What Is DoD Impact Level 4? IL-4 Requirements Explained

Written by: 
Team Knox
Published on: 
September 4, 2026

The Department of Defense (DoD) sorts every cloud workload it buys into one of four impact levels. Under the DoD Cloud Computing Security Requirements Guide V1R6, published in December 2025, Impact Level 4 governs Controlled Unclassified Information (CUI) such as personnel files, acquisition data, and export-controlled technical data.

The stakes for vendors are commercial. A FedRAMP Moderate authorization earns reciprocity only at IL-2, and DoD Mission Owners must select services holding an IL-4 or IL-5 Provisional Authorization from the Defense Information Systems Agency (DISA) before hosting CUI.

Key Takeaways

  • IL-4 governs DoD CUI. The CC SRG defines IL-4 as the tier for unclassified data whose disclosure could seriously harm DoD operations.  
  • Moderate is the floor. Moderate earns IL-2 reciprocity. IL-4 adds FedRAMP+ controls. It also requires U.S. data residency and DoD network connectivity.  
  • IL-4 permits multi-tenancy. Logical separation suffices at IL-4, while IL-5 requires physical separation for National Security Systems and IL-6 handles data up to SECRET.  
  • Authorization runs through DISA. A FedRAMP baseline, a DISA Provisional Authorization, and a Mission Owner authorization are three distinct steps.

IL-4 Is the DoD Cloud Standard for Controlled Unclassified Information

Impact Level 4 is a security tier defined in the CC SRG V1R6 (December 2025), and under which DISA issues Provisional Authorizations for DoD cloud services. IL-4 governs how a Cloud Service Offering (CSO) stores, processes, and transmits CUI and non-critical mission data: unclassified information whose unauthorized disclosure could be expected to have a serious adverse effect on organizational operations, assets, or individuals.

The CC SRG incorporated, superseded, and rescinded the DoD Cloud Security Model (CSM) V2.1, and its controls map to the DoD Risk Management Framework (RMF) process that Mission Owners already run for on-premises systems. The SRG's IL-4 scope covers CUI, non-CUI information, non-critical mission information, and non-national security systems. Classified information is never permitted in an IL-4 offering.

For sensitive non-public workloads within that scope, the Authorizing Official (AO) determines which ones require IL-4.

IL-4 Covers Several Distinct Categories of Sensitive Non-Public DoD Data

The National Archives and Records Administration (NARA) CUI Registry organizes CUI categories into organizational index groupings, but it assigns no impact levels: the owning organization designates information as CUI, and the mission AO determines the impact a given workload requires. Every CUI category below is therefore context-dependent rather than automatically IL-4.

  • Personally Identifiable Information (PII). Employee and applicant records, including personnel security questionnaires and contractor human resources (HR) files, fall under the registry's General Privacy category, defined by reference to Office of Management and Budget (OMB) M-17-12.  
  • Protected Health Information (PHI). Military medical treatment records, which sit in the Health Information category within the Privacy grouping.  
  • Military personnel files. The Military Personnel Records category covers service records of DoD employees and service members.  
  • Export-controlled data and Controlled Technical Information (CTI). The Export Controlled category covers International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR) items plus sensitive nuclear technology information, while Controlled Technical Information (CTI) covers technical information with military or space application, such as weapons system specifications.  
  • Critical infrastructure data. Base physical security plans under the Physical Security category, which covers protection of federal buildings and grounds, and water treatment vulnerability assessments under the Water Assessments category, which covers public drinking water systems.  
  • Law enforcement records. Criminal history records, terrorist screening data, DNA records, and informant identities within the Law Enforcement grouping.  
  • Financial data. DoD budget authorizations and expenditure estimates fall under the General Financial Information category within the Financial grouping, which covers information related to United States Government fiscal functions.

The DoD retired the For Official Use Only (FOUO) marking when it stood up the CUI program, but a DoD Inspector General management advisory flagged the continued use of unauthorized FOUO markings on new DoD documents and DoD officials' failure to implement the CUI program effectively. Legacy FOUO material must qualify under a specific CUI category before it can fall within IL-4's scope, subject to the Authorizing Official's determination.

The control overlay sets the protection requirements for IL-4 data.

