The Department of Defense Cloud Computing SRG Impact Levels are the four tiers — IL2, IL4, IL5, and IL6 — that the DoD uses to categorize cloud-hosted data by sensitivity and to set the security controls a cloud service provider must meet before the Defense Information Systems Agency will authorize it to host that data. The levels run from publicly releasable information at IL2 up to Secret-classified national security data at IL6, and the requirements grow substantially at each step: more isolation, tighter personnel rules, heavier documentation, and longer authorization timelines.
The Four Impact Levels
The Cloud Computing Security Requirements Guide defines four levels. There is no Impact Level 3. When the SRG was developed, what would have been a separate third tier was folded into IL4, and the numbering has stayed that way ever since.
IL2: Publicly Releasable Information
IL2 covers data already cleared for public release, such as recruiting materials or unclassified technical manuals approved for distribution. Because there is no confidentiality requirement, standard commercial cloud security practices are generally sufficient, and the tier aligns closely with the FedRAMP baseline used across civilian agencies. A breach here would not compromise military operations or expose sensitive personnel data.
IL4: Controlled Unclassified Information
IL4 applies to Controlled Unclassified Information that federal law or executive orders shield from public disclosure. Personnel records, health data, and certain export-controlled technical information sit at this level. None of it is classified, and none of it directly supports active military missions, but unauthorized access could trigger legal liability or compromise individual privacy. Providers must demonstrate logical separation between their government and commercial tenants, and all infrastructure must be located within the United States.1Whole Building Design Guide. DoD Cloud Computing SRG Impact Levels and Authorization Process
IL5: Mission-Critical CUI
IL5 is the highest tier for unclassified data. It covers CUI that directly supports military missions: troop movement logistics, weapons systems maintenance schedules, operational planning data. The information is not officially classified, but it could give an adversary a meaningful advantage if compromised. The jump from IL4 to IL5 is significant. Providers must physically separate DoD workloads from all non-federal tenants; only logical separation is permitted between DoD and other federal government tenants.2Microsoft Learn. Department of Defense Impact Level 5 – Azure Compliance
The line between IL4 and IL5 hinges on whether the data is mission-critical. Mission-critical data is anything whose loss or corruption would directly impair military operations or endanger personnel. Non-mission-critical data supports administrative functions like human resources, payroll, or supply chain management for non-deployed units. Getting the categorization wrong means either overspending on security infrastructure that isn’t needed or, worse, hosting sensitive operational data in an environment that isn’t hardened enough to protect it.
IL6: Classified at the Secret Level
IL6 handles information classified at the Secret level. Unauthorized disclosure could cause serious damage to national security. Everything processed at this tier is treated as a National Security System, and only dedicated, physically isolated hardware in highly secure facilities can host it. The personnel, facility, and oversight requirements make IL6 the most resource-intensive level to achieve and to maintain.3Microsoft Learn. Department of Defense (DoD) Impact Level 6 (IL6)
How Requirements Scale Across the Levels
The foundation for all four tiers is a framework called FedRAMP+: the FedRAMP security control baselines plus DoD-specific enhancements documented in the SRG.4The MITRE Corporation. FedRAMP – A Practical Approach The underlying controls are drawn from NIST Special Publication 800-53.5National Institute of Standards and Technology. NIST SP 800-53 Rev 5 For IL5, the minimum starting point is a FedRAMP High provisional authorization, supplemented by additional DoD controls and enhancements.2Microsoft Learn. Department of Defense Impact Level 5 – Azure Compliance What changes as you climb the tiers is how strictly those controls have to be implemented.
Infrastructure Isolation
At IL4, logical separation through software-defined networking and encrypted containers can be enough to keep government data apart from commercial tenants. At IL5, physical separation from all non-federal tenants is mandatory, with logical separation permitted only between DoD and other federal workloads. At IL6, the infrastructure must be entirely dedicated to classified workloads, with no shared resources of any kind.
Personnel
The SRG restricts who can touch systems hosting DoD data. At IL5, anyone with access must be a U.S. citizen, U.S. national, or U.S. person, and no foreign nationals may have access under any circumstances.2Microsoft Learn. Department of Defense Impact Level 5 – Azure Compliance At IL6, citizenship restrictions tighten further, and personnel must hold active security clearances appropriate to the classification level of the data they manage.3Microsoft Learn. Department of Defense (DoD) Impact Level 6 (IL6) These are federally administered investigations, not internal vetting a provider can substitute, and staffing around them is one of the more time-consuming aspects of standing up a compliant environment.
Cryptography and the FIPS 140-3 Transition
All data at rest and in transit must be protected by encryption modules validated through the Cryptographic Module Validation Program. Unvalidated encryption is treated as providing no protection at all.6National Institute of Standards and Technology. Cryptographic Module Validation Program The active concern for providers building today is the transition from FIPS 140-2 to FIPS 140-3. All FIPS 140-2 validation certificates move to the historical list on September 22, 2026. Modules on the historical list remain usable in existing systems, but new deployments should target FIPS 140-3 validated modules.7National Institute of Standards and Technology. FIPS 140-3 Transition Effort Any provider standing up a new offering for DoD authorization in 2026 or later should confirm its cryptographic modules carry FIPS 140-3 validation rather than legacy 140-2 certificates.
