{"id":126008,"date":"2024-09-23T15:38:00","date_gmt":"2024-09-23T22:38:00","guid":{"rendered":""},"modified":"2026-08-20T14:22:28","modified_gmt":"2026-08-20T21:22:28","slug":"understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update","status":"publish","type":"ms-industry","link":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2024\/09\/23\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\/","title":{"rendered":"Understanding Compliance Between Commercial, Government, DoD &amp; Secret Offerings &#8211; May 2026 Update"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">This article is the second of a series in the <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/Public-Sector-Blog\/bg-p\/PublicSectorBlog\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Tech Community Public Sector Blog<\/a> and touches on several key principles for compliance, including data residency versus data sovereignty.  For the first article in the series, please refer to <a href=\"https:\/\/aka.ms\/USSovereignCloud\" target=\"_blank\" rel=\"noopener noreferrer\">History of Microsoft Cloud Service Offerings leading to the US Sovereign Cloud for Government<\/a>.  To keep this article concise, I will refrain from repeating content from the first. I recommend that you review the first article if you are unfamiliar with the architectural relationships between Azure, Microsoft 365 and Dynamics 365.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this article, we will focus on each of the US-based cloud offerings from Microsoft and compare the differences in compliance, including the compendium of common factors customers may use to decide which of our offerings align with current and future requirements in demonstrating compliance with US Government regulations and underlying cybersecurity frameworks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em><strong>July 2025 Update &#8211; Access this article with the short URL <a href=\"https:\/\/aka.ms\/MSGovCompliance\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/aka.ms\/MSGovCompliance<\/a> <\/strong><\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"microsoft-365-commercial-azure-commercial\">Microsoft 365 Commercial + Azure Commercial<\/h2>\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/M365-Vs-Azure.webp\" alt=\"\" class=\"wp-image-125973 webp-format\" srcset=\"\" data-orig-src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/M365-Vs-Azure.webp\"><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"fedramp-in-azure\">FedRAMP in Azure<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Federal Risk and Authorization Management Program (FedRAMP) is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. FedRAMP enables government agencies to accelerate the adoption of cloud services with confidence, knowing they meet high security standards and comply with federal regulations. FedRAMP authorization is a rigorous and comprehensive process that involves extensive documentation, testing, and auditing by independent third-party assessors (3PAO). FedRAMP authorization demonstrates Microsoft\u2019s commitment to delivering cloud services that meet the most stringent security and compliance requirements of the US Government.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can demonstrate compliance with the FedRAMP High Impact Level in both Azure Commercial and Azure Government.  Azure Commercial and Azure Government each have a Provisional Authorization to Operate (P-ATO\/PA) from the FedRAMP Program Management Office (PMO). The PMO is the primary governance and decision-making body for FedRAMP. Representatives from the Department of Defense, the Department of Homeland Security, and the General Services Administration serve on the PMO board. The PMO grants a P-ATO to Cloud Service Providers (CSP) that have demonstrated FedRAMP compliance and may chose not to pursue an Agency ATO as they are not mutually exclusive.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can find a full list of Azure services that meet the requirements of FedRAMP High in the <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/azure-government\/compliance\/azure-services-in-fedramp-auditscope\" target=\"_blank\" rel=\"noopener noreferrer\">Azure compliance scope documentation<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For more information, please reference:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/aka.ms\/fedramp\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft FedRAMP Documentation (https:\/\/aka.ms\/fedramp)<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\">FedRAMP Package F1209051525:  <a href=\"https:\/\/marketplace.fedramp.gov\/products\/F1209051525\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Azure Commercial Cloud | FedRAMP Marketplace<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\">FedRAMP Package F1603087869:  <a href=\"https:\/\/marketplace.fedramp.gov\/products\/F1603087869\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Azure Government (includes Dynamics 365) | FedRAMP Marketplace<\/a><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"fedramp-in-microsoft-365\">FedRAMP in Microsoft 365<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Cloud services bundled together in Microsoft 365 are split into two separate sets of authorizations, Microsoft 365 and Azure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Microsoft 365 productivity services include:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Aesir<\/td><td>Microsoft 365 Suite User Experience (SUE)<\/td><td><strong>OneDrive SharePoint (ODSP)<\/strong><\/td><\/tr><tr><td>Cloud Input Intelligence (CII)<\/td><td><strong>Microsoft Purview<\/strong><\/td><td>Profile Data Roaming Service (PDRS)<\/td><\/tr><tr><td>Containers on Substrate-Managed Intelligent Clusters (COSMIC)<\/td><td><strong>Microsoft Teams (MSTeams)<\/strong><\/td><td>Search Content Service (SCS)<\/td><\/tr><tr><td>Customer Insight and Analysis (CIA)<\/td><td>ObjectStore<\/td><td>Substrate Intelligence Platform (SIP)<\/td><\/tr><tr><td><strong>Exchange Online (EXO)<\/strong><\/td><td>Office Intelligent Services (IS)<\/td><td>Terminal Service Gateway (TSG)<\/td><\/tr><tr><td>Falcon<\/td><td>Office Service Infrastructure (OSI)<\/td><td>Torus<\/td><\/tr><tr><td>IDEAs Personalization Service \u2013 RunTime (IPS-RT)<\/td><td><strong>Office for Web<\/strong><\/td><td><strong>Windows 365 (W365)<\/strong><\/td><\/tr><tr><td><strong>Microsoft 365 Copilot<\/strong><\/td><td><\/td><td><strong><em>More detail\u2026 <\/em><\/strong><a href=\"https:\/\/marketplace.fedramp.gov\/products\/MSO365MT\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">M365 Other Service(s)<\/a><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>All other services<\/em><\/strong> fall under Azure including (<em>but not limited to<\/em>) :<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Entra ID (Azure Active Directory)<\/td><td>Microsoft Cloud App Security<\/td><td>Azure Multi-factor Authentication (MFA)<\/td><\/tr><tr><td>Azure Information Protection<\/td><td>Microsoft Defender Advanced Threat Protection (MDATP)<\/td><td>Microsoft Stream<\/td><\/tr><tr><td>Azure Key Vault<\/td><td>Microsoft 365 Defender<\/td><td>Microsoft Defender Vulnerability Management<\/td><\/tr><tr><td>Azure Sentinel<\/td><td>Microsoft PowerApps<\/td><td>Microsoft Purview<\/td><\/tr><tr><td>Intune<\/td><td>Microsoft Stream<\/td><td>Microsoft Secure Score<\/td><\/tr><tr><td>Microsoft 365 Defender<\/td><td>Power BI<\/td><td><strong><em>Many more\u2026 <\/em><\/strong><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/azure-government\/compliance\/azure-services-in-fedramp-auditscope\" target=\"_blank\" rel=\"noopener noreferrer\">Azure compliance scope<\/a><\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">For the cloud services listed as in scope for Azure Commercial, we have the FedRAMP P-ATO as described in the previous section.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For the productivity services listed as in scope for Microsoft 365 Commercial, Microsoft does not support FedRAMP.  For those that have read previous versions of this blog, you may find it as a surprise that Microsoft 365 in Commercial has changed from FedRAMP High \u2018<em>Equivalent<\/em>\u2019 to \u2018<em>No<\/em>\u2019.  This changed as a result of the release of the U.S. Department of Defense memorandum for \u2018<a href=\"https:\/\/dodcio.defense.gov\/Portals\/0\/Documents\/Library\/FEDRAMP-EquivalencyCloudServiceProviders.pdf\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">FedRAMP Moderate Equivalency for Cloud Service Provider\u2019s Cloud Service Offerings<\/a>\u2019 dated December 21, 2023.  The memo outlines requirements to achieve \u2018<em>Equivalency<\/em>\u2019 including a Body of Evidence (BOE) that is not in scope for Microsoft 365 Commercial data enclaves other than for Microsoft 365 Government (GCC).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>For more information, please see the section below<\/em> <a href=\"#fedramp-in-gcc\">FedRAMP in GCC<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The FedRAMP Marketplace for \u2018<a href=\"https:\/\/marketplace.fedramp.gov\/products\/MSO365MT\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Microsoft 365 Government Community Cloud &amp; Supporting Services<\/a>\u2019 only applies to GCC and no other data enclaves of Microsoft 365 Commercial.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The accreditation package for \u2018<a href=\"https:\/\/marketplace.fedramp.gov\/products\/MSO365MT\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Microsoft 365 Government Community Cloud &amp; Supporting Services<\/a>\u2018 defines the scope of accreditation as covering the cloud services management plane and a dedicated portion of the data plane. This often confuses customers as the whole of the Commercial service is not within the accreditation boundary; only the data enclave for GCC as defined to support the accreditation package.  Any customer deciding to use the Microsoft 365 Commercial service to demonstrate FedRAMP compliance or equivalency will struggle to achieve this due to how the accreditation scope is defined.  In other words, the accreditation package and associated Body of Evidence (BOE) only includes the scope of accreditation for GCC.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You may wonder why the scope is different?  Take access controls as an example.  While the same access controls may be applied to any Commercial service data enclave (<em>the whole of the data plane<\/em>); they are applied with different Organizationally Defined Values (ODV).  Both Commercial and GCC data enclaves require personnel screening validations that are tied to access control requirements:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Commercial screening does not require US Citizenship and other US Government related requirements necessary to support the management of US government regulated data (e.g. Controlled Unclassified Information).<\/li>\n\n\n\n<li class=\"wp-block-list-item\">GCC screening does include these requirements and validates their existence prior to any access control action.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Such differences make the Commercial service untenable for Microsoft 365 to support FedRAMP holistically in the Commercial service.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>For context of what a \u2018data enclave\u2019 is, please refer to the <\/em><a href=\"https:\/\/aka.ms\/USSovereignCloud\" target=\"_blank\" rel=\"noopener noreferrer\"><em>History of Microsoft Cloud Service Offerings leading to the US Sovereign Cloud for Government<\/em><\/a><em>.<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"a-word-about-fedramp-in-commercial-and-how-it-relates-to-cui\">A word about FedRAMP in Commercial and how it relates to CUI<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A common misconception by many is regarding FedRAMP as \u2018the\u2019 requirement to protect <a href=\"https:\/\/www.archives.gov\/cui\/registry\/category-list\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Controlled Unclassified Information<\/a> (CUI) in a cloud service offering.  It is important to note that FedRAMP is just one component of overall compliance relative to CUI in a shared responsibility model.  