Skip to main content
Category: Cloud Security & Providers

DoD Cloud Service Catalog

Also known as: DISA Cloud Service Catalog
Simply put

The DoD Cloud Service Catalog is a listing of cloud-based services that the Department of Defense makes available to its components and mission partners, such as voice communications and other hosted capabilities. It helps DoD organizations identify cloud offerings that are intended to meet the department's security requirements. The specific services listed, and their eligibility for particular DoD environments, can change over time, so users should verify current offerings against official DISA sources.

Formal definition

A catalog of cloud service offerings made available for DoD use, associated with DISA's cloud service resources (for example, the listing at connect.disa.mil/catalog). Based on the available evidence, the catalog references services intended for DoD environments and impact levels, such as secure voice services described for DoD Impact Level 5 (IL5) and DoD365 environments, that fall under the broader DoD cloud computing security authorization framework maintained through the DoD Cloud Computing Security Requirements Guide (CC SRG). The CC SRG, developed by DISA, defines standards for categorizing DoD information and systems across defined Impact Levels and governs the standardized assessment and authorization process for cloud service offerings; the catalog itself should be understood as a service listing rather than the authorizing document. Note that catalog inclusion, applicable Impact Levels, and authorization status are subject to change; practitioners should confirm current service listings, authorization scope, and applicability against authoritative DISA and DoD Cyber Exchange sources, as this entry does not cover contractual terms, provisioning procedures, or specific authorization boundaries. Inclusion in the catalog should not be equated with a completed authorization for a given mission use case, and continuous monitoring and time-bound authorization obligations continue to apply.

Why it matters

For DoD components and mission partners, identifying cloud services that are intended to meet the department's security requirements is a recurring challenge. The DoD Cloud Service Catalog serves as a starting point for locating hosted capabilities, such as the secure voice services described for DoD Impact Level 5 (IL5) and DoD365 environments, that are oriented toward DoD environments. Rather than researching offerings piecemeal, organizations can consult the catalog to see what DISA makes available, which supports more consistent decision-making across the department.

The catalog matters most when it is understood in its proper context: as a service listing, not as an authorization document. Inclusion in the catalog should not be equated with a completed authorization for a given mission use case. Cloud service offerings for DoD use fall under the broader security authorization framework governed by the DoD Cloud Computing Security Requirements Guide (CC SRG), developed by DISA, which categorizes DoD information and systems across defined Impact Levels and defines the standardized assessment and authorization process. A common and consequential mistake is treating catalog presence as a substitute for confirming that a service is authorized at the appropriate Impact Level for a specific mission and environment.

Because the specific services listed, their applicable Impact Levels, and their authorization status can change over time, practitioners who rely on the catalog without verifying current listings against authoritative DISA and DoD Cyber Exchange sources risk provisioning services that do not match their actual security or authorization needs. Time-bound authorization and continuous monitoring obligations continue to apply regardless of a service's catalog status, so the catalog is best treated as one input into a broader due-diligence process rather than a final determination.

Who it's relevant to

DoD Components and Mission Partners
Organizations within the Department of Defense, and its mission partners, that need to identify cloud-based services, such as secure voice and other hosted capabilities, intended to meet DoD security requirements. They use the catalog as a starting point for discovery but should confirm current listings, applicable Impact Levels, and authorization status through authoritative DISA sources before relying on any offering.
Information System Security Managers and Authorizing Officials
Personnel responsible for making risk and authorization decisions for DoD systems. For them, the distinction between a service appearing in the catalog and a service being authorized at the appropriate Impact Level for a specific mission use case is critical. They must ensure that any selected offering aligns with the DoD CC SRG framework and that time-bound authorization and continuous monitoring obligations are met.
Cloud Service Providers Seeking DoD Use
Providers offering cloud service offerings for DoD environments, who should understand that catalog visibility is distinct from the standardized assessment and authorization process governed by the DISA-developed DoD Cloud Computing Security Requirements Guide. They should verify how their offerings are represented and confirm current requirements against official DISA and DoD Cyber Exchange sources.
Compliance Officers and Auditors
Professionals reviewing whether DoD cloud usage aligns with applicable security requirements. They should treat catalog inclusion as a service listing rather than evidence of a completed authorization, and should trace any relied-upon service back to its CC SRG Impact Level categorization and current authorization status through authoritative sources.

Inside DoD Cloud Service Catalog

Cloud Service Offering (CSO) Listings
Entries identifying commercial and government cloud service offerings that have been assessed for use by DoD components, typically annotated with the provider, the service, and the authorization status recognized for DoD use. The exact fields and structure should be verified against the current catalog maintained by the applicable DoD authority.
DoD Provisional Authorization (PA) Status
Indication of whether a CSO holds a DoD Provisional Authorization issued by the Defense Information Systems Agency (DISA) as the DoD cloud authorizing entity. A DoD PA is distinct from a FedRAMP authorization; the catalog generally reflects the DoD-specific status rather than substituting for a component's own Authority to Operate (ATO).
Impact Level (IL) Designation
Reference to the DoD Cloud Computing Security Requirements Guide (SRG) impact levels (commonly cited as IL2, IL4, IL5, and IL6) that categorize the sensitivity of information a CSO is authorized to handle. Impact levels are a DoD construct and should not be conflated with FedRAMP Low/Moderate/High baselines, though they build upon FedRAMP authorizations in most implementations.
Sponsoring or Authorizing Information
Details identifying the DoD entity associated with an offering's assessment or authorization. Readers should confirm current sponsorship, reciprocity, and inheritance details against the authoritative catalog and applicable SRG guidance rather than assuming a listing conveys blanket approval.

