Skip to content
All insights
AlignCross-platformBuying GuideJuly 16, 2026

CMMC and your ERP: why permissions alone won't pass an audit

A couple weeks back we sat down with a team standing up the US arm of a European additive manufacturing company. They make parts for defense and aerospace, which means they're dealing with controlled data from day one. Their instinct on the ERP was reasonable on the surface: put everything in one system, then use user permissions to control who sees the sensitive material. It's clean, it's convenient, and it avoids juggling multiple systems. It also won't hold up in an audit.

If you're an operations or finance leader in the defense supply chain evaluating an ERP, this is worth understanding before you commit, because the fix is a lot cheaper to design in early than to retrofit later.

Permissions control access, not storage

Here's the distinction that trips people up. ITAR (International Traffic in Arms Regulations) and CUI (Controlled Unclassified Information) rules care about where the data physically lives in the cloud, not just who can click on it. Role-based permissions decide whether a given user can view a record. They don't change the underlying infrastructure where that record is stored.

So if your controlled data is sitting in a commercial cloud environment and you've simply hidden it behind permissions from your overseas colleagues, an auditor is going to look at the storage boundary, not your permission matrix. The convenience of one system does not survive that review.

Permissions won't cut it. It's the underlying infrastructure where the data is stored that matters for passing an audit.

The GCC High question for Microsoft shops

Microsoft offers government community cloud environments (often called GCC High) built to handle this class of data. But not every Microsoft product has a compliant flavor. Business Central, for example, does not currently have a GCC High equivalent. That's not a knock on the product, it's a scoping fact you need to know going in.

When a client needs both a working ERP and a compliant home for controlled material, one pattern we've seen work is running them as separate worlds on purpose:

  • A commercial ERP and Microsoft 365 tenant for daily production, finance, and collaboration, with all the native integrations you'd expect.
  • A separate GCC High tenant used only for the activities that touch controlled data, treated almost like a secure room you enter when needed rather than your daily driver.
  • Deliberately loose links between the two (for example, a reference to a document rather than a live API connection), so the compliance boundary stays intact.
DESIGN IT EARLY

The compliance boundary is far easier and cheaper to build into your platform decision up front than to bolt on after you've picked a system and loaded it with data.

When one platform can't do it all

There's a trade-off in the two-worlds approach: it's less convenient than a single system. Some teams decide that friction is worth it to keep a simpler, lower-cost ERP. Others find their needs (multi-entity automation, multi-currency, tighter integration of controlled data) push them toward a heavier platform. Neither answer is wrong. The point is to make that call knowing the compliance rules drive it, not the other way around.

Talk it through

If you're building out a defense or aerospace operation and trying to figure out where your controlled data should actually live, we're glad to walk through the options with you and help you see the trade-offs clearly. Reach out any time and we'll talk it through.

See where you stand. Then move forward.

Book a free intro call. We'll talk through where you are today and map a plan for growth, protection, automation, and alignment.

30 minutesNo obligationGet an initial estimate within one week