Skip to main content
Category: Cloud Security & Providers

DoD Cloud Computing Security Requirements Guide

Also known as: CC SRG, DoD Cloud Computing SRG, Cloud Computing Security Requirements Guide
Simply put

The DoD Cloud Computing Security Requirements Guide is Department of Defense guidance that sets out the security conditions cloud service offerings generally must meet before DoD organizations can use them to handle DoD information. It is designed to help match a cloud service to the sensitivity of the data it will hold and to inform DoD authorization decisions. Because the specifics can change across revisions and depend on the type of information involved, readers should verify the current authoritative text before relying on any particular requirement.

Formal definition

The CC SRG is a DoD-issued guidance document that establishes the security requirements and authorization framework for the acquisition and use of cloud service offerings by DoD components. It is commonly used to align cloud services with defined information sensitivity tiers (often referred to as impact levels) and to govern how cloud offerings are assessed and authorized for DoD use, typically in relation to broader DoD Risk Management Framework (RMF) processes. The CC SRG addresses DoD-specific requirements and should not be treated as interchangeable with civilian FedRAMP authorization; a FedRAMP authorization does not by itself satisfy DoD requirements, and readers should confirm applicable impact levels, control expectations, and authorization procedures against the current official version, as these are subject to revision and DoD-specific interpretation. This entry does not cover contractual, implementation, or classified-system specifics, which must be confirmed against current authoritative sources.

Why it matters

The DoD Cloud Computing SRG matters because it is the DoD-specific bridge between commercial cloud services and the Department's obligation to protect its information according to sensitivity. DoD components cannot simply adopt any cloud service that happens to be available; the CC SRG helps ensure that the security posture of a given cloud service offering is matched to the sensitivity of the data it will handle. Without this alignment, a DoD organization risks placing sensitive information in an environment that was never assessed against DoD-specific expectations.

A persistent and consequential misunderstanding is the assumption that a FedRAMP authorization automatically qualifies a cloud service for DoD use. FedRAMP addresses federal civilian requirements, while the CC SRG addresses DoD-specific requirements; a FedRAMP authorization does not by itself satisfy DoD conditions. Treating the two as interchangeable can lead an organization to believe a service is approved for DoD data when additional DoD-specific assessment and authorization are still required. Similarly, readers should not conflate assessment with authorization, or treat any authorization as static, because the CC SRG operates within broader DoD Risk Management Framework processes that emphasize ongoing risk management rather than a one-time approval.

Because the CC SRG's specifics, including impact levels, control expectations, and authorization procedures, are subject to revision and DoD-specific interpretation, relying on outdated or generalized summaries can produce compliance gaps. Compliance officers and authorizing officials should confirm the current authoritative version before making decisions, and should recognize that contractual, implementation, and classified-system considerations fall outside the guidance summarized here and must be verified against current official sources.

Who it's relevant to

Authorizing Officials and ISSMs
Authorizing officials and information system security managers responsible for DoD systems use the CC SRG to inform decisions about whether a cloud service offering is appropriate for a given category of DoD information. They should treat authorization as time-bound and subject to continuous monitoring within the RMF, rather than as a permanent approval, and should verify current impact level and authorization expectations against the official version.
Government Contractors and Cloud Service Providers
Contractors and cloud service providers seeking to support DoD workloads need to understand that meeting the CC SRG's DoD-specific requirements is distinct from obtaining a civilian FedRAMP authorization. A FedRAMP authorization does not by itself satisfy DoD requirements, and providers should confirm the applicable impact levels and assessment expectations for the specific DoD information their service is intended to handle.
Compliance Officers and Auditors
Compliance officers and auditors evaluating DoD cloud usage rely on the CC SRG as a reference point for whether cloud offerings have been aligned to the correct sensitivity tier and properly authorized. They should distinguish assessment activities from authorization decisions, avoid equating compliance with security, and confirm control expectations and procedures against the current authoritative text, since these are subject to revision.
DoD Program and Acquisition Personnel
Personnel involved in acquiring cloud services for DoD components should use the CC SRG to match candidate services to the sensitivity of the data involved before procurement decisions are made. Contractual and implementation specifics fall outside the guidance summarized here and must be confirmed against current official DoD sources.

Inside CC SRG

Impact Levels (ILs)
The CC SRG organizes cloud service requirements into Information Impact Levels that reflect the sensitivity of the information and the potential consequences of loss of confidentiality, integrity, or availability. These levels generally distinguish between non-controlled unclassified information and Controlled Unclassified Information (CUI), with higher levels imposing more stringent requirements. Practitioners should verify the current level definitions and numbering against the applicable revision of the SRG, as these have evolved over time.
Relationship to FedRAMP
The CC SRG builds upon FedRAMP authorization as a baseline for cloud service offerings and layers additional DoD-specific requirements on top of it. A FedRAMP authorization does not, by itself, satisfy DoD requirements; the SRG defines the supplemental controls and conditions needed for DoD use. Confirm the precise inheritance relationship and any additional control requirements against the current SRG text.
DoD Provisional Authorization (PA)
The SRG describes the process by which the Defense Information Systems Agency (DISA) issues a DoD Provisional Authorization for a cloud service offering. A PA represents an assessment artifact at a given impact level, but individual DoD mission owners still generally must issue their own Authority to Operate (ATO) for their specific use of the service. Verify the current authorization workflow and roles against official DISA and DoD CIO guidance.
Authoring and Governing Authority
The CC SRG is maintained under DoD authority, with DISA playing a central role in its development and in the assessment and authorization activities it describes. It should not be treated as equivalent to NIST guidance or to the FedRAMP PMO's authorizations, though it references and relies on those frameworks.
Security Requirements and Controls Context
The SRG translates control expectations, drawing on baselines associated with NIST and FedRAMP, into DoD-specific requirements appropriate to each impact level. It addresses how cloud service offerings should protect DoD information but leaves detailed control catalog specifics to the underlying source publications, which readers should consult in their applicable revisions.

