Microsoft 365 for Small DoD Contractors: What CMMC Level 2 Actually Changes
- Shay

- Apr 8
- 28 min read
Updated: 2 days ago

Updated August 2026: I originally wrote about this client after helping a small defense contractor deal with a compromised Microsoft 365 email account. Since then, what started as an email security problem has become a much larger conversation about Microsoft 365 for small DoD contractors, CUI, and what CMMC Level 2 actually changes in the technology environment.
The company handles Controlled Unclassified Information, or CUI, which means the conversation has expanded well beyond securing a compromised mailbox. We now have to look at where CUI enters the business, how employees work with it, which systems touch it, where it is stored, how it needs to be shared with subcontractors, and what the company's technology environment needs to look like moving forward.
It Started With a Compromised Microsoft 365 Account
A small defense contractor reached out to me after one of the company's Microsoft 365 email accounts had been compromised. At first, the problem sounded relatively straightforward. We needed to regain control of the account, understand what had happened, secure the mailbox and determine what needed to change so the same type of incident would be less likely to happen again.
Instead, the company spent roughly five hours working through the incident with its existing email provider, and the support bill for that one event exceeded $1,000. What concerned me more than the cost of the incident, though, was what I began finding when I looked more closely at the Microsoft 365 environment behind the compromised account.
The company received its Microsoft email services through a third-party provider, and the particular administrative environment available to the client did not give me the level of visibility and control I wanted for the security work that needed to be done. This isn't an argument that purchasing Microsoft 365 through a reseller is inherently a problem. Plenty of businesses use legitimate Microsoft partners and Cloud Solution Providers. What matters is who controls the tenant, what administrative access is available, what licensing and security capabilities the company actually has, and whether the environment gives us what we need to properly secure, investigate and document it.
That would have been worth addressing for any small business, but this client had another requirement that changed the entire conversation. The company performs work for the Department of Defense and handles Controlled Unclassified Information, or CUI. At that point, I wasn't simply looking at how to better protect one mailbox. I needed to understand where CUI enters the company, where it goes after it arrives, who needs access to it, which computers and systems touch it, how it is shared with subcontractors, where additional copies may exist and whether the technology supporting those workflows is appropriate for the information being handled.
The compromised account was what brought us into the Microsoft environment, but CUI was what changed the architecture conversation.
Not Every DoD Contractor Needs to Leave Commercial Microsoft 365
This is an important distinction because I don't want a small government contractor reading about GCC High and assuming that doing business with the Department of Defense automatically means the company has to abandon commercial Microsoft 365.
For a contractor dealing with Federal Contract Information, or FCI, and CMMC Level 1, commercial Microsoft 365 can be part of an appropriate environment when the required controls are properly implemented and the systems handling FCI are managed accordingly. Level 1 focuses on the basic safeguarding requirements associated with protecting FCI, so the technical conversation begins with determining whether those safeguards are actually being met across Microsoft 365, employee computers, user accounts, endpoint protection, firewalls, remote access and the other systems involved.
For a Level 1 business, the right answer may therefore be to properly secure, manage and document the commercial Microsoft environment it already has rather than automatically replacing it. Once the company begins handling CUI, however, the conversation changes because we now have to look much more closely at the systems storing, processing and transmitting that information.
I go deeper into the differences between Level 1 and Level 2, and why the compliance and technical sides need to work together, in CMMC Compliance for Small Government Contractors: From Assessment to Actually Ready at Level 1 and Level 2.
The Question That Changes the Architecture: Do You Handle CUI?
For the contractor in this story, the answer is yes. CUI isn't an occasional document sitting in an isolated folder that nobody touches. It can arrive through email, employees need to work with it as part of normal projects, files need to be retained and organized, and appropriate information may need to be passed down to subcontractors performing their portion of the work.
Once I know CUI is moving through the business, I have to stop thinking only about whether Microsoft Defender is configured correctly or whether MFA has been turned on. I need to understand the information flow itself:
How does CUI enter the company?
Does it arrive through email, a customer portal, file transfer or another system?
Who actually needs access to it?
Where will employees store and work with it?
Which computers, servers and cloud services can access it?
Does it need to be shared with subcontractors?
Where are additional copies created through email, downloads or backups?
How does CUI eventually leave the environment or get disposed of?
Those answers begin to define the technical environment we actually have to protect. For this client, that is why the existing commercial Microsoft email environment has to be revisited. The question isn't simply whether the company has email security turned on. It is whether the environment supporting that email is appropriate for the information moving through it and how that information travels through the rest of the business.
