This is the question that triggers the most expensive scoping mistakes in CMMC. The legal foundation is DFARS 252.204-7012(b)(2)(ii)(D), and the operational guidance is in the DoW CIO's FedRAMP Authorization and Equivalency brief (Feb 2025).
What DFARS 252.204-7012 requires
"Contractors that use external cloud service providers that store, process, or transmit any covered defense information shall require and ensure that the cloud service provider meets security requirements equivalent to those established by the Government for the FedRAMP Moderate baseline."
The clause sets a floor: FedRAMP Moderate baseline. Two paths satisfy this floor.
Path 1 — FedRAMP Moderate Authorized (or higher)
The Cloud Service Offering (CSO) holds an Authority to Operate from the FedRAMP program at Moderate or High. Listed on the FedRAMP Marketplace at marketplace.fedramp.gov. Examples relevant to DoD contractors:
- Microsoft 365 GCC High — FedRAMP High and DoD IL5 authorized. The standard DoD-aligned path.
- AWS GovCloud (US) — FedRAMP High and DoD IL5 authorized.
- Azure Government — FedRAMP High and DoD IL5 authorized.
- Salesforce Government Cloud Plus — FedRAMP High authorized.
Path 2 — FedRAMP Moderate Equivalent
For CSOs that don't have an ATO, DoW provides an Equivalency path per the FedRAMP Authorization and Equivalency brief. Key facts:
- The CSO must achieve 100% compliance with the latest FedRAMP Moderate Baseline at the conclusion of an assessment conducted by a FedRAMP-recognized Third Party Assessment Organization (3PAO).
- The 3PAO produces a Body of Evidence (BoE) including SSP, Security Assessment Plan, Security Assessment Report, POA&M, and a Customer Responsibility Matrix.
- The BoE is reviewed by DCMA DIBCAC and, for CMMC assessments, by the C3PAO.
- Continuing operational POA&Ms after assessment are expected and acceptable.
- FedRAMP Moderate Equivalency does NOT confer FedRAMP Moderate Authorization. They are distinct.
The Microsoft 365 tiers
Microsoft offers Commercial, GCC, GCC High, and DoD tiers of Microsoft 365 with different authorization profiles. The authoritative source for which Microsoft tier matches which authorization level — and which tier you should use for your CUI scenario — is Microsoft's own compliance documentation. Microsoft maintains current FedRAMP and DoD impact level mappings for each cloud service in their Trust Center and Service Trust Portal. Verify each service you intend to use for CUI directly against Microsoft's published authorization documentation, not against vendor blogs or summary articles.
What this means in practice
- Verify on the FedRAMP Marketplace. Don't take vendor marketing at face value. The marketplace at marketplace.fedramp.gov is the authoritative source.
- Match the impact level to the data. CUI Basic typically requires Moderate; some Specified categories and DoD-defined OIG categories require High or DoD IL5.
- Get the CSP's body of evidence. For Equivalency, the 3PAO BoE is what the C3PAO will review at your assessment. Ask the CSP to provide it.
- Document the cloud relationship in your SSP. Per the L2 Scoping Guide ESP section, the OSC's SSP must reference the CSP's service description and Customer Responsibility Matrix.
Common errors
- Assuming SOC 2 equals FedRAMP. They are different programs. Only FedRAMP Authorization or Equivalency satisfies DFARS 7012 for CUI.
- Assuming GCC equals GCC High. Microsoft sells both; only GCC High meets DoD IL5.
- Treating commercial Outlook/SharePoint/OneDrive as acceptable for CUI "if it's just one document." A single CUI document on commercial M365 is a DFARS 7012 violation regardless of frequency.
- Confusing FedRAMP Moderate Authorized with FedRAMP Moderate Equivalent. Authorized has an ATO; Equivalent has a 3PAO BoE. Both can satisfy DFARS 7012.
Sources
- DoW CIO FedRAMP Authorization and Equivalency Brief (Feb 2025) — link
- FedRAMP Moderate Equivalency Memo — link
- DFARS 252.204-7012 — (b)(2)(ii)(D) — Cloud computing services for CDI — link
- FedRAMP Marketplace — link
- Microsoft Trust Center / Service Trust Portal — Government cloud compliance documentation — link
Implement CMMC controls in Microsoft 365 GCC High.
The CMMC Compliance Engine includes 8 M365 implementation guides (M365-01 through M365-08) covering MFA & Conditional Access, Purview, Defender, Sentinel, Audit, Intune, Email, and SharePoint for Microsoft 365 GCC High environments.
Get the CMMC Compliance Engine