Skip to main content
Category: Cloud Security & Providers

Impact Level 4

Also known as: IL4, DoD Impact Level 4, IL 4, DoD IL4
Simply put

Impact Level 4 (IL4) is one of the categories the U.S. Department of Defense uses to classify how sensitive its information and cloud systems are. It generally applies to Controlled Unclassified Information (CUI) and non-critical mission information that is not classified. In most implementations, cloud services handling IL4 data are subject to additional protections beyond those for lower-sensitivity information.

Formal definition

Impact Level 4 is an information categorization defined within the DoD Cloud Computing Security Requirements Guide (CC SRG), which establishes standards for categorizing DoD information and information systems across a set of Impact Levels. IL4 generally accommodates Controlled Unclassified Information (CUI), as well as non-CUI, non-critical mission, and non-national security information, and is applied to cloud-based services suitable for protecting such data. Some implementations impose data residency constraints requiring IL4 data to reside within U.S. territory or U.S.-controlled facilities; practitioners should verify current residency, tailoring, and authorization requirements against the applicable revision of the CC SRG. Note that IL4 is a categorization/authorization construct specific to DoD cloud services and is distinct from FedRAMP authorization and from higher DoD Impact Levels; readers should confirm the precise, current requirements against the official CC SRG text.

Why it matters

Impact Level 4 is the DoD categorization that governs how cloud services handle the large volume of Controlled Unclassified Information (CUI) and non-critical mission information the Department relies on day to day. Because much of what defense agencies and their contractors process, such as military personnel information handled in HR functions, falls into CUI categories, IL4 is often the practical threshold that determines whether a given cloud offering can lawfully support a workload. Selecting a cloud service that is not authorized at the appropriate Impact Level can mean CUI is stored or processed in an environment that does not meet DoD protection standards, exposing sensitive but unclassified data and creating compliance exposure for the mission owner.

IL4 also carries additional protections beyond those applied to lower-sensitivity information, and in some implementations this includes data residency constraints requiring the data to remain within U.S. territory or U.S.-controlled facilities. For organizations building or procuring cloud solutions, understanding these constraints early is critical because retrofitting residency and safeguarding requirements after the fact is costly and disruptive.

A frequent and consequential error is assuming that a FedRAMP authorization automatically satisfies DoD IL4 requirements. IL4 is a DoD-specific categorization and authorization construct defined in the Cloud Computing Security Requirements Guide (CC SRG) and is distinct from FedRAMP and from the higher DoD Impact Levels. Equating the two, or treating a cloud service's general security posture as equivalent to a DoD authorization, can leave a workload effectively unauthorized for DoD use. Practitioners should confirm the precise, current requirements against the official CC SRG rather than relying on generalized marketing claims.

Who it's relevant to

DoD mission owners and program offices
Teams that own or sponsor cloud workloads handling CUI or non-critical mission information need to determine whether their data falls into an IL4 category and ensure the cloud service they use is authorized at that level. This decision drives procurement, architecture, and residency planning early in a program's lifecycle.
Defense contractors and cloud solution providers
Organizations that process CUI categories, including, for example, military personnel information in HR functions, may need an IL4-authorized solution. Providers building offerings for the DoD market should understand that IL4 is a DoD-specific authorization distinct from FedRAMP, and that some implementations require U.S.-based or U.S.-controlled data residency.
Information system security managers and authorizing officials
Those responsible for authorization decisions should anchor IL4 determinations to the applicable revision of the CC SRG and confirm current residency, tailoring, and authorization requirements. They should avoid conflating a FedRAMP authorization with DoD IL4 coverage and verify that categorization is matched to an appropriately authorized service.
Compliance officers and auditors
Personnel assessing DoD cloud environments need to confirm that IL4 data is placed only in services authorized at the correct Impact Level and that any residency constraints are met. They should treat IL4 as a categorization and authorization construct that must be verified against official CC SRG text rather than assumed from a vendor's general security posture.

Inside IL4

DoD Cloud Computing Security Requirements Guide (SRG)
Impact Level 4 is one of the information impact levels defined in the DoD Cloud Computing SRG, which is maintained by the Defense Information Systems Agency (DISA). The SRG establishes the security requirements and authorization framework under which cloud service offerings are assessed for DoD use. Readers should verify the current SRG revision, as impact level definitions and requirements are updated over time.
Controlled Unclassified Information (CUI) scope
IL4 is generally associated with the accommodation of Controlled Unclassified Information (CUI) and other mission-critical, non-public unclassified data. It addresses non-classified information that nonetheless requires protection above the lowest impact level. Classified information is out of scope for IL4 and is handled under separate national security system authorities.
Relationship to other DoD impact levels
IL4 sits within a tiered set of DoD cloud impact levels and is distinct from lower levels intended for non-controlled or publicly releasable information and from higher levels intended for more sensitive unclassified national security information. Practitioners should confirm the specific level applicable to their data categorization rather than assuming IL4 by default.
Provisional Authorization (PA) context
Cloud service offerings are typically evaluated against IL4 requirements to receive a DoD Provisional Authorization from DISA. This provisional authorization is a prerequisite step and is distinct from an agency- or mission-owner-issued Authority to Operate (ATO), which remains a separate responsibility.
Relationship to FedRAMP baselines
IL4 requirements are generally built upon a FedRAMP baseline with additional DoD-specific security controls and requirements layered on top. A FedRAMP authorization alone does not automatically satisfy IL4; the additional DoD requirements must be met and verified against the current SRG.