Microsoft 365 for Small DoD Contractors Is More Than a Licensing Upgrade
One of the easiest ways to misunderstand this project would be to look at the client's existing Microsoft licensing and assume that moving to a better commercial Microsoft 365 plan solves the problem. It doesn't, because there is a difference between having more security capabilities inside a commercial Microsoft tenant and determining whether the cloud environment itself is appropriate for the information the contractor needs to handle.
There are many ordinary small-business environments where I recommend Microsoft 365 Business Premium because it gives me significantly better tools for managing identities, devices, endpoint security and access than Business Standard. I use those capabilities extensively, and I explain the configuration side in Microsoft 365 Security for Small Business: What Actually Needs to Be Configured?.
This client has a different problem. The company handles CUI, and some of that information needs to move through Microsoft cloud services, including email. We therefore have to determine whether the cloud environment itself is appropriate for the applicable requirements in addition to configuring the security controls inside it.
For this client, we are redesigning part of the environment, not simply upgrading a Microsoft subscription.
We Considered Several Architectures Before Choosing the Current Direction
GCC High wasn't the only architecture considered for this client, and the direction we're taking now wasn't the result of a single conversation. The business owner, the cybersecurity and CMMC compliance advisor working with the company, and I have had several roundtable discussions about what the future environment could look like. Those conversations have been important because we aren't only trying to determine what can satisfy the technical requirements on paper. We also have to build something that fits the way this company operates and that the owner and his employees can realistically use and maintain.
One of the first options considered was creating a separate CUI enclave using a solution such as PreVeil. An enclave can be attractive for a small contractor because, when the workflow allows it, normal business operations may be able to remain in the existing commercial environment while CUI is restricted to a smaller group of users, devices and systems. For a company where only a handful of employees occasionally handle CUI and that work can be cleanly separated from everything else, limiting the CUI environment can potentially reduce the scope and complexity of the larger cybersecurity and compliance effort.
As we worked through this contractor's actual workflow, however, the enclave approach became less attractive. CUI can arrive through email, it needs to be part of the company's normal project workflow, and appropriate information may need to be passed down to subcontractors. Maintaining separate CUI and normal-business email and file workflows would create another layer employees would have to navigate every day, and we had to consider whether that additional complexity could create more opportunities for information to end up in the wrong environment.
We also discussed a much broader change to the company's technology environment, with GCC High becoming part of a more cloud-centered architecture and the company potentially moving away from more of the on-premises server and Active Directory environment it uses today. During my IT Baseline Assessment, however, I had already identified an important dependency that had to be considered before we could seriously pursue that direction.
One of the company's servers supports the ERP system employees depend on to run the business, and that application relies on traditional on-premises Active Directory for authentication. We reached out to the ERP software vendor specifically to determine whether that dependency could be moved to Microsoft Entra ID instead, and the vendor confirmed that it could not. The application still requires Active Directory.
That discovery gave us another practical reason to keep the on-premises server environment intact, in addition to the owner's preference for maintaining his core infrastructure locally. This is the kind of dependency that can easily be missed if a compliance project starts with a proposed technology stack instead of first understanding the environment that is already there. We couldn't simply remove Active Directory or redesign the company around an all-cloud model without affecting an ERP system the business depends on every day.
The question therefore became how we could preserve the local server and Active Directory infrastructure the business still needs while changing the parts of the environment that need to handle CUI differently and making sure any local systems that interact with CUI are properly accounted for.
That brought us to the architecture we landed on during our most recent roundtable discussion. The current direction is to keep the company's core on-premises server and Active Directory environment while planning for GCC High for the Microsoft cloud workloads that need to handle CUI, including email, and building a structured SharePoint environment for the CUI files that need to be appropriately shared and collaborated on.
For this contractor, that creates a hybrid environment rather than forcing the entire business into an all-cloud model or requiring employees to work inside a completely separate CUI enclave. It also means the on-premises environment doesn't simply get ignored because email and collaboration workloads are moving to GCC High. We still have to determine which local systems interact with CUI, which users and devices have access, how identity will work across the environment, how the network is protected, where backups go and how all of those pieces fit within the CUI boundary.
That doesn't mean an enclave was the wrong answer, and it doesn't mean a broader move away from the company's local infrastructure would have been technically impossible. It means neither approach was the best fit after the business owner, the cybersecurity and CMMC compliance advisor and I worked through the requirements, the existing technology and the company's actual workflow together.
