# CMMC Shared Responsibility Model: You vs. Microsoft vs. Your MSP

> Buying GCC High doesn't make you CMMC compliant. See who is responsible for each of the 110 NIST 800-171 requirements (Microsoft, you, or your MSP).

canonical: https://secureframe.com/blog/cmmc-shared-responsibility-model

Here is one of the most pernicious misconceptions in [CMMC compliance](https://secureframe.com/hub/cmmc/what-is-cmmc): a defense contractor purchases Microsoft 365 GCC High licenses, tells leadership "we're on the government cloud now," and believes the hard work is done.

It is not.

As a [cloud service provider](https://secureframe.com/hub/cmmc/cloud) that supports meeting NIST SP 800-171 Rev 2 requirements, the underlying cybersecurity standard of [DFARS 7012 and CMMC](https://secureframe.com/blog/dfars-7012-vs-cmmc), [Microsoft GCC High](https://secureframe.com/blog/microsoft-gcc-high) gives an organization seeking certification (OSC) a strong head start on CMMC. But it does not get you to the finish line.

Microsoft will not configure your Conditional Access policies. Microsoft will not run your security awareness training. Microsoft will not show up to your internal review or [C3PAO assessment](https://secureframe.com/hub/cmmc/c3pao) and answer for your incident response plan.

Microsoft will, however, provide the infrastructure and security capabilities needed to protect [Controlled Unclassified Information (CUI)](https://secureframe.com/blog/controlled-unclassified-information-cui). You, the OSC, are responsible for configuring those capabilities, implementing your own policies, and demonstrating compliance through documentation and evidence, whether you [self-assess today or face a C3PAO assessment](https://secureframe.com/hub/cmmc/assessments) later.

That is what the CMMC shared responsibility model is about.

## What is the Microsoft shared responsibility model for CMMC?

## What is the Microsoft shared responsibility model for CMMC?

The Microsoft shared responsibility model defines which security tasks Microsoft as the cloud provider handles and which tasks you as the organization handle.

Under [CMMC](https://secureframe.com/hub/cmmc/documentation), a document called a Shared Responsibility Matrix (SRM) formally documents who is accountable for each of the 110 NIST SP 800-171 Rev 2 requirements (and their 320 assessment objectives) in your cloud environment to properly secure CUI. This document may also be referred to as a Customer Responsibility Matrix (CRM).

In a typical Microsoft GCC High deployment, there are at least two parties involved, sometimes three if an MSP is involved. Responsibilities are split between them:

1. **Microsoft:** The cloud platform provider, responsible for infrastructure security, data center physical controls, and certain technical controls inherited from its FedRAMP Authorization.*
2. **You (organization seeking certification):** The defense contractor, ultimately accountable for proving compliance with all 110 requirements.
3. **Your MSP or MSSP:** A managed service provider or managed security service provider who may handle some implementation tasks on your organization's behalf.

Sharing responsibility with a cloud service provider, and often an MSP, offers significant advantages for solving [long-standing information security challenges](https://secureframe.com/hub/cmmc/pentagon-cmmc-enforcement-challenges) that are especially acute for Defense Industrial Base (DIB) organizations pursuing CMMC. These include limited resources and unmet responsibilities that leave your organization vulnerable, such as insufficient backup and disaster recovery.

*****A note on naming**: FedRAMP Authorization is now called FedRAMP Certification under CR26. However, Authorization, the Rev5 baselines, and FedRAMP Moderate equivalency is still used in the context of DFARS 7012 and CMMC.

![Microsoft shared responsibility model across cloud service models.](https://images.prismic.io/secureframe-com/abmItbbci2UF6JF4_microsoft-shared-responsibility-model.png?auto=format,compress)

## Recommended reading

What Is GCC High? The Complete Microsoft 365 Guide for Defense Contractors

## How is responsibility divided in Microsoft GCC High for CMMC?

## How is responsibility divided in Microsoft GCC High for CMMC?

For [CMMC Level 2](https://secureframe.com/blog/cmmc-level-2-compliance), all 110 underlying cybersecurity requirements and 320 assessment objectives, and the controls needed to fully meet them, fall into one of three categories:

1. **Inherited from Microsoft:** The control is implemented at the platform level. Microsoft's FedRAMP authorization covers it, so you inherit the control from Microsoft. You can claim it without additional implementation, but you must document the inheritance in your System Security Plan.
2. **Shared responsibility:** The platform provides the technical capability, but your organization must configure it, use it, and prove it is working. Both parties have a role.
3. **Customer responsibility:** Microsoft has no role. The control is entirely yours: policies, procedures, physical security, personnel management, and training.

The critical takeaway: **being on GCC High does not automatically satisfy any control.** Even inherited controls require documentation. Even shared controls require active configuration. And customer controls require you to implement them from scratch.

In other words, CMMC compliance cannot be fully inherited. But it can be shared, and therefore simplified, with the right cloud service provider. For a deeper look at what GCC High is and why it matters for CMMC, see our [GCC High overview](https://secureframe.com/blog/microsoft-gcc-high).

### 1. What Microsoft covers (Inherited controls)

Microsoft 365 GCC High is FedRAMP High authorized, which means Microsoft has independently validated the security of its infrastructure to one of the most rigorous government standards.

