Skip to main content
Category: Cloud Security & Providers

Boundary Cloud Access Point

Also known as: BCAP, Boundary CAP, Cloud Access Point (BCAP variant)
Simply put

A Boundary Cloud Access Point (BCAP) is a security connection point used by the U.S. Department of Defense to link commercial cloud services to DoD networks. Its main job is to protect DoD networks from threats that could come from the cloud environment. It generally must be in place before an off-premises commercial cloud service can connect to the DISN or another applicable network.

Formal definition

The Boundary Cloud Access Point (BCAP) is a variant of the DoD Cloud Access Point (CAP) described within the DoD Secure Cloud Computing Architecture (SCCA) and related connection guidance. Per the DISN Connection Process Guide, a BCAP is generally required to connect off-premises, commercially owned and operated Cloud Service Offerings (CSOs) to the DISN (or other network). Its stated purpose is to protect the DISN from attacks originating in the cloud environment. Note that specific BCAP implementation, configuration, and boundary details are typically predetermined by the connecting organization and are out of scope for cloud-provider reference architectures; readers should verify current requirements against the authoritative DoD connection guidance and SCCA documentation.

Why it matters

The BCAP addresses a core risk in the DoD's adoption of commercial cloud: connecting off-premises, commercially owned and operated Cloud Service Offerings (CSOs) to the DISN creates a potential pathway for threats to reach DoD networks from the cloud environment. As the DoD's connection guidance and the DoD Secure Cloud Computing Architecture (SCCA) reflect, the BCAP exists specifically to protect the DISN from attacks that originate in the cloud environment, making it a gatekeeping control between commercial cloud and defense networks.

Because a BCAP is generally required before an off-premises commercial CSO can connect to the DISN (or another applicable network), it functions as a compliance and architectural prerequisite rather than an optional enhancement. Organizations planning cloud connectivity to DoD networks should treat the BCAP as part of the authorization and connection pathway, not as a substitute for the broader control and monitoring obligations that accompany operating a cloud service in a DoD context. Compliance with a connection requirement such as the BCAP should not be equated with overall security of the connected environment.

A frequent point of confusion is scope and ownership. Cloud-provider reference architectures (such as those published by commercial cloud vendors) generally treat BCAP implementation, configuration, and boundary details as predetermined by the connecting organization and out of scope for the provider's own guidance. Readers should therefore not assume that a cloud provider's documentation defines their BCAP obligations, and should verify current requirements against the authoritative DoD connection guidance and SCCA documentation, which may change across revisions.

Who it's relevant to

DoD cloud program and mission owners
Organizations planning to connect an off-premises, commercially owned and operated CSO to the DISN or another applicable network generally must account for a BCAP as a connection prerequisite. Because implementation and boundary details are predetermined by the connecting organization, mission owners bear responsibility for defining and standing up these requirements consistent with current DoD connection guidance and SCCA documentation.
Information System Security Managers and authorizing officials
ISSMs and AOs supporting DoD cloud connections should treat the BCAP as part of the connection and authorization pathway and verify its requirements against the authoritative DoD guidance. They should be careful not to equate meeting a connection requirement with achieving overall security, or to assume a cloud provider's reference architecture defines their BCAP obligations.
Cloud service providers and integrators serving DoD
Commercial cloud providers and integrators should recognize that BCAP implementation, configuration, and boundary details are generally predetermined by the connecting DoD organization and are commonly treated as out of scope for provider reference architectures. Coordination with the connecting organization is needed to align a CSO's connectivity with the applicable BCAP requirements.
Compliance officers and auditors
Those assessing DoD cloud connections should confirm whether a BCAP is required for a given off-premises commercial CSO connection to the DISN and verify that requirements are drawn from current DoD connection guidance and SCCA documentation rather than assumed from vendor materials, as these requirements may change across revisions.

Inside BCAP

Access Point Function
A Boundary Cloud Access Point (BCAP) generally functions as a controlled connection point that mediates traffic between a cloud service environment and the protected network boundary, providing inspection and policy enforcement for data traversing that boundary. The specific architecture and required capabilities are defined by the applicable DoD guidance, which the reader should verify against current authoritative text.
Boundary Protection Role
The BCAP contributes to boundary protection by concentrating and monitoring the flow of traffic to and from cloud services, supporting the broader objective of controlling the security perimeter of DoD systems. In most implementations it works alongside other boundary defense components rather than serving as a standalone control.
Cloud Connectivity Context
The concept applies to scenarios where DoD mission owners consume commercial or government cloud services and require a defined, monitored pathway consistent with DoD cloud security requirements. Applicability depends on the impact level and the specific DoD authorization framework in effect for the system.
Governing Authority
Requirements associated with cloud access points for DoD systems are generally established under DoD guidance rather than civilian FedRAMP authorization alone. Readers should confirm the precise governing publication, revision, and applicable impact level against current official DoD sources.