“The goal isn't to force the business into a compliance solution. The goal is to design the compliance environment around how the business actually needs to work.” — SNL-Tech Services
Why GCC High Is Part of the Planned Architecture for This Contractor
For this particular client, GCC High isn't replacing everything. It is solving a specific and important part of the architecture: the Microsoft cloud workloads that need to handle CUI. Email is one of those workloads because CUI can pass through it, so the current plan includes moving the appropriate email environment into Microsoft 365 GCC High.
Moving email into GCC High doesn't solve everything by itself. We still have to properly configure identities, administrative access, security policies, devices and the other technical controls around the environment. For this client, however, GCC High gives us a Microsoft environment around which we can build the CUI email and collaboration workflow without forcing the owner to abandon the local infrastructure his business still wants and, because of the ERP dependency we identified, still needs.
Email Can Carry CUI, but It Shouldn't Become the CUI Filing Cabinet
Email has to be part of the architecture because this client may receive or transmit CUI through it, but I don't want employee mailboxes becoming the long-term storage location for project files. If an employee receives a document that needs to be retained, worked on, referenced later or appropriately shared with a subcontractor, I want that information to have a defined home rather than existing indefinitely as an attachment across multiple employee mailboxes or being downloaded onto individual computers without a clear process for what happens next. That's where SharePoint becomes important.
SharePoint Gives Us a Chance to Build a Better CUI Workflow
The current plan is to build a structured SharePoint environment within GCC High for the CUI files that need to be retained, worked with and appropriately shared. This isn't about moving every company file into SharePoint simply because we're implementing GCC High. It is about giving the CUI workflow a deliberate location rather than allowing sensitive project information to accumulate wherever employees happen to save it.
A structured environment lets us design around questions the business will continue dealing with long after the initial project is finished:
Which employees actually need access to a project?
Which security groups should control that access?
What happens when an employee changes roles or leaves?
Where should the authoritative copy of a CUI document live?
Which subcontractors legitimately need access to particular information?
When should that access be removed?
Those aren't decisions I want employees making from scratch every time they click Share. The environment should support the way the information is supposed to be handled.
SharePoint and OneDrive configuration is also something I look at as part of my Microsoft 365 Tenant Security Review and Audit. External sharing, guest access, permissions, retention and the way those services are being used are all areas I want to understand before assuming the existing Microsoft environment is configured the way the business actually needs it to be.
Sharing CUI With Subcontractors Cannot Be an Afterthought
Subcontractor access is particularly important for this business because appropriate CUI may need to be passed down so a subcontractor can perform its portion of the work. That doesn't mean we can treat the process like ordinary commercial SharePoint sharing and simply send a link. Before building the collaboration model, we need to understand whether the subcontractor is authorized to receive the information, what requirements have been flowed down, what information the subcontractor actually needs, how the user or organization will authenticate, what environment the subcontractor is using, and what happens when that access is no longer required.
The questions include:
What CUI does the subcontractor actually need?
Is the subcontractor authorized and prepared to receive it?
What environment is the subcontractor using?
What approved method will be used to exchange the information?
Who controls access?
How and when will that access be removed?
GCC High also has collaboration differences from commercial Microsoft 365 that need to be accounted for when designing this workflow. That is why the subcontractor process needs to be understood before the SharePoint architecture is finalized rather than migrating everything first and figuring out external collaboration afterward.
This is one of the places where CMMC stops looking like a checklist of Microsoft settings and starts looking like systems architecture.
Keeping the Servers Local Doesn't Keep Them Outside the CUI Conversation
The owner's decision to maintain his local server and Active Directory environment is an important part of the architecture, but keeping something on-premises does not automatically put it outside the environment we need to consider. The question still comes back to CUI.
If a local server stores CUI, processes it or provides access to it, that server matters. If an employee downloads CUI from GCC High SharePoint and stores it on a local file server, we need to understand what just happened to the CUI boundary. If the server is backed up somewhere else, we need to understand whether those backups now contain CUI. If employees remotely access the server, remote access becomes part of the conversation as well.
This is another reason I keep coming back to information flow. I can't determine the scope of the environment simply by drawing a box around GCC High. I have to follow the CUI wherever the business actually uses it.
The Computers Accessing CUI Matter Just as Much as the Cloud
Moving email and collaboration into an appropriate Microsoft environment doesn't solve the larger problem if employees are accessing CUI from computers we don't understand or manage. I want to know which computers belong to the business, who uses them, how employees sign into Windows, whether encryption is enabled, whether endpoint protection is running, whether the systems are receiving updates, whether security policies are actually reaching them and whether we can reliably identify the devices accessing company resources.
