DoD Impact Level 2 (IL2): Data Scope, Baseline, and FedRAMP Reciprocity

DoD Impact Level 2 requirements are set by the Defense Information Systems Agency’s Cloud Computing Security Requirements Guide, and they boil down to two things: meet the FedRAMP Moderate security baseline from NIST Special Publication 800-53, and satisfy the personnel security items called out in the CC SRG. Because DoD grants full reciprocity at this level, a cloud service offering that already holds a FedRAMP Moderate or High authorization can qualify for an IL2 provisional authorization without going through a separate DoD security assessment.1Microsoft Learn. Department of Defense (DoD) Impact Level 2 (IL2) – Azure Compliance That reciprocity is what makes IL2 the most accessible entry point into the defense cloud market.

What Data IL2 Actually Covers

IL2 is the lowest tier in the DoD impact level framework. It covers two categories of information. The first is data that has been formally cleared for public release by the Defense Office of Prepublication and Security Review, which screens materials to confirm they contain no classified, export-controlled, or operationally sensitive content before approving distribution.2Defense Office of Prepublication and Security Review. Frequently Asked Questions for Department of Defense Prepublication Security and Policy Reviews The second is non-public unclassified data where unauthorized disclosure would cause only limited harm, such as general administrative information or routine mission support data that has not been tagged as Controlled Unclassified Information.3Department of Defense Chief Information Officer. DoD Cybersecurity Reciprocity Playbook

What you cannot place at IL2: anything marked as CUI, any classified material, and any critical military or contingency operations data. Those categories require IL4 (CUI), IL5 (CUI and National Security Systems data, U.S.-based infrastructure and personnel), or IL6 (classified up to Secret). Because CUI markings are sometimes inconsistent across DoD components, mission owners should resolve any classification doubt before placing data in an IL2 environment.1Microsoft Learn. Department of Defense (DoD) Impact Level 2 (IL2) – Azure Compliance Typical IL2 workloads include public-facing websites, general administrative tools, and non-sensitive mission support applications.

One historical note worth clearing up: Impact Level 3 was eliminated years ago, and its requirements were folded into IL2. References to IL3 in older documents should be treated as IL2.

The Security Baseline

The IL2 security baseline is FedRAMP Moderate, drawn from NIST 800-53. The CC SRG is explicit that DoD will not separately assess those controls for an IL2 provisional authorization — FedRAMP Moderate is both the floor and the ceiling.1Microsoft Learn. Department of Defense (DoD) Impact Level 2 (IL2) – Azure Compliance4Cloud Information Center. Cloud Security

Under NIST 800-53 Rev 5, the Moderate baseline spans several hundred controls across access management, audit logging, incident response, system integrity, and other security families. Providers must implement each applicable control and document how their environment satisfies it. Audit logging draws particular scrutiny: every administrative action within the cloud environment must be recorded, and logs must be retained long enough to support forensic review after a security incident.

Personnel security is the piece that catches providers off guard. Section 5.6.2 of the CC SRG lays out personnel security requirements that apply even at IL2.1Microsoft Learn. Department of Defense (DoD) Impact Level 2 (IL2) – Azure Compliance These are less restrictive than what IL4 or IL5 impose, but they exist, and reciprocity does not cover them. Providers still need to verify that staff with access to the environment meet the applicable screening criteria.

How FedRAMP Reciprocity Works at IL2

IL2 stands apart from every other impact level on this point. DoD grants full reciprocity with FedRAMP Moderate and High authorizations, which means a provider holding either does not repeat the security control assessment for IL2.3Department of Defense Chief Information Officer. DoD Cybersecurity Reciprocity Playbook The CC SRG puts it bluntly: the IL2 requirements “will not be extra assessed” beyond what FedRAMP already evaluated.1Microsoft Learn. Department of Defense (DoD) Impact Level 2 (IL2) – Azure Compliance

Reciprocity is not zero effort. The provider still owes the CC SRG personnel security items, and the mission owner selecting the service remains responsible for confirming the offering fits their specific data. Before relying on a vendor, check the FedRAMP Marketplace and confirm the authorization covers the specific cloud service offering you plan to use, not just the vendor’s broader portfolio.

