Most people arrive at this topic through a document. A customer sends a security questionnaire. An auditor asks for evidence. A contract clause turns up in a renewal. And somewhere in the conversation that follows, someone says the organization needs to "be compliant," and asks which Microsoft licenses to buy.
No license makes you compliant. Microsoft sells capability. Compliance is something your organization does with that capability, documents, and then demonstrates to a third party. That distinction determines what you are buying and what work remains after the purchase order clears.
What follows covers the four regimes Wired CIO works in most often, where the capabilities live in the licensing tiers, and the decisions that are hard to undo.
Microsoft sells capability, not compliance
Microsoft says this itself, in the documentation it publishes for each regime.
On the Health Insurance Portability and Accountability Act (HIPAA), Microsoft states that signing a Business Associate Agreement helps support your compliance, but that using Microsoft services does not on its own achieve HIPAA compliance. On the Food and Drug Administration's electronic records rule, Microsoft notes that no certification exists for it at all, and that customers who build applications subject to FDA regulation are responsible for ensuring those applications meet FDA requirements. On the Cybersecurity Maturity Model Certification (CMMC), Microsoft's guidance opens by saying compliance depends on customer configuration, implementation, and operational controls, as well as on qualified assessors.
None of that is hedging. It is an accurate description of how these regimes work. The regulator or the auditor examines your organization, your processes, and your evidence. The platform is one input.
Shared responsibility in plain terms
Cloud services split the work. Microsoft is responsible for the security of the cloud: the datacenters, the hardware, the service code, and the operational controls it has audited. You are responsible for security in the cloud: who has accounts, what those accounts can reach, how data is classified and retained, what devices connect, and whether anyone is reviewing any of it.
Microsoft publishes a shared responsibility model mapping this out by service type. The practical version is shorter: identity, data, configuration, and process are yours in every model, and in every regime below they are where most audit findings land.
There is a useful detail in Microsoft's audit reports on this point. At the end of a System and Organization Controls (SOC) 2 report is a section titled "User Entity Responsibilities," listing the controls you have to operate for the overall system to meet the standard. It is worth reading before your auditor reads it back to you.
The four regimes, briefly
FDA 21 CFR Part 11, meaning Title 21, Part 11 of the United States Code of Federal Regulations (CFR), governs electronic records and electronic signatures in life sciences. It applies to FDA-regulated research, clinical study, manufacturing, and distribution. It requires that electronic records be trustworthy substitutes for paper, that systems carry audit trails for data values, that electronic signatures have integrity, and that systems be validated and documented as doing what they are meant to do. There is no certification for it. Microsoft's position is that its SOC 1 and SOC 2 Type 2, ISO/IEC 27001, and ISO/IEC 27018 audits can be used as inputs to your own validation effort, and it publishes guidance for regulated life sciences workloads on Azure.
CMMC is the Department of Defense's framework for contractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). It has three levels, built on well-established standards from the National Institute of Standards and Technology (NIST). Its rollout status changed materially in July 2026, which is covered further down.
HIPAA governs the use, disclosure, and safeguarding of individually identifiable health information. It applies to covered entities, meaning healthcare providers, health plans, and clearinghouses, and to their business associates. A cloud service handling protected health information becomes a business associate too, which is why the Business Associate Agreement exists.
SOC 2 is not a regulation. It is an attestation performed by an independent accounting firm against the American Institute of Certified Public Accountants' Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. No law requires it. Customers do, usually in a procurement questionnaire and increasingly as a condition of the contract.
What auditors ask for, and what proves it
It is more useful to think in terms of the question being asked than the product being sold. Across all four regimes, the questions rhyme.
| The question an auditor or customer asks | The capability that answers it |
|---|---|
| Who accessed this record, and when? | Tenant-wide activity logging, kept long enough to cover the investigation: Microsoft Purview Audit, Standard and Premium |
| Can you produce records from three years ago, and show none were altered or deleted? | Retention policies, retention labels, and legal hold |
| Do you know where your sensitive data is, and is it marked? | Classification and sensitivity labeling |
| What stops someone emailing a patient list to a personal account? | Data loss prevention, across email, files, and endpoints |
| Would you notice an employee downloading everything before resigning? | Insider risk management |
| Can you find and export everything relevant to a legal matter? | eDiscovery, Standard and Premium |
| Who can sign in, from where, and on what device? | Conditional Access |
The first two deserve special attention. Audit logging tells you what happened; retention and hold tell you the record still exists to be examined. Everything else on that list can be reconstructed with effort. Those two cannot be reconstructed at all if they were not turned on at the time.
Where the capabilities sit in the licensing tiers
This is the part that surprises people, and it is worth being direct. A meaningful share of the compliance capability lives in the top Enterprise tier, Microsoft 365 E5, or in a specific add-on, rather than in Microsoft 365 Business Premium.