This is where a small business can discover that years of perfectly workable IT decisions have created a much less standardized environment than anyone realized. One employee may be using a local Windows account, another may have signed in with a personal Microsoft account, another computer may already be connected to the company's Microsoft environment, and the organization may have different Windows editions and security configurations across its computers. Employees may have been able to work that way for years, but it becomes much harder to centrally manage, secure and document those systems when they begin interacting with CUI.
For a small-business owner, the technical terminology is less important than the outcome. If we say only authorized and appropriately protected company computers can access CUI, can we identify those computers, manage them consistently and demonstrate that the controls we say are in place actually exist?
Protecting CUI Extends Beyond Microsoft 365
The Microsoft environment is only one part of what I need to consider for this contractor. If CUI touches an on-premises server, that server matters. If employees remotely connect to systems containing CUI, remote access matters. If the network allows systems inside and outside the intended CUI environment to communicate in ways we didn't account for, network architecture matters. If CUI is copied into a backup platform, the backup environment matters.
Depending on the contractor, the technical work may therefore involve:
Microsoft 365 and identity
Company computers and mobile devices
Endpoint protection and encryption
Servers and file storage
Firewalls and network segmentation
VPN and remote access
Backup and recovery
Logging and monitoring
Vendor and third-party access
Technical documentation
There isn't one Microsoft license, firewall or security product that protects the entire environment. The technology has to be designed, implemented, managed and documented as a system.
CMMC Compliance Guidance and Technical IT Implementation Have to Work Together
Preparing a small business that handles CUI isn't only an IT project, and it isn't only a compliance or documentation project. Both sides have to come together.
For this client, the owner brought in Steadfast Partners, a cybersecurity advisory firm with CMMC and governance, risk and compliance expertise, to help guide the compliance side of the project. My role at SNL-Tech Services is focused on understanding the technology environment and implementing the IT controls that come out of that work.
Those roles are different, but I think they are equally important. A cybersecurity and CMMC compliance advisor can help a business understand the requirements, work through CUI scoping and data flows, identify gaps, develop policies and procedures, and build the formal compliance documentation the business needs. Somebody still has to determine how those requirements translate into the Microsoft tenant, employee computers, Active Directory, servers, firewall, VPN, backups, endpoint security and other technology the company actually uses.
At the same time, I don't want to make compliance interpretations in isolation simply because I am the person configuring the technology. That is why the relationship between the business owner, the compliance advisor and the technical IT provider matters.
We have seen that play out directly with this client. Some of the most important decisions haven't been made by one person sitting at a computer changing settings. They have come from roundtable discussions involving the business owner, the cybersecurity and CMMC compliance advisor and me, where we could look at the compliance requirement, the technology involved and the operational impact on the business at the same time.
The discussions around a CUI enclave are a good example. We considered whether an enclave could limit the CUI environment, we discussed a broader GCC High architecture, my IT Baseline Assessment had already identified that the company's ERP system depends on traditional Active Directory, and we confirmed with the ERP vendor that it could not simply be moved to Entra ID. The owner also made it clear that he wanted to retain his local server infrastructure. Bringing those pieces together ultimately helped shape the hybrid direction we're pursuing now.
I talk more about why small contractors need both sides of that relationship in CMMC Compliance for Small Government Contractors: From Assessment to Actually Ready at Level 1 and Level 2.
“CMMC readiness requires both sides of the conversation. Someone has to understand the compliance requirements, and someone has to translate those requirements into the technology the business actually uses.” — SNL-Tech Services
My IT Baseline Assessment Helps Me Understand What Already Exists
Before I start making major changes, I want to understand the environment the business already has. My IT Baseline Assessment looks beyond Microsoft 365 and helps me understand how the company's technology actually fits together, including servers, applications, identity, networking, security, backups and other dependencies that could affect the decisions we make later.
The ERP system in this story is a good example of why that matters. Without understanding that dependency, it would have been easy to draw an architecture diagram showing the company moving away from traditional Active Directory. On paper, that might have looked cleaner. In the actual business, it could have affected an ERP system employees depend on every day. That is why I want the technology assessment to happen before major architecture decisions are made.
My Microsoft 365 Tenant Audit Goes Deeper Into the Microsoft Environment
The broader IT environment is one side of the picture, but I also want to understand what is actually happening inside Microsoft 365. My Microsoft 365 Tenant Audit looks at the Microsoft environment that exists today rather than starting with assumptions about what somebody believes was configured years ago.