Because [NIST 800-171 Rev 2](https://secureframe.com/hub/cmmc/vs-nist-800-171) (the standard CMMC Level 2 uses) is a subset of [NIST SP 800-53](https://secureframe.com/hub/cmmc/vs-nist-800-53) (the standard [FedRAMP](https://secureframe.com/hub/cmmc/vs-fedramp) uses), Microsoft's implementation of FedRAMP requirements helps ensure its in-scope cloud services meet or exceed the requirements of NIST SP 800-171.

So when you use GCC High, you inherit Microsoft's controls on:

- **[Physical and environmental security:](https://secureframe.com/blog/nist-800-171-gcc-high-physical-protection)** data centers with controlled access, CCTV, biometric authentication, and 24/7 monitoring.
- **[Configuration management:](https://secureframe.com/blog/nist-800-171-gcc-high-configuration-management)** DoD-grade network segregation keeping your data in U.S.-based, U.S.-personnel-only facilities.
- **[Media protection](https://secureframe.com/blog/nist-800-171-gcc-high-media-protection)** **at the hardware level:** encrypted storage and secure disposal of decommissioned hardware.
- **[Maintenance](https://secureframe.com/blog/nist-800-171-gcc-high-maintenance)** **at the hardware level:** physical maintenance of servers, storage, and networking infrastructure (excluding endpoints like laptops).
- **Platform-level cryptography:** FIPS 140-2 validated encryption modules for data at rest and in transit.
- **Availability and redundancy:** high-availability infrastructure and disaster recovery at the platform tier.
- **Continuous monitoring of the platform:** Microsoft monitors infrastructure-level security events.

These are controls where Microsoft does the work and you inherit them, so your only responsibility is to document the inheritance correctly in your [System Security Plan (SSP)](https://secureframe.com/blog/cmmc-ssp).

This is an important caveat. When Microsoft covers a control at the infrastructure level, it means the platform is capable of supporting the requirement. A C3PAO or DIBCAC assessor, prime buyer, or designated Internal Assessment Lead may review your SSP to confirm you understand which controls are inherited and from whom. Simply saying "Microsoft handles it" with no documentation is not sufficient. You need a Shared Responsibility Matrix that references the specific controls, Microsoft's FedRAMP authorization, and how that inheritance flows into your compliance posture.

#### How many controls does Microsoft provide?

While exact coverage depends on your licensing, enabled services, and service model, you can meet nearly half of NIST 800-171 requirements (52 of 110) with inherited controls from Microsoft when using GCC High as your cloud-native environment for CUI.

Note this [disclaimer](https://techcommunity.microsoft.com/blog/publicsectorblog/microsoft-product-placemat-for-cmmc---october-2024-update/4278617) from Microsoft: customers must individually determine the steps required to ensure their organization fully satisfies each recommended CMMC practice, in addition to or in place of what is described in program resources. This responsibility spans all Microsoft consumption decisions, including which offerings to procure and all associated configuration decisions.

### 2. What you must configure as the OSC (Shared controls)

This is where most defense contractors underestimate the work. Roughly half (58) of the 110 NIST 800-171 requirements are a shared responsibility in a GCC High environment. GCC High provides the capability to meet the requirement, but you must configure and document it to actually comply. Microsoft gives you a toolbox; you have to use the tools.

Here are the control families where most requirements are a shared responsibility:

**Access Control (AC)**

GCC High includes Entra ID (previously called Azure Active Directory) now with full support for Conditional Access policies, role-based access control (RBAC), and multi-factor authentication. None of these are pre-configured for your environment. You must:

- Build and enforce Conditional Access policies that require MFA for all users accessing CUI
- Define and assign roles with least-privilege access to SharePoint, Teams, Exchange
- Configure sign-in risk policies that block or challenge suspicious logins
- Restrict access to CUI from non-compliant or unmanaged devices

In other words, leaving Entra ID in its default configuration means you’ll have significant gaps in your access controls, regardless of what license you purchased.

Check out our [complete configuration guide for NIST 800-171 Access Control in GCC High](https://secureframe.com/blog/nist-800-171-gcc-high-access-control).

**Audit and Accountability (AU)**

Microsoft Purview provides a unified audit log across Microsoft 365. By default, audit logging is enabled for most workloads in GCC High, but you still must:

- Define which logs you review, how frequently, and who is responsible
- Configure log retention periods appropriate to your contract lifecycle
- Set up alerts for high-risk events (privilege escalation, mass downloads, failed logins)
- Document your log review process in your SSP

An audit log that no one reviews is not an effective operating control. C3PAO assessors test this by asking you to show them audit log review records and demonstrate what happens when an anomaly is detected.

Check out our [complete configuration guide for NIST 800-171 Audit & Accountability in GCC High](https://secureframe.com/blog/nist-800-171-gcc-high-audit-accountability).

**System and Communications Protection (SC)**

GCC High supports data encryption in transit and at rest. Microsoft Purview also provides:

- **Data Loss Prevention (DLP)** but you must write the DLP policies that define what counts as CUI and what to block
- **Sensitivity Labels** but you must design your label taxonomy, publish labels to users, and train users on how to apply them
- **Information Barriers** but you must configure them if your use case requires it
- **Network boundary configurations** you must define the architecture (what is [in-scope vs. out-of-scope for CUI](https://secureframe.com/blog/cmmc-scope))

Check out our [complete configuration guide for NIST 800-171 System & Communications Protection in GCC High](https://secureframe.com/blog/nist-800-171-gcc-high-system-communications).

