Skip to main content
Category: Cloud Security & Providers

Impact Level 2

Also known as: IL2, DoD IL2, DoD Impact Level 2
Simply put

Impact Level 2 (IL2) is the lowest of the U.S. Department of Defense's cloud information impact levels, used for public or non-critical mission information that is not sensitive. It generally covers data cleared for public release and non-controlled unclassified information, and cloud services at this level are typically expected to hold a FedRAMP authorization. Because it is intended for non-sensitive data, IL2 does not accommodate Controlled Unclassified Information (CUI) or classified information, which fall under higher impact levels.

Formal definition

IL2 is a DoD cloud information impact level that accommodates non-controlled unclassified information, including data cleared for public release and non-critical mission information; it does not cover CUI or classified data. Per the evidence, IL2 workloads can generally be hosted in a cloud service provider that minimally holds a FedRAMP Moderate provisional authorization (PA) together with a DoD Level 2 PA, subject to compliance with applicable requirements. Practitioners should note that impact levels, baselines, and authorization requirements are maintained by DoD and are subject to revision and agency tailoring; a FedRAMP authorization alone does not automatically satisfy all DoD requirements, and the current authoritative DoD guidance should be verified before relying on any specific requirement.

Why it matters

Impact Level 2 anchors the lowest tier of the Department of Defense's cloud information impact level framework, and understanding its boundaries prevents a costly category error: placing sensitive data on infrastructure that was never authorized to hold it. Because IL2 is intended only for non-controlled unclassified information, such as data cleared for public release and non-critical mission information, it generally does not accommodate Controlled Unclassified Information (CUI) or classified data, which the DoD directs to higher impact levels. Compliance officers and system owners who mistakenly treat IL2 as a general-purpose baseline for DoD workloads risk exposing CUI on an environment tailored for public-facing information.

IL2 also illustrates a distinction that experts routinely insist on correcting: a FedRAMP authorization and a DoD authorization are not the same thing. While IL2 workloads can generally be hosted in a cloud service provider that minimally holds a FedRAMP Moderate provisional authorization together with a DoD Level 2 provisional authorization, a FedRAMP authorization alone does not automatically satisfy all DoD requirements. Assuming otherwise can lead an organization to believe a service is DoD-ready when additional DoD-specific conditions still apply.

Finally, IL2 sits within a framework maintained by the DoD that is subject to revision and agency tailoring. Impact levels, associated baselines, and authorization expectations can change across guidance revisions, so treating any single description of IL2 as permanent or exhaustive is a common mistake. Practitioners should verify the current authoritative DoD cloud guidance before relying on any specific requirement, and should remember that compliance with an impact level is not equivalent to comprehensive security.

Who it's relevant to

DoD system owners and mission owners
Personnel responsible for placing DoD workloads in the cloud must correctly categorize their data before selecting an impact level. IL2 is appropriate only for non-controlled unclassified information such as publicly releasable and non-critical mission data; workloads involving CUI or classified information must be directed to higher impact levels.
Cloud service providers pursuing DoD authorization
Providers seeking to host DoD IL2 workloads generally need to demonstrate the expected authorizations, which per the evidence minimally include a FedRAMP Moderate provisional authorization together with a DoD Level 2 provisional authorization, subject to compliance with applicable requirements. Providers should confirm current DoD conditions rather than assuming a FedRAMP authorization alone is sufficient.
Compliance officers and authorizing officials
Those evaluating whether a service meets DoD requirements should not treat FedRAMP authorization as automatically satisfying DoD obligations. IL2's role as the lowest impact level makes it essential to verify that data categorization aligns with the level, and to consult current authoritative DoD guidance, which is subject to revision and tailoring.
Government contractors handling DoD data
Contractors supporting DoD missions must understand that IL2 does not accommodate CUI. Contractors handling CUI under defense obligations should confirm that their hosting environment is authorized at the appropriate higher impact level, and should verify DoD-specific requirements against current official sources rather than relying on an impact level summary alone.

Inside IL2

DoD Impact Level Framework
IL2 is one of the impact levels defined in the DoD Cloud Computing Security Requirements Guide (SRG), maintained by the Defense Information Systems Agency (DISA), which categorizes cloud service offerings by the sensitivity of the information they handle and the potential impact of a compromise.
Information Sensitivity Scope
IL2 generally covers non-controlled unclassified information and other data cleared for public release or information with a low confidentiality impact. Higher-sensitivity Controlled Unclassified Information (CUI) is typically addressed at higher impact levels (such as IL4 and above), and readers should verify current SRG categorizations against the authoritative text.
Relationship to FedRAMP
IL2 authorization is commonly associated with a FedRAMP baseline as a foundation, with the DoD SRG layering additional requirements. The specific FedRAMP baseline alignment should be confirmed against the current SRG revision, as these mappings are subject to change.
Authorizing Authority
Authorization decisions for cloud offerings at IL2 fall under DoD processes and authorizing officials, distinct from the civilian FedRAMP Program Management Office authorization path, even where a FedRAMP baseline underpins the offering.
Position Within the Impact Level Tiers
IL2 represents a lower-sensitivity tier relative to IL4 (CUI), IL5 (higher-sensitivity CUI and unclassified National Security Systems), and IL6 (classified information up to the applicable level). Exact tier boundaries and definitions should be verified against the current SRG.