For example, the CUI-Specified category for \u2018Export Controlled\u2019 (CUI\/\/EXPT) such as for data regulated by the International Traffic in Arms Regulation (ITAR) imposes an additional set of \u2018Specified\u2019 standards from the US Department of State that requires data sovereignty (e.g. US persons in US locations). Export-Controlled data such as ITAR technical data is one of the components of overall compliance to holistically safeguard CUI.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I often get pulled into customer conversations on suitability for CUI in the Microsoft 365 Commercial cloud.  While a very nuanced conversation (especially working with sub-contractors and supplier hosted in Commercial), Microsoft does not recommend it.  Why? We did not create Microsoft 365 Commercial to support the management of CUI.  Thus, in the table above for Microsoft 365, you can observe that CUI is presented as \u2018No\u2019.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The way I frame this out for customers is this: your higher watermark for compliance to gain coverage of CUI is in alignment with other controls above and beyond FedRAMP.  If you are affiliated with law enforcement and the criminal justice system, you will likely require CJIS adjudication from the FBI or from the US State you are in.  If you are affiliated with the Internal Revenue Service or Department of Revenue, you will likely require IRS 1075 for coverage of Federal Tax Information.  If you are affiliated with US Defense or Military, you will likely require export controls that include the ITAR and Export Administration Regulations (EAR).  Each one of these require screened US Persons and data residency\/sovereignty in the Continental United States (CONUS).  These are what will direct you to our Government cloud offerings and diminish Microsoft 365 Commercial as an option.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Note:<\/em> There is an entire article for <a href=\"https:\/\/aka.ms\/CUISovereignty\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft US Sovereign Cloud Myth Busters &#8211; CUI Effectively Requires Data Sovereignty<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"new-feature-releases-in-commercial\">New Feature Releases in Commercial<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Here is another aspect of Commercial to keep in mind.  The release of new features and services into Commercial clouds is not predicated on FedRAMP compliance the same way it is for release into Government clouds.  For example, a new feature can release to Commercial cloud tenants before it has FedRAMP compliance.  However, the new feature will not be released as Generally Available (GA) in Government cloud tenants until it complies with FedRAMP.  In my opinion, this is another compelling data point for our customers trying to decide on \u2018Commercial vs Government\u2019, as there is a risk of users organically adopting new features in your tenant before the features are authorized for FedRAMP.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Note: First-party products and features developed by Microsoft follow the NIST SP 800-53 control framework out of the starting gate, accelerating the path to FedRAMP authorization and reducing the risk of using such features before authorization.  However, this may not hold true for all products we ingest through 3rd-party acquisitions and partnerships that could require a much heavier lift to achieve the same levels of compliance.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft\u2019s <a href=\"https:\/\/cm-edgetun.pages.dev\/en-us\/security\/blog\/2024\/05\/03\/security-above-all-else-expanding-microsofts-secure-future-initiative\/?msockid=2569ceaba7e36ffd083cdacea65d6e45\" target=\"_blank\" rel=\"noopener noreferrer\">Secure Future Initiative (SFI)<\/a> makes security our top priority at Microsoft, above all else\u2014over all other features.  We have evolved our security approach, with our work guided by the following three security principles:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Secure by Design<\/strong>: Security comes first when designing any product or service.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Secure by Default<\/strong>: Security protections are enabled and enforced by default, require no extra effort, and are not optional.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Secure Operations<\/strong>: Security controls and monitoring will continuously be improved to meet current and future threats.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">I invite you to read Charlie Bell\u2019s blog on <a href=\"https:\/\/cm-edgetun.pages.dev\/en-us\/security\/blog\/2024\/05\/03\/security-above-all-else-expanding-microsofts-secure-future-initiative\/?msockid=2569ceaba7e36ffd083cdacea65d6e45\" target=\"_blank\" rel=\"noopener noreferrer\">Secure Future Initiative (SFI)<\/a>, as it has been driving security that is helpful for compliance as well.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"dfars-7012-and-nist-sp-800-171-in-microsoft-365-commercial\">DFARs 7012 and NIST SP 800-171 in Microsoft 365 Commercial<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This is for the Defense Industrial Base (DIB) including Aerospace and Defense (A&amp;D) contractors of the US Department of Defense (DoD).  It also applies to Federally Funded Research and Development Centers (FFRDCs), University Affiliated Research Centers (UARCs), energy and healthcare organizations.  To substantially contract with the DoD, you will likely need to demonstrate compliance with the Defense Federal Acquisition Regulation <a href=\"https:\/\/www.acquisition.gov\/dfars\/252.204-7012-safeguarding-covered-defense-information-and-cyber-incident-reporting.\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">supplement 252.204-7012<\/a> (DFARs 7012).  If you have the requirement, your contracts will have a DFARs 7012 Clause, or you will be notified of a \u2018<em>flow-down<\/em>\u2019 in sub-contracts to you.  DFARs 7012 mandates the protection of CUI and Covered Defense Information (CDI) with an implementation of NIST SP 800-171, and FedRAMP Moderate \u2018<em>or Equivalent<\/em>\u2019 Impact Level for clouds used to store, process, or transmit CUI.  It is a set of controls that are used to secure Non-Federal Information Systems (<em>predominately in the private sector<\/em>).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Due to not supporting FedRAMP in Microsoft 365 Commercial, you will observe a \u2018No\u2019 for DFARs 7012. <\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"dfars-7012-in-azure-commercial\">DFARs 7012 in Azure Commercial<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">As mentioned in the previous section, Microsoft 365 Commercial has a \u2018<em>No<\/em>\u2019 for DFARs 7012.  However, Azure Commercial can demonstrate support for DFARS clause 252.204-7012.  We have an auditor\u2019s attestation letter summarizing how DFARS 7012 is supported for Azure services.  This translates to a commitment where we demonstrate DFARs 7012 compliance in Azure Commercial.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Note: For more details on how we implement DFARs 7012 in Azure, please see <\/em><a href=\"https:\/\/aka.ms\/DFARsAzure\" target=\"_blank\" rel=\"noopener noreferrer\"><em>https:\/\/aka.ms\/DFARsAzure<\/em><\/a><em>.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The coverage of DFARs 7012 in Azure Commercial offers you more choice in the selection of Microsoft cloud offerings that best suit your requirements for the protection of CUI. For example, those organizations that choose Microsoft 365 Government (GCC) deployed on top of Azure Commercial cloud regions in the US may now have paired Azure services that meet DFARs 7012 requirements.  While we do not offer this same commitment for Microsoft 365 Commercial, we do offer DFARs 7012 compliance in Microsoft 365 Government (GCC) that operates in conjunction with Azure Commercial.  See below for more details in the GCC section.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"commercial-will-not-always-recognize-us-government-requirements\">Commercial will not always recognize US Government requirements<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">As I mentioned, there are guidance, operational and support differences between the services provided for Azure Commercial and Microsoft 365 Commercial, as opposed to those purpose built for the US Government.  There is no way to identify a government tenant within the Commercial service.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unfortunately, there is a painful learning curve when a customer discovers this post sale\/deployment while in the middle of an incident. I have been on calls assisting such customers that were routed through our global support staff and were frustrated that \u2018Microsoft\u2019 did not understand that they had US Government requirements and should not have been routed to offshore support personnel in Asia. That is how the global Commercial service works.  If you have requirements for screened US persons in US locations, there are Microsoft purpose-built cloud offerings exclusively for supporting US Government obligations that are more suitable to sovereignty requirements.  <em>See below in the GCC High + Azure Government section on support commitments for US persons.<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"regulation-changes-impact-to-commercial-versus-government\">Regulation Changes Impact to Commercial versus Government<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Recent updates to FedRAMP \u201c<em>Equivalency<\/em>\u201d requirements highlight the ongoing evolution of U.S. government standards and regulations. Industry has an obligation to mature cloud service offerings and consumption practices to match and even exceed these security and compliance requirements set forth by the US government (<em>and preferably as proactively as possible to reduce undue churn and reactive burdens<\/em>). While Microsoft strives to align all our cloud service offerings to the same set of security controls and practices as reasonably practical, Commercial services achieving government certifications like FedRAMP <strong>should not be presumed unless specifically stated<\/strong>. It&#8217;s crucial for customers to stay informed about these changes to avoid non-compliance risks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"fci-in-microsoft-365-commercial\">FCI in Microsoft 365 Commercial<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In general, all US Government contractors have a requirement in their contracts to comply with 15 safeguarding requirements and procedures for Federal Contract Information (FCI) in the Federal Acquisition Regulations (FAR) <a href=\"https:\/\/www.acquisition.gov\/far\/52.204-21-0\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">52.204-21 Basic Safeguarding of Covered Contractor Information Systems<\/a> (FAR 21). You may demonstrate compliance for the FAR 21 in Commercial to protect FCI, but there is a caveat.  Microsoft 365 Commercial is not intended for US Government requirements.  There is a risk that changes in regulations may lead to non-compliance in the future.  Ultimately, it is a risk decision your organization will need to make.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"cybersecurity-maturity-model-certification-cmmc\">Cybersecurity Maturity Model Certification (CMMC)<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">One of the most common questions I get is, \u201c<em>What cloud offerings meet the requirements for CMMC<\/em>\u201d?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cybersecurity frameworks are applied to all Microsoft cloud offerings consistently across the spectrum of services. Cybersecurity &#8216;<em>maturity<\/em>&#8216; is often represented as the efficacy of process and automation of practices. There are specific control requirements and ODVs that are unique to each cloud offering. For example, sovereign clouds such as Microsoft 365 Government (GCC High) and Azure Government have controls in place for restricting sensitive data access to only screened US persons with data processing, transmission and storage only within CONUS. Sovereign clouds are more restricted in terms of the specificity of control requirements in relation to other cloud environments.  