**Identification and Authentication (IA)**

GCC High supports FIPS 140-2 compliant authentication. You must enforce it. That means:

- Ensuring all authenticators used in your environment are FIPS-compliant
- Configuring password complexity and rotation policies through Azure AD
- Enforcing phishing-resistant MFA for privileged accounts where CMMC requires it
- Managing service account credentials and certificate-based authentication

Check out our [complete configuration guide for NIST 800-171 Identification & Authentication Controls in GCC High](https://secureframe.com/blog/nist-800-171-gcc-high-identification-authentication).

**System and Information Integrity (SI)**

GCC High provides malware protection and security alerting capabilities, but you are responsible for configuring alerts, reviewing security event data, and acting on anomalies.

The bottom line on shared controls: every control in this category represents a decision your organization must make, a policy your organization must write, and a configuration your organization must implement and maintain. Purchasing the license is Step 0. The actual work starts after that.

Check out our [complete configuration guide for NIST 800-171 System & Information Integrity in GCC High](https://secureframe.com/blog/nist-800-171-gcc-high-system-integrity).

**The bottom line on shared controls:** every control here represents a decision your organization must make, a policy you must write, and a configuration you must implement and maintain. Purchasing the license is only one step. The work to fully implement these NIST 800-171 requirements starts after that.

### 3. What is entirely on you (Customer controls)

In the [June 2025 Microsoft Product Placemat](https://9363439.fs1.hubspotusercontent-na1.net/hubfs/9363439/CMMC%20PDFs%20from%20Third-Party%20Sources/Microsoft%20Product%20Placemat%20for%20CMMC%20-%20LOCKED%20-%206-6-25.xlsm) (obtained directly from Microsoft’s Richard Wakeman), none of the 110 high-level requirements fall entirely to the customer in a GCC High deployment; every one is either inherited or shared.

That high-level view understates your real burden, though. When you look at all 110 requirements and their 320 assessment objectives, the share the customer is entirely responsible for is substantially larger. These objectives relate to your organizational policies, physical premises, people management, and operational procedures, and no GCC High license, regardless of tier, provides that coverage.

They concentrate in these families:

- **Awareness and Training (AT):** GCC High can support training delivery, but executing the program is on you. [Read the AT configuration guide.](https://secureframe.com/blog/nist-800-171-gcc-high-awareness-training)
- **Incident Response (IR):** GCC High can detect events and generate alerts, but responding to them is your responsibility. [Read the IR configuration guide.](https://secureframe.com/blog/nist-800-171-gcc-high-incident-response)
- **Personnel Security (PS):** your employment practices, such as screening staff before authorizing CUI access, are yours. [Read the PS configuration guide.](https://secureframe.com/blog/nist-800-171-gcc-high-personnel-security)
- **Risk Assessment (RA):** you conduct and document periodic risk assessments of your own environment. [Read the RA configuration guide.](https://secureframe.com/blog/nist-800-171-gcc-high-risk-assessment)
- **Security Assessment (CA):** you periodically assess your own controls and track remediation in a [Plan of Action and Milestones (POA&M)](https://secureframe.com/blog/plan-of-action-and-milestones-poam). [Read the CA configuration guide.](https://secureframe.com/blog/nist-800-171-gcc-high-security-assessment)

These operational responsibilities cannot be inherited from or shared with your cloud provider. But they can be shared with a managed service provider, or simplified with a compliance automation vendor like Secureframe.

## Recommended reading

GCC High vs GCC vs Commercial: Which Microsoft 365 Do You Need?

