The Department of Defense Impact Level 5 requirements sit on top of a FedRAMP High authorization and add DoD-specific controls for higher-sensitivity Controlled Unclassified Information and unclassified National Security Systems. A cloud offering has to demonstrate stronger isolation, U.S.-only data residency and personnel, FIPS-validated encryption, connectivity through NIPRNet Boundary Cloud Access Points, and continuous monitoring, and it has to earn a provisional authorization from the Defense Information Systems Agency before any DoD mission owner can use it for IL5 workloads.1Microsoft Learn. Department of Defense (DoD) Impact Level 5
What Data Belongs at IL5
IL5 covers two categories of information. The first is higher-sensitivity CUI that could cause serious harm if exposed. The second is unclassified National Security Systems.1Microsoft Learn. Department of Defense (DoD) Impact Level 5
Routine CUI does not automatically require IL5. The types that do include export-controlled information governed by ITAR (items on the U.S. Munitions List) and EAR (items on the Commerce Control List); higher-sensitivity privacy data such as military personnel records and health information; and critical infrastructure information covering systems like energy and transportation whose exposure could create national security risks.1Microsoft Learn. Department of Defense (DoD) Impact Level 5
The second category, unclassified NSS, is defined by NIST SP 800-59. A system qualifies if it involves intelligence activities, cryptologic activities related to national security, command and control of military forces, equipment that is an integral part of weapons systems, or functions critical to the direct fulfillment of military or intelligence missions.1Microsoft Learn. Department of Defense (DoD) Impact Level 5 Even when the information on such a system is unclassified, the system itself is treated as a national security asset.
One boundary worth being explicit about: classified information does not belong at IL5. Anything up to Secret is IL6 territory.2Microsoft Learn. Department of Defense (DoD) Impact Level 6 (IL6) Standard CUI that does not carry elevated risk can stay at IL4, and the agency’s authorizing official is the one who decides which bucket specific mission data lands in.1Microsoft Learn. Department of Defense (DoD) Impact Level 5
The Baseline: FedRAMP High Plus DoD FedRAMP+
Section 5.1.1 of the DoD Cloud Computing Security Requirements Guide sets the structure. A cloud service offering starts from a FedRAMP High provisional authorization, then adds the DoD FedRAMP+ controls and the additional requirements specified in the CC SRG. That combined package is what DISA assesses when awarding an IL5 provisional authorization.1Microsoft Learn. Department of Defense (DoD) Impact Level 5
The Cyber Exchange maintains the current version of the CC SRG, which applies to DoD-operated cloud services, commercial cloud service providers, and DoD contractors offering cloud services.3Cyber Exchange. DoD Cloud Computing Security The DoD FedRAMP+ overlays tighten NIST SP 800-53 controls in areas like access control, monitoring, and isolation.
Encryption and Monitoring
Encryption rules at IL5 are strict but well-defined. Data at rest must be encrypted with FIPS 140-2 validated cryptographic modules, using AES-256 and customer-managed encryption keys. Data in transit needs TLS 1.2 at a minimum, with TLS 1.3 preferred. API calls to the cloud provider must use FIPS-validated endpoints. The encryption configuration has to be documented in the System Security Plan and verified during the DISA authorization process.
Monitoring goes further than at lower levels. Logging and auditing must capture key usage, access attempts, and configuration changes. That expanded monitoring is one of the less visible parts of IL5 compliance, and it continues after authorization as part of the provider’s ongoing obligations.
Network Connectivity Through BCAPs
IL5 is where cloud connectivity stops looking anything like a commercial deployment. All DoD traffic between NIPRNet and a cloud provider’s infrastructure has to traverse one or more NIPRNet Boundary Cloud Access Points. Direct IL5 traffic to or from the open internet is not permitted, except through NIPRNet Internet Access Points and demilitarized zone capabilities provided by the mission owner, a DoD component, or DISA.
The practical consequence: a mission owner cannot stand up an IL5 environment and reach it over the public internet. The BCAP requirement creates a controlled chokepoint the DoD can monitor and defend, and major cloud providers that support IL5 run dedicated government regions with BCAP connectivity already in place.
Isolation, Data Residency, and Personnel
The infrastructure itself has to be separated from commercial tenants. The DoD Cloud Security Playbook notes that government cloud regions from major providers are physically isolated from commercial regions, which satisfies the physical isolation requirement without the cost of reserving individual machines. CUI for National Security Systems must use a cloud offering authorized at IL5 or higher, such as one of the U.S. Government-specific cloud regions.4Department of Defense Chief Information Officer. Cloud Security Playbook Volume 1
Data residency reinforces the isolation. IL5 workloads must reside in U.S.-only regions, and providers configure organizational policy constraints to enforce that automatically.5Google Cloud. Data Boundary for Impact Level 5 (IL5)
Personnel access is the other dividing line from IL4. IL5 environments route support cases to U.S. persons located in the United States.5Google Cloud. Data Boundary for Impact Level 5 (IL5) That restriction reflects the ITAR and EAR exposure carried by export-controlled data and the sensitivity of NSS workloads, either of which can create violations if a non-U.S. person gains access.
How a Cloud Offering Gets an IL5 Provisional Authorization
Authorization is managed by DISA’s Cloud Authorization Services (DCAS) team. Two pathways exist: leverage an existing FedRAMP authorization, or have a DoD component sponsor the cloud offering for a DoD provisional authorization directly.3Cyber Exchange. DoD Cloud Computing Security
Either way, the sequence looks similar. The cloud provider prepares documentation demonstrating compliance with DoD standards, including a System Security Plan mapped to the CC SRG. A Third Party Assessment Organization (3PAO) conducts an independent assessment against IL5 requirements. DCAS pre-screens, validates, and manages the package. If everything checks out, DISA’s Authorizing Official issues the provisional authorization.
The first pathway is more common for large commercial providers. They come in with FedRAMP High and demonstrate the additional DoD FedRAMP+ controls needed to reach IL5, and the CC SRG evaluation determines whether the offering warrants a provisional authorization.1Microsoft Learn. Department of Defense (DoD) Impact Level 5
Authorization is not permanent. Providers must comply with continuous monitoring requirements, which includes ongoing vulnerability scanning, regular security assessments, and reporting to DISA. DCAS maintains a catalog of authorized cloud service offerings, and providers that fall out of compliance can lose their authorization.
Who Is Responsible for What
An IL5 authorization does not shift every obligation onto the cloud provider. The DoD uses a shared responsibility model.
The provider is responsible for meeting the SRG baseline, furnishing compliance documentation to DISA, maintaining the authorized infrastructure, and staying current on monitoring requirements.1Microsoft Learn. Department of Defense (DoD) Impact Level 5
The government customer carries a different set of duties. Your agency’s authorizing official has to determine whether specific CUI or mission data actually belongs at IL5, categorize the information properly, and select the correct impact level.1Microsoft Learn. Department of Defense (DoD) Impact Level 5 Miscategorizing is where mission owners get into trouble. Putting IL5 data into an IL4 environment leaves it under-protected; pushing IL4 data into IL5 adds cost and operational drag with no security gain.