Common questions

Answers to the questions practitioners most commonly ask about DoD Cloud Service Catalog.

Does a cloud service being listed in the DoD Cloud Service Catalog mean it is automatically approved for any DoD mission or data type?
No. Listing generally reflects that a cloud service offering has achieved a DoD Provisional Authorization at a specified Impact Level, but it does not by itself authorize any particular mission use. The mission owner's Authorizing Official must still issue a system-specific Authority to Operate that accounts for the data types involved, the applicable Impact Level, and the specific system context. Treating catalog inclusion as blanket approval conflates a reusable provisional authorization with a mission-specific authorization decision. Verify the current authorization status and any conditions against the authoritative DoD source.
If a cloud service already holds a FedRAMP authorization, does that mean it satisfies DoD requirements and belongs in the DoD Cloud Service Catalog?
Not necessarily. FedRAMP authorization, maintained through the FedRAMP PMO, is generally a starting point but does not automatically satisfy DoD-specific requirements. DoD adds requirements beyond the FedRAMP baseline, which are expressed through the DoD Cloud Computing Security Requirements Guide (SRG) and its Impact Levels. A FedRAMP authorization does not equate to a DoD Provisional Authorization, and readers should confirm the specific authorization type and Impact Level against current official DoD guidance rather than assuming equivalence.
How should a mission owner use the catalog when selecting a cloud service offering?
In most implementations, the catalog is used to identify cloud service offerings that hold a DoD Provisional Authorization at an Impact Level appropriate to the data the mission owner intends to process, store, or transmit. The mission owner generally reviews the listed Impact Level against their own data categorization, then proceeds to obtain a mission-specific authorization. The catalog supports reuse of the provisional authorization body of evidence but does not replace the mission owner's own authorization responsibilities. Confirm current listings and Impact Levels against the authoritative DoD source.
What is the relationship between the catalog and the DoD Cloud Computing SRG when determining what data can be placed in a listed service?
The DoD Cloud Computing SRG generally defines the Impact Levels and the associated security requirements, while the catalog reflects the Impact Level at which a given offering has been provisionally authorized. To determine suitability, a reader typically matches the sensitivity of their data, for example CUI or other categorized information, to the Impact Level requirements in the SRG, then confirms the listed offering carries a provisional authorization at that level. This entry does not cover specific data categorization decisions, which must be confirmed against current DoD policy and the applicable SRG revision.
Does inclusion in the catalog remove the mission owner's continuous monitoring responsibilities?
No. A provisional authorization reflected in the catalog is time-bound and subject to ongoing conditions, and a mission owner's own authorization remains subject to continuous monitoring under the RMF. Compliance status shown at the point of listing should not be treated as permanent. Mission owners generally retain responsibility for monitoring their system's security posture and for tracking the continued authorization status of the underlying service. Verify current monitoring expectations against applicable DoD guidance.
Where should a reader confirm the current, authoritative status of a cloud service offering listed in the catalog?
Because authorization status, Impact Levels, and listing conditions can change, readers should confirm details against the current authoritative DoD source that maintains the catalog rather than relying on secondary references. This entry describes the catalog's general purpose and does not capture implementation, contractual, or authorization-status specifics, which a reader must verify against the applicable current official documentation and their Authorizing Official's guidance.

Common misconceptions

A cloud service listed in the DoD Cloud Service Catalog is automatically approved for any DoD system or mission.
Inclusion generally reflects a DoD Provisional Authorization at a specified impact level, not a mission-specific authorization. Individual DoD components typically must still obtain their own ATO through the Risk Management Framework (RMF), and reuse depends on the applicable impact level, data type, and component-level review.
A FedRAMP authorization means a cloud offering already satisfies DoD cloud requirements.
FedRAMP (managed by the FedRAMP PMO) and the DoD Cloud Computing SRG are distinct authorities. DoD impact levels build upon FedRAMP baselines in most implementations but add DoD-specific requirements. A FedRAMP authorization does not by itself confer a DoD Provisional Authorization or satisfy DoD-specific controls.
Once a service appears in the catalog, its authorization status is permanent.
Authorizations recognized in the catalog are time-bound and subject to continuous monitoring. Status can change across revisions, reassessments, or SRG updates, so practitioners should verify the current status directly rather than relying on a prior listing.

Best practices

Verify a cloud offering's current DoD Provisional Authorization status and impact level directly against the authoritative catalog maintained by the applicable DoD authority (such as DISA) before relying on it, rather than treating a prior listing as current.
Confirm that the offering's authorized impact level matches the sensitivity of the data and mission you intend to host, consulting the DoD Cloud Computing SRG for the applicable IL definitions.
Do not treat catalog inclusion or a DoD PA as a substitute for your component's own ATO; plan for the full RMF authorization process and any control inheritance or reciprocity you intend to claim.
Distinguish FedRAMP authorization from DoD authorization in your documentation, and confirm which DoD-specific requirements remain your responsibility rather than assuming FedRAMP status is sufficient.
Incorporate continuous monitoring expectations into your planning, since authorizations are time-bound and status can change across reassessments and SRG revisions.
When precise fields, impact-level applicability, or authorization boundaries are unclear, confirm them against current official DoD sources rather than inferring them from the catalog listing alone.