Skip to main content
AI Mode

How does Direct Routing for GCC High satisfy the voice communication requirements in DFARS 7012 and CMMC 2.0?

Direct Routing for GCC High satisfies DFARS 7012 and CMMC 2.0 voice requirements by routing all call traffic through FedRAMP High-authorized infrastructure, encrypting signaling and media, restricting data storage to U.S.-only facilities, and limiting access to screened U.S. personnel. These controls map directly to the NIST SP 800-171 requirements that both frameworks reference.

DFARS 252.204-7012 requires contractors to use cloud service providers that meet FedRAMP authorization for storing, processing, and transmitting covered defense information. GCC High holds FedRAMP High authorization, which satisfies this requirement for voice communications routed through Direct Routing. The 110 security controls in NIST SP 800-171, which CMMC Level 2 requires, include access control, audit and accountability, identification and authentication, and system and communications protection. Direct Routing in GCC High addresses these by enforcing role-based access through Microsoft Entra ID, maintaining audit logs of call activity, supporting multifactor authentication (including PIV and CAC cards), and encrypting all call traffic within the compliance boundary using TLS and SRTP. DFARS 7012 also requires contractors to flow these requirements down to subcontractors, which means subcontractors handling CUI in voice communications need the same level of compliant infrastructure.