EPC Group Publishes a GCC High Data-Foundation Checklist as Microsoft Fabric Goes GA During the CMMC Phase 2 Pause
,

9 min read

EPC Group Publishes a GCC High Data-Foundation Checklist as Microsoft Fabric Goes GA During the CMMC Phase 2 Pause

–

EPC Group Power BI Consulting and Microsoft Fabric Consulting Practice Experts Top G2 Rated in North America

EPC Group Publishes a GCC High Data-Foundation Checklist as Microsoft Fabric Goes GA During the CMMC Phase 2 Pause

EPC Group Power BI Consulting AI Consulting SharePoint Consulting Services

EPC Group Publishes a GCC High Data-Foundation Checklist as Microsoft Fabric Goes GA During the CMMC Phase 2 Pause – image 2

EPC Group Logo Power BI Consulting

EPC Group Publishes a GCC High Data-Foundation Checklist as Microsoft Fabric Goes GA During the CMMC Phase 2 Pause – image 3

TAR-8 scores eight tenant surfaces against 24 evidence points to guide Co-pilot and AI agent readiness.

Fabric went GA in GCC High on Oct 1, 2026; the Department of War suspended the CMMC Phase 2 transition in July. Nine checks to run before moving analytics.

Every defense contractor we have spoken with this quarter had a plan built around November 10, and the plan was a sprint…the suspension turns the sprint into a window.”— Errin O'Connor, Founder & Chief AI Architect, EPC GroupHOUSTON, TX, UNITED STATES, October 2, 2026 /EINPresswire.com/ — EPC Group, a Houston-headquartered Microsoft consultancy established in 1997, has issued a nine-point data-foundation checklist aimed at defense contractors considering Microsoft Fabric within GCC High. Microsoft achieved general availability for Fabric in its GCC High government cloud environment on October 1, 2026.

The Department of War halted the planned November 2026 progression to Phase 2 of the Cybersecurity Maturity Model Certification program on July 13, 2026, and has yet to announce a new start date. EPC Group’s advice: this suspension does not offer relief from NIST SP 800-171 obligations—it provides a planning opportunity for contractors to thoughtfully integrate their analytics estate within the compliance boundary instead of rushing to meet a deadline. The nine questions below should be answered in writing prior to provisioning the first Fabric capacity.

WHAT DID MICROSOFT MAKE AVAILABLE TODAY?

In a September 2, 2026 entry on the Microsoft US Government blog, Microsoft revealed that Microsoft Fabric in GCC High entered public preview on that date, with general availability set for October 1, 2026. Microsoft was clear regarding limitations: “feature availability at public preview and general availability will vary by workload and expand over time,” and “not all Microsoft Fabric capabilities will be available at launch,” advising readers to consult the Microsoft Learn supported-features list for specifics.

Douglas Phillips, President and Chief Technology Officer of Microsoft Specialized Clouds, offered a straightforward perspective on the launch: “The future of AI starts with data. With Microsoft Fabric in GCC High, government organizations can begin building that foundation today.”

Source for the Microsoft quotations above: https://www.microsoft.com/en-us/microsoft-cloud/blog/us-government/2026/09/02/microsoft-fabric-in-gcc-high-building-the-data-foundation-for-ai/

GCC High represents the Microsoft 365 and Azure Government environment that Microsoft targets at U.S. defense contractors and agencies managing Controlled Unclassified Information and export-controlled data. Fabric unifies OneLake, lakehouse and warehouse workloads, Real-Time Intelligence, data pipelines and Power BI under a single platform and capacity model within this environment, subject to the workload-specific availability Microsoft outlined.

That same week, during FabCon Europe in Barcelona, Microsoft’s Arun Ulag noted that “Fabric IQ in Copilot Chat and Cowork is generally available today” and that on-demand billing “expands consumption-based billing across Fabric workloads,” “automatically scaling resources up and down based on your demand.” Determining which of those commercial-cloud features reach GCC High, and when, is a critical question every contractor must address before designing around them—and each capability brings a governance decision: which semantic models are labeled before Copilot uses them, which actions an agent may take, and who monitors the meter.

Source for the Arun Ulag quotations: https://azure.microsoft.com/en-us/blog/fabcon-and-sqlcon-2026-in-barcelona-building-the-data-foundation-for-microsoft-copilot-and-agents/

WHERE DOES CMMC ACTUALLY STAND?

The CMMC acquisition rule, DFARS 252.204-7021, went into effect on November 10, 2025, phasing the requirement into contracts over three years. Phase 2—the stage where Level 2 third-party certification by a CMMC Third-Party Assessment Organization could become a contract award condition—was slated for November 10, 2026.