Data Sovereignty
All infrastructure supporting IL4 and above must be located within the United States.1Whole Building Design Guide. DoD Cloud Computing SRG Impact Levels and Authorization Process Operations outside the continental U.S. add complexity: host nation regulations can conflict with DoD sovereignty requirements, and any overseas data center requires negotiated agreements between the U.S. government and the host nation.8Department of Defense. DoD Outside the Continental United States (OCONUS) Cloud Strategy
Where CMMC Fits, and Where It Doesn’t
The Cybersecurity Maturity Model Certification program and the Cloud Computing SRG serve different purposes, and treating them as interchangeable is a common mistake. CMMC applies to defense contractors handling CUI. It assesses a contractor’s cybersecurity practices. It does not certify cloud platforms.9Microsoft Learn. Cybersecurity Maturity Model Certification (CMMC)
The intersection is narrow: if a defense contractor stores or processes CUI in a cloud environment, that cloud service must hold at least a FedRAMP Moderate authorization.10DoD CIO. Technical Application of CMMC Requirements A CMMC certification is not a substitute for the DoD Provisional Authorization process. A cloud provider still needs its own SRG authorization, and the defense contractor using that cloud still needs its own CMMC certification.
Earning and Keeping the Authorization
Once a provider knows the Impact Level it is targeting, the rest of the work is documentation, third-party assessment, DISA review, and continuous monitoring for the life of the authorization.
The Documentation Package
The System Security Plan sits at the center. It maps every required control to the provider’s specific implementation, including system architecture diagrams, network boundary definitions, data flow paths, and physical server locations.11DoD Procurement Toolbox. System Security Plan and Plans of Action Development Guide Auditors will hold the provider to exactly what the SSP says. Alongside the SSP, an accredited Third-Party Assessment Organization tests every control and produces a Security Assessment Report. Any weakness goes into a Plan of Action and Milestones with remediation deadlines tied to severity.4The MITRE Corporation. FedRAMP – A Practical Approach
Supply chain dependencies belong in the package too. If a platform-as-a-service offering runs on another provider’s infrastructure, that layered relationship must be documented in full. A cloud offering that leverages another provider’s authorized service can lose its own authorization if the underlying provider loses theirs.12Defense Information Systems Agency. Cloud Service Provider Security Requirements Guide
DISA Review and the Provisional Authorization
The complete package goes to DISA’s Cloud Assessment Division. An initial intake review confirms every required document is present; incomplete packages get returned before substantive evaluation. Technical review follows, with back-and-forth requests for clarification. Timelines vary with system complexity and Impact Level, but the process commonly takes several months and can stretch beyond a year at higher tiers.
The end product is a Provisional Authorization. A PA signals that the DoD considers the risk of using the cloud service acceptable at a given Impact Level. It does not award a contract. It places the provider on the approved list so that individual military branches and agencies can issue their own Authorizations to Operate on top of it, often adding mission-specific requirements. The PA is the floor, not the ceiling.
Continuous Monitoring and Revocation
Authorization is not a one-time event. Providers must maintain continuous monitoring and submit regular security reports feeding into DoD systems that give the government near-real-time visibility into the security posture of authorized environments.13SAM.gov. Continuous Monitoring and Risk Scoring (CMRS) Request for Information The DISA Authorizing Official can revoke a PA if the provider loses its underlying FedRAMP authorization, fails to maintain SRG compliance or contract obligations, or makes changes affecting the system’s risk posture without approval.12Defense Information Systems Agency. Cloud Service Provider Security Requirements Guide The government also retains the right to conduct unannounced audits at any point during the authorization lifecycle.
What Noncompliance Costs
Losing authorization or misrepresenting compliance carries consequences beyond removal from the approved list.
Under the Federal Acquisition Regulation, the government can terminate a contract for default when a contractor fails to perform. If a contract requires the provider to maintain a DoD Provisional Authorization and the PA is lost, the contracting officer has grounds to terminate. Providers typically receive a written cure notice with at least 10 days to fix the problem. If the problem is not resolved, the government can terminate, reprocure the services from another provider, and hold the original provider liable for excess costs.14Acquisition.gov. FAR Subpart 49.4 – Termination for Default
Providers that misrepresent compliance with DoD cybersecurity requirements face potential liability under the False Claims Act. The Department of Justice’s Civil Cyber-Fraud Initiative specifically targets contractors who falsely certify that they meet required security standards to receive payment. Liability under the FCA can reach three times the government’s actual damages plus per-claim penalties. No court has yet ruled on the merits of an FCA cybersecurity case through trial, but DOJ has signaled through settlements and public statements that this is an active enforcement priority.
The January 2025 Cloud Computing SRG also makes explicit that if a provider loses its PA and refuses or is unable to correct the underlying problem, that situation may constitute a breach of contract.12Defense Information Systems Agency. Cloud Service Provider Security Requirements Guide Revocation and breach can run in parallel: the authorization loss removes eligibility for DoD work, while the breach determination opens the door to contract remedies including damages.
Time and Cost to Expect
The financial investment scales with Impact Level. The third-party assessment alone represents a significant line item. For FedRAMP Moderate environments, which underpin many IL4 engagements, independent assessment costs commonly run into six figures. High-impact assessments supporting IL5 cost more, reflecting the additional controls and the complexity of physically isolated infrastructure.
Beyond the assessment itself, budget for the engineering work to implement FedRAMP+ controls, the personnel costs of maintaining a U.S.-citizen-only operations staff with appropriate clearances at higher levels, legal costs of documentation preparation, and the ongoing expense of continuous monitoring. The authorization process itself can consume a year or more of calendar time, during which the provider is spending without DoD revenue. First-time entrants routinely underestimate both timeline and total cost, particularly at IL5 and above where physical infrastructure isolation eliminates the cost efficiencies of shared cloud resources.