As of July 2026 the enterprise lineup is E3, E5, and a newer top bundle called E7, which packages E5 with Microsoft 365 Copilot and other components. For compliance purposes E5 remains the tier where the capabilities live, and E7 includes E5. Current contents and pricing are in the enterprise plan comparison and the small and medium business plan comparison. Broadly, according to Microsoft's Purview service description:
Available at Business Premium and E3:
- Audit (Standard), enabled by default
- Retention policies and retention labels, including publishing labels for manual use
- Manual sensitivity labeling
- Data loss prevention for Exchange Online, SharePoint Online, and OneDrive
- Conditional Access, which requires Microsoft Entra ID P1 and is explicitly available to Business Premium customers
Requires E5 or a specific add-on:
- Audit (Premium), which is where longer log retention lives
- Automatic and policy-based sensitivity labeling, including trainable classifiers
- Endpoint data loss prevention, meaning data leaving via a laptop rather than via email
- Insider risk management
- eDiscovery (Premium)
- Adaptive policy scopes for retention
The pattern is consistent. Business Premium gives you the ability to do the thing manually and for a person to configure it. E5 gives you the ability to do it automatically, at scale, and to keep the evidence longer.
What a smaller business can do about it
Moving an entire organization to E5 to satisfy one clause in one contract is rarely proportionate. There are three routes that usually are.
Buy the add-on rather than the tier. Microsoft sells Purview capability as add-ons that sit on top of a Business Premium base, described in the service description as Microsoft Purview Suite for Business Premium and Microsoft Defender + Purview Suite for Business Premium. They require a Business Premium base license and are capped at 300 seats in total. For a company under that ceiling, this is usually the shortest path to Audit (Premium) and the wider Purview set without changing the underlying plan.
License by role rather than by headcount. Several of these capabilities are licensed per user who benefits from the service. If the regulated work is done by 12 people in quality and regulatory affairs, the licensing conversation can start there rather than at the whole company. The rules on who counts as benefiting are specific and worth checking per capability, because for some solutions the affected population is broader than the team operating the tool.
Solve some of it outside the license. Audit records can be exported programmatically into a system where you already keep long-term data. That trades a licensing cost for an engineering and operating cost, which is sometimes the right trade. It is worth pricing both.
None of these are shortcuts around a requirement. They are ways of scoping the purchase to the obligation.
The Business Associate Agreement for HIPAA
If HIPAA applies to you, this part is more straightforward than expected.
Microsoft offers a HIPAA Business Associate Agreement to its covered entity and business associate customers, and it is available through the Microsoft Online Services Data Protection Addendum by default. It covers the standard commercial cloud, not only a government or specialized environment, and the in-scope services list is long: Azure, Microsoft 365 and Office 365, Dynamics 365, Microsoft Intune, Windows 365, Power Apps, Power Automate, and Power BI among them.
Three things to know. Microsoft will not sign your organization's own Business Associate Agreement template, because the service is standardized across all customers. Microsoft's Business Associate Agreement document is published and can be reviewed by your counsel. And, as Microsoft states in its own frequently asked questions, having the agreement does not make your organization HIPAA compliant. It establishes what Microsoft is responsible for.
The government cloud decision for defense work
If your work touches Department of Defense contracts, one architectural decision has to be made early, because reversing it is genuinely difficult.
Microsoft operates the commercial cloud, a Government Community Cloud (GCC), and a Government Community Cloud High (GCC High). These are different environments, not different price tiers of the same thing.
According to Microsoft's own service description and CMMC guidance:
- Commercial supports CMMC Level 1 requirements, and Microsoft describes Federal Risk and Authorization Management Program (FedRAMP) High authorization for some services.
- GCC provides compliance with the Defense Federal Acquisition Regulation Supplement (DFARS) and the relevant federal cloud requirements, with customer content stored in the United States and access restricted to screened Microsoft personnel.
- GCC High supports CMMC Level 2 and Level 3 requirements when configured appropriately, along with DFARS and the International Traffic in Arms Regulations (ITAR).
The dividing line Microsoft draws is specific: GCC is not suitable to hold what is called CUI Specified, which includes export-controlled categories such as ITAR data, and Microsoft states that it will only agree to ITAR contract language for the GCC High environment. The determining factor is the category of controlled information in your contracts, not a general sense of how careful you would like to be.
Two consequences follow, and both are commercial.
Cost and functionality differ significantly. The government environments cost more than commercial and do not have feature parity with it. Microsoft's own guidance acknowledges the parity gap and argues some of it is deliberate. Features arrive later, and some do not arrive at all. That is an operating constraint for the whole business, not only for the regulated team.
Migrating later is a project, not a setting. Microsoft's own guidance advises allocating at least three months for the migration phase, and the process resembles migrating from any other cloud rather than flipping a switch. Mailboxes, files, identities, and integrations all move. Choosing commercial now and GCC High in 18 months means doing the work twice.