I review licensing, identities, administrative access, authentication, security policies, Microsoft Defender configuration, risky users and risky sign-ins, devices, SharePoint and OneDrive, external access, vendor relationships, third-party application integrations and other Microsoft controls relevant to the environment.
I explain that process in more detail in Microsoft 365 Tenant Security Review: What I Look for During a Microsoft 365 Audit. Together, the IT Baseline Assessment and Microsoft 365 Tenant Audit give me a much better picture of what already exists, what the business depends on and what needs to change before implementation begins.
My Run Book Documents the Technical Environment
When I originally became involved with this client, I was trying to understand decisions made inside an environment somebody else had configured. During an incident, that can mean spending valuable time determining who has access, what a setting does, why something was configured a particular way or whether a security control was ever enabled in the first place. I don't want to recreate that problem while building the client's new environment.
As I implement technical controls, I maintain a run book that documents the technology environment and the meaningful decisions behind it. Depending on the client, that can include Microsoft 365 configuration, administrative access, identities, devices, networks, firewall rules, remote access, backups, vendor relationships, third-party integrations and the technical controls that have been implemented.
The reason behind a decision matters too. If a particular exception exists, I want to document why it exists. If we change an access policy, I want a record of when it changed and why. If an outside vendor is integrated into the environment, I want to know what that integration does and what access was granted. If SharePoint is structured specifically around the company's CUI workflow, I want someone looking at the environment two years from now to understand why it was built that way.
In this case, I would also want the documentation to show why traditional Active Directory remains part of the architecture and the ERP dependency that helped drive that decision, rather than leaving someone in the future to wonder why the company didn't simply move that function into Entra ID.
My run book is technical documentation. It is not designed to be the client's CMMC documentation, System Security Plan or compliance package. My role is to document the technical environment I assess, the controls I implement, the configuration decisions that are made and, when appropriate, the technical evidence associated with that work.
I can then provide that documentation to the cybersecurity and CMMC compliance advisor so they have an accurate technical record of what actually exists and what has been implemented when they develop and maintain the company's formal compliance documentation.
For this particular client, that relationship does not end when the implementation project is finished because the company uses SNL-Tech Services for ongoing Managed IT Services. The run book therefore doesn't become a document that gets created at the end of remediation and then sits untouched. It becomes part of how I manage the environment.
When a meaningful configuration changes, a vendor is added, an integration changes, a security control is modified or the architecture evolves, I document the change and why it was made. That gives the business an ongoing technical record of its environment and gives the cybersecurity and CMMC compliance advisor a current technical reference as the company's compliance documentation continues to be maintained.
Microsoft changes, employees come and go, computers are replaced, vendors need access, applications are added and the business itself evolves. A control that was properly implemented and documented today still needs to be managed tomorrow. Part of my role through Managed IT Services is making sure the technical environment continues to be managed, monitored and documented as those changes occur rather than treating compliance remediation as a one-time project.
“If a security control matters enough to implement, it matters enough to document why it exists.” — SNL-Tech Services
Backup Can Quietly Expand the CUI Environment
Backup is another area where I want to follow the information rather than treating the backup product as a separate IT decision. If a server, mailbox or SharePoint site containing CUI is copied into a backup platform, that backup can contain CUI too, which means I need to understand where the backup is stored, who can access it, what security requirements apply to the service, how long information is retained and whether recovery has actually been tested.
This is particularly important with Microsoft 365 because I don't describe OneDrive and SharePoint themselves as the company's independent backup strategy. They are collaboration and productivity platforms with native retention and recovery capabilities. The contractor still needs an intentional backup and recovery strategy appropriate for the information being protected.
If CUI goes into the backup, the backup becomes part of the CUI conversation too.
AI Is a Conversation We Still Need to Have
AI hasn't been a major part of the work we've discussed so far for this client. Like many businesses, employees may use tools such as ChatGPT, Claude or Microsoft Copilot for ordinary tasks such as helping draft an email, but I haven't identified AI as part of this company's CUI workflow, and I don't want to imply that it is.
It is, however, a conversation we need to have as we continue building the company's CUI environment.
For a contractor handling CUI, the question isn't simply whether employees use AI. We need to establish what information is permitted to go into those tools and where the boundary is. Current DoD guidance specifically addresses the need for policies and technical guardrails around AI use and warns against putting sensitive Department data into public, commercial AI systems.
For this client, I would approach CUI and AI conservatively: CUI should be prohibited from AI tools by default unless a specific AI service, environment and use case have been reviewed and determined to be appropriate for handling that information. An employee having a paid ChatGPT, Claude, Copilot or other business AI account does not by itself make that account an approved place for CUI.
