Impact Level 6
Impact Level 6 (IL6) is a category the Department of Defense uses to classify cloud information systems that handle its most sensitive data, generally covering information classified up to the SECRET level. It represents the highest impact level in the DoD's cloud impact-level framework and calls for strong protections against unauthorized access. Because IL6 involves classified data, it carries stricter requirements than lower impact levels used for unclassified information.
IL6 is one of the DoD Impact Levels defined within the DoD Cloud Computing Security Requirements Guide (CC SRG), which establishes standards for categorizing DoD information and information systems. According to the evidence, IL6 is reserved for the storage and processing of information classified up to the SECRET level and is described as the highest impact level in the DoD framework, applied to systems containing data deemed critical to national security and requiring maximum protection against unauthorized disclosure. IL6 should not be conflated with lower impact levels (such as IL4 and IL5, which generally address Controlled Unclassified Information rather than classified data), and readers should note that the specific control tailoring, authorization requirements, and applicability differ by CC SRG revision and DoD implementation; the precise control baselines and current requirements should be verified against the applicable authoritative CC SRG text. This entry does not cover implementation specifics, authorization procedures, or the distinct handling and accreditation obligations that apply to classified systems.
Why it matters
IL6 marks the boundary where DoD cloud authorization moves from protecting Controlled Unclassified Information into safeguarding classified national security information up to the SECRET level. For compliance officers and authorizing officials, this distinction is fundamental: an IL6 system handles data whose unauthorized disclosure could cause serious damage to national security, which is why the DoD Cloud Computing Security Requirements Guide (CC SRG) treats it as the highest impact level in the framework and calls for maximum protection against unauthorized access. Misclassifying a system, or assuming that a lower impact level authorization is sufficient for classified workloads, is a serious and consequential error.
Who it's relevant to
Inside IL6
Common questions
Answers to the questions practitioners most commonly ask about IL6.