IL-4 Security Controls Extend FedRAMP Moderate with a DoD FedRAMP+ Overlay

IL-4 builds on FedRAMP Moderate or High levels, and layers DoD-specific FedRAMP requirements drawn from the National Institute of Standards and Technology (NIST) SP 800-53 Rev5 (September 2020), enumerated in Table D-1 of the DoD Cloud Computing Security Requirements Guide (SRG) V1R6. The exact total depends on the SRG edition and authorization path, so CSPs should verify the current control set against the edition in the DISA Document Library instead of relying on version-unattributed totals.

A FedRAMP High PA is accepted for an IL-4 PA without an assessment of the extra control enhancements. Non-control SRG requirements still apply, and every IL-4 Cloud Service Provider (CSP) needs a DoD additions assessment by a Third-Party Assessment Organization (3PAO) submitted to DISA.

DoD operational requirements also apply:

  • U.S. data residency. All data stored and processed for or by the DoD must reside in facilities under the exclusive legal jurisdiction of the United States. The overseas base jurisdiction exception applies only to DoD and military bases abroad operating under Status of Forces Agreements.  
  • Access management and NIPRNet connectivity. When the user base is NIPRNet-based, and the impact level is 4 or 5, off-premises connectivity routes through the Non-classified Internet Protocol Router Network (NIPRNet) via a DISA-managed Boundary Cloud Access Point (BCAP), absent a DoD CIO waiver. A DoD-added personnel access requirement restricts system access to U.S. citizens, nationals, or persons, with foreign personnel permitted only under AO approval.  
  • Continuous monitoring (ConMon). CSPs submit continuous monitoring materials, undergo recurring assessments, and remediate identified vulnerabilities according to the applicable requirements.

These requirements distinguish IL-4 operations from a FedRAMP-only deployment.

IL-4 Occupies the Middle Tier of the DoD Cloud Impact Spectrum

The active model runs four levels: IL-2, IL-4, IL-5, and IL-6. The original 2015 SRG inherited six levels from the CSM and consolidated them, merging IL-1 into IL-2 and IL-3 into IL-4 while keeping the original numbering "to remain consistent with previous versions of the Cloud Security Model." The spectrum runs from publicly releasable data to classified SECRET.

Impact LevelData TypeClassification StatusFedRAMP EquivalentRepresentative Use Case
IL-2Publicly releasable or low-sensitivity non-CUIUnclassified, non-controlledFedRAMP Moderate provides IL-2 reciprocity (DoD authorization issued separately)Public-facing DoD information; routine administrative data
IL-4CUI and non-critical mission data, including data supporting military or contingency operationsUnclassified, controlledFedRAMP Moderate or High plus the FedRAMP+ overlayContractor CUI workloads; personnel records; acquisition data
IL-5Higher-sensitivity CUI and unclassified National Security System dataUnclassifiedFedRAMP High plus FedRAMP+ and National Security System (NSS) overlaysUnclassified National Security Systems; mission-critical higher-sensitivity CUI
IL-6Classified information up to SECRETClassifiedOutside FedRAMP's scope; separate DoD processSECRET workloads on dedicated, classified-rated infrastructure

The IL-4-to-IL-5 boundary is the one vendors most often misjudge. IL-5 covers National Security Systems: systems involving intelligence activities, cryptography, or command and control of military forces. IL-5 requires a FedRAMP High baseline, physical separation from all non-federal tenants down to hypervisors, storage arrays, and network switches, U.S.-citizen-only administrator access, and deployment in federal government community or DoD private clouds.

IL-4 accepts logical separation on commercial infrastructure, which makes it the practical target for SaaS products handling standard DoD CUI without an NSS use case. Pursuing IL-5 instead introduces dedicated-infrastructure requirements that do not apply at IL-4.

FedRAMP and DoD approval remain separate authorization layers.

IL-4 and FedRAMP Moderate Are Related but Not the Same Authorization

FedRAMP is the civilian federal baseline; DoD impact levels are overlays on top of it. A FedRAMP Moderate authorization earns reciprocity only at IL-2. Reaching IL-4 invokes the FedRAMP+ model, in which the DoD, per the General Services Administration (GSA) Cloud Information Center, "adds specific security controls and requirements necessary to meet and assure DoD's security considerations and requirements."

