Skip to main content
Category: Cloud Security & Providers

Impact Level 4/5/6 (DoD)

Also known as: IL4/IL5/IL6, DoD Impact Levels, DoD ILs, Cloud Impact Levels
Simply put

DoD Impact Levels are a classification framework used by the Department of Defense to categorize information systems and the data they handle according to how sensitive the information is and how serious the consequences would be if it were exposed. Higher-numbered levels correspond to more sensitive data and stricter security requirements. Impact Levels 4 and 5 generally cover non-public unclassified information, while Impact Level 6 covers classified information up to the secret level, according to the evidence provided.

Formal definition

DoD Impact Levels (ILs) are categories defined under the DoD Cloud Computing Security Requirements Guide (CC SRG), which sets the standards for categorizing DoD information and information systems. Based on the evidence, IL4 applies to systems handling non-public, unclassified data where unauthorized disclosure could have adverse effects, IL5 applies to more sensitive controlled unclassified information (specifics not detailed in the evidence provided), and IL6 is the highest level described here, covering classified information up to the secret level where breach impact could be substantial. Practitioners should note that the CC SRG is maintained by DoD (as referenced through the GSA Cloud Information Center) rather than by the FedRAMP PMO, and that DoD authorization at a given Impact Level is distinct from, and not automatically satisfied by, FedRAMP authorization. The evidence does not enumerate the specific control baselines, tailoring, or authorization procedures for each level; readers should verify precise IL definitions, applicable control sets, and effective requirements against the current authoritative DoD CC SRG.

Why it matters

DoD Impact Levels determine which cloud services and information systems are permitted to handle specific categories of Department of Defense data, and they set the security expectations that flow from that categorization. A misclassification, placing more sensitive information in an environment authorized only for a lower Impact Level, can expose non-public unclassified or classified information to unacceptable risk. Because higher-numbered levels correspond to more sensitive data and stricter security requirements, understanding where a given system and its data fall within this framework is a foundational step before pursuing a DoD authorization.

A critical point that experienced practitioners emphasize is that DoD authorization at a given Impact Level is distinct from, and not automatically satisfied by, FedRAMP authorization. The DoD Cloud Computing Security Requirements Guide (CC SRG) is maintained by DoD rather than by the FedRAMP PMO, so a cloud service provider holding a FedRAMP authorization has not thereby met the DoD requirements for IL4, IL5, or IL6. Treating the two as interchangeable is a common and consequential error that can stall a program or leave data in an environment not appropriately authorized for it.

Equally important, achieving an authorization at a given Impact Level should not be treated as a permanent or one-time event, nor should it be conflated with security itself. Authorizations are time-bound and subject to continuous monitoring, and the specific control baselines, tailoring, and authorization procedures for each level are set out in the current authoritative DoD CC SRG, not summarized in full here, which readers must consult directly.

Who it's relevant to

DoD Mission and Program Owners
Program owners responsible for DoD information systems need to determine the correct Impact Level for their data and workloads before selecting a cloud environment. Placing data in an environment authorized only for a lower Impact Level than the data requires can create unacceptable exposure, so accurate categorization against the current CC SRG is a prerequisite for any move to the cloud.
Cloud Service Providers Serving DoD
Providers seeking to support DoD workloads must pursue authorization at the appropriate Impact Level under the DoD CC SRG. They should not assume that an existing FedRAMP authorization satisfies DoD requirements, since the CC SRG is maintained by DoD rather than the FedRAMP PMO and DoD authorization is a distinct process.
Authorizing Officials and ISSMs
Authorizing officials and information system security managers evaluating DoD cloud environments must confirm that the target Impact Level matches the sensitivity of the data, non-public unclassified information for IL4 and IL5, and classified information up to the secret level for IL6, and must treat any resulting authorization as time-bound and subject to continuous monitoring rather than permanent.
Compliance Officers and Assessors
Those assessing DoD cloud systems should anchor their work to the current authoritative CC SRG, verifying the applicable control baselines and tailoring for each Impact Level rather than relying on generalized summaries. They should also keep assessment distinct from authorization, and compliance distinct from security, when reporting findings.

Inside IL4/IL5/IL6

DoD Impact Levels (ILs)
A categorization scheme defined in the DoD Cloud Computing Security Requirements Guide (SRG), maintained under DISA/DoD CIO authority, that distinguishes cloud service offerings by the sensitivity of the information they handle and the potential impact of compromise. The ILs apply to DoD systems and are distinct from the FedRAMP impact levels used for federal civilian systems.
Impact Level 4 (IL4)
Generally applies to Controlled Unclassified Information (CUI) and other non-public, unclassified information requiring protection above the baseline for public data. In most implementations IL4 accommodates the majority of DoD CUI workloads that are not subject to more restrictive handling requirements.
Impact Level 5 (IL5)
Generally applies to higher-sensitivity CUI, mission-critical information, and National Security Systems (NSS) information that remains unclassified but warrants stronger separation and controls than IL4. IL5 typically imposes additional isolation and personnel or physical requirements relative to IL4; readers should confirm the specific conditions against the current SRG.
Impact Level 6 (IL6)
Generally applies to information classified up to the SECRET level. IL6 environments are subject to classified handling requirements and are outside the scope of unclassified FedRAMP and typical CUI authorization pathways. Specific handling obligations should be verified against classified-system authorities and the applicable SRG revision.
Relationship to FedRAMP
DoD generally leverages FedRAMP authorization as a starting point and applies additional DoD-specific requirements (often described as FedRAMP-plus) before granting a DoD Provisional Authorization or ATO. A FedRAMP authorization alone does not automatically satisfy DoD IL requirements.
Governing publication
The DoD Cloud Computing SRG is the primary reference for IL definitions and associated requirements. Because the SRG and related guidance are revised over time, practitioners should anchor decisions to the current authoritative version rather than a remembered baseline.