## Microsoft GCC High Shared Responsibility Matrix across the 14 CMMC domains

## Microsoft GCC High Shared Responsibility Matrix across the 14 CMMC domains

The table below shows the general responsibility distribution of all 110 high-level requirements across the 14 NIST SP 800-171 control families in a GCC High deployment, based on the June 2025 Microsoft Product Placemat.

```
<style>
#microsoft-gcc-high-shared-responsibility-matrix-across-the-14-cmmc-domains-table {
  margin-bottom: 32px;
  font-family: Assistant, sans-serif;
  border-collapse: collapse;
}
#microsoft-gcc-high-shared-responsibility-matrix-across-the-14-cmmc-domains-table td,
#microsoft-gcc-high-shared-responsibility-matrix-across-the-14-cmmc-domains-table th {
  padding: 1rem;
  border: 1px solid #fff;
}
#microsoft-gcc-high-shared-responsibility-matrix-across-the-14-cmmc-domains-table thead {
  background-color: #0CAB6B;
  color: #fff;
}
#microsoft-gcc-high-shared-responsibility-matrix-across-the-14-cmmc-domains-table thead strong,
#microsoft-gcc-high-shared-responsibility-matrix-across-the-14-cmmc-domains-table thead th,
#microsoft-gcc-high-shared-responsibility-matrix-across-the-14-cmmc-domains-table thead tr {
  color: #fff;
  font-weight: bold;
}
#microsoft-gcc-high-shared-responsibility-matrix-across-the-14-cmmc-domains-table thead tr th {
  font-family: Assistant, sans-serif;
}
#microsoft-gcc-high-shared-responsibility-matrix-across-the-14-cmmc-domains-table tbody tr:nth-of-type(odd) {
  background-color: #EBE9E5;
}
#microsoft-gcc-high-shared-responsibility-matrix-across-the-14-cmmc-domains-table tbody tr:nth-of-type(odd) th {
  background-color: inherit;
}
#microsoft-gcc-high-shared-responsibility-matrix-across-the-14-cmmc-domains-table tbody tr:nth-of-type(2n) {
  background-color: #F5F4F2;
}
#microsoft-gcc-high-shared-responsibility-matrix-across-the-14-cmmc-domains-table tbody tr:nth-of-type(2n) th {
  background-color: inherit;
}
#microsoft-gcc-high-shared-responsibility-matrix-across-the-14-cmmc-domains-table tbody tr th,
#microsoft-gcc-high-shared-responsibility-matrix-across-the-14-cmmc-domains-table tbody tr td {
  color: #091922;
}
</style>

<table id="microsoft-gcc-high-shared-responsibility-matrix-across-the-14-cmmc-domains-table">
<thead>
<tr><th>Control family</th><th>Abbr.</th><th>Total requirements</th><th>Microsoft (inherited)</th><th>Shared</th><th>Customer</th></tr>
</thead>
<tbody>
<tr><th>Access Control</th><td>AC</td><td>22</td><td>3</td><td>19</td><td>0</td></tr>
<tr><th>Audit & Accountability</th><td>AU</td><td>9</td><td>0</td><td>9</td><td>0</td></tr>
<tr><th>Awareness & Training</th><td>AT</td><td>3</td><td>0</td><td>3</td><td>0</td></tr>
<tr><th>Configuration Management</th><td>CM</td><td>9</td><td>7</td><td>2</td><td>0</td></tr>
<tr><th>Identification & Authentication</th><td>IA</td><td>11</td><td>1</td><td>10</td><td>0</td></tr>
<tr><th>Incident Response</th><td>IR</td><td>3</td><td>3</td><td>0</td><td>0</td></tr>
<tr><th>Maintenance</th><td>MA</td><td>6</td><td>6</td><td>0</td><td>0</td></tr>
<tr><th>Media Protection</th><td>MP</td><td>9</td><td>8</td><td>1</td><td>0</td></tr>
<tr><th>Personnel Security</th><td>PS</td><td>2</td><td>0</td><td>2</td><td>0</td></tr>
<tr><th>Physical Protection</th><td>PE</td><td>6</td><td>6</td><td>0</td><td>0</td></tr>
<tr><th>Risk Assessment</th><td>RA</td><td>3</td><td>3</td><td>0</td><td>0</td></tr>
<tr><th>Security Assessment</th><td>CA</td><td>4</td><td>4</td><td>0</td><td>0</td></tr>
<tr><th>System & Communications Protection</th><td>SC</td><td>16</td><td>10</td><td>6</td><td>0</td></tr>
<tr><th>System & Information Integrity</th><td>SI</td><td>7</td><td>1</td><td>6</td><td>0</td></tr>
<tr><th>Totals</th><td></td><td>110</td><td>52</td><td>58</td><td>0</td></tr>
</tbody>
</table>
```

We confirmed these numbers against the GCC High coverage listed in the CMMC Practice Details table for all 110 requirements in the Microsoft Product Placemat for CMMC (June 2025 update). Note that this reflects only the high-level requirement categorization.

To see which assessment objectives within each family are inherited versus shared versus customer-only, you need to access Microsoft's Customer Responsibility Matrix through the Microsoft Service Trust Portal, or request it by email. Your SSP should reference this document and map it to your specific system boundary.

If you want a more detailed look at how the 110 requirements are divided between you and Microsoft, download our full [CMMC Shared Responsibility Matrix for Microsoft GCC High](https://secureframe.com/compliance-resources/cmmc-shared-responsibility-matrix-for-microsoft-gcc-high). It shows which requirements are inherited, shared, or fully yours in GCC High versus a Commercial or GCC deployment on Azure Commercial. In another tab, it maps the Microsoft service coverage type for each high-level requirement across the F3, G3, and G5 licenses, which we'll explain in detail in the next section.

## CMMC Shared Responsibility Matrix for Microsoft GCC High

Ready to map your compliance responsibilities? Download the full matrix to see exactly where Microsoft's coverage ends and yours begins. It breaks down all 110 requirements two ways: who owns each control (inherited, shared, or customer) in GCC High versus a Commercial or GCC deployment, plus a tab showing the Microsoft service-coverage type for each control across the F3, G3, and G5 licenses.

## How the type of GCC High license affects your total CMMC work

## How the type of GCC High license affects your total CMMC work

Picking Microsoft 365 GCC High over GCC and Commercial can significantly reduce the burden of CMMC and the underlying NIST 800-171 implementation. The next choice that can further reduce that burden is the type of GCC High license you purchase. The license doesn’t change the shared responsibility count: the 52 inherited and 58 shared control split above is true for any GCC High license and answers the question of who owns or is accountable for which requirements. But this is not the only way Microsoft counts its control coverage, and it is not the number you will usually hear Microsoft cite.

There are two different lenses that answer different questions about CMMC in GCC High:

- **The first is responsibility**. Who is accountable for the control? This is the SSP or assessment and architecture view, and it does not change by licensing tier.
- **The other is service coverage**. Does Microsoft have a service that is the leading technology component that satisfies the control, a supporting one, an available enabler that must be configured, or totally absent from the Microsoft stack? This is the licensing and configuration view, and it changes by licensing tier.

