Skip to main content
Category: Authorization & Accreditation

DoD Provisional Authorization

Also known as: PA, DISA Provisional Authorization, DoD PA
Simply put

A DoD Provisional Authorization (PA) is an approval that lets a cloud service provider handle Department of Defense data after showing it meets DoD cloud security requirements. It is not permanent; it is granted for a set period and depends on the provider keeping up with ongoing security monitoring. Having a PA generally allows DoD organizations to store, process, or evaluate certain categories of DoD data in that cloud service.

Formal definition

A DoD Provisional Authorization (PA) is an authorization enabling a cloud service offering (CSO) to process and store DoD information consistent with the applicable DoD cloud security requirements, such as the impact levels described in the DoD Cloud Computing Security Requirements Guide (SRG). According to the DoD Cyber Exchange, there are generally two pathways to obtain a PA: leveraging an existing FedRAMP authorization or having a DoD component sponsor a CSO. A PA is time-bound rather than permanent, tied to a defined term and to ongoing continuous monitoring, and readers should note that a PA is distinct from a FedRAMP authorization and from a mission owner's own Authority to Operate (ATO), which must still be pursued for a specific system. Precise impact-level scoping, PA validity periods, and current issuance procedures should be verified against the applicable DoD SRG and DISA guidance, as these details evolve across revisions.

Why it matters

A DoD Provisional Authorization is the mechanism that allows a commercial cloud service offering to be trusted with Department of Defense information at defined impact levels. Without a PA, a cloud service provider generally cannot store, process, or serve as an environment where DoD components store, process, or even evaluate certain categories of DoD data. For mission owners weighing cloud adoption, the presence of a current PA is a threshold indicator that a cloud service offering has been assessed against the applicable DoD cloud security requirements, such as those described in the DoD Cloud Computing Security Requirements Guide (SRG).

A critical point that experts insist on is that a PA is not permanent and is not equivalent to authorization to run a specific mission system. A PA is time-bound, granted for a defined term, and contingent on the provider sustaining continuous monitoring. Treating a PA as a one-time, indefinite approval is a common and consequential mistake. Equally important, a PA covers the cloud service offering; it does not relieve a mission owner of the obligation to pursue its own Authority to Operate (ATO) for the specific system deployed in that cloud. Compliance at the provider level and authorization at the system level are distinct steps.

Another frequent misunderstanding is assuming that a FedRAMP authorization automatically satisfies DoD requirements. While leveraging an existing FedRAMP authorization is one recognized pathway toward a PA, a PA is distinct from a FedRAMP authorization, and DoD-specific requirements and impact-level scoping still apply. Readers should verify current impact-level definitions, PA validity periods, and issuance procedures against the applicable DoD SRG and DISA guidance, as these details evolve across revisions.

Who it's relevant to

Cloud Service Providers Serving DoD
Providers seeking to serve DoD customers need a PA before their cloud service offering can be used to store, process, or evaluate DoD data at the relevant impact levels. They must understand the two pathways to a PA (leveraging FedRAMP or DoD component sponsorship) and sustain the continuous monitoring on which the time-bound PA depends.
DoD Mission Owners and Program Managers
Teams selecting a cloud environment should confirm that a candidate cloud service offering holds a current PA at the appropriate impact level. They should also recognize that a provider's PA does not substitute for the mission owner's own Authority to Operate, which must still be obtained for their specific system.
Information System Security Managers and Authorizing Officials
These roles must distinguish between provider-level provisional authorization and system-level authorization, and account for the time-bound nature of a PA and its dependence on continuous monitoring when making risk decisions. They should verify current impact-level scoping and validity periods against the applicable DoD SRG and DISA guidance.
Compliance and Assessment Professionals
Assessors and compliance staff should be careful not to conflate a PA with a FedRAMP authorization or to assume FedRAMP status automatically satisfies DoD requirements. Because PA procedures, terms, and impact-level definitions evolve across revisions, they should anchor their work to the current authoritative DoD SRG and DISA sources rather than to prior versions.

Inside PA

Issuing Authority (DISA)
A DoD Provisional Authorization is typically granted by the Defense Information Systems Agency (DISA), generally acting on behalf of the DoD, following an assessment of a cloud service offering against the DoD Cloud Computing Security Requirements Guide (SRG). Practitioners should verify the current issuing authority and process against official DISA and DoD CIO guidance, as roles and procedures may evolve.
Basis in the DoD Cloud Computing SRG
A PA is generally tied to the DoD Cloud Computing Security Requirements Guide, which defines Impact Levels (commonly referenced as IL2, IL4, IL5, and IL6) that layer additional DoD-specific requirements onto an underlying FedRAMP baseline. The specific Impact Level associated with a PA scopes the types of information the cloud service is assessed to handle; confirm the applicable level against the current SRG revision.
Provisional (Not Final) Nature
The term 'provisional' indicates that the authorization represents a DoD-level assessment of a cloud service offering rather than a final Authority to Operate (ATO) for any specific mission owner's system. A PA generally provides reusable assessment evidence that individual DoD components and mission owners can leverage, but it does not by itself authorize a particular system to operate.
Relationship to Mission Owner Authorization
A PA is generally intended to be inherited or reused by DoD mission owners, who remain responsible for authorizing their own systems and workloads built on the cloud service, typically under the Risk Management Framework (RMF). The mission owner's Authorizing Official issues the system-level authorization decision that accounts for the specific implementation and residual risk.
Scope and Impact Level Boundary
A PA covers a defined cloud service offering at a specified Impact Level and does not extend to services, configurations, or higher impact levels outside its assessed boundary. Handling of Controlled Unclassified Information (CUI) or higher-sensitivity data generally requires the correspondingly higher Impact Level; verify the assessed boundary before relying on a PA.