Common questions

Answers to the questions practitioners most commonly ask about CC SRG.

Does a FedRAMP authorization automatically mean a cloud service can host DoD workloads?
No. A FedRAMP authorization is a prerequisite but does not by itself satisfy DoD requirements. The DoD Cloud Computing SRG builds on FedRAMP and adds DoD-specific requirements, and cloud offerings are evaluated against Impact Levels defined in the SRG. A Cloud Service Offering must obtain a DoD Provisional Authorization consistent with the applicable Impact Level, and the mission owner must still complete its own authorization steps. Verify current requirements against the SRG and applicable DoD guidance, because the relationship between FedRAMP and DoD authorization is layered rather than automatic.
Is a Provisional Authorization under the CC SRG the same as an Authority to Operate (ATO) for my system?
No. A DoD Provisional Authorization applies to the cloud service offering and is not equivalent to an ATO for the mission owner's system. The mission owner or authorizing official generally remains responsible for authorizing the specific information system that runs on the cloud service, typically through the RMF. Treating a provider's provisional authorization as a system ATO is a common error; assessment and provider-level authorization are distinct from the mission owner's authorization. Confirm the specific division of responsibilities against current SRG and RMF guidance.
How do I determine which Impact Level applies to a workload I plan to move to the cloud?
The applicable Impact Level generally depends on the sensitivity of the information involved, such as the type of Controlled Unclassified Information and the associated confidentiality, integrity, and availability considerations described in the SRG. The SRG defines Impact Levels used to categorize cloud offerings and the data they may host. Because tailoring and interpretation can be mission-specific, mission owners should work with their authorizing official and reference the current SRG text rather than assuming a level based on general data descriptions.
What responsibilities remain with the mission owner even when using an authorized cloud service?
The CC SRG generally reflects a shared responsibility model in which the cloud service provider addresses certain controls and the mission owner remains responsible for others, including the configuration and security of the system, application, and data it deploys on the service. The mission owner also generally retains responsibility for authorizing its own system and for continuous monitoring of what it controls. Consult the applicable SRG and any Provisional Authorization documentation to confirm the precise allocation of responsibilities for a given offering.
How does the CC SRG relate to the RMF when authorizing a system in the cloud?
The CC SRG provides requirements for the cloud service layer, while the mission owner's system is generally authorized through the RMF process. In most implementations the mission owner leverages the cloud provider's provisional authorization and inherited controls, then addresses remaining controls in its own RMF authorization package. The two are complementary rather than interchangeable. Verify the current process and any inheritance details against the SRG and applicable DoD RMF guidance.
Does a Provisional Authorization remain valid indefinitely once granted?
No. Authorizations under the CC SRG are subject to continuous monitoring and are not permanent. As with an ATO, ongoing conditions, changes to the offering, and evolving requirements can affect authorization status, and revisions to the SRG may change applicable expectations. Mission owners and providers should track continuous monitoring obligations and confirm current authorization status against official sources rather than assuming an authorization persists unchanged.

Common misconceptions

A FedRAMP authorization means a cloud service is automatically approved for DoD use.
FedRAMP authorization generally serves as a baseline, but the CC SRG imposes additional DoD-specific requirements and a separate DoD Provisional Authorization process. FedRAMP status alone does not satisfy DoD requirements, and mission owners typically still need their own authorization decision.
A DoD Provisional Authorization is the same as an Authority to Operate for a mission owner's system.
A Provisional Authorization is an assessment-level artifact for the cloud service offering. It is distinct from a mission owner's ATO, which remains time-bound, subject to continuous monitoring, and specific to how that owner deploys and uses the service. Assessment is not the same as authorization.
The impact levels in the CC SRG are fixed and interchangeable with FedRAMP impact levels.
The SRG's Information Impact Levels are DoD-specific and reflect information sensitivity such as CUI, and their definitions and numbering have changed across revisions. They should not be assumed identical to FedRAMP baselines, and the current SRG revision should be verified.

Best practices

Confirm the impact level applicable to your data (including whether CUI is involved) against the current revision of the CC SRG before selecting or authorizing a cloud service offering.
Treat FedRAMP authorization as a baseline only, and identify the additional DoD-specific requirements the SRG layers on top before relying on a cloud service for DoD workloads.
Distinguish between a DISA-issued Provisional Authorization for the service and your own mission owner ATO, and plan to obtain the authorization decision appropriate to your deployment.
Maintain continuous monitoring after authorization, recognizing that an ATO is time-bound and not a permanent approval.
Verify roles, workflow, and authorization processes against current official DISA and DoD CIO guidance rather than relying on prior versions of the SRG, since requirements evolve across revisions.
Consult the underlying source publications for detailed control specifics rather than assuming the SRG restates the full control catalog.