Skip to main content
Category: Cloud Security & Providers

Impact Level 6

Also known as: IL6, DoD Impact Level 6, IL 6
Simply put

Impact Level 6 (IL6) is a category the Department of Defense uses to classify cloud information systems that handle its most sensitive data, generally covering information classified up to the SECRET level. It represents the highest impact level in the DoD's cloud impact-level framework and calls for strong protections against unauthorized access. Because IL6 involves classified data, it carries stricter requirements than lower impact levels used for unclassified information.

Formal definition

IL6 is one of the DoD Impact Levels defined within the DoD Cloud Computing Security Requirements Guide (CC SRG), which establishes standards for categorizing DoD information and information systems. According to the evidence, IL6 is reserved for the storage and processing of information classified up to the SECRET level and is described as the highest impact level in the DoD framework, applied to systems containing data deemed critical to national security and requiring maximum protection against unauthorized disclosure. IL6 should not be conflated with lower impact levels (such as IL4 and IL5, which generally address Controlled Unclassified Information rather than classified data), and readers should note that the specific control tailoring, authorization requirements, and applicability differ by CC SRG revision and DoD implementation; the precise control baselines and current requirements should be verified against the applicable authoritative CC SRG text. This entry does not cover implementation specifics, authorization procedures, or the distinct handling and accreditation obligations that apply to classified systems.

Why it matters

IL6 marks the boundary where DoD cloud authorization moves from protecting Controlled Unclassified Information into safeguarding classified national security information up to the SECRET level. For compliance officers and authorizing officials, this distinction is fundamental: an IL6 system handles data whose unauthorized disclosure could cause serious damage to national security, which is why the DoD Cloud Computing Security Requirements Guide (CC SRG) treats it as the highest impact level in the framework and calls for maximum protection against unauthorized access. Misclassifying a system, or assuming that a lower impact level authorization is sufficient for classified workloads, is a serious and consequential error.

Who it's relevant to

Authorizing Officials and ISSMs
Those responsible for authorizing DoD cloud systems must correctly identify when a workload rises to the SECRET level and therefore falls under IL6 rather than a lower impact level. They should treat any resulting authorization as time-bound and dependent on continuous monitoring, and confirm control tailoring against the applicable CC SRG revision rather than assuming static requirements.
Government Contractors and Cloud Service Providers
Providers seeking to support classified DoD workloads up to SECRET need to understand that IL6 carries stricter expectations than the IL4 and IL5 levels used for unclassified CUI. A FedRAMP authorization or a lower DoD impact level does not automatically satisfy IL6, and providers should verify current requirements and the distinct classified-handling obligations against authoritative sources.
Compliance Officers and Auditors
Compliance and assessment personnel should guard against conflating IL6 with lower impact levels or treating authorization as equivalent to security. Because IL6 involves classified data and the associated accreditation obligations differ from unclassified pathways, auditors should anchor their reviews to the applicable CC SRG revision and confirm that impact-level classification decisions are properly documented.

Inside IL6

DoD Impact Level Framework
IL6 is one of the security impact levels defined in the DoD Cloud Computing Security Requirements Guide (SRG), which is maintained by the Defense Information Systems Agency (DISA). The SRG establishes impact levels (commonly referenced as IL2, IL4, IL5, and IL6) that map cloud offerings to categories of information sensitivity and required security controls.
Classified Information Scope
IL6 is generally associated with the accommodation of information classified up to and including the SECRET level. This distinguishes it from lower impact levels, which are intended for unclassified information, including Controlled Unclassified Information (CUI) at IL4 and higher-sensitivity CUI or mission-critical information at IL5. Practitioners should verify the current SRG text for the precise information categories covered.
Baseline and Overlay Alignment
IL6 authorizations are generally built on NIST SP 800-53 controls as tailored through the DoD Cloud Computing SRG and applicable overlays for classified national security systems. Because IL6 addresses classified information, additional requirements beyond the standard federal civilian or unclassified DoD baselines typically apply. The exact control selection depends on the applicable revision and DoD tailoring.
Authorization Authority
Authorization decisions for IL6 offerings fall within DoD authorities and processes, generally under the Risk Management Framework (RMF) with a DoD authorizing official. A commercial cloud provider's authorization at IL6 does not by itself substitute for a system owner's own authorization responsibilities.
Connectivity and Isolation Requirements
Because IL6 handles classified information up to SECRET, it is generally associated with more restrictive connectivity, physical, personnel, and network isolation requirements than unclassified impact levels. Specific requirements should be confirmed against the current SRG and relevant classified-system guidance.

Common questions

Answers to the questions practitioners most commonly ask about IL6.