Common questions

Answers to the questions practitioners most commonly ask about PA.

Does a DoD Provisional Authorization (PA) mean my cloud service is fully authorized to operate for any DoD mission owner?
No. A DoD PA is not an Authority to Operate (ATO). A PA is generally issued by the Defense Information Systems Agency (DISA) and represents an assessment that a Cloud Service Offering (CSO) meets the requirements of the DoD Cloud Computing Security Requirements Guide (SRG) at a given impact level. Each DoD mission owner must still issue its own ATO for the specific system and use case built on that CSO, factoring in mission-specific risk. Treating a PA as a substitute for an ATO conflates assessment with authorization, which are distinct steps.
If my cloud offering already holds a FedRAMP authorization, does that automatically give it a DoD Provisional Authorization?
Not automatically. FedRAMP authorization and a DoD PA are distinct, though related. The DoD Cloud Computing SRG generally builds on FedRAMP baselines but adds DoD-specific requirements, particularly at higher impact levels. A FedRAMP authorization may serve as a foundation, but a CSO must still be assessed against the applicable DoD SRG requirements to receive a PA. Assuming FedRAMP status alone satisfies DoD requirements is a common and consequential mistake.
How does a DoD PA relate to the impact levels defined in the Cloud Computing SRG?
A DoD PA is generally scoped to a specific impact level as defined in the DoD Cloud Computing SRG. The impact level reflects the sensitivity of the information (for example, non-controlled versus CUI) and other risk considerations. A PA granted at one impact level does not extend to higher impact levels; a CSO seeking to host more sensitive information would generally need to be assessed and authorized at the corresponding higher level. Verify the specific impact level definitions and requirements against the current SRG revision.
What steps does a mission owner still need to take after a CSO receives a PA?
After a CSO holds a PA, the mission owner is generally responsible for authorizing its own system built on that offering, typically through the Risk Management Framework (RMF) process, and issuing an ATO for the specific deployment. This includes addressing customer-responsible controls, inheriting provider-responsible controls appropriately, documenting the shared responsibility boundary, and implementing continuous monitoring. Confirm current process expectations with the relevant Authorizing Official and applicable DoD guidance.
Is a DoD PA permanent once granted?
No. Like an ATO, a PA is time-bound and subject to ongoing conditions, including continuous monitoring and periodic reassessment. Changes to the CSO, to the underlying baselines, or to the governing SRG revision can affect a PA's standing. Organizations should not treat a PA as a one-time, permanent status and should track its currency against the issuing authority's records.
Where should I verify the current requirements and status associated with a DoD PA?
Requirements for a DoD PA are anchored to the DoD Cloud Computing SRG, which is maintained by DISA and is subject to revision. Because impact level definitions, control baselines, and process expectations change across revisions, readers should verify current requirements against the applicable SRG revision and confirm the authorization status of a specific CSO through official DoD sources. This entry does not cover contractual, legal, or implementation specifics that must be confirmed against current authoritative text.

Common misconceptions

A DoD Provisional Authorization is a permanent, final authorization that lets a mission owner operate a system.
A PA is a provisional, DoD-level assessment result, not a final system authorization. Individual mission owners generally must still obtain their own authorization (such as an ATO under the RMF) for their specific systems, and authorizations are time-bound and subject to continuous monitoring rather than permanent.
FedRAMP authorization automatically satisfies DoD Provisional Authorization requirements.
The DoD Cloud Computing SRG generally layers additional DoD-specific requirements on top of a FedRAMP baseline, particularly at higher Impact Levels. A FedRAMP authorization alone does not automatically confer a DoD PA; confirm the additional DoD requirements for the applicable Impact Level.
A PA at one Impact Level covers all data types and workloads.
A PA is scoped to a specific cloud service offering and a specific Impact Level. It does not cover services or data sensitivity beyond its assessed boundary, and higher-sensitivity information generally requires a higher Impact Level assessment.

Best practices

Verify the specific Impact Level and assessed boundary of any PA against the current DoD Cloud Computing SRG before relying on it for a workload, and confirm that the data types you intend to process fall within that level.
Do not treat a PA as a system authorization; plan for your own mission owner authorization (typically under the RMF) and confirm which security responsibilities the cloud service inherits versus which remain the mission owner's obligation.
Confirm the current issuing authority, process, and status of any PA directly with DISA or official DoD sources rather than assuming a prior authorization remains valid.
Treat any inherited authorization as time-bound and subject to continuous monitoring; establish processes to track the ongoing validity and monitoring status of the underlying cloud service.
Distinguish a FedRAMP authorization from a DoD PA in your documentation and confirm that the additional DoD-specific SRG requirements for your Impact Level are satisfied.
Verify all control baselines, Impact Level requirements, and citations against the current authoritative SRG revision, since these change over time and may be subject to agency-specific tailoring.