That does not mean AI can never be used in an environment involving CUI. The Department itself is developing and deploying approved AI environments capable of operating at higher security impact levels. The distinction matters. The question isn't simply whether something is AI. The questions are where the AI operates, what information it can access, what controls surround it, whether the environment is appropriate for the data involved, and whether that particular use has been reviewed and approved.
For this particular client, AI should therefore become part of the governance discussion rather than something I assume is already integrated into the CUI environment. If the business eventually wants to use AI with information inside that environment, that would become another architecture and compliance decision for the business owner, the cybersecurity and CMMC compliance advisor and me to work through together.
For now, the more immediate issue is establishing the boundary so employees know the difference between using AI to help draft an ordinary business email and giving an AI system access to CUI.
I discuss the broader issue of creating those boundaries in AI Governance for Small Business.
“AI governance isn't about assuming employees are doing something wrong. It's about defining where the boundaries are before someone has to guess.” — SNL-Tech Services
The CMMC Phase II Pause Doesn't Mean the Cybersecurity Work Stops
The July 2026 CMMC change is important, particularly for small contractors that were preparing for the next phase of implementation. It does not, however, make the technology problems we've identified disappear.
This company still handles CUI. Its ERP system still depends on Active Directory. CUI can still arrive through email. Employees still need to work with it. Subcontractors may still need appropriate information, and the computers, servers, backups, remote access and third-party systems involved still need to be understood and protected.
That is why I don't think a small contractor should interpret a change in the CMMC implementation schedule as a reason to stop working on the underlying environment. The schedule and mechanics of CMMC can change. The responsibility to understand and protect the information the business has been entrusted with does not disappear with a change in the timeline.
The Compromise Wasn't the CMMC Project. It Exposed Why the Larger Conversation Matters.
Looking back at the incident that originally brought me into this client's Microsoft environment, resetting the compromised account was the smaller part of the problem. The incident forced us to look at who controlled the environment, what visibility we had, what security capabilities were available and how much we actually knew about the systems the business was depending on every day.
Once CUI became part of that discussion, the scope changed considerably. The business owner, the cybersecurity and CMMC compliance advisor and I have worked through several possible approaches. We considered an enclave. We considered a much broader move toward a cloud-centered environment. My IT Baseline Assessment identified an ERP application that still depends on traditional Active Directory, and we confirmed that dependency with the software vendor. We also listened to the owner's requirement that he wants to maintain his local server infrastructure rather than moving the entire business into the cloud.
The current direction reflects all of those conversations and discoveries: retain the local infrastructure that the business continues to need, move the Microsoft cloud workloads that need to handle CUI into GCC High, build SharePoint around the CUI collaboration workflow, and continue evaluating the local systems, devices, network, backups and other technology based on whether and how they interact with CUI.
For this particular client, my involvement will also continue through Managed IT Services after the initial implementation work is completed. That means I am not designing the environment, implementing the controls and then handing the client a run book and walking away. I will continue managing the technical environment, maintaining the documentation and working with the business as its technology changes.
When appropriate, that updated technical information can also continue to be provided to the company's cybersecurity and CMMC compliance advisor so the compliance side is working from an accurate picture of what actually exists.
CMMC Is Not a Product You Buy
A small contractor preparing for CMMC can very quickly receive proposals for GCC High, enclave products, security software, new computers, consulting, assessments, documentation and a long list of other technology and services. Some of those things may absolutely be necessary, but I don't think the project should begin with the shopping list.
I want to begin with the business and the information. What contracts do you have? What information do you receive? Is it FCI or CUI? Where does the information enter the company? Who actually needs access to it? Where does it need to go? Which systems touch it? Which outside organizations need to receive it? What existing applications and infrastructure does the business depend on every day?
That last question matters because a technology decision that looks clean on an architecture diagram can create a very real operational problem if it breaks the ERP system employees need to run the company. If the business only handles FCI, the right answer may be properly securing and documenting the commercial Microsoft 365 environment it already has. If the company handles CUI, we have a different architecture conversation. An enclave may make sense for one contractor, a broader GCC High environment may make sense for another, while a hybrid environment may make more sense for a business with legitimate reasons for maintaining part of its local infrastructure.
Once we understand those things, I can help design, implement and document the technology around them. For this particular client, that relationship continues through my Managed IT Services, which means I will also be responsible for the ongoing technical management of the environment after the initial implementation work is complete.
