DoD Impact Levels (IL) are the security categories the Department of Defense uses to decide which cloud services can host which mission data. They are defined in the DoD Cloud Computing Security Requirements Guide (CC SRG), published by the Defense Information Systems Agency (DISA), and now aligned to NIST SP 800-53 Rev. 5.
If you want DoD mission owners to run on your cloud, platform, or SaaS offering, the Impact Level you are authorized for decides which data they can put there, and which programs you can win.
The levels
Four levels, set by the data you host
Each level adds requirements on top of the one below it. We help you target the level your mission owners actually need, so you are not building for IL5 when IL4 wins the contract.
IL2
Non-controlled unclassified data
Public or non-sensitive unclassified DoD information. Built on an existing FedRAMP Moderate authorization.
IL4
Controlled Unclassified Information
CUI such as export-controlled, privacy, and protected health data. FedRAMP Moderate plus DoD FedRAMP+ controls.
IL5
Higher-sensitivity CUI and NSS
Mission-critical CUI and unclassified National Security Systems. FedRAMP High plus FedRAMP+ controls.
IL6
Classified information up to SECRET
Classified information, with the classified overlay, cleared personnel, and facility requirements to match.
FedRAMP and DoD Impact Levels
FedRAMP gets you in the door. Impact Levels get you to the mission
A FedRAMP authorization is the foundation, but it does not by itself make your offering a DoD authorization. Above IL2, the DoD adds its own requirements on top.
Area
FedRAMP
DoD IL4/5
Applies to
Federal agencies
DoD components and mission owners
Primary purpose
Authorizes cloud services for federal agency use
Authorizes cloud services to host DoD CUI and mission data
Typical information
Federal information at Low, Moderate, or High impact
CUI, mission-critical data, and unclassified National Security Systems (IL5)
Security basis
FedRAMP baseline built on NIST SP 800-53
FedRAMP Moderate (IL4) or High (IL5) baseline plus DoD FedRAMP+ requirements
DoD-specific controls
None required
FedRAMP+ controls and DoD parameters
Authorization
FedRAMP authorization
DISA Provisional Authorization, then a mission owner ATO
Architecture
FedRAMP boundary and controls
FedRAMP plus tenant separation, BCAP connectivity, personnel screening, and STIG hardening
Why it matters
The right Impact Level opens the DoD market
Market access
Sell to DoD mission owners, not just civilian agencies Without an Impact Level authorization, DoD programs cannot put CUI or mission data on your offering.
FedRAMP reuse
Build on the work you have already done A well-scoped IL effort extends your FedRAMP package instead of starting over, saving time and budget.
Faster mission ATOs
Make it easy for DoD programs to say yes A DISA PA lets each mission owner reuse your authorization package rather than evaluating you from scratch.
Competitive edge
Stand apart from commercial-only competitors IL4 and IL5 authorizations are hard to earn, which is exactly why mission owners and primes look for them.
Our federal background
Built on real assessment experience, not consulting theory
We know what an assessor looks for, because we have been the assessor.
InfoGuard’s federal practice is led by a former FedRAMP 3PAO assessor with hands-on experience taking cloud offerings from readiness through authorization, and an active Secret clearance.
Assessor perspective
We prepare you against the same controls, evidence, and testing an independent 3PAO will apply, so the assessment holds no surprises.
Architecture first
Impact Levels are won or lost in the architecture: boundary, separation, BCAP connectivity, identity, and encryption. That is where we start.
Hands-on senior leadership
Senior practitioners work alongside your engineers from gap assessment through authorization, not a junior analyst running a checklist.
One effort, multiple frameworks
We map your controls and evidence once across FedRAMP, DoD Impact Levels, CMMC, and SOC 2, so each new authorization builds on the last.
Your compliance investment should deliver more than checklists and documentation. It should improve your cybersecurity as well.
How we help
From gap assessment to Provisional Authorization, and beyond
01
Impact Level & Gap Assessment
We confirm the level your target mission owners need and assess your offering against the FedRAMP baseline and DoD FedRAMP+ requirements for that level.
02
Architecture & Boundary
We design the authorization boundary, tenant separation, BCAP connectivity, and data flows the level requires, without pulling in systems that do not belong.
03
Build & Remediation
We implement the technical and operational controls your design calls for, including STIG hardening, identity, logging, encryption, and incident response to DoD.
04
Authorization Package
We build or extend your SSP and supporting documentation to cover FedRAMP+ controls and DoD parameters, written to match how your environment really works.
05
Assessment Readiness
A readiness review that mirrors 3PAO testing confirms your evidence holds up, then we stay engaged through the assessment and DISA review.
06
Continuous Monitoring
We keep your controls, POA&M, and monthly continuous monitoring deliverables current so your authorization stays in good standing.
FAQ
DoD Impact Level questions, answered
Levels and authorization
Does a FedRAMP authorization automatically give me a DoD Impact Level?
FedRAMP Moderate is generally accepted for IL2. For IL4 and above, the DoD adds FedRAMP+ controls, separation, connectivity, and personnel requirements, so a FedRAMP authorization is the starting point rather than the finish line.
How does DoD IL4 compare to FedRAMP Moderate?
Both are built for moderate-impact data, and IL4 starts from the FedRAMP Moderate baseline. The difference is the customer. FedRAMP Moderate authorizes your offering for federal agencies; IL4 lets DoD mission owners host CUI on it. To get there, IL4 adds DoD FedRAMP+ controls and parameters, STIG-hardened configurations, incident reporting to DoD, personnel screening, and a NIPRNet connection through a BCAP. It is authorized by DISA with a Provisional Authorization rather than through FedRAMP alone.
What is the difference between a DISA PA and an ATO?
A DISA Provisional Authorization says your cloud offering meets the requirements for a given Impact Level. Each DoD mission owner still issues its own Authority to Operate for the specific workload it runs on your offering, typically reusing your PA package.
Do I need a DoD sponsor?
In most cases, yes. DoD authorizations are typically pursued with a DoD mission owner who intends to use your offering. We help you prepare the package and the conversation with your sponsor.
Which level do we need, IL4 or IL5?
It depends on the data your mission owners plan to host. Most CUI fits IL4. IL5 is for higher-sensitivity CUI and unclassified National Security Systems, and its physical separation requirement can significantly change your architecture and cost. We help you confirm the right target before you build.
Scope, timing, and cost
Is IL4 the same as FedRAMP Moderate equivalency for CMMC?
No. FedRAMP Moderate equivalency under DFARS 252.204-7012 applies to cloud services that defense contractors use to store CUI. Impact Levels apply to cloud offerings hosting DoD mission data directly. Some providers need both, and we help you sort out which applies to you.
How long does an Impact Level authorization take?
It depends on your current FedRAMP status, the target level, and how much architectural change is needed. Building on an existing FedRAMP authorization is usually much faster than starting from scratch. We give you a realistic timeline once we have scoped your offering.
How much does it cost?
Cost depends on your target level, your existing authorization, and the remediation and architecture work required. There is no flat fee. We provide a firm quote after an initial gap assessment.
Do you work with SaaS companies, not just large cloud providers?
Yes. SaaS and platform providers often have the strongest products and the fewest people who have been through a DoD authorization. That is exactly where InfoGuard helps most.
Cybersecurity first
A checkbox compliance provider won't cut it
You need real cybersecurity and cloud architecture expertise to host mission data the DoD depends on, and to pass an assessment built to find the gaps.
Tell us about your offering and the DoD customers you are targeting. We’ll reply with next steps, whether that’s an Impact Level gap assessment, an architecture review, or a readiness assessment.