If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
CUI in Commercial Microsoft 365: What to Do Now
Somebody worked out that you have CUI in commercial Microsoft 365, sitting alongside the payroll spreadsheets and the shop calendar. It is the most common finding in the small defense supply base, and it happens for an entirely rational reason: you bought business software to run a business, and controlled information arrived later without anyone renegotiating where it would live.
The instinct at this point is to call Microsoft and ask to move everything. Resist that for a week. The expensive version of this project moves your whole company. The sensible version moves the data. Which one you end up with is decided in the next few days, not in the migration. This article sits under Something Just Happened and You Need CMMC: A Triage Guide.
What the clause actually demands of a cloud service
DFARS 252.204-7012 says that if you use an external cloud service provider to store, process or transmit covered defense information, that provider must meet security requirements equivalent to the FedRAMP Moderate baseline, and must satisfy the incident reporting, media preservation, malicious software submission, forensic access and damage assessment obligations in paragraphs (c) through (g) of the clause.
The clause in full is covered in What DFARS 252.204-7012 Requires, in Plain English. Read that second half again, because it is the part that gets skipped. Equivalency to a security baseline is a technical claim. The obligations in (c) through (g) are contractual commitments, and they mean the provider has to preserve images and media for at least 90 days after an incident and provide the government access for forensic analysis. Those are commitments a provider either makes to you in writing or does not.
Two other requirements sit alongside it. NIST SP 800-171 requires FIPS validated cryptography to protect controlled information, and FIPS 140-2 certificates move to historical status on September 21, 2026, so a certificate number you were quoted two years ago deserves rechecking. And if any of your data is export controlled under ITAR or EAR, access is restricted to United States persons, which is a personnel and data residency question rather than an encryption question.
Find the CUI in commercial Microsoft 365 before you choose a destination
Nobody can scope a migration they have not measured. Spend two days on this and the rest of the project gets smaller.
- Mail. Search for the customer domains that send you technical packages, and for the marking text itself. Attachments in mailboxes are where most of it lives, and mailboxes are the hardest place to clean up later.
- Files. SharePoint, OneDrive and any mapped file server. Look for drawing numbers, specification numbers and the folder that engineering actually uses rather than the one on the network diagram.
- Chat. Teams messages and channel files. People paste drawings into chat and nobody remembers doing it.
- Endpoints. Engineering laptops and the machine that drives the CMM. Local copies are common and they are inside your boundary whether you like it or not.
- Elsewhere. Personal cloud accounts, USB drives, the ERP system, printed drawings on the floor, and the quoting mailbox that three people share.
Write down what you find and who put it there. That inventory becomes the first section of your System Security Plan, so the work is not wasted even if the migration decision changes. If a delivery date is already committed, 90 days to get compliant covers what fits around a migration.
Four honest paths out, and what each one costs
| Path | Fits when | Practical cost | Watch out for |
|---|---|---|---|
| Move the whole tenant to a government community cloud offering | Most of your business is defense, and controlled information touches most departments | Highest. Per user licensing goes up and the migration runs three to six months | Feature differences and third party integrations that do not exist in the government environments. Inventory your add ins first. |
| Keep the commercial tenant and stand up a separate compliant enclave for controlled work | Defense is a minority of revenue and only a handful of people touch controlled information | Moderate. You license only the users who need it | Discipline. The enclave only works if data genuinely stays inside it, which is a process problem more than a technology problem. |
| Stay commercial and document equivalency plus the paragraph (c) through (g) commitments | You have written confirmation from the provider covering both halves of the clause, and no export controlled data | Lowest in cash, highest in documentation and in risk if the confirmation does not hold up | Marketing pages are not commitments. What matters is what appears in your licensing terms, and whether export controlled data is present. |
| Get out of scope | You can genuinely stop receiving controlled information and still do the work | Sometimes near zero | Requires your customer’s cooperation and a written change to how they send you data. Worth asking. Rarely asked. |
The differences between the two government environments are laid out in Microsoft 365 GCC vs GCC High for CMMC, and the choice between them is worth making before you sign anything.
Two notes that save arguments later. The government community environments are not interchangeable with each other, and the one appropriate for export controlled data is not the same as the general government offering. Confirm which one your data requires before you sign, in writing, from Microsoft or your licensing partner. And be aware that some smaller providers advertise government tenants they resell without the corresponding contractual commitments, so read the actual terms.
Sequence the work so you are not exposed in the middle
The riskiest period in this project is the six weeks when data exists in both places and nobody is sure which copy is authoritative. Reduce that window deliberately.
- Stop the inflow first. Tell your customer, in writing, the address or portal you want controlled information sent to going forward. This costs nothing and it stops the pile growing.
- Stand up the destination and prove it works with two or three users before anyone else moves.
- Move the identified data, then verify it arrived before you touch the source copies.
- Remove the source copies deliberately and with a record. Mailboxes need the same attention as file shares, and retention policies can quietly keep copies you believe you deleted.
- Write the boundary down in the System Security Plan and tell your people plainly where controlled work happens now. A boundary nobody has been told about is not a boundary.
One thing not to do
Do not mass delete controlled information from the commercial tenant to make the problem disappear. If your customer sent you data you should not have received, or sent it through a channel that was not appropriate, deletion destroys the record of what happened and complicates any notification obligation. Contain it, document it, notify the sender, then remediate. The full sequence is in CUI-marked drawings you weren’t expecting.
Frequently asked
Questions about this topic
Can you ever keep CUI in commercial Microsoft 365 legitimately?
Is GCC High required for CMMC?
How long does a migration take?
Do we have to move everyone?
What about the copies already sitting in mailboxes?
Does moving to a government tenant make us compliant?
Keep reading
More in Trigger Events & Urgent Situations
- 90 Days to CMMC Compliance: What Is Really Possible →
- CMMC Compliant MSP? How to Verify What Yours Claims →
- CMMC Level 2 Certification an RFP Wants? Bid Anyway →
- CMMC Trigger Events: A Triage Guide for Contractors →
- CUI Marked Drawings You Were Not Expecting? Do This →
- Cybersecurity Questionnaire From Your Prime? Do This →
- DFARS 7021 Clause Found After Award? Read This First →
- Dropped Without CMMC? What a Prime Can Actually Do →
- Expired SPRS Score and a Bid Due? Fix It This Week →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5