“The goal isn't to force the business into a compliance solution. The goal is to design the compliance environment around how the business actually needs to work.” — SNL-Tech Services
For this particular client, the compromised email account started the conversation. Understanding where the CUI goes, understanding the technology the business already depends on, and then continuing to manage that environment is what determines where we go from here.
Frequently Asked Questions
Didn't the Department Pause CMMC in 2026?
Yes. In July 2026, the Department suspended the transition to CMMC Phase II while it conducts a broader review of the program. That changed part of the assessment timeline, but it did not eliminate the underlying requirements contractors may already have for protecting FCI and CUI. A contractor should look at the requirements in its actual contracts rather than assuming the pause means cybersecurity work can stop.
Can a CMMC Level 1 Contractor Use Commercial Microsoft 365?
Potentially, yes. A contractor handling FCI needs to evaluate its environment against the applicable safeguarding requirements. Commercial Microsoft 365 does not automatically satisfy those requirements simply because the company purchased Microsoft licensing. The environment still has to be appropriately configured, operated and managed.
For a real-world example of how this can come up for a very small subcontractor, see CMMC Level 1 for Small Business: How I Helped a Landscaping Company Answer a Bid Question Before End of Day.
Does Every DoD Contractor Need GCC High?
No. Doing business with the Department of Defense does not automatically mean a contractor needs GCC High. The information the contractor handles, its contractual requirements and the systems that store, process or transmit that information should drive the architecture.
Does Handling CUI Automatically Mean We Have to Move Everything to GCC High?
No. The environment needs to be evaluated based on where CUI is stored, processed and transmitted and which requirements apply to those systems. An enclave may make sense for one contractor, while another may need a broader government-cloud architecture.
For the contractor discussed here, the current direction is a hybrid architecture that retains the company's local server and Active Directory infrastructure while using GCC High for Microsoft cloud workloads that need to handle CUI.
Can We Keep Active Directory and Local Servers?
Potentially, yes. Those systems need to be evaluated based on their role in the environment and whether they interact with CUI. In the contractor discussed here, an important ERP application still requires traditional Active Directory, which became one of the factors considered when we designed the planned hybrid architecture.
Can't We Just Replace Active Directory With Microsoft Entra ID?
Not necessarily. Microsoft Entra ID and traditional Active Directory are not interchangeable for every application. Some line-of-business applications still depend on traditional Active Directory.
In this client's case, we contacted the ERP software vendor to determine whether the application's Active Directory dependency could be moved to Entra ID, and the vendor confirmed that it could not. This is exactly why I want to understand application dependencies before recommending that a business eliminate its existing server environment.
What Is a CUI Enclave?
A CUI enclave is a deliberately limited environment designed to contain the users, devices, applications and workflows that handle CUI rather than allowing that information to spread throughout the company's broader technology environment. For some small contractors, an enclave can reduce the scope of the environment that needs to be protected, but the architecture still has to fit the way the company actually works.
Why Didn't an Enclave Work for the Contractor in This Article?
An enclave was one of the approaches considered during the planning process. Because CUI can arrive through email, is part of normal project work and may need to be appropriately passed to subcontractors, maintaining separate CUI and normal-business workflows would introduce additional operational complexity for this particular company.
After the owner, cybersecurity and CMMC compliance advisor and I worked through the requirements together, an enclave did not appear to be the best fit for the environment we need to build.
Can We Use GCC High SharePoint to Share CUI With Our Subcontractors?
Potentially, but the workflow needs to be designed around the applicable CUI requirements, the subcontractor's environment and the collaboration capabilities available in the environment. The contractor needs to understand whether the subcontractor is authorized to receive the information, what requirements have been flowed down, how access will be authenticated and what sharing method is appropriate.
Why Do I Need Both a Cybersecurity and CMMC Compliance Advisor and an IT Provider?
Because they perform different jobs, and for a small contractor without both capabilities internally, I think having both sides represented is important.
A cybersecurity and CMMC compliance advisor can help the business understand the requirements, scope the environment, develop policies and procedures and prepare the formal compliance documentation. A technical IT provider implements the technology behind those requirements across Microsoft 365, endpoints, servers, networks, identity, backup and the other systems the business actually uses.
Can SNL-Tech Services Work With Our Existing Cybersecurity or CMMC Compliance Advisor?
Yes. That is the model I prefer. The cybersecurity and CMMC compliance advisor can guide the compliance requirements, policies, formal documentation and readiness work while I focus on the technical environment, architecture and implementation of the IT controls.
