DoD Cloud Computing SRG: Impact Levels & Authorization

Written by: 
Team Knox
Published on: 
August 27, 2026

Before hosting Department of Defense (DoD) data, a commercial cloud must satisfy the DoD Cloud Computing Security Requirements Guide (CC SRG) V1R6, published in December 2025, for the relevant impact level. The Defense Information Systems Agency, or DISA, maintains the CC SRG, which defines how DoD uses cloud computing securely.

For SaaS vendors, the SRG is the gap between a FedRAMP authorization and actual DoD revenue. The Federal Risk and Authorization Management Program opens civilian agency doors, but DoD adds its own requirements on top, and vendors that misread them misjudge both DoD authorization timelines and cost.

Key Takeaways

  • DISA sets the rules. The CC SRG defines the security model and controls any cloud provider must satisfy before hosting DoD data, and compliance is mandatory.  
  • Impact levels drive requirements. Four impact levels, IL-2, IL-4, IL-5, and IL-6, scale controls to data sensitivity; IL-4 is the practical ceiling for most commercial SaaS products.  
  • FedRAMP is the floor. DoD adds FedRAMP+ controls, separation rules, and boundary requirements on top of applicable FedRAMP security baselines; an Authority to Operate (ATO) under FedRAMP, without DoD authorization, doesn't grant DoD access.  
  • DISA restructured the SRG. The 2024 revision replaced the single guide with separate guidance for providers and DoD consumers.

The DoD Cloud Computing SRG Is DISA's Foundational Security Guidance for Cloud Services Hosting DoD Data

The DoD Cloud Computing SRG is the security rulebook every commercial cloud must follow to host DoD workloads. It defines the security model, control baselines by impact level, separation and boundary requirements and connectivity rules that apply to cloud service providers and their DoD customers. The CC SRG defines the security model and requirements DoD uses for cloud computing, including the necessary security controls, and maps to the DoD Risk Management Framework (RMF).

DISA publishes the guide as two audience-specific documents distributed through DISA's DoD Cloud Computing Security (DCCS) Document Library and DISA cloud security library. The current release is DoD Cloud Computing SRG V1R6, dated December 2025 and the DCCS Document Library entry is dated August 11, 2026. It incorporates, supersedes, and rescinds the earlier DoD Cloud Security Model.

Compliance is mandatory for any cloud service provider (CSP) that will host DoD information. The enforcement mechanism is the DoD Provisional Authorization (PA), which DISA grants only after a CSP demonstrates it meets the SRG. One distinction matters up front: the SRG is a requirements document, while FedRAMP is an authorization program.

The applicable impact level determines each workload's control and infrastructure baseline.

Impact Levels Assign DoD Data into Four Sensitivity Tiers with Distinct Requirements

The SRG's organizing structure is the impact level (IL): the combination of a workload's data sensitivity and the damage a confidentiality, integrity, or availability breach would cause. DISA later revised the original six-level impact model, folded levels 1 and 3 into 2 and 4, and kept the original numbering, so IL-3 no longer exists.

  • IL-2 covers publicly releasable and low-sensitivity unclassified data not designated as Controlled Unclassified Information (CUI). A FedRAMP Moderate authorization baseline is typically a prerequisite for IL-2 reciprocity, but DoD authorizing officials issue DoD authorizations separately. Virtual or logical separation between DoD and federal tenants is sufficient, but physical separation from non-DoD and non-federal tenants is required.  
  • IL-4 covers CUI and mission-critical data supporting military or contingency operations. It requires FedRAMP Moderate or High plus DoD-specific FedRAMP+ controls. Logical or virtual separation is acceptable, but traffic must route through the Non-classified Internet Protocol Router Network (NIPRNet) via a Boundary Cloud Access Point (BCAP). A DoD PA is required.  
  • IL-5 covers higher-sensitivity CUI and unclassified National Security Systems (NSS) data. A DoD PA is required, and its controls and infrastructure requirements are stricter than those for IL-4.  
  • IL-6 covers classified information up to SECRET. It uses dedicated classified cloud infrastructure in classified processing facilities and operates in a classified-network-only environment.