Common questions

Answers to the questions practitioners most commonly ask about IL4.

Does a FedRAMP authorization automatically mean a cloud service can handle IL4 data?
No. FedRAMP authorization and DoD Impact Level authorization are distinct. IL4 is a designation under the DoD Cloud Computing Security Requirements Guide (SRG), maintained by DISA, and it generally builds upon a FedRAMP baseline but adds DoD-specific requirements. A FedRAMP Moderate or High authorization does not by itself satisfy DoD IL4 requirements; a separate DoD Provisional Authorization (PA) process and additional controls generally apply. Verify the current SRG and the specific offering's authorization status against official DoD sources.
Is an IL4 authorization permanent once granted?
No. Like other DoD authorizations, an IL4 Provisional Authorization is time-bound and subject to continuous monitoring. Maintaining the authorization generally requires ongoing assessment, reporting, and remediation activities rather than a one-time approval. Confirm the current continuous monitoring and reauthorization expectations against the applicable SRG and DoD guidance.
What type of information is IL4 generally intended to protect?
IL4 is generally associated with Controlled Unclassified Information (CUI) and other non-public, unclassified information that requires protection. It is distinct from levels intended for public or non-critical information and from levels intended for higher-sensitivity or national security information. Because categorization can involve agency-specific interpretation, confirm the applicable data categorization and Impact Level against the current SRG and your authorizing official's guidance.
How does IL4 relate to the RMF and NIST control baselines?
DoD Impact Levels are applied in conjunction with the Risk Management Framework (RMF) and generally draw upon NIST SP 800-53 controls, with DoD tailoring and additional SRG-specific requirements layered on top of a FedRAMP baseline. The specific control set and any parameter tailoring depend on the applicable revisions of the governing publications, so verify the current baseline and any DoD overlays against official sources.
Who is responsible for granting and accepting an IL4 authorization?
A DoD Provisional Authorization for a cloud service offering is generally issued through the DoD process associated with the SRG, but a Provisional Authorization is not the same as a mission owner's Authority to Operate. Individual DoD mission owners typically must still make their own authorization decision, accept residual risk, and issue an ATO for their specific use. Confirm the current roles and responsibilities with your authorizing official and the applicable guidance.
Does meeting IL4 requirements mean a system is secure?
No. Achieving an IL4 authorization reflects compliance with a defined set of requirements at a point in time; it is not equivalent to being secure. Continuous monitoring, sound operational practices, and ongoing risk management remain necessary. Compliance and security are related but distinct concepts, and this entry does not cover implementation, contractual, or legal specifics that should be verified against current official sources.

Common misconceptions

A FedRAMP-authorized cloud service is automatically approved for IL4 use in the DoD.
FedRAMP authorization is generally a foundation for IL4, but it does not by itself satisfy DoD requirements. IL4 typically imposes additional DoD-specific controls and requires a DoD Provisional Authorization. FedRAMP authorization and DoD authorization are distinct processes issued under different authorities.
A DoD Provisional Authorization at IL4 is the same as an Authority to Operate (ATO).
A Provisional Authorization issued by DISA is an assessment-based approval of the cloud service offering, not a mission-owner ATO. The mission or system owner must still obtain and maintain their own authorization for the specific system and use case. Assessment and authorization are separate activities.
IL4 is the correct level for any sensitive or classified DoD information.
IL4 is generally intended for CUI and mission-critical unclassified information, not classified data. Classified systems fall under separate national security system authorities, and more sensitive unclassified information may require a higher impact level. Data categorization should drive the level selection.

Best practices

Confirm your data categorization against current DoD guidance before assuming IL4 applies, since CUI and other unclassified information may map to different impact levels depending on sensitivity and mission criticality.
Verify the specific requirements against the current revision of the DoD Cloud Computing SRG maintained by DISA, because impact level definitions and control expectations are updated over time.
Treat any FedRAMP authorization as a starting point, not a substitute, and confirm that the additional DoD-specific controls layered on top for IL4 are met and independently verified.
Distinguish the DoD Provisional Authorization from your own mission-owner ATO, and ensure the system-level authorization is obtained and maintained separately for your specific use case.
Treat authorization as time-bound and subject to continuous monitoring rather than a one-time or permanent status, and maintain ongoing evidence of control effectiveness.
Consult current official DISA and DoD sources to confirm contractual, categorization, and implementation specifics rather than relying on general summaries, and engage your authorizing official early.