Organizations pursuing CMMC, NIST 800-171, or DFARS compliance often need access to Microsoft’s official FedRAMP documentation for Microsoft 365 GCC High. These documents help organizations understand inherited controls, customer responsibilities, and Microsoft’s security control implementations.

Microsoft makes these compliance artifacts available through the Microsoft Service Trust Portal, but access to certain FedRAMP documents requires approval from Microsoft’s FedRAMP team.

What Documentation Is Available?

Depending on Microsoft’s current authorization scope, approved organizations may gain access to documents such as:

  • FedRAMP High authorization documentation
  • System Security Plans (SSPs)
  • Security Assessment Reports (SARs)
  • Shared Responsibility Matrices
  • Customer Responsibility Matrices
  • Boundary and architecture documentation
  • Additional compliance assessment artifacts

These resources are particularly valuable for organizations preparing for CMMC Level 2 assessments because they help identify which controls are inherited from Microsoft and which controls remain the responsibility of the customer.

How to Request Access

To request access, send an email to O365FedRAMP@microsoft.com and include the following information:

Organization Information

  • Organization name
  • Microsoft 365 tenant name or Tenant ID

Examples:

  • contoso.onmicrosoft.com
  • g71f0dfg-5h6j-231j-frk9-b6n98536032p

Point of Contact Information

Microsoft currently permits up to two Points of Contact (POCs) per organization.

For each POC, provide:

  • Full name
  • Email address
  • Cell phone number

Important Email Address Requirements

Microsoft recommends using a non-Microsoft tenant email address due to cross-tenant access restrictions. This can be:

  • An alternate business email address, or
  • A personal Microsoft Account (MSA)

Cell phone numbers are required for multi-factor authentication during the onboarding process.

Accessing the Documents

After Microsoft approves the request, the designated contacts will be granted access to the FedRAMP documentation through the Microsoft Service Trust Portal, https://servicetrust.microsoft.com

Within the Service Trust Portal, approved users can access the FedRAMP compliance package and supporting documentation for Microsoft 365 Government GCC High.

Why These Documents Matter

Microsoft’s GCC High environment follows a shared responsibility model. While Microsoft manages many security controls within the cloud service, customers remain responsible for implementing and maintaining other controls within their environment.

The Shared Responsibility Matrix and related FedRAMP documentation help organizations:

  • Understand inherited controls
  • Identify customer-managed responsibilities
  • Support SSP development
  • Prepare for CMMC and NIST 800-171 assessments
  • Gather evidence for compliance audits

At Nimbus Logic, these documents are frequently used when developing compliance documentation, shared responsibility matrices, and assessment readiness packages for organizations operating in Microsoft 365 GCC High environments.