Common questions

Answers to the questions practitioners most commonly ask about IL4/IL5/IL6.

Does a FedRAMP authorization automatically allow a cloud service to host DoD data at Impact Level 4 or 5?
No. FedRAMP authorization, issued through the FedRAMP PMO, is a prerequisite for many DoD cloud use cases, but it does not by itself satisfy DoD requirements for the Impact Levels defined in the DoD Cloud Computing Security Requirements Guide (SRG). DoD generally applies additional controls, personnel, connectivity, and assessment requirements layered on top of a FedRAMP baseline, and a DoD Provisional Authorization (PA) issued by DISA is typically the relevant DoD-side determination. Readers should confirm the current SRG requirements and the specific authorization pathway against official DoD sources, because these requirements are subject to revision and agency tailoring.
Is an Impact Level the same thing as a FISMA or NIST SP 800-53 security categorization?
Not exactly. DoD Impact Levels are defined in the DoD Cloud Computing SRG and are specific to how DoD categorizes cloud environments by information sensitivity and, for higher levels, classification and mission impact. This is distinct from a FIPS 199 / NIST SP 800-53 low/moderate/high categorization used broadly across federal systems, though the concepts are related and the SRG draws on those baselines. Treating the two as interchangeable can lead to selecting the wrong control set or authorization pathway. Verify the mapping in the applicable SRG revision rather than assuming a one-to-one equivalence.
How do the different Impact Levels generally differ in the kind of information they are intended to host?
In most implementations under the DoD Cloud Computing SRG, the higher-numbered Impact Levels correspond to more sensitive information and stricter requirements. Lower levels are generally associated with non-controlled or CUI-type information, while higher levels address more sensitive CUI, National Security Systems, and classified information up to certain classification thresholds. The precise information types, connectivity, and personnel requirements assigned to each level are defined in the SRG and can change across revisions, so readers should confirm the current level definitions and boundaries against the authoritative text before making placement decisions.
How does an organization determine which Impact Level applies to a given system or data set?
The determination generally depends on the sensitivity and classification of the information to be processed or stored, the mission impact of its loss, and any applicable CUI or National Security System considerations, evaluated against the criteria in the DoD Cloud Computing SRG. This is typically a coordinated decision involving the mission owner, the information owner, and the responsible Authorizing Official under the DoD Risk Management Framework. Because categorization drives control selection and cost, organizations should document the rationale and confirm the current SRG criteria rather than assuming a level from a prior project.
What is the relationship between a cloud service's Impact Level authorization and a system's Authority to Operate (ATO)?
A DoD Provisional Authorization associated with an Impact Level generally applies to the cloud service offering, while the mission owner's system built on that service still requires its own authorization decision from an Authorizing Official under the RMF. A provider's authorization at a given Impact Level does not by itself confer an ATO on the system using it. Additionally, any such authorization is time-bound and subject to continuous monitoring rather than permanent, so both the provider's and the system owner's authorization status should be tracked against current requirements.
Can data at a higher Impact Level be placed in an environment authorized only at a lower level?
As a general rule, information should be hosted in an environment authorized at or above the Impact Level appropriate to that information under the DoD Cloud Computing SRG; placing higher-sensitivity data in a lower-level environment is typically not permitted. The specific rules on aggregation, mixing of information types, and connectivity constraints are defined in the SRG and may be tailored by the responsible Authorizing Official. Because these boundaries carry security and contractual consequences, confirm the applicable SRG provisions and obtain the Authorizing Official's determination before commingling data across levels.

Common misconceptions

DoD Impact Levels are the same as FedRAMP impact levels (Low/Moderate/High).
They are distinct. FedRAMP Low/Moderate/High applies to federal civilian systems and is administered under the FedRAMP PMO, while DoD Impact Levels (IL4/5/6) are defined in the DoD Cloud Computing SRG and add DoD-specific requirements on top of a FedRAMP baseline. A FedRAMP authorization does not automatically meet DoD IL requirements.
Achieving an IL authorization is a permanent approval to operate.
An authorization, including a DoD Provisional Authorization or ATO tied to an Impact Level, is time-bound and subject to continuous monitoring. It can be revised, suspended, or revoked, and it does not by itself equate to being secure; ongoing assessment and monitoring remain required.
IL6 is just a higher unclassified tier and can be handled like IL4/IL5 with extra controls.
IL6 generally covers information classified up to SECRET and is subject to classified handling authorities that fall outside typical unclassified CUI and FedRAMP pathways. It cannot be treated as a simple extension of the unclassified levels.

Best practices

Determine the correct Impact Level by first categorizing the information involved (public, CUI, higher-sensitivity CUI/NSS, or classified) and confirming the applicable IL definitions against the current DoD Cloud Computing SRG revision.
Do not assume a FedRAMP authorization satisfies DoD requirements; verify the DoD-specific (FedRAMP-plus) conditions and obtain the appropriate DoD Provisional Authorization or ATO before operating at the target IL.
Treat any IL authorization as time-bound and maintain a continuous monitoring program, since authorization can be revised or revoked and compliance status must be sustained rather than achieved once.
Distinguish assessment from authorization in your planning, recognizing that completing an assessment does not grant permission to operate at a given Impact Level.
For IL6 and any classified information, engage the appropriate classified-system authorities early, since these workloads fall outside typical unclassified CUI and FedRAMP pathways.
Anchor internal policies and documentation to the current authoritative SRG version and validate specific IL requirements against official sources, as impact-level conditions and controls change across revisions.