Common questions

Answers to the questions practitioners most commonly ask about IL2.

Does an Impact Level 2 authorization mean a cloud service is approved for all DoD data?
No. IL2 addresses accommodation of non-controlled unclassified information and information cleared for public release, generally the lowest of the DoD cloud impact levels. It does not authorize handling of CUI or higher-sensitivity data, which are addressed at higher impact levels (such as IL4 and IL5). Confirm the specific data types and the current DoD Cloud Computing Security Requirements Guide (SRG) authorized by the applicable authority before placing any data at IL2.
If a cloud offering already holds a FedRAMP authorization, does that automatically satisfy IL2 requirements?
Not necessarily. FedRAMP authorization is issued for federal civilian use and is maintained by the FedRAMP PMO, while DoD impact levels are defined under the DoD Cloud Computing SRG and evaluated through DoD processes. FedRAMP authorization frequently serves as a foundation for a DoD provisional authorization, but the DoD adds its own requirements and review. Verify how the DoD treats the specific FedRAMP baseline against the current SRG rather than assuming equivalence.
How is IL2 typically distinguished from higher impact levels when scoping a system?
IL2 is generally associated with non-controlled unclassified information and public-release information, whereas higher levels accommodate CUI and more sensitive data with correspondingly stronger requirements. Scoping should start by classifying the data the system will process, store, or transmit and then mapping that classification to the appropriate impact level as defined in the current DoD Cloud Computing SRG. Confirm the mapping against the applicable revision, as impact level criteria can change.
Is an IL2 authorization permanent once granted?
No authorization to operate should be treated as permanent. Authorizations are time-bound and subject to continuous monitoring, and an offering's status can change with reassessment, changes to the environment, or updates to governing guidance. Track the authorization's terms and continuous monitoring obligations, and verify current status through official DoD channels.
Where should a team look to confirm the current requirements applicable to IL2?
The governing source is the DoD Cloud Computing Security Requirements Guide, which defines the impact levels and their associated requirements. Because impact level definitions and requirements can be revised, confirm the applicable revision and any agency- or mission-specific tailoring with the relevant authorizing official rather than relying on prior versions.
Does meeting IL2 requirements mean a system is secure?
Compliance with an impact level's requirements is not the same as being secure. IL2 represents a defined set of baseline expectations for a category of data, but security depends on ongoing risk management, continuous monitoring, and appropriate operational practices. Treat IL2 as a floor for the applicable data category and continue to assess and manage risk beyond the documented requirements.

Common misconceptions

An IL2 authorization means a cloud service can host any DoD data, including CUI.
IL2 is generally scoped to lower-sensitivity, non-controlled unclassified information. Hosting CUI typically requires a higher impact level such as IL4 or above. Practitioners should confirm the data categorization against the current DoD SRG before placing workloads.
A FedRAMP authorization automatically satisfies DoD IL2 requirements.
While a FedRAMP baseline often serves as the foundation, the DoD SRG imposes additional requirements and a separate DoD authorization decision. FedRAMP authorization alone does not automatically confer DoD provisional authorization at any impact level.
An IL2 authorization is a permanent approval to operate.
Authorizations are time-bound and contingent on continuous monitoring. An IL2 provisional authorization must be maintained and can be revoked or require reauthorization if the security posture, scope, or applicable requirements change.

Best practices

Verify the intended data categorization against the current DoD Cloud Computing SRG before selecting IL2, confirming that the workload does not include CUI or other data requiring a higher impact level.
Do not assume a FedRAMP authorization is sufficient for DoD use; confirm the additional DoD SRG requirements and the separate DoD authorization path apply to your offering.
Treat any IL2 provisional authorization as time-bound and dependent on continuous monitoring, and maintain the processes needed to sustain it rather than viewing it as a one-time milestone.
Confirm the specific FedRAMP baseline alignment and impact level definitions against the current SRG revision, since these mappings and boundaries are subject to change.
Distinguish assessment activities from the authorization decision, and identify the correct DoD authorizing official responsible for the IL2 authorization.
Document data flows and system boundaries clearly so that any information exceeding IL2 sensitivity is routed to an appropriately authorized higher impact level environment.