There is a middle path. Some organizations put only the regulated work in GCC High, as a data enclave, and leave everything else in commercial. Microsoft's guidance is even-handed on this: an enclave can reduce cost compared with moving everyone, but it notes that the most common way controlled data leaves the boundary is through personal storage and email, which sit outside the enclave. If you go that route, the boundary needs to be designed rather than assumed.
Where the CMMC program stands as of July 2026
This is a moving target, and anything written about CMMC ages quickly. As of this writing:
Phase 1 began on November 10, 2025, requiring CMMC Level 1 and Level 2 self-assessments on applicable contracts. Phase 2, which would have made third-party certification mandatory from November 10, 2026, was suspended with immediate effect on July 13, 2026, along with the later phases, and a reform task force reporting to the department's Chief Information Officer was asked to review the program and report back within about 60 days. This was reported by Federal News Network and analyzed by government contracts counsel.
What has not changed is more important than what has. DFARS 252.204-7012 remains in effect, and with it the requirement to implement the 110 security controls in NIST Special Publication 800-171 for covered defense information, plus cyber incident reporting. The Federal Acquisition Regulation (FAR) basic safeguarding requirements at 52.204-21 remain. Level 1 and Level 2 self-assessments and annual affirmations remain.
The practical reading for a business owner: the certification appointment has been postponed, and the underlying security requirements have not. Work done now against NIST Special Publication 800-171 is not wasted. Waiting for the program to settle before starting the control work is a bet on a timeline nobody currently controls. If certification timing affects a specific bid, confirm the current position against the contract language in front of you rather than against anything written earlier, including this.
Documentation Microsoft publishes that you can hand an auditor
You do not have to build evidence about Microsoft's own controls. Microsoft has it audited and publishes it on the Service Trust Portal: independently audited compliance reports, including SOC 1 and SOC 2 Type 2 reports, ISO certifications, and related documentation your auditors can compare against your own requirements. Access requires an existing subscription or free trial account, a condition set by the accounting profession rather than by Microsoft. Azure customers can also retrieve Azure certificates and audit reports from within the Azure portal.
Two details that make these reports more useful:
- Microsoft commissions a full SOC 1 and SOC 2 Type 2 examination annually, covering a rolling 12-month window that runs October 1 to September 30. Reports are issued a few months after the period closes.
- For the gap between the end of an audited period and the next report, Microsoft issues quarterly bridge letters, which are self-attestations covering the intervening months. If your auditor asks for coverage of a period that the latest report does not reach, the bridge letter is the answer.
Microsoft also publishes Purview Compliance Manager, with assessment templates for HIPAA, CMMC, FDA 21 CFR Part 11, and many others. It is a useful scoping and tracking tool. It is not an attestation, and no score inside it means anything to an auditor on its own.
Gotchas that catch non-technical buyers
- Audit log retention only surfaces during an incident. Audit (Standard) retains records for 180 days. If you discover in month eight that something happened in month two, the record may be gone, and no purchase made afterward brings it back. Longer retention is an Audit (Premium) capability, and the 10-year retention option requires a separate per-user add-on that is explicitly not retroactive. This is the licensing decision people most regret making late.
- Retention on top of Audit (Premium) is not uniform. Microsoft Entra ID, Exchange, OneDrive, and SharePoint get one year by default. Other services default to 180 days unless someone creates a retention policy.
- "We have E5" is not the same as "the licenses are assigned." Several of these capabilities apply per user with the appropriate license assigned. A tenant-wide purchase with unassigned licenses produces gaps that only appear when you go looking for the record.
- Turning a capability on is not the same as configuring it. Data loss prevention with no policies, or insider risk management with no scenarios, is a line item, not a control. Auditors ask what the policy says and who reviews the alerts.
- The government cloud decision is effectively one-way. Choose the environment based on the categories of controlled information in your contracts, and make the decision before you migrate, not after.
- A partner and an auditor are different roles. Wired CIO can design, implement, document, and operate the controls, and prepare the evidence you hand over. We do not issue attestations, certify compliance, or provide legal advice, and no IT partner can. The assessor's independence is part of what makes the assessment worth anything, so the two roles are kept separate by design.
Where to start
The productive first conversation is rarely about licenses. It is about the specific obligation: the clause in the contract, the question on the questionnaire, or the finding from the last assessment. From there the mapping is usually quick, because most of it comes down to which records you must be able to produce, how far back, and who has to be prevented from doing what.
If you have a customer questionnaire open on your desk, or a contract that just added a clause you have not seen before, bring us the document. Wired CIO works as a fully managed or co-managed IT partner, and we will walk through what your current licensing covers, what it does not, and what the gap costs to close.