For clients using my Managed IT Services, that relationship can continue after the initial implementation because I remain involved in the ongoing management of the technology environment. As meaningful technical changes are made, I maintain the run book and can provide updated technical information to the client's compliance advisor so the formal compliance documentation is based on what actually exists in the environment.
What Is an IT Baseline Assessment?
My IT Baseline Assessment looks at the broader technology environment so I can understand what the business actually has, how the systems work together and what dependencies need to be considered before major changes are made. That can include servers, identity, business applications, networking, endpoint security, remote access, backups and other parts of the environment.
For the contractor discussed in this article, the assessment helped identify the ERP system's dependency on traditional Active Directory, which later became important during the architecture discussions.
What Is a Microsoft 365 Tenant Audit?
My Microsoft 365 Tenant Audit is a deeper review of the Microsoft environment itself. I look at areas including licensing, identities, administrative access, authentication, security policies, Microsoft Defender configuration, risky users and risky sign-ins, devices, SharePoint and OneDrive, vendor access, third-party application integrations and other controls that can affect the security and management of the tenant.
I explain the audit in more detail in Microsoft 365 Tenant Security Review: What I Look for During a Microsoft 365 Audit.
Do You Document the Technical Work You Perform?
Yes. Documentation is part of my technical implementation process. I maintain a run book that records the environment, important technical controls, configuration decisions, vendor and third-party integrations, and meaningful changes made to the systems I manage.
For Managed IT clients, that run book continues to be maintained as the environment changes. It isn't designed to replace the company's formal CMMC documentation or System Security Plan. I can provide my technical documentation to the client's cybersecurity and CMMC compliance advisor so they have an accurate record of the environment and the technical work that has been completed, and they can determine how that information should be incorporated into the company's formal compliance documentation.
What Happens After the Technical Controls Are Implemented?
For clients using SNL-Tech Services for Managed IT Services, implementation is not the end of the relationship. I continue managing the technical environment, maintaining documentation and addressing changes that can affect the controls already in place.
Employees change, devices are replaced, vendors are added, Microsoft changes its platforms and the business adopts new technology. Those changes need to be managed rather than assuming the environment will remain exactly as it looked on the day the initial implementation was completed.
Do We Need an AI Policy if We Handle CUI?
Yes. Even if AI is not currently part of the company's CUI workflow, employees need clear guidance about what information can and cannot be entered into AI systems.
Current DoD guidance calls for policies and technical guardrails around AI use and specifically warns against putting sensitive Department data into public, commercial AI systems. For a small contractor, my starting point would therefore be simple: CUI is prohibited from AI by default unless the specific AI service, environment and use case have been reviewed and approved for handling that information.
I discuss the broader small-business side of this in AI Governance for Small Business.
Additional SNL-Tech Services Articles
Sources & References
U.S. Department of Defense Chief Information Officer — CMMC
Official Department of Defense information about the Cybersecurity Maturity Model Certification program, implementation requirements and current program status.
U.S. Department of Defense Chief Information Officer — Implementing Suspension of CMMC Phase II
The July 2026 DoD guidance covering the suspension of Phase II implementation and explaining what continues during the suspension.
Federal Acquisition Regulation — FAR 52.204-21
The federal safeguarding requirements for Federal Contract Information that form the basis for CMMC Level 1.
Defense Federal Acquisition Regulation Supplement — DFARS 252.204-7012
DoD contractual requirements covering safeguarding covered defense information and cyber incident reporting.
National Institute of Standards and Technology — NIST SP 800-171
NIST guidance for protecting Controlled Unclassified Information in nonfederal systems and organizations.
Microsoft — Office 365 GCC High and DoD
Microsoft's official service description for GCC High and DoD environments, including eligibility, compliance, differences from commercial Microsoft 365, and the use of GCC High by contractors holding or processing DoD Controlled Unclassified Information (CUI). Microsoft states that eligible non-DoD organizations can use GCC High and that the environment can provide the necessary inheritance for CMMC.
U.S. Department of Defense Chief Information Officer — Brilliant at the Basics
This is the particularly important source for the AI section. The July 2026 guidance for Defense Industrial Base partners tells organizations to establish policies and technical guardrails for AI use and explicitly addresses preventing sensitive Department information from being entered into public, commercial AI systems.
Chief Digital and Artificial Intelligence Office — Responsible AI and Generative AI
CDAO resources covering the Department's approach to artificial intelligence, responsible AI, generative AI and approved Department AI capabilities.
Chief Digital and Artificial Intelligence Office — GenAI Toolkit
DoD CDAO guidance and guardrails for evaluating and managing generative AI risks.




Comments