Enterprise automation, designed, built and operated in the United States.

DoD Impact Levels IL2 to IL6 Explained: A Provider's Guide

A plain reading of the DoD Cloud Computing SRG impact levels, what belongs at each, and how to pick the one your mission owners actually need.

DoD impact levels are the Defense Department's scale for matching a cloud environment to the sensitivity of the information it holds. They come from the DoD Cloud Computing Security Requirements Guide (CC SRG), maintained by DISA, and the ones in current use are IL2, IL4, IL5 and IL6. In plain terms: IL2 is for unclassified information that is not controlled, IL4 is for controlled unclassified information (CUI) supporting non-critical missions, IL5 is for higher-sensitivity CUI and unclassified national security systems, and IL6 is for classified information up to Secret. IL1 and IL3 no longer exist as separate levels; their content was folded into IL2 and IL4 in an earlier SRG revision, which is why older diagrams still circulating are misleading.

If the real question is which level to pursue and what it will take, the honest answer is that you do not pick a level — the data and the mission owner pick it for you, and your job is to sequence the work. FedRAMP Moderate is the practical entry ticket for IL2 and IL4; FedRAMP High underpins IL5; both are augmented by additional CC SRG controls and control enhancements. IL6 is not one more rung on the same ladder. It is a different line of business: a classified enclave, cleared facilities and cleared people, SIPRNet connectivity, and a DoD sponsor. Cost and schedule are driven far less by the number of controls than by how much of your organization you have to duplicate — regions, pipelines, support teams, and staff — to satisfy separation, personnel and connectivity rules.

What an impact level actually measures

The SRG derives each level from the sensitivity of the information combined with the potential impact of its compromise, expressed mainly through confidentiality and integrity. It is not a maturity score and it is not a ranking of vendors. A provider authorized at IL5 is not inherently better engineered than one at IL2; it is permitted to hold different information under different conditions. The level also attaches to a specific cloud service offering and a specific authorization boundary, not to the company as a whole. Providers lose credibility with program offices by advertising a corporate impact level when only a subset of services carry the provisional authorization, and mission owners are increasingly checking the service catalog entry rather than the marketing claim.

IL2: non-controlled unclassified information

IL2 covers information approved for public release and other unclassified data that carries no control markings, supporting missions where loss would not cause meaningful harm. The baseline is FedRAMP Moderate. IL2 services can be reached over the public internet without routing through a DoD cloud access point, personnel requirements are set by contract rather than by the SRG, and tenancy is ordinary commercial multi-tenancy. This is where most commercial providers begin, and it is a legitimate destination for public-facing sites, open data, training content and development environments that hold no real mission data.

The recurring mistake is assuming IL2 is good enough for CUI because the underlying baseline is the same one many civilian agencies accept. It is not. The moment a program puts export-controlled technical data, procurement-sensitive material or privacy information into the environment, the requirement moves to IL4, and the gap is structural rather than paperwork.

IL4: controlled unclassified information

IL4 is the workhorse level. It covers CUI as defined by DoD policy and the federal CUI program — export-controlled technical data, privacy information, procurement sensitive material, critical infrastructure information — along with other non-public unclassified data supporting non-critical missions. The baseline is FedRAMP Moderate plus the SRG's additional requirements, commonly called FedRAMP+ controls and control enhancements.

The architectural changes start here. Traffic between the DoD and the service is expected to traverse a boundary cloud access point onto NIPRNet rather than arriving over the open internet. Infrastructure holding the data must sit in the United States or US territories under US jurisdiction. Privileged access and roles that can reach DoD data are restricted to US persons, which reshapes any follow-the-sun support model. Virtual and logical separation from non-DoD tenants is acceptable, but you have to be able to evidence how it is enforced. For defense suppliers, this level also intersects with DFARS clauses requiring that cloud services holding covered defense information meet FedRAMP Moderate equivalency and support DoD incident reporting, which makes an IL4 provisional authorization a clean way to answer a program office's questions.

