Impact Level 4/5/6 (DoD)
DoD Impact Levels are a classification framework used by the Department of Defense to categorize information systems and the data they handle according to how sensitive the information is and how serious the consequences would be if it were exposed. Higher-numbered levels correspond to more sensitive data and stricter security requirements. Impact Levels 4 and 5 generally cover non-public unclassified information, while Impact Level 6 covers classified information up to the secret level, according to the evidence provided.
DoD Impact Levels (ILs) are categories defined under the DoD Cloud Computing Security Requirements Guide (CC SRG), which sets the standards for categorizing DoD information and information systems. Based on the evidence, IL4 applies to systems handling non-public, unclassified data where unauthorized disclosure could have adverse effects, IL5 applies to more sensitive controlled unclassified information (specifics not detailed in the evidence provided), and IL6 is the highest level described here, covering classified information up to the secret level where breach impact could be substantial. Practitioners should note that the CC SRG is maintained by DoD (as referenced through the GSA Cloud Information Center) rather than by the FedRAMP PMO, and that DoD authorization at a given Impact Level is distinct from, and not automatically satisfied by, FedRAMP authorization. The evidence does not enumerate the specific control baselines, tailoring, or authorization procedures for each level; readers should verify precise IL definitions, applicable control sets, and effective requirements against the current authoritative DoD CC SRG.
Why it matters
DoD Impact Levels determine which cloud services and information systems are permitted to handle specific categories of Department of Defense data, and they set the security expectations that flow from that categorization. A misclassification, placing more sensitive information in an environment authorized only for a lower Impact Level, can expose non-public unclassified or classified information to unacceptable risk. Because higher-numbered levels correspond to more sensitive data and stricter security requirements, understanding where a given system and its data fall within this framework is a foundational step before pursuing a DoD authorization.
A critical point that experienced practitioners emphasize is that DoD authorization at a given Impact Level is distinct from, and not automatically satisfied by, FedRAMP authorization. The DoD Cloud Computing Security Requirements Guide (CC SRG) is maintained by DoD rather than by the FedRAMP PMO, so a cloud service provider holding a FedRAMP authorization has not thereby met the DoD requirements for IL4, IL5, or IL6. Treating the two as interchangeable is a common and consequential error that can stall a program or leave data in an environment not appropriately authorized for it.
Equally important, achieving an authorization at a given Impact Level should not be treated as a permanent or one-time event, nor should it be conflated with security itself. Authorizations are time-bound and subject to continuous monitoring, and the specific control baselines, tailoring, and authorization procedures for each level are set out in the current authoritative DoD CC SRG, not summarized in full here, which readers must consult directly.
Who it's relevant to
Inside IL4/IL5/IL6
Common questions
Answers to the questions practitioners most commonly ask about IL4/IL5/IL6.