05/23/2026
We are seeing some trends across our conversations in the Defense Industrial Base:
“If you’re in GCC High, you’re compliant.”
Through a little discovery, it's often clear that this isn't the case.
GCC High is a powerful foundation, but not a complete compliance solution on its own: https://rolleit.com/2026/04/06/the-misunderstanding-around-gcc-high/
Compliance cannot be inherited… security in the cloud is a shared responsibility.
That means while Microsoft secures the infrastructure, your organization is still responsible for configuring and proving the majority of controls.
In fact:
-Roughly half of NIST 800-171 controls require customer configuration in GCC High
-Critical controls like MFA, Conditional Access, RBAC, and DLP are NOT configured by default
-Organizations must actively manage audit logging, alerting, data classification, and access policies to be compliant
Cloud security guidance reinforces that:
Customers are responsible for securing data, identities, and access configurations in Azure and Microsoft 365 environments
GCC High gives you the tools but the organization has to implement them correctly.
That’s where Rolle IT Cybersecurity comes in.
We help organizations:
• Architect and configure GCC High environments aligned to CMMC & NIST 800-171
• Implement identity, access, and data protection controls correctly
• Build audit-ready documentation and evidence
• Turn compliance into a repeatable, defensible process
If you’re relying on GCC High alone, you’re only halfway there. [email protected]