Common questions

Answers to the questions practitioners most commonly ask about BCAP.

Does having a BCAP mean my cloud service is automatically authorized for DoD use?
No. A Boundary Cloud Access Point is a network security and connection construct, not an authorization decision. It generally provides a protected point of connection and inspection between DoD networks and cloud environments, but it does not by itself confer an Authority to Operate (ATO) or a DoD Provisional Authorization. Authorization is a separate process, and readers should not conflate the existence or use of a BCAP with the assessment and authorization outcomes required for the applicable impact level. Confirm authorization status against the current official DoD guidance.
Is a BCAP the same thing as a Cloud Access Point (CAP), or are these interchangeable terms?
They are related but should not be treated as interchangeable without checking the governing DoD guidance. The terminology around cloud access points has evolved, and specific terms may carry distinct meanings depending on the applicable version of DoD cloud connection and security requirements. Because these constructs and their naming can change across revisions, verify the exact term, definition, and scope in the current authoritative DoD source rather than assuming equivalence.
How does a BCAP relate to the impact level of the cloud service being connected?
Connection and inspection requirements generally vary by impact level, and the role a BCAP plays typically depends on the sensitivity of the information and the applicable DoD cloud requirements. Because impact-level requirements and the associated boundary protections are subject to DoD guidance and revision, confirm which requirements apply to your specific impact level against the current official text rather than assuming a single uniform approach.
Who is responsible for standing up and operating a BCAP?
Responsibilities are generally allocated among DoD components, service providers, and the connecting organization according to the applicable DoD guidance and the specifics of the connection. Because roles can differ by component and by the arrangement in place, organizations should verify their specific responsibilities, and those of any provider, against the governing DoD requirements and any applicable agreements rather than assuming a default allocation.
Does using a BCAP satisfy continuous monitoring obligations?
Not on its own. A BCAP may support monitoring and inspection functions at the connection point, but it does not replace the broader continuous monitoring obligations associated with an authorization. Authorizations are time-bound and subject to ongoing monitoring, and compliance with connection requirements is distinct from meeting the full set of continuous monitoring expectations. Confirm the specific monitoring responsibilities that apply to your system against current DoD guidance.
What should I verify before relying on a BCAP for a specific project?
Confirm the applicable DoD guidance and version in effect, the impact level and information type involved, the authorization status of the cloud service, the allocation of responsibilities among your organization and any providers, and the continuous monitoring obligations that apply. Because these requirements are subject to revision and may be interpreted differently across DoD components, validate all specifics against the current official sources rather than relying on general descriptions.

Common misconceptions

A FedRAMP authorization for a cloud service means a BCAP is unnecessary for DoD use.
FedRAMP authorization does not automatically satisfy DoD-specific requirements. DoD cloud consumption generally imposes additional boundary and access controls, and a BCAP may be required as part of meeting those DoD obligations. Verify the applicable DoD requirements and impact level against current authoritative guidance.
Deploying a BCAP by itself makes a system compliant or secure.
A BCAP is one boundary component and does not equate to either compliance or security. It must be implemented within a broader authorized architecture and continuous monitoring program. Compliance and security are distinct objectives, and neither is established solely by the presence of an access point.
Once a BCAP is stood up and authorized, its approval is permanent.
Authorizations associated with systems using a BCAP are time-bound and subject to continuous monitoring rather than permanent. The connection and its controls must be maintained, assessed, and re-evaluated over time consistent with the applicable authorization process.

Best practices

Confirm the current governing DoD guidance, revision, and applicable impact level before designing or relying on a BCAP, rather than assuming a fixed requirement.
Do not treat a cloud service's FedRAMP authorization as sufficient for DoD use; verify and satisfy the additional DoD-specific boundary and access requirements separately.
Integrate the BCAP into a broader boundary protection architecture and continuous monitoring program instead of treating it as a standalone security solution.
Distinguish clearly between assessment and authorization activities for systems relying on a BCAP, and ensure both are addressed under the applicable process.
Treat any authorization covering the BCAP as time-bound and maintain ongoing monitoring, reassessment, and re-authorization as required.
Validate all impact-level determinations, applicability, and configuration requirements against current official DoD sources before implementation.