That transition is now on hold. In a July 13, 2026 memorandum, the Under Secretary of War for Acquisition and Sustainment ordered a pause on pending and future CMMC implementation milestones while a CMMC Reform Task Force evaluates the program. The Department’s implementing procedures state: “during this suspension the Department will enforce baseline compliance with NIST SP 800-171 Rev 2 through CMMC Level 1 and CMMC Level 2 self-assessment and select Government-led assessments.”

Source for the suspension and the quotation above: https://dodcio.defense.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf

A September 3, 2026 class deviation—DFARS Class Deviation 2026-O0025, Revision 3, issued by the Department’s Defense Pricing, Contracting, and Acquisition Policy office—made the suspension binding for contracting officers. As of now, the Department has not reinstated a Phase 2 start date.

Source: https://www.acq.osd.mil/dpap/dars/classdev/DFARS_RFO/Part-240/2026-O0025_Rev3_TAB_A_Deviation_Memo.pdf

What remains unchanged is the aspect most contractors underestimate. DFARS 252.204-7012 still mandates safeguarding covered defense information. NIST SP 800-171 Revision 2 continues as the assessed baseline. Self-assessment scores must still be submitted to the Supplier Performance Risk System, and the CMMC program rule at 32 CFR Part 170 stays in force. Any contractor interpreting the pause as permission to stop building evidence will face the same 110 requirements later, with less time available.

Sources: DFARS 252.204-7012 https://www.ecfr.gov/current/title-48/chapter-2/subchapter-H/part-252/subpart-252.2/section-252.204-7012 — NIST SP 800-171 Rev. 2 https://csrc.nist.gov/pubs/sp/800/171/r2/upd1/final — 32 CFR Part 170 https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-D/part-170

“Every defense contractor we have spoken with this quarter had a plan built around November 10, and the plan was a sprint,” said Errin O’Connor, Founder and Chief AI Architect of EPC Group. “The suspension turns the sprint into a window. Fabric arriving in GCC High is the opportunity: for the first time, ‘where does the evidence live’ can be answered with a governed analytics layer inside the boundary instead of a spreadsheet outside it. But an assessor—your own senior official affirming a self-assessment, or a C3PAO later—does not care how modern the platform is. It cares whether it is in scope, labeled, logged and owned.”

THE NINE-POINT CHECKLIST

EPC Group’s checklist targets contractors intending to migrate Power BI reporting, security telemetry analytics or program data into Fabric within GCC High during the pause. Each point requires a documented answer before the first capacity is provisioned.

Confirm the workload is actually available in GCC High today. Microsoft states availability varies by workload at general availability and expands over time. Check the Microsoft Learn supported-features list at https://learn.microsoft.com/en-us/fabric/enterprise/us-government-community-cloud-high for the specific items—lakehouse, warehouse, Real-Time Intelligence, data pipelines, mirroring, Copilot and Fabric IQ—that the design depends on. A design relying on a preview feature is a design that must wait.

Decide whether the Fabric workspace is inside the assessment scope. If Controlled Unclassified Information will reside in OneLake, the workspace, its capacity and its administrators fall within the Level 2 assessment boundary—self-assessed currently, third-party-assessed whenever the Department mandates it. Document that decision and the data-flow diagram now, while no one is requesting it.

Map identity before data. Fabric inherits Microsoft Entra identity in GCC High. Verify that conditional access, privileged identity management and the access-review cadence already required under NIST SP 800-171 extend to Fabric workspace roles, capacity admins and OneLake shortcuts. A shortcut to an external source represents an access path an assessor will follow.

Apply Microsoft Purview sensitivity labels to the semantic models and lakehouses that will contain CUI, and confirm that the Purview controls Fabric already supports in the commercial cloud—sensitivity-label inheritance, and data-loss-prevention policies with the restrict-access action on semantic models and lakehouses—are available in GCC High before depending on them.

Route Fabric and OneLake audit events into the logging and monitoring evidence trail. NIST SP 800-171 audit and accountability requirements do not exempt a new platform. Determine where Fabric activity logs will land, how long they are retained and who reviews them, and record this in the System Security Plan.

Set the capacity posture in writing. Microsoft’s capacity overage feature, currently in preview, bills excess compute at a multiple of the pay-as-you-go rate rather than throttling, with opt-in per capacity and an administrator-set daily limit. Decide, per capacity, whether overage is enabled or disabled and what the cap is, and designate the owner who reviews the Capacity Metrics app.

Treat agents as principals. Microsoft has previewed a data engineering agent and operations agents that operate from lists of pre-approved actions. In a CMMC-scoped environment, an agent is a non-human identity with an approved-actions list, an owner, a workspace scope and a log. Write the list before the agent exists.

Sequence the first workload by evidence value, not by ambition. The ideal first workload is one already generating a finding or a manual hand-off: a Power BI estate refreshing from file shares, or the consolidation of configuration, access-review and incident evidence into a single governed reporting layer for the assessment itself.