Speaking at Secureframe's National Cybersecurity Summit, Richard Wakeman, Chief Security Architect for the U.S. Aerospace and Defense vertical at Microsoft, [explained](https://www.youtube.com/watch?v=H9HfBzacjJ0&list=PLJdpBvnGXRXo-hdFhxqaPbaE2ewlOOXCe&index=4&pp=iAQB0gcJCRMMAYcqIYzv):

"If you turn all the knobs and dials and configure all the products and services that Microsoft offers you, you're around 86 of the controls. To get to a full 110, you have training, monitoring operations, and a number of other things that are not technology. There's always an organizational shared responsibility between you and the cloud service provider."

That "86" is larger than the 52 inherited controls in the table above, and the gap is not a mistake or contradiction. It is the difference between a control you *inherit* in GCC High and a control a Microsoft service can *primarily satisfy once you configure it*.

In [Microsoft's 2025 placemat](https://9363439.fs1.hubspotusercontent-na1.net/hubfs/9363439/CMMC%20PDFs%20from%20Third-Party%20Sources/Microsoft%20Product%20Placemat%20for%20CMMC%20-%20LOCKED%20-%206-6-25.xlsm) (obtained directly from Wakeman), a G5 license includes a primary Microsoft service for exactly 86 of the 110 controls. Here's how Wakeman explained it: there is "a delta between the ones that you actually inherit" and the ones where "you don't really inherit anything, but if you go and configure that particular product, you can meet the intent of that control using those Microsoft capabilities."

Device management with Intune is his example: nothing is inherited, but if configured correctly by the customer to protect devices, it does most of the technical work for implementing and meeting the intent of that control.

### Primary vs secondary services: Explaining all four coverage types in GCC High

Microsoft's [CMMC Product Placemat](https://www.microsoft.com/en-us/download/details.aspx?id=102536) sorts each of the 110 Level 2 controls into one of four service-coverage types, which are explained in detail by Microsoft's Justin Orcutt in this [video with GRC Academy](https://www.youtube.com/watch?v=x50a0VPeNIY):

- **Primary service:** A Microsoft service is the leading component and goes most of the way toward meeting the requirement. He points to the example of [access control](https://secureframe.com/blog/nist-800-171-gcc-high-access-control): "[Entra ID] is going to be the primary product contributing to many of the access control family of practices."
- **Secondary service:** A Microsoft service supports the control, but the primary way you meet it is often a process. Orcutt’s example is layering device compliance from Intune and Defender for Endpoint onto a Conditional Access policy, so the device, not just the user, is verified before it can reach CUI.
- **Available enablers:** Microsoft has capabilities you can configure toward the control, but meaningful work also falls outside the Microsoft stack.
- **No available enablers:** No Microsoft service can help at all. Orcutt says a good example is usually a policy or procedure that Microsoft can't help with at all, like a sign-in log at a physical location.

Microsoft's latest services now provide at least an available enabler for all 110 high-level requirements, even the most process-driven practices such as personnel screening and sanitizing equipment sent off site for maintenance. However, while no Level 2 control is mapped to "No available enablers" in the latest CMMC product placemat, the same distinction made above for the responsibility model applies here for product capability: A control with primary service coverage is still yours to configure, document, and prove in order to fully meet that high-level control and all its assessment objectives. 

### How coverage shifts by license: F3 vs G3 vs G5

Because the coverage types depend on which services your license includes, the mix moves as you change tiers.

The table below shows how Microsoft's placemat maps the 110 Level 2 controls for the three [GCC High](https://secureframe.com/blog/gcc-high-pricing) productivity licenses. (The placemat maps E3 and E5, the commercial equivalents of the government G3 and G5 SKUs, so those numbers stand in for G3 and G5.)

```
<style>
#how-the-type-of-gcc-high-license-can-further-affect-your-cmmc-work-table {
  margin-bottom: 32px;
  font-family: Assistant, sans-serif;
  border-collapse: collapse;
}
#how-the-type-of-gcc-high-license-can-further-affect-your-cmmc-work-table td,
#how-the-type-of-gcc-high-license-can-further-affect-your-cmmc-work-table th {
  padding: 1rem;
  border: 1px solid #fff;
}
#how-the-type-of-gcc-high-license-can-further-affect-your-cmmc-work-table thead {
  background-color: #0CAB6B;
  color: #fff;
}
#how-the-type-of-gcc-high-license-can-further-affect-your-cmmc-work-table thead strong,
#how-the-type-of-gcc-high-license-can-further-affect-your-cmmc-work-table thead th,
#how-the-type-of-gcc-high-license-can-further-affect-your-cmmc-work-table thead tr {
  color: #fff;
  font-weight: bold;
}
#how-the-type-of-gcc-high-license-can-further-affect-your-cmmc-work-table thead tr th {
  font-family: Assistant, sans-serif;
}
#how-the-type-of-gcc-high-license-can-further-affect-your-cmmc-work-table tbody tr:nth-of-type(odd) {
  background-color: #EBE9E5;
}
#how-the-type-of-gcc-high-license-can-further-affect-your-cmmc-work-table tbody tr:nth-of-type(odd) th {
  background-color: inherit;
}
#how-the-type-of-gcc-high-license-can-further-affect-your-cmmc-work-table tbody tr:nth-of-type(2n) {
  background-color: #F5F4F2;
}
#how-the-type-of-gcc-high-license-can-further-affect-your-cmmc-work-table tbody tr:nth-of-type(2n) th {
  background-color: inherit;
}
#how-the-type-of-gcc-high-license-can-further-affect-your-cmmc-work-table tbody tr th,
#how-the-type-of-gcc-high-license-can-further-affect-your-cmmc-work-table tbody tr td {
  color: #091922;
}
</style>

<table id="how-the-type-of-gcc-high-license-can-further-affect-your-cmmc-work-table">
<thead>
<tr><th>Coverage type</th><th>F3</th><th>G3</th><th>G5</th></tr>
</thead>
<tbody>
<tr><th>Primary service</th><td>70 (64%)</td><td>77 (70%)</td><td>86 (78%)</td></tr>
<tr><th>Secondary service</th><td>29 (26%)</td><td>25 (23%)</td><td>22 (20%)</td></tr>
<tr><th>Available enablers</th><td>11 (10%)</td><td>8 (7%)</td><td>2 (2%)</td></tr>
<tr><th>No available enablers</th><td>0</td><td>0</td><td>0</td></tr>
<tr><th>Total</th><td>110</td><td>110</td><td>110</td></tr>
</tbody>
</table>
```

