data exists in both places and nobody is sure which copy is authoritative. Reduce that window deliberately.

  1. Stop the inflow first. Tell your customer, in writing, the address or portal you want controlled information sent to going forward. This costs nothing and it stops the pile growing.
  2. Stand up the destination and prove it works with two or three users before anyone else moves.
  3. Move the identified data, then verify it arrived before you touch the source copies.
  4. Remove the source copies deliberately and with a record. Mailboxes need the same attention as file shares, and retention policies can quietly keep copies you believe you deleted.
  5. Write the boundary down in the System Security Plan and tell your people plainly where controlled work happens now. A boundary nobody has been told about is not a boundary.

One thing not to do

Do not mass delete controlled information from the commercial tenant to make the problem disappear. If your customer sent you data you should not have received, or sent it through a channel that was not appropriate, deletion destroys the record of what happened and complicates any notification obligation. Contain it, document it, notify the sender, then remediate. The full sequence is in CUI-marked drawings you weren’t expecting.

Frequently asked

Questions about this topic

Can you ever keep CUI in commercial Microsoft 365 legitimately?
It depends on the data and on what the provider commits to in your terms. DFARS 252.204-7012 requires security equivalent to the FedRAMP Moderate baseline plus the incident reporting, media preservation and forensic access obligations in paragraphs (c) through (g). Export controlled data carries additional United States person access restrictions that commercial offerings generally do not address. Get the answer in writing from Microsoft or your licensing partner rather than from a marketing page.
Is GCC High required for CMMC?
No specific product is required. The clause states requirements, not brands. A government community environment is the most common way small contractors satisfy them, particularly where export controlled data is present, but the obligation is to meet the requirements by whatever means you can document.
How long does a migration take?
Three to six months for a full tenant migration at a typical small contractor, driven mostly by mail and file volume, third party integrations and user readiness rather than by technical difficulty. A narrow enclave for a small group of users can be operating in four to eight weeks.
Do we have to move everyone?
No, and usually you should not. If only engineering and contracts touch controlled information, license and migrate those people and leave the rest of the company where it is. Scope discipline is the largest single cost lever in this entire project.
What about the copies already sitting in mailboxes?
They are in scope until they are gone, and mailboxes are where this work is most often left half finished. Search the tenant, remove the copies deliberately, and check that retention and archive policies are not preserving them somewhere you forgot about.
Does moving to a government tenant make us compliant?
It addresses a subset of the technical requirements and none of the administrative ones. Policy, training, access control, personnel screening, physical protection, incident response, media handling and audit review remain your responsibility regardless of which tenant you are in.

The audit is gone. The liability isn't.

Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.

Talk to Greypike about SPRS Attestation Assurance

Greypike Inc.

SBA-certified Veteran-Owned Small Business

Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff

CAGE 9WVS6 · UEI N6CJNGDARFM5

(703) 214-9246 info@greypike.com greypike.com

Table of Contents