Even though control requirements may vary from one cloud environment to another, each may demonstrate a level of cybersecurity maturity in alignment with CMMC.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In other words, you may demonstrate compliance with CMMC in the Commercial cloud depending on what level you are pursuing.   CMMC by itself should not be the only decision factor on choosing which cloud offering is most appropriate.  For example, CMMC 2.0 Level 2 and higher is intended for protection of CUI.  I have captured details regarding CUI throughout this article to help you make a more informed decision.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To net it out, Microsoft recommends the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">You may demonstrate compliance with CMMC 2.0 Level 1 for the data protection of FCI in Commercial and in our Government clouds. However, there is a caveat mentioned above that Microsoft 365 Commercial is not intended for US Government requirements.  The safer long-term risk posture is to use our Government cloud service offerings.<\/li>\n\n\n\n<li class=\"wp-block-list-item\">We recommend the US Sovereign Cloud with Azure Government and Microsoft 365 Government (GCC High) for data protection of CUI in alignment with CMMC 2.0 Levels 2-3.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">We understand you may have a different risk appetite and choose a different basis for your cybersecurity program. We do have customers that chose GCC (<em>versus GCC High<\/em>), in cases where they have CUI-Basic that does not require explicit commitments to protect CUI-Specified and ITAR\/EAR export-controlled data.  Others have added additional compensating controls, such as FIPS 140-2 validated end-to-end encryption to protect export-controlled data. However, many in the DIB (<em>especially the larger tier 1 prime contractors<\/em>) have chosen the US Sovereign cloud due to the comprehensive data protection offered holistically across all categories of CUI.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Ultimately, this is a risk decision made by the customer in meeting their current and future requirements. <\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is important to note that while cost and risk are prime decision criteria for our customers, many also consider future changes to their business strategy and scope of competition. Our Government cloud offerings are segregated environments where it is neither a short nor inexpensive customer project to migrate from one to another. If opportunities arise in the future to pursue business requiring a higher watermark for compliance, or a potential increase of work in other regions or industries, you may promote such criteria to assess in a decision of which cloud to choose.  There are many criteria to assess in such a decision, but we have attempted to portray the keys ones in context of this article.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"microsoft-365-government-gcc\">Microsoft 365 Government (GCC)<\/h2>\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/M365.webp\" alt=\"\" class=\"wp-image-125972 webp-format\" srcset=\"\" data-orig-src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/M365.webp\"><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"scope-of-services-in-gcc\">Scope of Services in GCC<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Microsoft 365 Government (GCC) cloud offering is a data enclave of Commercial.  A data enclave in this context is a segregated environment, with infrastructure residing in Azure regions.  In the case of GCC, the data enclave is in CONUS and paired with Azure Commercial US regions.  There is a commitment to ensure data residency and data processing is in CONUS for the primary Office workloads.  In addition, only screened US persons in US locations are authorized for customer content access.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>The service description for all Microsoft 365 Government offerings may be found at <\/em><\/strong><em><a href=\"https:\/\/aka.ms\/o365usgovservicedescription\" target=\"_blank\" rel=\"noopener noreferrer\">http:\/\/aka.ms\/o365usgovservicedescription<\/a><\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At the time of this writing, the service availability for GCC covered workloads are:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Exchange Online &amp; Exchange Online Protection<\/li>\n\n\n\n<li class=\"wp-block-list-item\">SharePoint Online &amp; OneDrive for Business Online<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Teams &amp; Voice (Phone System &amp; Audio Conferencing)<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Office for the web<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Microsoft Defender<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Power BI Pro<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Project Online<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><em>and more as documented in the <\/em><a href=\"https:\/\/learn.microsoft.com\/en-us\/office365\/servicedescriptions\/office-365-platform-service-description\/office-365-us-government\/office-365-us-government#service-availability-for-each-plan\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Service availability for each plan<\/em><\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Given GCC is a data enclave of Commercial, there are several shared services.  These shared services may have data processing globally Outside the Continental United States (OCONUS) and leverage a global follow-the-sun support model.  Most notably, this includes a global network and a global directory.  For example, Entra ID (formerly Azure Active Directory) in Azure Commercial is shared with GCC.  Entra ID is supported globally and may have data processing (authentication) occur OCONUS along with service management by global support personnel. This is one of the reasons Microsoft will not commit to export controls in GCC.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>As a result, you will observe a \u2018No\u2019 in the column for ITAR &amp; EAR for GCC along with a caveat for CMMC Levels 2-3.<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"customer-support-for-gcc-and-azure-commercial\">Customer Support for GCC and Azure Commercial<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft 365 Government (GCC) customer support is provided under the same <a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/admin\/m365-feature-descriptions?view=o365-worldwide&amp;tabs=Support\" target=\"_blank\" rel=\"noopener noreferrer\">terms and conditions<\/a> offered to Microsoft 365 Commercial, without assurances for agent physical location nor citizenship.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>The latest version of the Customer Support Terms and Conditions for GCC (referencing the above statement) can be found <\/em><a href=\"https:\/\/docs.microsoft.com\/en-us\/office365\/servicedescriptions\/office-365-platform-service-description\/office-365-us-government\/gcc#office-365-government-gcc-customer-support\" target=\"_blank\" rel=\"noopener noreferrer\"><em>here<\/em><\/a><em>.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">GCC operates in conjunction with Azure Commercial, which is supported with a global follow-the-sun support model as well.  For products and services that fall under Azure Commercial, such as IaaS and PaaS deployments in the same tenant as GCC, the Azure <a href=\"https:\/\/aka.ms\/ost\" target=\"_blank\" rel=\"noopener noreferrer\">Product Terms<\/a> outlines coverage for customer support.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Many people are confused by this.  After all, I mentioned above that GCC restricts access to restricted customer content to authorized screened US Persons only.  This is true of datacenter personnel who request temporary permission elevation under management oversight, granting access to customer content only when necessary.  While datacenter personnel are limited in their access to restricted customer content, customer support personnel have no direct standing access to the datacenter nor to customer content.  They can only be exposed to sensitive information when it is provided directly by the customer during a customer support ticket.  We remind you not to share any controlled, sensitive, or confidential information with support personnel as part of your support incident, and follow your own internal data sharing controls, policies and procedures when engaging with Microsoft customer support.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Note:  <\/em><a href=\"https:\/\/aka.ms\/CustomerLockbox\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Microsoft Purview Customer Lockbox<\/em><\/a><em> is a popular feature to moderate access to your data.   We even have <\/em><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security\/fundamentals\/customer-lockbox-overview\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Customer Lockbox for Azure<\/em><\/a><em> releasing to more and more Azure services<\/em><em>.<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"dfars-7012-in-gcc\">DFARs 7012 in GCC<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">As mentioned in the section for DFARS 7012 in Commercial, this applies to the DIB, FFRDCs, UARCs, etc. working with the DoD.  Ultimately, NIST SP 800-171 is holistically derived from NIST SP 800-53.  Think of it as a subset of the controls that apply Non-Federal Information Systems.  Given Microsoft uniformly implements NIST SP 800-53, in accordance with Appendix C of 800-171, we have coverage for NIST SP 800-171 controls in GCC.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In addition to NIST SP 800-171, GCC and its pairing with Azure Commercial can demonstrate support for DFARS clause 252.204-7012 sub-paragraphs (c)-(g).  We have an auditor\u2019s attestation letter that shows on two pages summarizing how those sub-paragraphs are supported.  Microsoft will support a flow-down for DFARs 7012 in GCC.  This translates to a commitment where we demonstrate DFARs 7012 compliance in GCC.  As a result of the flow-downs commitment, you will observe a \u2018Yes\u2019 in the GCC column for DFARs 7012.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Note: For more details on how we implement DFARs 7012 in GCC, please see <\/em><a href=\"https:\/\/aka.ms\/DFARsGCC\" target=\"_blank\" rel=\"noopener noreferrer\"><em>https:\/\/aka.ms\/DFARsGCC<\/em><\/a><em>.<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"controlled-unclassified-information-is-a-maybe-in-gcc\">Controlled Unclassified Information is a Maybe in GCC<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The NIST SP 800-60 Volume 2 registry is rather large.  There are many <a href=\"https:\/\/www.archives.gov\/cui\/registry\/category-marking-list\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">CUI categories<\/a>, to include multiple information types.  The question is, which CUI category is in scope?  This is especially true for the <a href=\"https:\/\/www.dodcui.mil\/CUI-Registry-New\/\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">DoD CUI Program Registry<\/a>. Several categories may not require data sovereignty, such as Privacy, Legal, etc. Is it permissible to rely on data residency in GCC?  Maybe.  However, many of the CUI-Specified categories to include Defense, Export Controlled, Nuclear, etc. undoubtedly require the US Sovereign cloud and are not appropriate for storage within GCC.  Ultimately, customers are responsible for ensuring they review the relevant regulations and Microsoft&#8217;s offering prior to determining which Microsoft Government cloud service offering is the best fit to support their obligations for CUI.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>As not all CUI-Specified can be supported, you will observe a caveated \u2018Yes\u2019 in the GCC column for CUI.<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"cmmc-in-gcc\">CMMC in GCC<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You may demonstrate compliance with CMMC 2.0 Level 1 in GCC for protection of FCI.  You may also demonstrate compliance with CMMC 2.0 Levels 2-3 with notable caveats.  