Getting Authorized Without an Existing FedRAMP ATO

If a provider does not hold FedRAMP authorization, the second path is DoD sponsorship: a DoD component sponsors the cloud service offering for a provisional authorization directly through DISA.5Cyber Exchange. DoD Cloud Computing Security The request goes through the DoD Cloud Authorization Services (DCAS) team, which schedules an initial contact meeting with the sponsor and the provider to determine the best path forward.6Defense Information Systems Agency. DoD Cloud Authorization Process

The provider then submits an authorization package. Its core is the System Security Plan, which functions as the security blueprint for the entire cloud service — architecture, data flows, control implementations, and authorization boundary.7FedRAMP. System Security Plan (SSP) The Security Assessment Plan describes the testing methodology and is signed by both the provider and the independent assessor before testing begins.8FedRAMP. Security Assessment Plan (SAP) Any weaknesses identified during testing go into a Plan of Action and Milestones, with a remediation entry for every risk in the assessment report.9FedRAMP. Plan of Action and Milestones (POA&M) For DoD submissions, the package also includes a DoD SSP Addendum and a CSO Architecture Brief, filed through the Cloud eMASS system.6Defense Information Systems Agency. DoD Cloud Authorization Process

A Third-Party Assessment Organization runs the independent assessment. For FedRAMP Moderate, 3PAO fees typically fall between $125,000 and $195,000, with higher costs for more complex environments. The complete package goes to DISA’s joint validation team for review. Well-prepared packages with mature documentation can reach authorization in roughly three to six months; packages with significant gaps require remediation cycles that stretch the timeline.

The DISA Authorizing Official evaluates residual risk and decides whether to issue a Provisional Authorization. A PA carries an expiration date and can be leveraged by any DoD mission owner until it is revoked or expires. Before expiration, a provider with satisfactory security posture can be reauthorized with an updated PA memo. Separately, each mission owner issues an Authority to Operate scoped to their specific system running on the authorized service. The PA covers the underlying infrastructure; the ATO covers what the mission owner builds on top.6Defense Information Systems Agency. DoD Cloud Authorization Process

Templates and guidance for the FedRAMP documents are available on fedramp.gov, and DoD-specific templates are on the DISA Cyber Exchange document library.5Cyber Exchange. DoD Cloud Computing Security

Who Is Responsible for What

A provisional authorization does not mean the provider handles all security. The split depends on the service model.

  • Infrastructure as a Service: the provider secures the physical hardware; the mission owner handles network security, operating systems, applications, and authentication.
  • Platform as a Service: the provider secures the hardware and operating system; the mission owner controls deployed applications and some network security services such as web application firewalls, with some controls shared.
  • Software as a Service: the provider secures the hardware, virtual environment, operating system, and application; the mission owner configures use policies and remains responsible for data and any settings within their control.

In every model, the mission owner keeps responsibility for the security of DoD data and any configuration they control. Ambiguity about who owns which control is where security gaps form, so the delineation should be documented.10RMF.org. Cloud Computing Mission Owner Security Requirements Guide Overview Mission owners implementing Risk Management Framework controls need to identify which controls they inherit from the PA, which are shared, and which they implement themselves.

Keeping the Authorization

Authorization is the start. Providers holding a DoD PA must comply with continuous monitoring requirements that mirror FedRAMP’s ConMon framework, with monthly, annual, and as-needed activities.6Defense Information Systems Agency. DoD Cloud Authorization Process

Each month, providers submit an updated POA&M, a current system inventory, and vulnerability scan results to their secure repository. Vulnerability resolution follows a 30-90-180-day timeline keyed to severity, with the shortest window for critical and high items. Independent assessors run full annual assessments, and significant changes trigger out-of-cycle assessments.11FedRAMP. Continuous Monitoring Overview

Falling behind on ConMon deliverables is one of the fastest ways to lose a PA. DISA tracks compliance closely. A provider that lets remediation deadlines slip or misses monthly reporting risks revocation, which pulls the rug out from under every mission owner relying on the service.

Network Access Rules

Because IL2 handles the lowest-sensitivity DoD data, its connectivity requirements are the least restrictive in the framework. Access occurs over the public internet with standard controls like user authentication.12Defense Information Systems Agency. DISN Connection Process Guide That is a meaningful difference from IL4 and above, which route through dedicated Cloud Access Points or Boundary Cloud Access Points sitting between commercial infrastructure and the Defense Information Systems Network.

Providers still must maintain logical separation from other commercial tenants sharing the same physical hardware. Non-defense customer data cannot mingle with defense-managed environments. But the heavy gateway infrastructure required at higher impact levels does not apply at IL2, and that combination of internet-based access and FedRAMP reciprocity is what makes this level the practical starting point for commercial providers entering the defense market.