Plan the exit from the commercial cloud deliberately. Contractors with Power BI Premium or Fabric in the commercial tenant should document what moves, what is retired and what stays—with dates—so the boundary diagram an assessor reviews matches reality on the day it is requested, whenever that day occurs.

WHAT AN ASSESSOR WILL ASK ABOUT AN ANALYTICS PLATFORM

An assessor evaluating a Level 2 environment does not assess Fabric as a product; they assess the organization’s implementation of the 110 NIST SP 800-171 requirements across the systems in scope. For an analytics platform, the questions cluster into five families. Access control: who holds workspace, capacity and tenant-level roles, how they are reviewed, and whether shortcuts or mirrored sources create pathways to external data. Audit and accountability: which events the platform logs, where they are retained, for how long, and who reviews them.

Configuration management: how workspaces, capacities and connections are provisioned, documented and change-approved. Identification and authentication: whether every human and non-human identity—including agents—authenticates through the tenant’s identity provider under the same conditional-access rules as the rest of the environment. And system and information integrity: how sensitivity labels, data-loss-prevention policies and information-protection controls apply to the data the platform stores and to the AI experiences that read it.

A contractor that can answer those five families with documents rather than demonstrations positions the analytics estate as an asset in the assessment rather than an exception to it.

EPC Group’s publicly available 8-Surface Tenant AI Readiness Standard, TAR-8, was developed precisely for this ordering challenge. It scores the eight surfaces of a Microsoft 365 and Azure tenant that any AI or analytics deployment depends on—identity, information protection, oversharing, agent identity, external-model access, cost governance and the rest—and its gating rules require the underlying surface to be controlled before the workload relying on it is activated.

For a GCC High tenant, the eight surfaces map directly onto the five assessor question families above, which is why the firm recommends running the TAR-8 score before the first Fabric capacity is provisioned.

The standard is public at https://www.epcgroup.net/insights/microsoft-365-tenant-ai-readiness-8-surface-standard and the firm delivers it as a fixed-scope readiness assessment: https://www.epcgroup.net/services/microsoft-365-copilot-readiness-assessment

THE NINETY-DAY WINDOW, OCTOBER 1 TO DECEMBER 31

Given that the Department has not released a replacement schedule, EPC Group advises contractors to set their own timeline: the calendar quarter when Fabric became available, concluding before most Power BI Premium renewals come due. Days one through fifteen: review Microsoft’s supported-features list against the intended design, document the assessment-scope decision in writing, and inventory the commercial-tenant analytics estate that will move, retire or stay.

Days sixteen through forty-five: extend conditional access, privileged identity management and access reviews to Fabric roles; apply sensitivity labels to the semantic models and lakehouses that will hold CUI; route Fabric audit events into the existing evidence trail and record the retention decision in the System Security Plan. Days forty-six through seventy-five: provision the first capacity with a written overage posture and a named owner, migrate the first workload—the one already generating a finding—and document the data-flow diagram.

Days seventy-six through ninety: conduct an internal evidence review against the five question families, correct gaps, freeze the boundary diagram, and update the SPRS self-assessment score so the environment on record matches the one that was built.

The seven decisions a Fabric buyer should settle before a capacity renewal—including the GCC High-specific ones—are outlined in EPC Group’s companion analysis released today.

WHAT EPC GROUP’S RECORD IN THIS SPACE ACTUALLY IS

EPC Group separates third-party facts from company-reported figures and applies that standard to itself. The firm holds all six Microsoft Solutions Partner designations, verifiable through Microsoft’s partner directory. It has been recognized as a G2 Leader in Business Intelligence Consulting for seven consecutive quarterly reports through Fall 2026 and received a Fall 2026 Momentum Leader badge—designations G2 calculates from verified client reviews and market-presence data. Source: https://www.g2.com/products/epc-group/reviews

Company-reported, from EPC Group’s own records: over 1,500 Power BI deployments and more than 500 Microsoft Fabric implementations since 1997, within over 11,000 enterprise engagements. The subset of engagements documented with claim levels and hashed source files—including federal, defense and public-sector records for NASA Johnson Space Center, the National Institutes of Health, the Federal Reserve Bank of New York, Northrop Grumman and Texas state agencies—is published, with a methodology page explaining what each record does and does not establish, in the firm’s Evidence Center: https://www.epcgroup.net/evidence-center

Defense contractors and agencies wanting the nine points applied to their own tenant can request a GCC High, Fabric and CMMC scoping call at


David Hall

David Hall

David is the senior editor at TheCyberMag. He has a background in journalism and has worked with various media outlets, covering topics ranging from threat intelligence and data privacy to cybercrime and cloud security. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.