The intent of CMMC 2.0 Levels 2+ is to safeguard CUI.  As mentioned in the previous section, GCC is not permissible for all categories of CUI.  Most notably, GCC does not support export-controlled data, such as ITAR and EAR natively.  As such, we recommend the US Sovereign Cloud with Microsoft 365 Government (GCC High) and Azure Government for CMMC Levels 2-3 to <em>holistically<\/em> safeguard <em>all<\/em> categories of CUI.  <em>Please see the CMMC section above in Commercial for more rationale.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>You will observe a \u2018Yes\u2019 in the GCC column for CMMC L1.  However, as not all CUI-Specified can be supported, you will observe a caveated \u2018Yes\u2019 in the GCC column for CMMC L2-3.<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"fedramp-in-gcc\">FedRAMP in GCC<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For the productivity services listed as in scope for Microsoft 365, you can demonstrate compliance with the FedRAMP High Impact Level in the GCC data enclave.  At the time of this writing, we successfully completed multiple FedRAMP High Impact Level audits, including a Security Assessment Reports (SAR).  This is sufficient for us advertising FedRAMP High \u2018<em>Equivalency\u2019<\/em>, as it completes Microsoft\u2019s scope of responsibility towards FedRAMP accreditation for a Federal Agency ATO. In other words, we support accreditation with Federal agencies at the FedRAMP High Impact Level.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft validates the controls for Microsoft 365 into FedRAMP holistically because we operate all instances of Microsoft 365 employing a consistent control framework and uniform implementations of controls based on the US National Institute for Standards and Technology (NIST) Special Publication (SP) 800-53, Revision 5 (<a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/53\/r5\/upd1\/final\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">NIST SP 800-53<\/a> &#8211; <em>a requirement of FedRAMP<\/em>).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The FedRAMP Marketplace for \u2018<a href=\"https:\/\/marketplace.fedramp.gov\/products\/MSO365MT\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Microsoft 365 Government Community Cloud &amp; Supporting Services<\/a>\u2019 lists our package with Agency ATOs from over 30 different Federal Government Agencies for FedRAMP Moderate Impact Level.  In brief, this means the FedRAMP PMO has completed its review of one or more Agency ATOs. It also indicates the FedRAMP PMO is satisfied that Microsoft meets the FedRAMP requirements and had earned a listing on the Marketplace as \u2018<em>Authorized<\/em>\u2019. With the Agency ATOs in place, the FedRAMP PMO will not complete a P-ATO for Microsoft 365 as that would be redundant to Agencies\u2019 work and is not mutually exclusive.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Together, the P-ATOs for Azure Commercial along with the Agency ATOs for Microsoft 365 (GCC) provide holistic coverage for FedRAMP authorizations covering the Microsoft 365 Government (GCC) suite of cloud services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For more information, please reference:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/aka.ms\/fedramp\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft FedRAMP Documentation (https:\/\/aka.ms\/fedramp)<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\">FedRAMP Package MSO365MT:  <a href=\"https:\/\/marketplace.fedramp.gov\/products\/MSO365MT\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Microsoft 365 Government Community Cloud &amp; Supporting Services | FedRAMP Marketplace<\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>July 2025 Note:<\/em><\/strong>  We have updated the name of the MSO365MT package to reflect alignment specifically with GCC.  The new name \u201c<strong>Microsoft 365 Government Community Cloud &amp; Supporting Services<\/strong>\u201d replaces \u201c<em>Office 365 Multi-Tenant &amp; Supporting Services<\/em>\u201d. The intent of the update from \u201cOffice 365\u201d to \u201cMicrosoft 365\u201d is to align the name on the FedRAMP Marketplace with the branding used in the M365 sales process. The service boundary, control scope, and included applications as defined in the FedRAMP package have not changed. Nor is there a change to the underlying infrastructure and inventory.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">To be covered by the GCC FedRAMP authorization, customers must purchase a GCC SKU.<\/li>\n\n\n\n<li class=\"wp-block-list-item\">To determine what M365 products you are using, you can reference your contract documentation or visit the Admin Center for your M365 tenant and check Settings &gt; Org Settings &gt; Data Location.<\/li>\n\n\n\n<li class=\"wp-block-list-item\">If you have further questions, please contact M365GovQnA@microsoft.com and cc: your Microsoft account team.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"govramp-in-gcc\">GovRAMP in GCC<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/govramp.org\/\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">GovRAMP<\/a> is a non-profit membership organization comprised of CSPs, government officials, and 3PAOs.  The GovRAMP standard is based on the NIST 800-53, Revision 5 catalog of security controls along with FedRAMP, and enables state and local governments to manage third-party risk and verify cloud security.  Cloud solutions that secure GovRAMP certifications are listed in its <a href=\"https:\/\/govramp.org\/product-list\/\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Authorized Products List<\/a>.  States that are required to have their own cybersecurity standards have extended reciprocity with the GovRAMP certification or adopted GovRAMPas their standard.  Microsoft helped to develop the GovRAMP standard and continues to support its role in US state and local government cybersecurity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As mentioned above in the section on FedRAMP in Azure, both Azure Commercial and Azure Government each maintain FedRAMP High P-ATOs issued by the FedRAMP PMO in addition to Moderate and High Agency ATOs issued by individual federal agencies for the in-scope services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The following cloud service offerings have achieved the GovRAMP Authorized Security Status for the High Impact Level as shown on the <a href=\"https:\/\/govramp.org\/product-list\/\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Authorized Products List<\/a>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Microsoft 365 Government (GCC)<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Azure Commercial<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Azure Government<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Dynamics 365 Commercial<\/li>\n\n\n\n<li class=\"wp-block-list-item\">Dynamics 365 Government (GCC)<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><em>For more information, please reference<\/em> <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/compliance\/offerings\/offering-stateramp\" target=\"_blank\" rel=\"noopener noreferrer\">StateRAMP &#8211; Azure Compliance<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"dod-cc-srg-in-gcc-and-azure-commercial\">DoD CC SRG in GCC and Azure Commercial<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The Defense Information Systems Agency (DISA) is an agency of the DoD that is responsible for developing and maintaining the DoD Cloud Computing (CC) Security Requirements Guide (SRG). The SRG defines the baseline security requirements used by the DoD to assess the security posture of a CSP and establishes a baseline requiring a FedRAMP Moderate authorization for all information Impact Levels (IL).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SRG Section 5.1.1 (DoD use of FedRAMP Security Controls) states that IL2 information may be hosted in a CSP that minimally holds a FedRAMP Moderate authorization.  Given that Microsoft 365 Government (GCC) and Azure Commercial are both FedRAMP Moderate authorized (and higher), you may <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/compliance\/offerings\/offering-dod-il2\" target=\"_blank\" rel=\"noopener noreferrer\">demonstrate compliance for IL2<\/a>.  As such, there is effectively \u2018<em>Equivalency<\/em>\u2019 between DoD CC SRG IL2 and FedRAMP Moderate.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>For more information, please see <\/em><a href=\"https:\/\/learn.microsoft.com\/en-us\/compliance\/regulatory\/offering-dod-il2\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Microsoft SRG Documentation<\/em><\/a><em>.<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"criminal-justice-information-services-in-gcc\">Criminal Justice Information Services in GCC<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The most dominant tenant populations in GCC include State and Local Government (SLG) entities, such as highway patrol, sheriff, local law enforcement, etc. that require CJIS.  The CJIS security policy provides 13 areas that should be evaluated to determine if cloud services can be used and are consistent with CJIS requirements. These areas correspond closely to the NIST SP 800-53 control implementation for FedRAMP Moderate with a security policy aligning with CJIS.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft will sign the CJIS Security Addendum in states with CJIS Information Agreements. These tell state law enforcement authorities responsible for compliance with CJIS Security Policy how Microsoft&#8217;s cloud security controls help protect the full lifecycle of data and ensure appropriate background screening of operating personnel with access to CJI. Microsoft continues to work with state governments to enter into CJIS Information Agreements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft has assessed the operational policies and procedures of Azure Government, Microsoft 365 Government (GCC), and Dynamics 365 Government (GCC), and will attest to their ability in the applicable services agreements to meet FBI requirements for the use of in-scope services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CJIS status in the United States<\/p>\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/US-Map.webp\" alt=\"\" class=\"wp-image-125971 webp-format\" srcset=\"\" data-orig-src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/US-Map.webp\"><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">48 states and the District of Columbia with management agreements, highlighted on the map in green include:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Alabama, Alaska, Arizona, Arkansas, California, Colorado, Connecticut, Delaware, Florida, Georgia, Hawaii, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Louisiana, Maine, Maryland, Massachusetts, Michigan, Minnesota, Mississippi, Missouri, Montana, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, North Dakota, Oklahoma, Ohio, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Texas, Utah, Vermont, Virginia, Washington, West Virginia, Wisconsin, and the District of Columbia.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft&#8217;s commitment to meeting the applicable CJIS regulatory controls allows Criminal Justice organizations to implement cloud-based solutions and be compliant with CJIS Security Policy V5.8.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Current as of April 2024 &#8211; <\/em><a href=\"https:\/\/learn.microsoft.com\/en-us\/compliance\/regulatory\/offering-CJIS\" target=\"_blank\" rel=\"noopener noreferrer\">Criminal Justice Information Services (CJIS) Security Policy &#8211; Microsoft Compliance<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Note: This section also applies to CJIS in Azure Government as well.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>For information from the FBI: <\/em><a href=\"https:\/\/www.fbi.gov\/file-repository\/csp-v5_5-to-nist-controls-mapping-1.pdf\/view\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Security Control Mapping of CJIS Security Policy<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"microsoft-365-government-gcc-high-azure-government\">Microsoft 365 Government (GCC High) + Azure Government<\/h2>\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/M365-US-Sovereign-Cloud.webp\" alt=\"\" class=\"wp-image-125970 webp-format\" srcset=\"\" data-orig-src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/M365-US-Sovereign-Cloud.webp\"><\/figure>\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/Azure-Commercial-Vs.