**Notable takeaways:**

- No Level 2 control falls into "no available enablers" at any licensing tier, but the controls Microsoft only has secondary services or available enables for, such as personnel screening and off-site equipment sanitization, still fall mostly to you to implement.
- Moving from F3 to G5 shifts 16 controls into primary-service coverage, from 70 to 86. That’s why F3 tends to fit frontline staff who only need email rather than CUI users.
- A higher license moves more controls into Microsoft's primary coverage, but no control is fully met until you configure it, document it in your SSP, and can prove it to a [C3PAO](https://secureframe.com/hub/cmmc/certification-levels) or defend it for a self-assessment.

This is why Wakeman steers most CUI users toward the top tier: "The easy button is going to be G5, because it includes the holistic security stack, including Defender for Endpoint."

**A note on Business Premium.** Microsoft's placemat maps base Business Premium only at CMMC Level 1, so there is no official Level 2 service map for it. Based on its actual service set, base Business Premium primary-covers an estimated 76 of the 110 controls, roughly on par with G3, because it includes the core identity, device, configuration, and email protection services plus Defender for Business (which G3 does not carry).

With the optional [Microsoft Defender and Microsoft Purview add-ons](https://secureframe.com/blog/gcc-high-business-premium), primary service coverage on Business Premium rises to an estimated 85 controls, essentially matching G5. These are approximations rather than exact figures since Microsoft did not publish Level 2 control mapping for [Business Premium](https://secureframe.com/blog/gcc-high-business-premium), but they line up with Wakeman's own estimate: “Business Premium, with the add-ons for Purview and Defender, is at near parity with a G5 at half the cost.”

*As an authorized AOS-G reseller, Secureframe offers competitive pricing on Microsoft 365 GCC High licenses, including Business Premium, G3 and G5. [Browse licenses on our Marketplace](https://secureframe.com/marketplace/microsoft).*

## Recommended reading

GCC High Pricing and Licensing Guide: Per-User Costs Explained [July 1, 2026 Pricing Update]

## How an MSP fits into the Shared Responsibility Matrix (and the risks of over-delegating)

## How an MSP fits into the Shared Responsibility Matrix (and the risks of over-delegating)

Many defense contractors rely on a managed service provider (MSP) to handle their IT environment. MSPs can play a legitimate and valuable role in CMMC compliance, but only if the relationship is structured correctly and documented thoroughly.

Here is what MSPs can legitimately take on:

- Managing the GCC High tenant configuration (Conditional Access, Intune baselines, sensitivity labels)
- Running your SIEM and monitoring security logs on your behalf
- Managing endpoint detection and response tools
- Providing incident triage and first-response support
- Maintaining patching and configuration management for endpoints

Here is what MSPs cannot do:

- **Be CMMC certified on your behalf.** You, the OSC, must achieve certification yourself. It cannot be delegated to or inherited from an MSP.
- **Take accountability for controls the MSP has no visibility into.** Physical security, personnel screening, and training gaps are yours regardless of what the MSP contract says.
- **Testify to a third-party.** When a C3PAO assessor (or prime buyer or internal CMMC lead) asks who reviews your audit logs and how often, your staff must answer with evidence that they understand and participate in the process.

### The documentation requirement when using an MSP

Under CMMC, if an External Service Provider (ESP) handles any part of your control implementation, that relationship must be documented in detail in your SSP. The CMMC final rule allows ESPs to be assessed alongside an OSC, but only if the SSP clearly delineates what the ESP is responsible for versus what the OSC retains.

Vague language like "our MSP handles security" will not satisfy an assessor. For each objective where the MSP is involved, your SSP must specify which task the MSP performs, how you verify it, and what evidence exists that it has been performed.

### The over-delegation risk

One of the most dangerous mistakes is genuinely delegating a control to an MSP with no way to verify or evidence the work. If your SIEM alerts fire and your MSP is responsible for reviewing them but you have no ticketing records, SLA reports, or documented reviews, you have a documentation gap a C3PAO or DIBCAC assessor can find that leaves you vulnerable to legal exposure.

