DoD Cloud Service Catalog
The DoD Cloud Service Catalog is a listing of cloud-based services that the Department of Defense makes available to its components and mission partners, such as voice communications and other hosted capabilities. It helps DoD organizations identify cloud offerings that are intended to meet the department's security requirements. The specific services listed, and their eligibility for particular DoD environments, can change over time, so users should verify current offerings against official DISA sources.
A catalog of cloud service offerings made available for DoD use, associated with DISA's cloud service resources (for example, the listing at connect.disa.mil/catalog). Based on the available evidence, the catalog references services intended for DoD environments and impact levels, such as secure voice services described for DoD Impact Level 5 (IL5) and DoD365 environments, that fall under the broader DoD cloud computing security authorization framework maintained through the DoD Cloud Computing Security Requirements Guide (CC SRG). The CC SRG, developed by DISA, defines standards for categorizing DoD information and systems across defined Impact Levels and governs the standardized assessment and authorization process for cloud service offerings; the catalog itself should be understood as a service listing rather than the authorizing document. Note that catalog inclusion, applicable Impact Levels, and authorization status are subject to change; practitioners should confirm current service listings, authorization scope, and applicability against authoritative DISA and DoD Cyber Exchange sources, as this entry does not cover contractual terms, provisioning procedures, or specific authorization boundaries. Inclusion in the catalog should not be equated with a completed authorization for a given mission use case, and continuous monitoring and time-bound authorization obligations continue to apply.
Why it matters
For DoD components and mission partners, identifying cloud services that are intended to meet the department's security requirements is a recurring challenge. The DoD Cloud Service Catalog serves as a starting point for locating hosted capabilities, such as the secure voice services described for DoD Impact Level 5 (IL5) and DoD365 environments, that are oriented toward DoD environments. Rather than researching offerings piecemeal, organizations can consult the catalog to see what DISA makes available, which supports more consistent decision-making across the department.
The catalog matters most when it is understood in its proper context: as a service listing, not as an authorization document. Inclusion in the catalog should not be equated with a completed authorization for a given mission use case. Cloud service offerings for DoD use fall under the broader security authorization framework governed by the DoD Cloud Computing Security Requirements Guide (CC SRG), developed by DISA, which categorizes DoD information and systems across defined Impact Levels and defines the standardized assessment and authorization process. A common and consequential mistake is treating catalog presence as a substitute for confirming that a service is authorized at the appropriate Impact Level for a specific mission and environment.
Because the specific services listed, their applicable Impact Levels, and their authorization status can change over time, practitioners who rely on the catalog without verifying current listings against authoritative DISA and DoD Cyber Exchange sources risk provisioning services that do not match their actual security or authorization needs. Time-bound authorization and continuous monitoring obligations continue to apply regardless of a service's catalog status, so the catalog is best treated as one input into a broader due-diligence process rather than a final determination.
Who it's relevant to
Inside DoD Cloud Service Catalog
Common questions
Answers to the questions practitioners most commonly ask about DoD Cloud Service Catalog.