DoD Provisional Authorization
A DoD Provisional Authorization (PA) is an approval that lets a cloud service provider handle Department of Defense data after showing it meets DoD cloud security requirements. It is not permanent; it is granted for a set period and depends on the provider keeping up with ongoing security monitoring. Having a PA generally allows DoD organizations to store, process, or evaluate certain categories of DoD data in that cloud service.
A DoD Provisional Authorization (PA) is an authorization enabling a cloud service offering (CSO) to process and store DoD information consistent with the applicable DoD cloud security requirements, such as the impact levels described in the DoD Cloud Computing Security Requirements Guide (SRG). According to the DoD Cyber Exchange, there are generally two pathways to obtain a PA: leveraging an existing FedRAMP authorization or having a DoD component sponsor a CSO. A PA is time-bound rather than permanent, tied to a defined term and to ongoing continuous monitoring, and readers should note that a PA is distinct from a FedRAMP authorization and from a mission owner's own Authority to Operate (ATO), which must still be pursued for a specific system. Precise impact-level scoping, PA validity periods, and current issuance procedures should be verified against the applicable DoD SRG and DISA guidance, as these details evolve across revisions.
Why it matters
A DoD Provisional Authorization is the mechanism that allows a commercial cloud service offering to be trusted with Department of Defense information at defined impact levels. Without a PA, a cloud service provider generally cannot store, process, or serve as an environment where DoD components store, process, or even evaluate certain categories of DoD data. For mission owners weighing cloud adoption, the presence of a current PA is a threshold indicator that a cloud service offering has been assessed against the applicable DoD cloud security requirements, such as those described in the DoD Cloud Computing Security Requirements Guide (SRG).
A critical point that experts insist on is that a PA is not permanent and is not equivalent to authorization to run a specific mission system. A PA is time-bound, granted for a defined term, and contingent on the provider sustaining continuous monitoring. Treating a PA as a one-time, indefinite approval is a common and consequential mistake. Equally important, a PA covers the cloud service offering; it does not relieve a mission owner of the obligation to pursue its own Authority to Operate (ATO) for the specific system deployed in that cloud. Compliance at the provider level and authorization at the system level are distinct steps.
Another frequent misunderstanding is assuming that a FedRAMP authorization automatically satisfies DoD requirements. While leveraging an existing FedRAMP authorization is one recognized pathway toward a PA, a PA is distinct from a FedRAMP authorization, and DoD-specific requirements and impact-level scoping still apply. Readers should verify current impact-level definitions, PA validity periods, and issuance procedures against the applicable DoD SRG and DISA guidance, as these details evolve across revisions.
Who it's relevant to
Inside PA
Common questions
Answers to the questions practitioners most commonly ask about PA.