IL5: higher-sensitivity CUI and unclassified national security systems

IL5 handles CUI that requires more protection than IL4 affords, mission-critical information, and unclassified national security systems categorized under the CNSS process. The baseline moves to FedRAMP High plus SRG augmentation, but the control count is not the interesting part. What changes is separation: IL5 requires separation from non-federal tenants, with the current SRG revision accepting strong virtual separation where it is genuinely enforced and demonstrable rather than mandating dedicated hardware in every case. The management plane, not just the workload, falls inside that expectation.

Personnel requirements tighten as well. Positions with access are assigned sensitivity designations and require favorably adjudicated background investigations, which means recruiting, onboarding and offboarding all become authorization artifacts. Key management expectations rise, with mission owners asking harder questions about who can access keys and under what process. In practice, most providers end up operating IL5 in a distinct region or partition with its own build and release path, because retrofitting these constraints onto a commercial region is more expensive than standing up a separate one.

IL6: classified information up to Secret

IL6 is for classified national security information up to the Secret level, and it is a categorically different undertaking. The environment connects through SIPRNet rather than NIPRNet. Facilities must be accredited for classified processing and operated under the applicable industrial security and physical security standards. Personnel need active US security clearances at the appropriate level, not just favorable investigations. Infrastructure is dedicated and separated from all non-DoD and lower-level tenants. Cryptography for transport relies on NSA-approved solutions rather than FIPS-validated commercial modules alone.

Just as important, IL6 requires DoD sponsorship. You cannot self-fund your way to an IL6 offering and then look for buyers, and the offering cannot be marketed, demonstrated or procured the way a commercial service is. Providers that succeed here almost always arrive with a named program, a funded requirement and a mission owner willing to carry the authorization forward.

What changes architecturally between IL4, IL5 and IL6

  • Connectivity. IL2 is reachable over the internet. IL4 and IL5 route through a boundary cloud access point to NIPRNet, with port, protocol and service management rules applied. IL6 connects only through the SIPRNet access path.
  • Tenancy and separation. Commercial multi-tenancy at IL2; logical separation from non-DoD tenants at IL4; separation from non-federal tenants, including the management plane, at IL5; dedicated infrastructure at IL6.
  • Personnel. Contractual screening at IL2; US persons for privileged roles at IL4; position sensitivity designations and adjudicated investigations at IL5; active clearances at IL6. Each step narrows your hiring pool and your support coverage model.
  • Physical. US and US territory locations under US jurisdiction from IL4 upward, with IL6 adding accredited classified processing facilities and the physical controls that come with them.
  • Cryptography and key management. FIPS-validated modules across IL2 through IL5, with customer-controlled key options and stricter key access governance becoming the norm at IL5. IL6 moves to NSA-approved cryptography for protecting classified traffic.
  • Monitoring and reporting. Higher levels expect support for DoD-directed sensing and boundary defense, defined incident reporting into DoD channels within the timeframe your agreement specifies, and continuous monitoring evidence delivered on the cadence the SRG sets.
  • Engineering and release. The practical consequence of all of the above is a separate pipeline: separate artifacts, separate approvals, separate change control, and a separate on-call rotation staffed by people who meet the level's personnel rules.

Who authorizes what

DISA issues the provisional authorization against the SRG for a cloud service offering. That provisional authorization is not an authority to operate. A DoD mission owner still issues its own ATO under the Risk Management Framework for the system it builds on your service, inheriting what it reasonably can and adding controls for everything above your boundary. Packages are typically managed in eMASS, and the shared responsibility matrix you publish becomes one of the most scrutinized documents you produce, because it determines what the mission owner has to do itself.

Where an independent assessment is required, it must come from an accredited assessment organization. We are not an accreditation body and we do not issue authorizations. We prepare providers for assessment, build and test the evidence, and deliver the independent portions of the work with accredited partners so the assessment and the readiness work stay properly separated. Our approach to security and compliance assessments is built around that separation.

