The Department of Defense sorts cloud-hosted data into four impact levels — IL2, IL4, IL5, and IL6 — with each level adding stricter infrastructure isolation, personnel restrictions, and network controls that a cloud service provider must meet before hosting a single file. The framework lives in the Cloud Computing Security Requirements Guide (SRG) maintained by the Defense Information Systems Agency, and the level assigned to any given system reflects the damage that would result if the wrong person accessed the data inside.
How a System Gets Its Level
Before an impact level is assigned, analysts categorize the information the system will handle using Federal Information Processing Standards Publication 199, the government-wide standard for security categorization.1National Institute of Standards and Technology. FIPS 199 – Standards for Security Categorization of Federal Information and Information Systems NIST Special Publication 800-60 helps map common government information types to recommended categories.2Computer Security Resource Center. NIST SP 800-60 Vol 1 Rev 1 – Guide for Mapping Types of Information and Information Systems to Security Categories
Each data type gets rated across confidentiality, integrity, and availability, and each of those three dimensions is scored low, moderate, or high depending on how much damage a failure would cause. For National Security Systems, the Committee on National Security Systems Instruction 1253 preserves all three ratings separately rather than collapsing them into a single high-water mark.3Defense Counterintelligence and Security Agency. CNSSI No 1253 – Security Categorization and Control Selection for National Security Systems The resulting categorization drives which impact level applies, and with it every infrastructure, personnel, and network requirement the provider must satisfy.
You may notice the numbering skips from 2 to 4. Impact Level 3 existed as a separate tier but was folded into IL2, and current guidance recognizes only four active levels.4Cloud Information Center. Cloud Security
Impact Level 2: Public and Low-Sensitivity Unclassified Data
IL2 is the entry point. It covers two kinds of unclassified information: data already cleared for public release, and low-sensitivity mission data that is not Controlled Unclassified Information. Recruiting websites, general reference material, and publicly available DoD content sit here. If the information leaked, no one would be meaningfully harmed.
The security baseline is straightforward. DoD grants full reciprocity to any cloud service offering that already holds a FedRAMP Moderate or FedRAMP High authorization from the Joint Authorization Board, meaning the provider does not undergo a separate DoD assessment of security controls.5Microsoft Learn. Department of Defense (DoD) Impact Level 2 (IL2) – Azure Compliance The provider still has to meet the personnel security requirements in the SRG, but no additional control enhancements sit on top of the FedRAMP baseline. Dedicated hardware and physical separation from commercial tenants are not required at this level.
Impact Level 4: Controlled Unclassified Information
IL4 is where the requirements take a real step up, because this tier protects Controlled Unclassified Information. CUI is not classified, but its unauthorized disclosure could still cause operational problems or violate legal protections. The CUI Registry covers more than twenty category groupings, and the range is broader than most people expect.6Microsoft Learn. Department of Defense Impact Level 4 – Azure Compliance
CUI that requires an IL4 environment includes:
- Privacy data such as military personnel records, health information, and Social Security numbers
- Export-controlled information restricted under the International Traffic in Arms Regulations or Export Administration Regulations
- Law enforcement records, including criminal history data and accident investigations
- Financial data such as bank secrecy records and budget documents
- Defense information such as naval nuclear propulsion data and unclassified controlled nuclear information
- Critical energy infrastructure information
IL4 accommodates CUI categorized up to moderate confidentiality and moderate integrity under CNSSI 1253.6Microsoft Learn. Department of Defense Impact Level 4 – Azure Compliance Providers holding a FedRAMP High authorization can use it as the basis for an IL4 provisional authorization, but DISA still assesses SRG requirements that go beyond the FedRAMP control set. Robust audit trails, advanced identity management, and detailed access logging are expected so that agencies can reconstruct exactly who accessed what after an incident.