Does a FedRAMP High authorization automatically qualify a cloud service for IL6?
No. FedRAMP authorization, including at the High baseline, and DoD Impact Level authorization under the DoD Cloud Computing Security Requirements Guide (SRG) are distinct processes maintained by different authorities, the FedRAMP PMO for FedRAMP and the DoD (through DISA and the responsible authorizing official) for Impact Levels. IL6 generally addresses classified information up to the SECRET level and imposes requirements that go beyond a FedRAMP civilian authorization, including handling of national security systems and connectivity constraints. A FedRAMP authorization may serve as a reciprocity input in some cases, but it does not by itself satisfy DoD IL6 requirements. Confirm the current SRG revision and applicable DoD guidance for authoritative details.
Once a system receives an IL6 authorization, is that authorization permanent?
No. Like other DoD authorizations issued under the Risk Management Framework, an authorization associated with IL6 is time-bound and conditioned on ongoing continuous monitoring rather than being permanent. The authorizing official's decision reflects an acceptable level of risk as of the authorization, and that determination can be revisited or revoked if the risk posture changes, if continuous monitoring reveals unaddressed deficiencies, or upon expiration. Authorization is also distinct from assessment: completing a security assessment does not itself grant authority to operate. Verify the specific terms, duration, and conditions in the applicable authorization documentation.
What type of information is IL6 intended to protect, and how does it differ from lower Impact Levels?
IL6 is generally associated in the DoD Cloud Computing SRG with classified information up to the SECRET level, whereas lower Impact Levels address unclassified information, including Controlled Unclassified Information (CUI) at certain levels. Because IL6 involves classified national security systems, it is subject to requirements that differ from those governing unclassified CUI environments. This entry does not cover the full set of classification-handling, physical, personnel, and connectivity requirements that apply; readers should confirm scope and applicability against the current SRG revision and relevant DoD and national security system policy.
Who serves as the authorizing official for an IL6 environment?
Authorization decisions for DoD systems, including those at IL6, are generally made by a designated authorizing official operating within the DoD's RMF governance structure, with DISA and other DoD stakeholders involved in the process defined by the Cloud Computing SRG. The specific authorizing official and the division of responsibilities can vary by component, mission owner, and system. Because roles and delegations are organization-specific, confirm the responsible authorizing official and the governing process against current DoD guidance and your component's implementing policy.
How does continuous monitoring apply to an IL6 system after authorization?
Continuous monitoring is a core expectation under the RMF and applies to authorized DoD systems, including at IL6. In most implementations this involves ongoing assessment of controls, tracking of changes to the system and its risk posture, and reporting to the authorizing official so that the authorization decision remains informed over time. The specific frequency, metrics, and reporting mechanisms depend on the applicable DoD and SRG guidance and any component-specific tailoring. This entry does not prescribe a continuous monitoring implementation; verify current requirements against authoritative sources.
Does meeting IL6 requirements mean a system is fully secure?
No. Compliance with IL6 requirements demonstrates that a system has met a defined set of controls and conditions and has received an authorization decision, but compliance is not the same as security. An authorized environment can still carry residual and evolving risk, which is why continuous monitoring and ongoing risk management are part of the framework. Treating an authorization as a guarantee of security is a common mistake. Organizations should maintain security practices beyond the minimum compliance requirements and verify their obligations against current authoritative guidance.

Common misconceptions

IL6 is just a higher-security version of FedRAMP that any FedRAMP-authorized cloud can meet.
IL6 is defined under the DoD Cloud Computing SRG maintained by DISA, not by the FedRAMP PMO. FedRAMP authorization does not automatically satisfy DoD impact level requirements, and IL6 in particular addresses classified information up to SECRET, which falls outside the scope of standard FedRAMP civilian authorization. These are distinct authorities and processes that a reader must confirm against current official sources.
An IL6 authorization is a permanent designation that, once granted, remains valid indefinitely.
An Authority to Operate is time-bound and subject to continuous monitoring; it is not permanent. IL6 offerings and the systems built on them generally remain subject to ongoing oversight, reauthorization, and the possibility of authorization being revoked based on risk. Meeting IL6 requirements at a point in time does not remove the continuous monitoring obligation.
Achieving IL6 means a system is secure and compliant for all DoD classified missions.
Compliance with an impact level is not equivalent to security, and it does not by itself authorize a specific mission system. A cloud offering's IL6 status describes the environment's assessed suitability for information up to a certain classification, but the system owner still bears responsibility for its own RMF authorization, control implementation, and mission-specific requirements. Assessment is also distinct from authorization.

Best practices

Confirm IL6 requirements against the current revision of the DoD Cloud Computing SRG maintained by DISA rather than relying on summaries, since impact level definitions and control tailoring can change across revisions.
Do not assume FedRAMP authorization satisfies IL6 obligations; verify DoD-specific authorization status and understand that IL6 addresses classified information up to SECRET under separate DoD authorities.
Treat any IL6 authorization as time-bound and maintain an active continuous monitoring program, planning for reauthorization rather than assuming the authorization is permanent.
Distinguish clearly between the cloud provider's environment authorization and your own system's RMF authorization, ensuring system-owner responsibilities and mission-specific controls are addressed separately.
Engage the appropriate DoD authorizing official and security stakeholders early to confirm connectivity, isolation, personnel, and physical requirements applicable to classified information before committing to an architecture.
Document the boundary between assessment activities and authorization decisions, and verify classified-system overlay and NIST SP 800-53 control selections against current DoD tailoring guidance.