Authorization scope varies by provider and cloud offering. Most vendors reach IL-2 through FedRAMP Moderate reciprocity rather than pursuing it directly. For commercial products that need to handle CUI or mission-critical data, IL-4 is the practical target.

For IL-4, the FedRAMP baseline is the starting point for the additional DoD controls.

FedRAMP Authorization Is Necessary but Not Sufficient for DoD Cloud Access

FedRAMP is a government-wide program built on a "do once, use many times" model: one standardized assessment that many agencies can reuse. DoD treats that assessment as its minimum baseline, then applies what the SRG calls FedRAMP+. The additional requirements include:

  • DoD-specific controls;  
  • stricter parameter values;  
  • impact-level separation requirements; and  
  • DoD boundary and connectivity rules.

These additions define the DoD-specific delta on top of the FedRAMP baseline. Reciprocity reduces effort; it does not waive the requirement. An existing FedRAMP ATO doesn't automatically produce a DoD ATO.

A FedRAMP authorization provides eligibility and a large head start because the existing assessment package and tested controls carry forward, so the DoD delta is an increment rather than a restart. The 2024 CSP SRG organized that baseline-to-impact-level relationship within the provider-specific guidance.

The 2024 SRG Restructuring Introduced Four Major Changes

DISA maintains the DoD Cloud Computing SRG V1R6 (December 2025), published through DISA's DCCS Document Library and DISA cloud security library. The 2024 restructuring brought several headline changes, with operational updates folded in.

  • A split by audience. The CSP SRG governs cloud providers hosting DoD data; the Mission Owner (MO) SRG governs the DoD components and program managers consuming those services. MOs hosting workloads in CSP infrastructure must account for the requirements assigned to both parties.  
  • Formalized FedRAMP reciprocity. IL-2 keeps full reciprocity with FedRAMP Moderate or High; higher impact levels add DoD-specific controls and requirements to the applicable FedRAMP baseline.  
  • NIST SP 800-53 Rev5 alignment. The new documents use the Rev5 security control catalog, published by the National Institute of Standards and Technology in September 2020, as the basis for their security requirements.  
  • Boundary updates. The BCAP remains a requirement for applicable workloads connecting to NIPRNet or the Secret Internet Protocol Router Network (SIPRNet).

Provider and mission-owner responsibilities also determine each party's role in authorization.

CSPs Follow a Structured DoD Authorization Process to Earn an ATO

The DoD cloud authorization process runs from impact level determination through DISA review to a mission owner's final sign-off. Each step builds on the last, and much of the effort centers on inheritance: rather than reimplementing every control, a CSP can inherit compliance from an underlying FedRAMP-authorized boundary and focus its own work on the DoD-specific delta. That inheritance model shapes both the sequence below and the cost of reaching an ATO.

1. Determine the Applicable Impact Level

The mission owner classifies the workload using CC SRG guidance, weighing data sensitivity against the impact of a confidentiality, integrity, or availability breach. This single decision fixes the control baseline, the separation model, and most of the downstream cost.

It also determines whether a workload can ride on a FedRAMP Moderate baseline or must build toward High, and whether virtual separation is sufficient or physical separation is required. Getting this call right early prevents expensive rework once assessment work begins.

2. Establish the FedRAMP Foundation

Every DoD path builds on a FedRAMP assessment package, so the FedRAMP baseline is the starting point. IL-2 rides on FedRAMP Moderate reciprocity, IL-4 requires Moderate or High, and IL-5 requires High.

A CSP without any FedRAMP authorization starts here, and vendors operating within a pre-authorized boundary can inherit most of these controls from the platform provider. The scope of that inheritance determines how much independent implementation work remains before the DoD-specific overlay begins.

