Secure Cloud Computing Architecture
Secure Cloud Computing Architecture (SCCA) is a standardized set of cloud security and management services adopted by the U.S. Department of Defense (DoD) to help protect mission applications and data that run in commercial cloud environments. It defines a consistent way to secure the connection between DoD networks and the cloud, as well as the applications hosted there. Cloud providers such as AWS, Oracle, and Microsoft (through the related Secure Azure Computing Architecture) offer implementations designed to align with SCCA requirements.
SCCA is a DoD-adopted suite of enterprise-level cloud security and management services intended to provide a scalable, cost-effective, and standardized approach to boundary and application-level security for DoD mission workloads hosted in commercial cloud environments. Its requirements are defined in the DoD Secure Cloud Computing Architecture Functional Requirements Document (FRD); per the FRD, SCCA is intended to enable DoD mission applications operating at DoD Information System Impact Levels 2, 4, 5, and 6, with the Cloud Access Point (CAP) portion tailored to particular impact levels. Vendor SCCA implementations (for example, landing zones offered by cloud service providers) are designed to align with these functional requirements, but readers should verify the current FRD revision, the specific impact levels supported by a given implementation, and applicable DISA guidance against official sources, as scope and tailoring can vary by revision and by authorization. Note that SCCA addresses architecture and security services and is distinct from the authorization process itself; deploying an SCCA-aligned architecture does not by itself confer an Authority to Operate.
Why it matters
For DoD components and their contractors, moving mission applications and data into commercial cloud environments introduces boundary and application-level security challenges that must be resolved consistently rather than reinvented for each program. SCCA matters because it gives the Department a standardized, enterprise-level approach to securing the connection between DoD networks and commercial cloud offerings and to protecting the workloads hosted there. Without a common architecture, each mission owner would face inconsistent boundary protections, uneven management services, and greater risk of misconfiguration when connecting sensitive workloads to commercial infrastructure.
SCCA also shapes how cloud service providers position their offerings for the defense market. Vendors such as AWS and Oracle publish SCCA-aligned landing zones, and Microsoft offers the related Secure Azure Computing Architecture (SACA) as a way for DoD and civilian customers to align with the SCCA Functional Requirements Document (FRD). This alignment gives mission owners a starting point that is designed to map to DoD functional requirements, but the burden of confirming that a given implementation meets the applicable requirements, and supports the impact levels a workload actually needs, remains with the DoD customer.
A critical point for compliance officers and authorizing officials is that SCCA is an architecture and a set of security services, not an authorization. Deploying an SCCA-aligned architecture does not by itself confer an Authority to Operate (ATO). Treating adoption of a vendor's SCCA landing zone as equivalent to being authorized, or as equivalent to being secure, is a common and consequential mistake; the architecture must still be assessed and authorized under the applicable DoD process, and readers should verify the current FRD revision and applicable DISA guidance against official sources.
Who it's relevant to
Inside SCCA
Common questions
Answers to the questions practitioners most commonly ask about SCCA.