If your MSP says "we handle CMMC" as a blanket offering, ask them to show you the Shared Responsibility Matrix. Ask which of the 110 requirements and 320 assessment objectives they implement, which they share with you, and which are entirely yours. If they cannot answer at that level of specificity, you are at risk.

## How “shared compliance” gets assessed: Self-assessment, C3PAO, or prime flowdown

## How “shared compliance” gets assessed: Self-assessment, C3PAO, or prime flowdown

During the [CMMC Phase 2 pause](https://secureframe.com/blog/cmmc-news-2026-phase-2-pause), many contractors are self-assessing against NIST 800-171 and posting their scores and affirmations in [SPRS](https://secureframe.com/blog/cmmc-sprs) rather than undergoing a Certified Third-Party Assessor Organization (C3PAO) assessment right now. Organizations can still pursue Level 2 (C3PAO) certification proactively, and primes can still require it through contract flowdown.

Whichever path applies to you, the way your controls are evaluated is the same, and the burden of responsibility largely falls on your organization, not your cloud provider or MSP.

Your SSP is the primary document of compliance: a well-structured SSP that accurately reflects your environment (including which controls are inherited from Microsoft and what your MSP handles) and is supported by evidence is the foundation of a defensible result.

A Level 1 or Level 2 assessment, either a self-assessment or C3PAO, uses three methods:

1. **Examine:** the assessor reviews your SSP, policies, procedures, configuration screenshots, logs, training records, and the SRM. They check that the SRM exists, accounts for all 110 requirements and 320 objectives, and matches what you have actually implemented.
2. **Interview:** the assessor talks to your staff and asks things like "walk me through what happens when an employee is terminated." Microsoft and your MSP cannot answer these for you.
3. **Test:** the assessor verifies controls work as described, across inherited, shared, and customer controls. They may try to access a system without MFA, request evidence that DLP policies are active, or ask to see a recent incident log review.

That means:

- If your Conditional Access policies are not configured, you will not fully meet Access Control regardless of license tier.
- If your training records show no documented completion, you will not fully meet Awareness and Training.
- If your incident response plan has never been tested, you will not fully meet Incident Response.

This is also what you are attesting to. Whether the result is a self-assessment score or a C3PAO certification, a senior company official signs an affirmation  in [SPRS](https://secureframe.com/blog/cmmc-sprs) that the assessment result is accurate and that the organization will continue to maintain compliance. That affirmation carries [False Claims Act exposure](https://secureframe.com/blog/false-claims-act), and while settlements are rare, they typically carry hefty fines. A defensible shared-responsibility picture is not just important for a point-in-time assessment. It is important for being able to stand behind what you have posted and affirm every year.

## Recommended reading

CMMC Phase 1 Self-Assessment Guide: Level 1 and Level 2 Requirements

## "We thought we were CMMC compliant": 5 common shared responsibility mistakes

## "We thought we were CMMC compliant": 5 common shared responsibility mistakes

These patterns appear consistently when organizations fail assessments or run their first gap analysis and find gaps they did not expect.

### "We bought GCC High so we're covered."

GCC High provides the environment with some controls in place that fulfill some [CMMC requirements](https://secureframe.com/hub/cmmc/compliance-requirements). But you provide the compliance. Without configuring Conditional Access, enabling MFA enforcement, deploying Intune baselines, writing DLP policies, classifying data with sensitivity labels, and dozens of other configurations, GCC High is a compliant-capable platform that is not operating in a compliant way.

### "Our MSP handles CMMC."

An MSP can implement some technical controls, but cannot own your policies, answer assessment questions about your procedures, own the physical and personnel controls that are entirely yours, or certify you. If your SSP is not specific about what your MSP does and does not do, you have documentation gaps that will surface during assessment.

### "We have MFA so access control is done."

MFA is one requirement within Access Control. The AC family has 22 requirements covering account management, least privilege, session controls, remote access, and privileged-user controls. Passing MFA enrollment does not satisfy the family.

### "We enabled audit logging."

Enabling logging is a prerequisite. The requirements are to review logs, investigate anomalies, protect log integrity, and retain logs appropriately. A log that sits unreviewed is not a functioning control.

### "Our MSP wrote our SSP."

An SSP written by an MSP or consultant is not a guarantee of compliance. If it does not deeply reflect your business, data flows, physical environment, and personnel practices, or if it was built in spreadsheets and is stale by assessment time, or if your team cannot explain it, it will produce findings. Your SSP must accurately describe your current environment, including everything your vendors do not handle, and be clearly understood by your team.

For help identifying gaps before you self-assess or sit for a C3PAO, see our [CMMC gap analysis guide](https://secureframe.com/blog/cmmc-gap-analysis).

## Recommended reading

How to Run a CMMC Level 2 Gap Analysis Before You Submit Your SPRS Self-Assessment and Score

## Building your CMMC Shared Responsibility Matrix

## Building your CMMC Shared Responsibility Matrix

Creating an SRM is not optional for organizations using cloud services in their CMMC boundary. The assessment guidance requires that for each objective, it is clear who is responsible: you, your cloud provider, or your MSP.

