Boundary Cloud Access Point
A Boundary Cloud Access Point (BCAP) is a security connection point used by the U.S. Department of Defense to link commercial cloud services to DoD networks. Its main job is to protect DoD networks from threats that could come from the cloud environment. It generally must be in place before an off-premises commercial cloud service can connect to the DISN or another applicable network.
The Boundary Cloud Access Point (BCAP) is a variant of the DoD Cloud Access Point (CAP) described within the DoD Secure Cloud Computing Architecture (SCCA) and related connection guidance. Per the DISN Connection Process Guide, a BCAP is generally required to connect off-premises, commercially owned and operated Cloud Service Offerings (CSOs) to the DISN (or other network). Its stated purpose is to protect the DISN from attacks originating in the cloud environment. Note that specific BCAP implementation, configuration, and boundary details are typically predetermined by the connecting organization and are out of scope for cloud-provider reference architectures; readers should verify current requirements against the authoritative DoD connection guidance and SCCA documentation.
Why it matters
The BCAP addresses a core risk in the DoD's adoption of commercial cloud: connecting off-premises, commercially owned and operated Cloud Service Offerings (CSOs) to the DISN creates a potential pathway for threats to reach DoD networks from the cloud environment. As the DoD's connection guidance and the DoD Secure Cloud Computing Architecture (SCCA) reflect, the BCAP exists specifically to protect the DISN from attacks that originate in the cloud environment, making it a gatekeeping control between commercial cloud and defense networks.
Because a BCAP is generally required before an off-premises commercial CSO can connect to the DISN (or another applicable network), it functions as a compliance and architectural prerequisite rather than an optional enhancement. Organizations planning cloud connectivity to DoD networks should treat the BCAP as part of the authorization and connection pathway, not as a substitute for the broader control and monitoring obligations that accompany operating a cloud service in a DoD context. Compliance with a connection requirement such as the BCAP should not be equated with overall security of the connected environment.
A frequent point of confusion is scope and ownership. Cloud-provider reference architectures (such as those published by commercial cloud vendors) generally treat BCAP implementation, configuration, and boundary details as predetermined by the connecting organization and out of scope for the provider's own guidance. Readers should therefore not assume that a cloud provider's documentation defines their BCAP obligations, and should verify current requirements against the authoritative DoD connection guidance and SCCA documentation, which may change across revisions.
Who it's relevant to
Inside BCAP
Common questions
Answers to the questions practitioners most commonly ask about BCAP.