-Govt.webp\" alt=\"\" class=\"wp-image-125969 webp-format\" srcset=\"\" data-orig-src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/Azure-Commercial-Vs.-Govt.webp\"><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"itar-in-gcc-high-and-azure-government\">ITAR in GCC High and Azure Government<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">These cloud services are purpose built for export controls in the US, to include ITAR and EAR.  I have customers interpret that GCC is suitable for export controls.  I&#8217;ve even had customers decide that Commercial is sufficient.  I tell them that I am not a lawyer, and I cannot give you legal counsel, but I think that is extremely unwise.  I can&#8217;t stop you from leveraging Commercial or GCC for CUI-Specified categorized as Export Controlled (CUI\/\/EXPT), especially for ITAR and EAR. I hope you take advantage of every data protection feature that we offer you!  GCC High and Azure Government were created to give you a commitment for export controls in the US.  This includes a US Sovereign Cloud accreditation boundary encompassing all services attached to Azure Government, Microsoft 365 Government (GCC High) and Dynamics 365 Government (GCC High).  For example, the network is sovereign and constrained to CONUS.  The GCC High directory services with Entra ID are provided by Azure Government and are sovereign to the US.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"dod-cc-srg-equivalency-in-gcc-high\">DoD CC SRG Equivalency in GCC High<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">We have evolved the US Sovereign Cloud to include PII protections.  PII protections are now all the way up to IL4 in GCC High (aligned with FedRAMP High).  In fact, we manage the GCC High environment with the same set of control scope and ODVs as the DoD environment.  This translates to SRG \u2018<em>equivalency<\/em>\u2019 of both IL4 and IL5 in GCC High.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, for most Federal contractors and the DIB, SRG impact level is a moot point.  Technically speaking, the SRG only applies to Federal information systems.  IL4 is not an authorization the DoD will provide to a non-Federal nor private-sector entities, nor is it for a CSP cloud environment not in use directly by the DoD.  For the DIB, DFARs 7012 and CMMC is what applies to non-Federal and private sector information systems.  As such, Microsoft has pivoted away from advertising the SRG impact levels in alignment with Microsoft 365 Government (GCC High).  We now focus on how our DIB\/FFRDC\/UARC customers may demonstrate compliance with CMMC leveraging our cloud service offerings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That said, we often get pulled into customer conversations where they have a contract with the US DoD including a CC SRG IL5 requirement.  The DoD is telling their prime contractor \u201c<em>You must put this data in an IL5 environment<\/em>\u201d with no exceptions.  However, the environment is in the contractor\u2019s information systems.  The DoD does not certify a contractor\u2019s environment for the CC SRG, regardless of whether it\u2019s on-premises or in the cloud.  As such, the CC SRG does not apply to contractor-owned environments.  It\u2019s impossible for a contractor to certify their information systems as IL5 because it\u2019s not a DoD-owned environment.  As such, I break it down this way\u2026<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>Gov\u2019t Owned, Gov\u2019t Operated<\/strong> (GOGO) = CC SRG IL 2\/4\/5 (NIST SP 800-53) under DISA security cognizance.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Gov\u2019t Owned, Contractor-Operated<\/strong> (GOCO) = CC SRG IL 2\/4\/5 (NIST SP 800-53) under DISA security cognizance.  The Contractor masquerades on-behalf of the DoD.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Contractor-Owned, Contractor-Operated<\/strong> (COCO) = DFARS 7012 + CUI-Specified protections (e.g. DDTC regs for ITAR).  DISA does NOT have security cognizance.  CMMC will in the future.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">An older slide (<em>circa 2017<\/em>) but still helpful in visualizing the below breakdown between GOGO (DoD Information Systems), GOCO (Systems Operated on Behalf of the DoD) and COCO (Contractor\u2019s Internal System) and the appropriate alignment with NIST 800-171 vs SRG.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"999\" height=\"761\" src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/Information-System-Security-Requirements.jpeg\" alt=\"\" class=\"wp-image-125968\" srcset=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/Information-System-Security-Requirements.jpeg 999w, https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/Information-System-Security-Requirements-300x229.jpeg 300w, https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/Information-System-Security-Requirements-768x585.jpeg 768w\" sizes=\"auto, (max-width: 999px) 100vw, 999px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Reference from \u2018<a href=\"https:\/\/business.defense.gov\/Portals\/57\/Documents\/Cybersecurity.pdf\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Protecting the DoD\u2019s Unclassified Information<\/a>\u2019<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We are IL5 compliant for the DoD cloud we provide for GOGOs and GOCOs\u200b. In accordance with the requirements imposed by the DoD, Microsoft will not allow COCOs in the DoD cloud.  Only the DoD can sponsor tenancy in that service, yet they have not allowed any COCOs to date. If a customer feels they require a cloud service accredited at IL5, this is an issue they need to raise with the DoD. IL5 is defined as to restrict tenancy to only entities authorized by DISA\u200b.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We offer IL4\u200b \u2018<em>Equivalent<\/em>\u2019 cloud services in GCC High. It\u2019s \u2018<em>Equivalent<\/em>\u2019 because the DoD has not granted IL4 to GCC High since they have no intent from their mission owners in the DoD consuming that service (instead intending them to utilize the DoD cloud services).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If a contractor has DoD compliance requirements for a COCO, we expect those to fall under security cognizance for DFARS 7012 and CMMC that GCC High can support.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"dod-cc-srg-in-azure-government\">DoD CC SRG in Azure Government<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Cloud services in Azure Government are authorized for DoD CC SRG IL2 and IL4.  In addition, Azure Government has over <a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/120-azure-government-services-now-authorized-for-dod-il5-workloads\/#:~:text=Our%20latest%20addition%20of%2023%20new%20services%20brings,to%20enable%20mission%20owners%20to%20do%20more,%20faster.\" target=\"_blank\" rel=\"noopener noreferrer\">120 services accredited at IL5<\/a> (<em>148<\/em> <em>as of the time of this writing<\/em>).  These services include a broad range of IaaS, PaaS and SaaS capabilities.  When supporting IL5 workloads on Azure Government, the isolation requirements can be met in different ways.  The <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-government\/documentation-government-impact-level-5\" target=\"_blank\" rel=\"noopener noreferrer\">Isolation guidelines for IL5 workloads<\/a> documentation addresses configurations and settings for the isolation required to support IL5 data with specific service instructions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can find a full list of Azure Government services that meet the requirements of the DoD in the <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-government\/compliance\/azure-services-in-fedramp-auditscope\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Government audit scope documentation<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>For more information, please reference:<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/compliance\/offerings\/offering-dod-il4\" target=\"_blank\" rel=\"noopener noreferrer\">Department of Defense Impact Level 4 &#8211; Azure Compliance<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/compliance\/offerings\/offering-dod-il5\" target=\"_blank\" rel=\"noopener noreferrer\">Department of Defense Impact Level 5 &#8211; Azure Compliance<\/a><em> <\/em><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"dfars-7012-and-nist-sp-800-171-in-gcc-high-and-azure-government\">DFARs 7012 and NIST SP 800-171 in GCC High and Azure Government<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft will support a Flow-Down for DFARs 7012 in GCC High and in Azure Government.  This translates to a commitment where we demonstrate DFARs 7012 compliance in the US Sovereign Cloud.  This includes DFARs 7012 alignment with NIST SP 800-171 in a shared responsibility model with the Customer.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Note: You may access our Attestation of Compliance with DFARS included with our Body of Evidence (BoE).<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"fedramp-high-in-gcc-high\">FedRAMP High in GCC High<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You can demonstrate compliance with the FedRAMP Moderate and High Impacts Level in GCC High.  We have several Federal Agencies actively deployed in GCC High, demonstrating compliance with FedRAMP High.  The Agency ATOs include but are not limited to the U.S. Department of Homeland Security (DHS), the U.S. Department of Justice (DoJ), the U.S. Federal Bureau of Investigation (FBI), and the U.S. Department of the Treasury.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Note<\/strong>: The FedRAMP High Impact Level is not a requirement for DFARs 7012 compliance.  FedRAMP Moderate \u2018<em>or Equivalent<\/em>\u2019 is specifically required for DFARs 7012.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For more information, please reference:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/aka.ms\/fedramp\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft FedRAMP Documentation (https:\/\/aka.ms\/fedramp)<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\">FedRAMP Package FR1824057433:  <a href=\"https:\/\/marketplace.fedramp.gov\/products\/FR1824057433\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Microsoft 365 Government Community Cloud-High | FedRAMP Marketplace<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\">Body of Evidence (BoE) section below<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">As discussed in the section for FedRAMP in Microsoft 365 Commercial, holistic coverage for Microsoft 365 includes both Office 365 productivity services and Azure services bundled together.  The section below on Azure Government includes all the cloud services that fall in-scope for the Azure Government P-ATO.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"fedramp-high-in-azure-government-and-dynamics-365-gcc-high\">FedRAMP High in Azure Government and Dynamics 365 GCC High<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">As described above for Azure Commercial, Azure Government has a P-ATO for FedRAMP High from the FedRAMP PMO.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are over <a href=\"https:\/\/devblogs.microsoft.com\/azuregov\/azure-government-expands-compliance-coverage-with-142-services-now-fedramp-high\/?_lrsc=547bf8c3-4ac3-4c0d-a7d9-1bc5f2183132\" target=\"_blank\" rel=\"noopener noreferrer\">140 Azure services<\/a> (161 services as of the time of this writing) covered by the FedRAMP High P-ATO in Azure Government.  You may even observe that Dynamics 365 Government (GCC High) falls under the scope of the Azure Government P-ATO in the <a href=\"https:\/\/marketplace.fedramp.gov\/products\/F1603087869\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">FedRAMP Marketplace<\/a> where the P-ATO is recognized as \u2018<em>Authorized<\/em>\u2019 by the FedRAMP PMO.