# Defense Contractors Implement CMMC Level 2

Discussion of CMMC Level 2 implementation indicates that organizations with committed IT staff may find the work manageable, but preparing system security plan (SSP) documentation and aligning policies and procedures can require substantial effort. Legacy equipment and business processes may increase implementation difficulty, while Microsoft GCC High may help organizations with ITAR-related needs and control inheritance; for other organizations, it may provide limited advantages over GCC.

- Contractors should assess the effort needed to document their SSP and align internal policies and procedures when planning CMMC Level 2 implementation.
- Organizations with legacy systems or processes should account for potential remediation and process changes, rather than assuming implementation will be a straightforward enclave build.
- Companies evaluating Microsoft GCC High should weigh its potential ITAR-related and control-inheritance benefits against their specific needs and compare them with GCC.

**Jurisdictions:** federal
**Industries:** Defense & Military, Information Technology
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** October 08, 2026

### Vendors
- Microsoft ()

### Key Quotes
> The most difficult part for many orgs is taking the time to write out their SSP and make sure policies & procedures align properly.
> — Original poster

> Its not complicated until you have legacy gear and business process that have to change... not everything is a greenfield enclave build
> — Community commenter

### Sources
- [CMMC issues](https://www.reddit.com/r/CMMC/comments/1x0ekmt/cmmc_issues) - reddit-cmmc