The sequence has three steps:

  1. Obtain FedRAMP authorization. The CSP first obtains FedRAMP authorization at the Moderate or High levels.  
  2. Secure a DISA Provisional Authorization. DISA then issues a Provisional Authorization after a 3PAO assessment of the FedRAMP+ controls, which requires a DoD component sponsor before the assessment begins.  
  3. Issue a mission-specific Authority to Operate (ATO). Finally, the Mission Owner, the DoD organization actually using the service, issues an ATO for its specific system.

Mission Owners find pre-vetted services in the DISA Provisional Authorization DoD Cloud Catalog, maintained by the DoD Cloud Authorization Services (DCAS) team at cyber.mil/dccs. Listing a product is what puts it in front of them.

IL-4 Authorization Is Required When a System Processes Non-Public DoD CUI

The mission AO weighs data, mission, users, and contract language together when determining whether IL-4 applies. CSPs can apply the same criteria to their own pipeline.

  • The data is CUI. If the system stores, processes, or transmits CUI as defined by Executive Order 13556 and the NARA registry, and the system is not a designated NSS, IL-4 is the minimum cloud tier. Acquisition data, personnel records, and medical records sit squarely in this scope.  
  • The system operates on behalf of the Government. The Defense Federal Acquisition Regulation Supplement (DFARS) clause DFARS 252.239-7010 requires safeguards "in accordance with the Cloud Computing Security Requirements Guide (SRG)". For CUI, that level is IL-4.  
  • The user community is NIPRNet-based. The CSP SRG requires the NIPRNet BCAP whenever the user base is NIPRNet-based, and the impact level is 4 or 5, absent a DoD CIO waiver.  
  • Contract clauses reach the CSP indirectly. For contractor-operated systems, DFARS 252.204-7012 requires external CSPs to meet FedRAMP Moderate equivalency, as defined by DoD CIO guidance. The clause omits explicit references to IL-4 and the CC SRG. Whether equivalency or an IL-4 PA applies depends on whether the system operates on behalf of the Government.

Once IL-4 applies, the vendor has two options: build the compliant boundary from scratch or deploy inside a pre-authorized environment that already carries the FedRAMP baseline, FedRAMP+ overlay, and DISA Provisional Authorization. The first path means standing up the full control set and shepherding a 3PAO assessment through DISA. The second lets tenants inherit shared infrastructure controls and focus on application-specific work.

A Pre-Authorized IL-4 Boundary Compresses the Path to Handling DoD CUI

For commercial SaaS handling standard DoD CUI, the FedRAMP baseline chosen at the outset determines the cost, timeline, and infrastructure burden of reaching IL-4. Matching that baseline to the actual mission scope avoids IL-5's dedicated-infrastructure model, and inheriting a pre-authorized boundary avoids rebuilding the shared controls that every IL-4 CSP already implements. That inheritance is the single largest lever a vendor has over authorization cost and time-to-mission.

Knox Systems operates a FedRAMP-as-a-Service platform built on that model, with tenants inheriting 60% to 80% of required NIST SP 800-53 Rev5 controls on day one and completing authorization in about 90 days.

Knox currently supports FedRAMP Moderate, FedRAMP High, and DISA IL-4. IL-5 authorization is in process, with an estimated completion date of December 2026. CSPs retain responsibility for their application-layer controls, continuous monitoring, DISA review, and the Mission Owner's system-specific ATO, but the scope of that work is significantly reduced.

Book a meeting to scope your IL-4 path.

FAQs about DoD Impact Level 4

What Are the Requirements for DoD Impact Level 4?

The DoD Readiness Assessment Report (RAR) and DoD component sponsorship establish eligibility to begin the assessment path. They do not substitute for the 3PAO assessment, DISA review, or mission-specific approval.

Which Cloud Providers Are Authorized at IL-4?

Mission Owners should check the DCAS catalog at the time of procurement and confirm the specific offering, impact level, and current authorization status. A provider name alone does not establish that every service is approved for IL-4.

How Many Controls Are in DoD IL-4?

Scope against Table D-1 and the DoD Rev5 System Security Plan (SSP) Addendum, then account for the selected FedRAMP baseline and requirements outside the control overlay. A published total detached from those inputs is not a reliable estimate of implementation effort.