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"fedramp-body-of-evidence\">FedRAMP Body of Evidence<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The FedRAMP Body of Evidence (BoE) is a collection of documents, artifacts, and evidence that demonstrate the security controls implemented by a CSP to demonstrate compliance with the FedRAMP security control baseline through an assessment conducted by a FedRAMP authorized 3PAO.  It provides a comprehensive record of the security measures in place to protect federal data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft 365 and Azure\u2019s BoEs include the following:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><strong>SSP<\/strong>: The <strong>System Security Plan<\/strong> provides an overview of the security requirements for the Cloud Services and describes the controls in place or planned for implementation to provide a level of security appropriate for the information to be transmitted, processed or stored by the system.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>CIS &amp; CRM<\/strong>: The <strong>Control Implementation Summary<\/strong> (CIS) report includes control implementation responsibility and implementation status of the FedRAMP security controls.  Also included in the CIS is an Excel spreadsheet for the <strong>Customer Responsibility Matrix<\/strong> (CRM).  The CRM identifies what controls are inherited from the cloud service provider, versus those controls that are the responsibility of the customer (tenant owner).  Most importantly, the CRM identifies the controls that are shared responsibility of both the CSP and the customer.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>SAR<\/strong>: The Security Assessment Report is generated by the 3PAO during the annual assessment.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>SAP<\/strong>: The Security Assessment Plan (SAP) lists the scope and security controls selected for annual assessment by the 3PAO.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>Penetration Testing Report<\/strong>: Cloud penetration testing report produced by Azure FedRAMP High and DoD SRG compliance program.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>DFARs Compliance Attestation Letter<\/strong>:  Attestation of Compliance with Defense Federal Acquisition Regulation Supplement (DFARs) clause 252.204-7012.<\/li>\n\n\n\n<li class=\"wp-block-list-item\"><strong>CMMC<\/strong> <strong>Compliance Attestation Letter<\/strong>:  Attestation of Compliance with Cybersecurity Maturity Model Certification (CMMC) Requirements.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For more information on the specific requirements for a BoE, please review the U.S. Department of Defense memorandum for \u2018<a href=\"https:\/\/dodcio.defense.gov\/Portals\/0\/Documents\/Library\/FEDRAMP-EquivalencyCloudServiceProviders.pdf\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">FedRAMP Moderate Equivalency for Cloud Service Provider\u2019s Cloud Service Offerings<\/a>\u2019 dated December 21, 2023.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The BoE is considered highly sensitive and confidential information.  Historically, many CSPs have not been willing to share their BoE with customers, especially for Government cloud offerings.  However, Microsoft is transparent and will allow for customers of our government solutions to access the BoE under a Non-Disclosure Agreement (NDA).  To request the BoE, you must be a customer and make an E-mail request to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\">Microsoft 365 GCC High: <a href=\"mailto:O365FedRAMP@microsoft.com\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">O365FedRAMP@microsoft.com<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\">Azure Government: <a href=\"mailto:AzFedDoc@microsoft.com\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">AzFedDoc@microsoft.com<\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><em>Note<\/em><\/strong><em>: If you have your Microsoft NDA handy and can provide the document ID, it can save time during the request.<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"cmmc-in-the-us-sovereign-cloud\">CMMC in the US Sovereign Cloud<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">You may demonstrate compliance with all maturity levels of CMMC in the US Sovereign Cloud.  We exclusively recommend our US Sovereign Cloud with Microsoft 365 Government (GCC High) and Azure Government for data protection of CUI in alignment with CMMC 2.0 Levels 2-3.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"cjis-in-azure-government\">CJIS in Azure Government<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">CJIS in Azure Government is aligned with the same description as provided above in the section \u201cCriminal Justice Information Services in GCC\u201d.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"cjis-in-gcc-high\">CJIS in GCC High<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Criminal Justice Information Services in Microsoft 365 Government (GCC High) is described as for \u2018Federal\u2019 only.  CJIS Information Agreements are signed primarily at the US State level.  Most US States have Information Agreements established for both Microsoft 365 Government (GCC) and for Azure Government.  However, those agreements are not in scope for Microsoft 365 Government (GCC High).  This is because no State nor local government entities deploy into GCC High.  To date, only Federal agencies and the DIB\/FFRDC\/UARC deploy into GCC High.  Thus, a US State has not had the need to sign a CJIS Information Agreement for GCC High.  It doesn\u2019t mean that GCC High is non-compliant with CJIS.  That is evident as the US Federal Bureau of Investigation (FBI) is deployed in GCC High.  Hence, the FBI has authorized the use of GCC High for CJIS at the \u2018Federal\u2019 level.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"nerc-and-ferc-in-the-us-sovereign-cloud\">NERC and FERC in the US Sovereign Cloud<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft has engaged with multiple entities obligated to demonstrate compliance requirements of the North American Electric Reliability Corporation (NERC) and\/or the Federal Energy Regulatory Commission (FERC).  They find the US Sovereign Cloud with Microsoft 365 Government (GCC High) High and Azure Government to be the closest match of Microsoft cloud service offerings to fulfill their requirements. Due to the dynamic scope of applicability that an entity may define, we recommend you request explicit support from your Microsoft account team if you have compliance requirements in this area.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"customer-support-for-the-us-sovereign-cloud\">Customer Support for the US Sovereign Cloud<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The US Sovereign Cloud with Azure Government, Microsoft 365 Government (GCC High) and Dynamics 365 Government (GCC High) offer differentiated support staffing, with technical support provided 24&#215;7 by screened US Persons in a US Location.  However, these terms do not preclude the use of global support staff in customer support escalations. It is not uncommon for Microsoft customer support to rely on support engineers that specialize in specific services or technologies and are subject matter experts in niche areas.  These support engineers might be located anywhere in the world and could be introduced to provide expertise and guidance on a specific customer support ticket. Since customer support personnel have no direct standing access to the datacenter nor to customer content, they can only be exposed to sensitive information when it is provided directly by the Customer during a customer support ticket.  We remind you not to share any controlled, sensitive, or confidential information with support personnel as part of your support incident, and follow your own internal data sharing controls, policies and procedures when engaging with Microsoft customer support.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Important:  Within the US Sovereign Cloud, you may request your ticket to remain limited and restricted to \u201cscreened US Persons in a US Location\u201d only.  However, availability of the subject matter engineer may be limited to US time zones as <\/em><em>opposed to 24&#215;7 support.  This may negatively impact the response and mitigation of the Customer support ticket.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>Note:  <\/em><a href=\"https:\/\/aka.ms\/CustomerLockbox\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Microsoft Purview Customer Lockbox<\/em><\/a><em> is a popular feature to moderate access to your data.   We even have <\/em><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/security\/fundamentals\/customer-lockbox-overview\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Customer Lockbox for Azure<\/em><\/a><em> releasing to more and more Azure services<\/em><em>.<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"considerations-for-us-person-only-tenant-for-government-clouds\">Considerations for US person-only Tenant for Government Clouds<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This is an organizational decision, and not one that is required to achieve compliance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are no restrictions for US persons nor for citizenship checks imposed by Microsoft on tenant owners (organizations) giving access control to their tenants in US Government cloud service offerings.  As with all Cloud Service Providers (CSP), it is a shared scope of responsibility for compliance.  Microsoft commits to personnel that are US persons on the back end with the CSP specific scope of responsibility, but it is the organization\u2019s (customer\u2019s) responsibility to protect their content according to their own regulatory requirements.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"microsoft-365-government-dod\">Microsoft 365 Government (DoD)<\/h2>\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/US-Sovereign-Cloud.webp\" alt=\"\" class=\"wp-image-125967 webp-format\" srcset=\"\" data-orig-src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/US-Sovereign-Cloud.webp\"><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">If you are not in the DoD, don&#8217;t worry about it.  You&#8217;re not getting into the service.  Only the DoD and those approved by them (<em>such as service providers or entities authorized by the DoD<\/em>) are allowed into the DoD regions for Microsoft 365 and Azure Government.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That said, if you are a DoD contractor with requirements for DoD CC SRG IL5, please read the section above on \u2018DoD CC SRG Equivalency in GCC High\u2019.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"azure-government-secret-office-365-government-secret\">Azure Government Secret + Office 365 Government Secret<\/h2>\n\n\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/Compliance-Types.webp\" alt=\"\" class=\"wp-image-125966 webp-format\" srcset=\"\" data-orig-src=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2026\/06\/Compliance-Types.webp\"><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"dod-cc-srg-in-azure-government-secret\">DoD CC SRG in Azure Government Secret<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">CC SRG IL6 is reserved for the storage, processing and transmission of information classified up to the <a href=\"https:\/\/csrc.nist.gov\/glossary\/term\/collateral_information\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Collateral<\/a> Secret level. For a hyper-scale cloud offering, information that must be processed and stored at IL6 can only be hosted in an air-gapped government community cloud. Because of the requirement that the entire cloud infrastructure be dedicated and separate (air-gapped) from other CSP infrastructures, IL6 may only be provided by CSPs under contract to the DoD or a federal agency.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Azure Government Secret maintains an IL6 P-ATO at the high confidentiality, high integrity, and customer-determined availability (H-H-x) information categorization. In addition, DISA is the primary Authorizing Official (AO) for Azure Government Secret, with all other Secret compliance frameworks recognizing a program of reciprocity with the DoD CC SRG.  