How to decide which level to pursue

Start with the data, not the ambition. Write down every category of information the service will hold in the first year of operation, mark which carries CUI designations, and note anything that touches a national security system. That inventory sets your floor. Then look at demand: talk to the program offices that would actually buy, and ask what level their authorizing official requires and what their timeline is. An IL5 authorization with no sponsoring mission owner is an expensive shelf item.

Next, test your organization against the personnel and separation rules honestly. If your support model depends on engineers outside the United States, IL4 already changes how you operate, and IL5 changes it further. If you cannot staff a cleared team or do not have a sponsor, IL6 is a future conversation rather than a roadmap item. Finally, scope the boundary narrowly. Authorize the services your mission owners need, prove them, and extend. Wide initial boundaries are the most common reason authorization efforts stall.

The usual sequence is FedRAMP Moderate, then IL2, then IL4, then FedRAMP High and IL5 as a deliberate re-architecture rather than an upgrade. The main cost drivers along that path are duplication of environments and pipelines, the cost and scarcity of screened or cleared staff, evidence generation and continuous monitoring, and remediation where the existing architecture does not match the separation model. The assessor's time is rarely the largest line.

Where to start

If you are early, a gap assessment against the target level will tell you whether the work is documentation or re-architecture, and those are very different programs. Our other guides cover adjacent ground, and if you are on the buying side of this, the security questions to ask an automation vendor apply directly to anyone claiming a DoD impact level. Our own controls and posture are documented on our trust page. When you are ready to scope a path to IL4 or IL5, get in touch and we will start from your data inventory and your mission owners rather than from a control list.

Questions we get asked about this

IL4 covers controlled unclassified information supporting non-critical missions and builds on the FedRAMP Moderate baseline. IL5 covers higher-sensitivity CUI, mission-critical information and unclassified national security systems, and builds on FedRAMP High. The practical differences are tenant separation from non-federal tenants, stricter personnel screening, and tighter expectations around key management and the management plane.

They were retired in an earlier revision of the DoD Cloud Computing SRG. IL1 was consolidated into IL2 and IL3 was consolidated into IL4. Diagrams showing six active levels are out of date, and referencing them in a proposal signals that the material has not been checked against the current SRG.

In practice, yes. The SRG uses FedRAMP baselines as its foundation, with FedRAMP Moderate underpinning IL2 and IL4 and FedRAMP High underpinning IL5, then adds DoD-specific controls and control enhancements on top. Reciprocity means the FedRAMP work is not wasted, but it is the starting point rather than the finish line.

No. IL2 is for unclassified information that carries no control markings, including data approved for public release. Controlled unclassified information requires IL4 at minimum, and higher-sensitivity CUI belongs at IL5. This is the most common misclassification we see when reviewing provider architectures.

Yes. IL6 handles classified information up to Secret, so personnel with access need active US security clearances at the appropriate level, and the facilities must be accredited for classified processing. It also requires SIPRNet connectivity, dedicated infrastructure and DoD sponsorship, which makes it a different undertaking from the unclassified levels rather than an incremental step.

DISA issues the provisional authorization for a cloud service offering against the SRG. That is not an authority to operate on its own. A DoD mission owner still issues its own ATO under the Risk Management Framework for the system it builds on the service, inheriting what the provider's authorization covers and adding controls above the boundary.

No, though FedRAMP High is the baseline IL5 starts from. IL5 adds DoD-specific requirements covering tenant separation, connectivity through a DoD access point, personnel screening, and monitoring and reporting obligations. A FedRAMP High authorization is necessary groundwork but does not by itself permit DoD IL5 workloads.

The timeline depends far more on architecture than on paperwork. If the existing environment already meets the separation, location and personnel rules for the target level, the work is largely evidence and assessment; if it does not, you are running a re-engineering program first. Having a sponsoring mission owner and a narrowly scoped boundary are the two biggest accelerators.

Bring us the process you were reading this for

Confidential assessment led by senior engineers. No obligation.