Organizations pursuing CMMC, NIST 800-171, or DFARS compliance often need access to Microsoft’s official FedRAMP documentation for Microsoft 365 GCC High. These documents help organizations understand inherited controls, customer responsibilities, and Microsoft’s security control implementations.
Microsoft makes these compliance artifacts available through the Microsoft Service Trust Portal, but access to certain FedRAMP documents requires approval from Microsoft’s FedRAMP team.
What Documentation Is Available?
Depending on Microsoft’s current authorization scope, approved organizations may gain access to documents such as:
- FedRAMP High authorization documentation
- System Security Plans (SSPs)
- Security Assessment Reports (SARs)
- Shared Responsibility Matrices
- Customer Responsibility Matrices
- Boundary and architecture documentation
- Additional compliance assessment artifacts
These resources are particularly valuable for organizations preparing for CMMC Level 2 assessments because they help identify which controls are inherited from Microsoft and which controls remain the responsibility of the customer.
How to Request Access
To request access, send an email to O365FedRAMP@microsoft.com and include the following information:
Organization Information
- Organization name
- Microsoft 365 tenant name or Tenant ID
Examples:
contoso.onmicrosoft.comg71f0dfg-5h6j-231j-frk9-b6n98536032p
Point of Contact Information
Microsoft currently permits up to two Points of Contact (POCs) per organization.
For each POC, provide:
- Full name
- Email address
- Cell phone number
Important Email Address Requirements
Microsoft recommends using a non-Microsoft tenant email address due to cross-tenant access restrictions. This can be:
- An alternate business email address, or
- A personal Microsoft Account (MSA)
Cell phone numbers are required for multi-factor authentication during the onboarding process.
Accessing the Documents
After Microsoft approves the request, the designated contacts will be granted access to the FedRAMP documentation through the Microsoft Service Trust Portal, https://servicetrust.microsoft.com
Within the Service Trust Portal, approved users can access the FedRAMP compliance package and supporting documentation for Microsoft 365 Government GCC High.
Why These Documents Matter
Microsoft’s GCC High environment follows a shared responsibility model. While Microsoft manages many security controls within the cloud service, customers remain responsible for implementing and maintaining other controls within their environment.
The Shared Responsibility Matrix and related FedRAMP documentation help organizations:
- Understand inherited controls
- Identify customer-managed responsibilities
- Support SSP development
- Prepare for CMMC and NIST 800-171 assessments
- Gather evidence for compliance audits
At Nimbus Logic, these documents are frequently used when developing compliance documentation, shared responsibility matrices, and assessment readiness packages for organizations operating in Microsoft 365 GCC High environments.