Over 67 Azure Government Secret services are accredited for IL6 as of the time of this writing.  These services include a broad range of IaaS, PaaS and SaaS capabilities.  We have many more services in the queue for authorization by DISA as we speak.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Note<\/strong>:  <em>Azure Government Secret is the first and only classified cloud service offering (CSO) to have received the highest possible P-ATO at the H-H-x information categorization.<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can find a full list of Azure Government services that meet the requirements of the DoD in the <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/azure-government\/compliance\/azure-services-in-fedramp-auditscope\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Government audit scope documentation<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>For more information, please reference:<\/em><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/compliance\/offerings\/offering-dod-il6\" target=\"_blank\" rel=\"noopener noreferrer\">Department of Defense Impact Level 6 &#8211; Azure Compliance<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/azure.microsoft.com\/en-us\/explore\/global-infrastructure\/government\/national-security\/\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Government for national security<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/core-infrastructure-and-security\/introduction-to-microsoft-azure-government-secret\/ba-p\/2043581\" target=\"_blank\" rel=\"noopener noreferrer\">Introduction to Microsoft Azure Government Secret<\/a><\/li>\n\n\n\n<li class=\"wp-block-list-item\"><a href=\"https:\/\/azure.microsoft.com\/en-us\/blog\/announcing-new-azure-government-capabilities-for-classified-mission-critical-workloads\/\" target=\"_blank\" rel=\"noopener noreferrer\">Announcing new Azure Government capabilities for classified mission-critical workloads<\/a><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"dod-cc-srg-in-office-365-government-secret\">DoD CC SRG in Office 365 Government Secret<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Since announcing the general availability of Azure Government Secret, our mission has been to support all US government agencies, departments, municipalities, public sector employees and industry with IL6 compliant productivity and collaboration tools. Office 365 Government Secret is authorized for IL6 and generally available for use by the DoD today with hundreds of thousands of seats actively deployed. In addition, this O365 environment is built to support the DoD along with US Federal Civilian, Intelligence Community (IC), and US government partners (industry) working within the Secret enclave with our SaaS capabilities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><em>For more information, please reference<\/em> <a href=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-365\/blog\/2022\/03\/28\/announcing-office-365-government-secret-cloud-to-help-secure-classified-data\/\" target=\"_blank\" rel=\"noopener noreferrer\">Announcing Office 365 Government Secret cloud<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"national-industrial-security-program-operations-manual\">National Industrial Security Program Operations Manual<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.dcsa.mil\/Industrial-Security\/NISP-Authorization-Office-NAO\/\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">National Industrial Security Program<\/a> (NISP) has oversight by the DoD\u2019s <a href=\"https:\/\/www.dcsa.mil\/\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Defense Counterintelligence and Security Agency<\/a> (DCSA).  Just as facilities and individuals require a clearance to gain access to classified information, cleared contractor Information Systems (IS) must be assessed and authorized prior to processing classified information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">DCSA serves as the Authorizing Official (AO) for contractor IS, such as for Contractor-Owned &amp; Contractor-Operated (COCO) Internal Research &amp; Development (IRAD) environments. The NISP has published guidance for industry to properly manage and protect against unauthorized disclosure of classified information, including <a href=\"https:\/\/csrc.nist.gov\/glossary\/term\/collateral_information\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Collateral classifications<\/a> (Confidential &amp; Secret).  The NISP has recognized a program of reciprocity with the DoD CC SRG IL6 including authorizations for use of cloud by industry based on the <a href=\"https:\/\/www.federalregister.gov\/documents\/2020\/12\/21\/2020-27698\/national-industrial-security-program-operating-manual-nispom\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">NISP Operations Manual<\/a> (NISPOM).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can now demonstrate compliance with the NISPOM and achieve an ATO using Azure Government Secret.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Note<\/strong>: <em>Azure Government Secret is the first and only classified cloud service offering (CSO) to be authorized by the NISP with industry partners connecting to our hyper-scale cloud using non-government (aka \u2018private\u2019) COCO networks.<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"joint-special-access-programs-implementation-guide\">Joint Special Access Programs Implementation Guide<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A <a href=\"https:\/\/en.wikipedia.org\/wiki\/Special_access_program\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Special Access Program<\/a> (SAP) is a highly classified program established to protect sensitive information and impose enhanced security measures with compartmentalized access requirements that go beyond what is typically required for information at the same (Collateral) classification levels.  In addition to Collateral controls (e.g. IL6 &amp; NISPOM), a SAP imposes more rigorous requirements, non-disclosure agreements (NDA) to get \u2018read-in\u2019 to the program, special document markings, etc.  Within the DoD, a SAP is better known with Special Access Required (SAR) markings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Note<\/strong>: Word to the wise, when talking about SAP with your fellow cybersecurity fellows, make sure you differentiate between SAP for classified IS, as opposed to the ERP company solutions. It\u2019s amazing how often you can talk past each other!<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A big difference between Collateral versus SAP\/SAR requirements is requiring cleared personnel, facilities (SAPF) and IS to be \u2018read-in\u2019 to the program, effectively compartmentalizing access to the individual program.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.dcsa.mil\/portals\/91\/documents\/ctp\/nao\/JSIG_2016April11_Final_(53Rev4).pdf\" target=\"_blank\" rel=\"noopener nofollow noreferrer\">Joint Special Access Programs Implementation Guide<\/a> (JSIG) provides standardized policies for cybersecurity and information assurance, procedures, and implementation guidance for use in the management of IS at all classification levels under the purview of the SAP Authorizing Official (AO).  Based on NIST SP 800-53, the NIST Risk Management Framework (RMF) and JSIG Protection Levels (e.g. PL2, PL3), JSIG includes the compliance control set required to achieve an ATO for SAP IS environments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Azure Government Secret maintains JSIG ATOs at Protection Levels up to 3 (PL3).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For more information, please reference <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/compliance\/offerings\/offering-jsig\" target=\"_blank\" rel=\"noopener noreferrer\">Joint Special Access Program Implementation Guide  &#8211; Azure Compliance<\/a><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"intelligence-community-directive\">Intelligence Community Directive<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Intelligence Community Directive (ICD) 503, also known as \u2018Risk Management for Federal Information Systems\u2019 is a standard developed by NIST in collaboration with the US Intelligence Community (IC) for risk management and certification of IS across the IC. It provides a framework for managing risk and ensuring the confidentiality, integrity, and availability of information systems within US Federal agencies. ICD 503 is closely related to the NIST RMF and enables the IC to use NIST and Committee on National Security Systems (CNSS) standards for security assessments.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Azure Government Secret maintains ICD 503 ATOs with classified facilities authorized according to ICD 705.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For more information, please reference <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/compliance\/offerings\/offering-icd-503\" target=\"_blank\" rel=\"noopener noreferrer\">Intelligence Community Directive (ICD) 503 &#8211; Azure Compliance<\/a><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"azure-government-top-secret-office-365-government-top-secret\">Azure Government Top Secret + Office 365 Government Top Secret<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Generally speaking, we do not disclose many details on our Top Secret (TS) Cloud Service Offerings (CSO) without an exclusive sponsorship by the US Government, other than what is mentioned in the blog article \u2018<a href=\"https:\/\/azure.microsoft.com\/en-us\/blog\/azure-government-top-secret-now-generally-available-for-us-national-security-missions\/\" target=\"_blank\" rel=\"noopener noreferrer\">Azure Government Top Secret now generally available for US national security missions<\/a>\u2019.  That said, TS does have support for JSIG and ICD 503\/705 at TS classification levels (e.g. Collateral TS &amp; TS\/SCI), like what is described above for Secret.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"appendix\">Appendix<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Please follow me <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/user\/v2\/viewprofilepage\/user-id\/276160\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a> and on <a href=\"https:\/\/www.linkedin.com\/in\/wakeman\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">LinkedIn<\/a>. Here are my additional blog articles:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><th scope=\"col\">Blog Title<\/th><th scope=\"col\">Aka Link<\/th><\/tr><tr><td>Microsoft Collaboration Framework<\/td><td><a href=\"https:\/\/aka.ms\/ND-ISAC\/CollabFramework\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/aka.ms\/ND-ISAC\/CollabFramework<\/a><\/td><\/tr><tr><td>ND-ISAC MSCloud &#8211; Reference Identity Architectures for the US Defense Industrial Base<\/td><td><a href=\"https:\/\/aka.ms\/ND-ISAC\/IdentityWP\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/aka.ms\/ND-ISAC\/IdentityWP<\/a><\/td><\/tr><tr><td><strong><em>New!<\/em><\/strong>  Microsoft Product Placemat for CMMC<\/td><td><a href=\"https:\/\/aka.ms\/CMMC\/Placemat\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/aka.ms\/CMMC\/Placemat<\/a><\/td><\/tr><tr><td>Microsoft CMMC Acceleration Update<\/td><td><a href=\"https:\/\/aka.ms\/CMMC\/Acceleration\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/aka.ms\/CMMC\/Acceleration<\/a><\/td><\/tr><tr><td>History of Microsoft Cloud Service Offerings leading to the US Sovereign Cloud for Government<\/td><td><a href=\"https:\/\/aka.ms\/USSovereignCloud\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/aka.ms\/USSovereignCloud<\/a><\/td><\/tr><tr><td>The Microsoft 365 Government (GCC High) Conundrum &#8211; DIB Data Enclave vs Going All In<\/td><td><a href=\"https:\/\/aka.ms\/AA6frar\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/aka.ms\/AA6frar<\/a><\/td><\/tr><tr><td>Microsoft US Sovereign Cloud Myth Busters &#8211; A Global Address List (GAL) Can Span Multiple Tenants<\/td><td><a href=\"https:\/\/aka.ms\/AA6seih\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/aka.ms\/AA6seih<\/a><\/td><\/tr><tr><td>Microsoft US Sovereign Cloud Myth Busters &#8211; A Single Domain Should Not Span Multiple Tenants<\/td><td><a href=\"https:\/\/aka.ms\/AA6vf3n\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/aka.ms\/AA6vf3n<\/a><\/td><\/tr><tr><td>Microsoft US Sovereign Cloud Myth Busters &#8211; Active Directory Does Not Require Restructuring<\/td><td><a href=\"https:\/\/aka.ms\/AA6xn69\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/aka.ms\/AA6xn69<\/a><\/td><\/tr><tr><td>Microsoft US Sovereign Cloud Myth Busters &#8211; CUI Effectively Requires Data Sovereignty<\/td><td><a href=\"https:\/\/aka.ms\/CUISovereignty\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/aka.ms\/CUISovereignty<\/a><\/td><\/tr><tr><td>Microsoft expands qualification of contractors for government cloud offerings<\/td><td><a href=\"https:\/\/aka.ms\/GovCloudEligibility\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/aka.ms\/GovCloudEligibility<\/a><\/td><\/tr><tr><td>Microsoft Expands Support for the DIB \u2013 Announcing Support for DFARS in Azure Commercial<\/td><td><a href=\"https:\/\/aka.ms\/DFARsAzure\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/aka.ms\/DFARsAzure<\/a><\/td><\/tr><tr><td>Microsoft Expands Support for the DIB \u2013 Announcing Support for DFARS in Microsoft 365 Government (GCC)<\/td><td><a href=\"https:\/\/aka.ms\/DFARsGCC\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/aka.ms\/DFARsGCC<\/a><\/td><\/tr><tr><td><strong><em>New!