3. Implement the DoD-Specific FedRAMP+ Controls

The applicable impact level adds DoD-specific security controls, stricter parameter values, separation requirements, and boundary rules on top of the FedRAMP foundation. Collectively, these are known as FedRAMP+. The delta varies by impact level: IL-4 layers CUI-focused controls and BCAP routing over Moderate or High, while IL-5 tightens parameters further for higher-sensitivity CUI and unclassified NSS data. CSPs that inherit their FedRAMP baseline typically concentrate engineering effort here, on the DoD-specific increment rather than the full catalog.

4. Undergo Assessment by a DoD-Recognized 3PAO

A DoD-recognized Third-Party Assessment Organization (3PAO) reviews documentation, runs vulnerability scans and penetration tests, and compiles a Security Assessment Report (SAR) for submission to DISA. The 3PAO validates both the inherited FedRAMP controls and the DoD-specific FedRAMP+ additions.

Assessment quality directly affects downstream review time, so vendors should choose an assessor familiar with DoD workloads and coordinate scope carefully to avoid gaps between inherited controls and those the CSP implemented directly.

5. Submit the Authorization Package for DoD Review

The authorization package includes the System Security Plan, the SAR, a Plan of Action and Milestones (POA\&M), and a continuous monitoring plan. DISA reviews the package, and review time depends heavily on the quality of the assessment submitted.

Well-organized packages that clearly document inheritance boundaries, control ownership, and residual risks move faster; incomplete or inconsistent packages return for rework. Package quality is the one input a vendor fully controls, and it should be treated as a strategic deliverable.

6. Receive a Provisional Authorization from DISA

The PA pre-qualifies the cloud service offering to host DoD missions and lists it in the DoD Cloud Authorization Services (DCAS) portal. A PA enables contract bidding but does not itself authorize any specific workload.

PAs carry expiration dates and continuous monitoring conditions the CSP must maintain and renew. Vendors should treat the PA as market eligibility rather than the finish line, because a mission owner's ATO is still required before real DoD workloads can move onto the offering.

7. Obtain the ATO from the Mission Owner's Authorizing Official

The DoD component or mission owner sponsoring the service, through its Authorizing Official, grants the ATO or an interim authority to test under the NIST RMF authorization process as DoD applies it. The authorization remains subject to continuous monitoring for its full life, with ongoing post-ATO requirements including monthly POA\&M updates and scan submissions. Incident response and change control obligations continue as well, making authorization an operating commitment rather than a one-time milestone.

SaaS Vendors Entering the DoD Market Need More Than FedRAMP Alone

FedRAMP gets a SaaS product into civilian agencies, but it does not, on its own, unlock DoD revenue. Selling into the DoD requires clearing the CC SRG's FedRAMP+ controls, separation rules, and boundary requirements at the impact level a sponsoring mission owner actually needs, then sustaining that posture through continuous monitoring. Vendors that treat DoD compliance as an extension of their FedRAMP effort, aligned to a specific DoD mission owner and impact level, close the gap faster and more cheaply than those who wait for a contract to force the question.

Inheritance is what makes that economically viable for most SaaS vendors.

Knox Systems is a FedRAMP-as-a-Service platform whose pre-authorized government cloud platform supports FedRAMP Moderate, FedRAMP High, and DISA IL-4, with IL-5 authorization in process and estimated for December 2026. Vendors inherit 60% to 80% of required NIST SP 800-53 Rev5 controls, so engineering effort concentrates on the DoD-specific delta rather than the full baseline.

If the federal pipeline is waiting on DoD-compliant authorization, book a meeting to scope your path.

FAQs About the DoD Cloud Computing SRG

What Cloud Service Does the DoD Use?

DoD uses the Joint Warfighting Cloud Capability (JWCC), a multi-award cloud services contract awarded in December 2022. Its providers are Amazon Web Services (AWS), Google, Microsoft, and Oracle. The contract covers unclassified through top-secret work.

Can a Vendor Start Without an Agency Sponsor?

Knox's pre-authorized platform model allows SaaS vendors to begin the authorization journey without first securing an agency sponsor. A DoD workload still requires authorization from the appropriate government official.