Network architecture changes here too. All traffic to and from an IL4 cloud environment must traverse NIPRNet Boundary Cloud Access Points, and no direct IL4 traffic touches the open internet except through NIPRNet Internet Access Points and DMZ capabilities provided by the mission owner, a DoD component, or DISA.7DoD CIO. Cloud Security Playbook Volume 1
Impact Level 5: Higher-Sensitivity CUI and National Security Systems
IL5 protects higher-sensitivity unclassified data tied directly to military operations and National Security Systems. The data is still unclassified, but its compromise could affect mission execution in ways that standard CUI protections are not designed to handle. The SRG also places CUI at IL5 when it is categorized above moderate confidentiality or integrity under CNSSI 1253.8Microsoft Learn. Department of Defense (DoD) Impact Level 5 (IL5) – Azure Compliance
Only federal government community clouds or DoD private clouds qualify at IL5. Physical separation from non-DoD and non-federal government tenants is mandatory, so the provider cannot host IL5 workloads on infrastructure shared with commercial customers or state and local government agencies. Virtual or logical separation between DoD and other federal government tenants is sufficient, but the physical boundary against everyone else has to be real.9DoD. Cloud Service Provider Security Requirements Guide – January 2025
Data residency rules tighten as well. All IL5 and National Security Systems data must remain under U.S. jurisdiction, which covers the fifty states, the District of Columbia, U.S. territories, and in some cases DoD installations on foreign soil where a Status of Forces Agreement provides legal jurisdiction.9DoD. Cloud Service Provider Security Requirements Guide – January 2025 The same NIPRNet BCAP routing that applies at IL4 applies here, and no direct IL5 traffic touches the public internet.7DoD CIO. Cloud Security Playbook Volume 1
Impact Level 6: Classified Data Up to Secret
IL6 is reserved for classified information up to the Secret level. Under Executive Order 13526, Secret applies to information whose unauthorized disclosure could reasonably be expected to cause serious damage to national security.10GovInfo. 3 CFR EO 13526 – Executive Order 13526 Classified National Security Information At this level the requirements shift from controlling access to fundamentally isolating the environment from everything else.
IL6 cloud infrastructure operates as a Secret Internet Protocol Router Network (SIPRNet) enclave. The entire cloud service offering is a closed, self-contained environment connected only to SIPRNet, with no pathway to the public internet or to lower-classification government networks. Facilities housing IL6 infrastructure must be approved for processing classified information at or above the Secret level. Physical separation from non-DoD and non-federal tenants is required, and because the entire infrastructure must be dedicated and separate from other cloud environments, IL6 offerings can only come from providers under direct contract with DoD or a federal agency.11Microsoft Learn. Department of Defense Impact Level 6 – Azure Compliance
Only personnel with appropriate security clearances can interact with IL6 systems. The air gap from unclassified networks is absolute. Data transfer occurs through controlled, secure channels, with no wireless or wired connection to any network outside the SIPRNet enclave. Continuous monitoring and rigorous inspections are standard conditions for keeping authorization at this level.
What About Top Secret and SCI Data
The SRG stops at IL6 and does not define an impact level for Top Secret or Sensitive Compartmented Information. That data does go into cloud environments, but under a different accreditation framework. Providers hosting Top Secret workloads operate under the Director of National Intelligence’s Intelligence Community Directive 503 and NIST Special Publication 800-53, rather than the SRG’s impact level system. Those environments sit entirely outside the IL2-through-IL6 stack and are managed through intelligence community authorization processes rather than DISA provisional authorizations.
Personnel and Data Residency Rules Across Levels
Personnel restrictions escalate with each level, and providers routinely underestimate the compliance burden. At IL2, the SRG imposes no specific citizenship requirements beyond what FedRAMP already demands. At IL4, IL5, and IL6, all administrators must be U.S. citizens, U.S. nationals, or U.S. persons, and no foreign persons may access the data at any of those levels.12DoD. DoD Cloud Computing Mission Owner SRG – January 2025 Users at IL4 and above follow the same nationality restrictions, though foreign personnel may be permitted with authorizing official approval under current DoD policies.
Data residency requirements apply across all levels but become explicit and strict at IL5 and above. All government data stored and processed for DoD must reside in a facility under exclusive U.S. legal jurisdiction, which generally means the fifty states, the District of Columbia, and U.S. territories as defined in the Federal Acquisition Regulation. DoD installations on foreign soil may qualify depending on the applicable Status of Forces Agreement, and that determination rests with the responsible authorizing official.9DoD. Cloud Service Provider Security Requirements Guide – January 2025
How Providers Get Authorized
A cloud service provider that wants to host DoD workloads has to earn a Provisional Authorization (PA) from DISA. The process runs through the DoD Cloud Authorization Services team and follows a defined sequence: intake through a DoD sponsor, review of the security assessment plan by the Joint Validation Team, testing by an accredited third-party assessment organization, JVT validation and remediation of findings, an authorization recommendation reviewed by the Defense Security/Cybersecurity Authorization Working Group, and a final decision by the DISA authorizing official.13DISA. DoD Cloud Authorization Process After authorization, the provider has to keep up with continuous monitoring, resolving vulnerabilities on 30-, 90-, and 180-day timelines and completing annual reassessments.
Reciprocity trims the process at the lower levels. At IL2, providers with an existing FedRAMP Moderate or High authorization can receive a DoD PA without a separate security control assessment.5Microsoft Learn. Department of Defense (DoD) Impact Level 2 (IL2) – Azure Compliance At IL4, a FedRAMP High authorization covers the security controls portion, but DISA still assesses the non-control requirements from the SRG. At IL5 and IL6, the full authorization process applies with no shortcuts. Missing a vulnerability remediation deadline or failing an annual assessment can result in suspension of the PA, which immediately affects every DoD mission owner running workloads in that environment.13DISA. DoD Cloud Authorization Process