<\/em><\/strong>  Support for DFARS in Microsoft 365 Government (GCC High)<\/td><td><a href=\"https:\/\/aka.ms\/DFARsGCCH\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/aka.ms\/DFARsGCCH<\/a><\/td><\/tr><tr><td><strong><em>New!<\/em><\/strong>  Support for FedRAMP in Microsoft 365 Government (GCC High)<\/td><td><a href=\"https:\/\/aka.ms\/FedRAMPGCCH\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/aka.ms\/FedRAMPGCCH<\/a><\/td><\/tr><tr><td>Microsoft Federal Successfully Completes Voluntary CMMC Assessment<\/td><td><a href=\"https:\/\/aka.ms\/JSVA\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/aka.ms\/JSVA<\/a><\/td><\/tr><\/tbody><\/table><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>This article is the second of a series in the Microsoft Tech Community Public Sector Blog and touches on several key principles for compliance, including data residency versus data sovereignty. For the first article in the series, please refer to History of Microsoft Cloud Service Offerings leading to the US Sovereign Cloud for Government.<\/p>\n","protected":false},"author":57,"featured_media":127971,"template":"","meta":{"ep_exclude_from_search":false,"_classifai_error":"","_classifai_text_to_speech_error":"","_innovation_original_canonical_url":"https:\/\/techcommunity.microsoft.com\/blog\/publicsectorblog\/understanding-compliance-between-commercial-government-dod--secret-offerings---m\/4225436","ms-ems-related-posts":[],"footnotes":""},"categories":[1942],"tags":[],"content-type":[118],"job-function":[],"coauthors":[1215],"class_list":["post-126008","ms-industry","type-ms-industry","status-publish","has-post-thumbnail","hentry","category-us-government","content-type-thought-leadership"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Understanding Compliance Between Commercial, Government, DoD &amp; Secret Offerings - May 2026 Update | The Microsoft Cloud Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2024\/09\/23\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Understanding Compliance Between Commercial, Government, DoD &amp; Secret Offerings - May 2026 Update | The Microsoft Cloud Blog\" \/>\n<meta property=\"og:description\" content=\"This article is the second of a series in the Microsoft Tech Community Public Sector Blog and touches on several key principles for compliance, including data residency versus data sovereignty. For the first article in the series, please refer to History of Microsoft Cloud Service Offerings leading to the US Sovereign Cloud for Government.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2024\/09\/23\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\/\" \/>\n<meta property=\"og:site_name\" content=\"The Microsoft Cloud Blog\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-20T21:22:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2024\/09\/CLO22_TechOffice_009.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1280\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@MSCloud\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"40 minutes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data2\" content=\"Microsoft: From Inside the Cloud\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/us-government\\\/2024\\\/09\\\/23\\\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\\\/\",\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/us-government\\\/2024\\\/09\\\/23\\\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\\\/\",\"name\":\"Understanding Compliance Between Commercial, Government, DoD &amp; Secret Offerings - May 2026 Update | The Microsoft Cloud Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/us-government\\\/2024\\\/09\\\/23\\\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/us-government\\\/2024\\\/09\\\/23\\\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/CLO22_TechOffice_009.jpg\",\"datePublished\":\"2024-09-23T22:38:00+00:00\",\"dateModified\":\"2026-08-20T21:22:28+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/us-government\\\/2024\\\/09\\\/23\\\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/us-government\\\/2024\\\/09\\\/23\\\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/us-government\\\/2024\\\/09\\\/23\\\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/CLO22_TechOffice_009.jpg\",\"contentUrl\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/CLO22_TechOffice_009.jpg\",\"width\":1920,\"height\":1280,\"caption\":\"A person sitting at a table in front of a computer.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/us-government\\\/2024\\\/09\\\/23\\\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Industry Articles\",\"item\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/ms-industry\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Understanding Compliance Between Commercial, Government, DoD &amp; Secret Offerings &#8211; May 2026 Update\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/\",\"name\":\"The Microsoft Cloud Blog\",\"description\":\"Build the future of your business with AI\",\"publisher\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/#organization\",\"name\":\"Microsoft Cloud Blog\",\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/microsoft_logo.webp\",\"contentUrl\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/microsoft_logo.webp\",\"width\":400,\"height\":400,\"caption\":\"Microsoft Cloud Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/en-us\\\/microsoft-cloud\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/MSCloud\",\"https:\\\/\\\/www.linkedin.com\\\/showcase\\\/microsoft-cloud-platform\\\/\",\"https:\\\/\\\/www.youtube.com\\\/@MicrosoftCloud\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Understanding Compliance Between Commercial, Government, DoD &amp; Secret Offerings - May 2026 Update | The Microsoft Cloud Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2024\/09\/23\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\/","og_locale":"en_US","og_type":"article","og_title":"Understanding Compliance Between Commercial, Government, DoD &amp; Secret Offerings - May 2026 Update | The Microsoft Cloud Blog","og_description":"This article is the second of a series in the Microsoft Tech Community Public Sector Blog and touches on several key principles for compliance, including data residency versus data sovereignty. For the first article in the series, please refer to History of Microsoft Cloud Service Offerings leading to the US Sovereign Cloud for Government.","og_url":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2024\/09\/23\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\/","og_site_name":"The Microsoft Cloud Blog","article_modified_time":"2026-08-20T21:22:28+00:00","og_image":[{"width":1920,"height":1280,"url":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2024\/09\/CLO22_TechOffice_009.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_site":"@MSCloud","twitter_misc":{"Est. reading time":"40 minutes","Written by":"Microsoft: From Inside the Cloud"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2024\/09\/23\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\/","url":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2024\/09\/23\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\/","name":"Understanding Compliance Between Commercial, Government, DoD &amp; Secret Offerings - May 2026 Update | The Microsoft Cloud Blog","isPartOf":{"@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2024\/09\/23\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\/#primaryimage"},"image":{"@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2024\/09\/23\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\/#primaryimage"},"thumbnailUrl":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2024\/09\/CLO22_TechOffice_009.jpg","datePublished":"2024-09-23T22:38:00+00:00","dateModified":"2026-08-20T21:22:28+00:00","breadcrumb":{"@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2024\/09\/23\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2024\/09\/23\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2024\/09\/23\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\/#primaryimage","url":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2024\/09\/CLO22_TechOffice_009.jpg","contentUrl":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2024\/09\/CLO22_TechOffice_009.jpg","width":1920,"height":1280,"caption":"A person sitting at a table in front of a computer."},{"@type":"BreadcrumbList","@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/us-government\/2024\/09\/23\/understanding-compliance-between-commercial-government-dod-secret-offerings-may-2026-update\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/"},{"@type":"ListItem","position":2,"name":"Industry Articles","item":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/ms-industry\/"},{"@type":"ListItem","position":3,"name":"Understanding Compliance Between Commercial, Government, DoD &amp; Secret Offerings &#8211; May 2026 Update"}]},{"@type":"WebSite","@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/#website","url":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/","name":"The Microsoft Cloud Blog","description":"Build the future of your business with AI","publisher":{"@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/#organization","name":"Microsoft Cloud Blog","url":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2023\/10\/microsoft_logo.webp","contentUrl":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-content\/uploads\/2023\/10\/microsoft_logo.webp","width":400,"height":400,"caption":"Microsoft Cloud Blog"},"image":{"@id":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/MSCloud","https:\/\/www.linkedin.com\/showcase\/microsoft-cloud-platform\/","https:\/\/www.youtube.com\/@MicrosoftCloud"]}]}},"bloginabox_display_generated_audio":false,"_links":{"self":[{"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/ms-industry\/126008","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/ms-industry"}],"about":[{"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/types\/ms-industry"}],"author":[{"embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/users\/57"}],"version-history":[{"count":1,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/ms-industry\/126008\/revisions"}],"predecessor-version":[{"id":126009,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/ms-industry\/126008\/revisions\/126009"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/media\/127971"}],"wp:attachment":[{"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/media?parent=126008"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/categories?post=126008"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/tags?post=126008"},{"taxonomy":"content-type","embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/content-type?post=126008"},{"taxonomy":"job-function","embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/job-function?post=126008"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/en-us\/microsoft-cloud\/blog\/wp-json\/wp\/v2\/coauthors?post=126008"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}