1. **Download or request Microsoft's CRM.** Access the Customer Responsibility Matrix for GCC High through the Service Trust Portal (with an active deployment) or request it by email. It maps each NIST SP 800-171 requirement and objective to Microsoft, Customer, or Shared. Start here.
2. **Map your MSP's scope.** For each control the MSP implements, document the specific task, how you monitor performance, and what evidence they provide. This feeds directly into your SSP.
3. **Identify the gaps.** Controls neither inherited from Microsoft nor covered by your MSP are yours to implement, and are your remediation priorities. Many organizations discover here that training, incident response, risk assessment, and security assessment programs do not exist in any formal way.
4. **Document in your SSP.** For each requirement and objective, identify the responsible party, describe the implementation, and reference the evidence. Reference the Microsoft CRM and FedRAMP authorization for inherited controls, your MSP's contribution for MSP-managed controls, and your internal program for customer-only controls.
5. **Keep it current.** The SRM is a living document. When your CSP or MSP changes offerings, or when you move workloads in or out of scope, update it. An assessor will verify it reflects current reality and will know if it is stale.

## Simplify CMMC shared responsibility with Secureframe Defense

## Simplify CMMC shared responsibility with Secureframe Defense

CMMC compliance does not happen by buying the right cloud license or security tool. It is built control by control by your organization and your cloud service provider (and MSP, if you use one).

[Secureframe Defense](https://secureframe.com/blog/announcing-secureframe-defense-for-cmmc) provisions a CMMC-compliant GCC High environment for you and enforces the required NIST 800-171 configurations and automatically pulls that configuration evidence over time. It also shows exactly which controls are met, which still need configuration, and which require operational work like policies. Your shared responsibility matrix is built into the platform so you always know who owns what.

Learn more about Secureframe Defense for CMMC by [visiting our website](https://secureframe.com/cmmc) or [talking to an expert](https://secureframe.com/request-cmmc-demo). For ongoing CMMC news and analysis, our editorial hub is at [cmmc.com](https://cmmc.com).

*This post was originally published in April 2026 and has been updated for accuracy and comprehensiveness.*

## Purchase Microsoft 365 GCC High licenses through Secureframe

As an authorized AOS-G reseller, Secureframe offers competitive pricing on Microsoft 365 GCC High licenses, including Business Premium, G3 and G5.

### Does GCC High automatically make me CMMC compliant?

No. GCC High is a FedRAMP High authorized platform that supports meeting NIST 800-171 requirements. But the platform must be configured for your organization, your SSP, POA&M, and policies must be written and maintained, and your staff must be trained. None of this happens automatically when you buy a license.

### How many of the 110 NIST 800-171 controls does Microsoft cover?

In a GCC High deployment, Microsoft is responsible for 52 of the 110 requirements at the platform level, so roughly half are met by inherited controls. The rest are shared: the technical capability exists in Microsoft, but your organization must configure it. At the high-level requirement level, none are now entirely the customer's responsibility. However, CMMC requires all 110 requirements and 320 assessment objectives to be fully met, so the customer's real scope is much larger at the objective level.

### Does more expensive licensing mean Microsoft covers more of CMMC for me?

Partly. A higher license moves more controls into Microsoft's primary-service coverage: a G5 license has a primary Microsoft service for about 86 of the 110 controls, versus 77 for G3 and 70 for F3. But responsibility does not change with license; those controls are still yours to configure, document, and prove. See our GCC High pricing and licensing guide for the tier-by-tier breakdown.

### Does my MSP need its own CMMC certification?

If your MSP processes, stores, or transmits CUI as part of service delivery, they may need to meet CMMC requirements. The final rule allows an MSP acting as an ESP to be assessed alongside the OSC. If your MSP makes blanket compliance claims without being assessed or certified, that is a risk to understand before your own assessment.

### What is the difference between a Shared Responsibility Matrix and a Customer Responsibility Matrix?

The terms are sometimes used interchangeably, but technically a Customer Responsibility Matrix (CRM) is a contract-specific document from a cloud provider (like Microsoft) mapping which requirements and objectives the provider, customer, and shared parties own. A Shared Responsibility Matrix (SRM) is typically a higher-level document created by the organization that incorporates the vendor CRM along with how responsibilities split with an MSP, giving a complete picture across all requirements and objectives.

### Can I delegate all of my CMMC compliance to my MSP or a consultant?

You can delegate some control implementation and maintenance, but not accountability. As the OSC, you are ultimately responsible for demonstrating that controls are in place, operating effectively, and fully meeting all applicable requirements and objectives, regardless of who implements them. If your MSP implements a control incorrectly, or you lack evidence, the finding belongs to your assessment.

### What happens if my SSP doesn't accurately reflect who is responsible for each control?

Examiners will identify discrepancies between what your SSP says and what they observe in your environment or hear in interviews. Discrepancies become findings, which can result in a failed assessment, required remediation, or a conditional certification with a corrective action plan. Accurate documentation from the start is far easier than explaining discrepancies under assessment pressure.

### Are there any CMMC customer controls I’m entirely responsible for in GCC High?

No. In the earlier 2024 version of Microsoft Product Placemat for CMMC 2.0 (Preview), which is still the only version available on its site, one requirement (CM.L2-3.4.8 on application allowlisting) was categorized as fully customer-owned. However, the 2025 update reclassifies it as shared, since Microsoft capabilities like App Control now provide a partial enabler you can configure to help partially meet the requirement.
