Fortinetics Book a call →
Menu
DEFENSE CLOUD

DoD Impact Level 4 vs Impact Level 5: the delta that catches CSPs out

CSP SRG Impact Levels sit on top of FedRAMP. IL4 covers Controlled Unclassified Information; IL5 covers Unclassified National Security System/National Security Information, and reaches CUI where the AO determines it needs more protection than IL4 affords. V1R3 (2 July 2025) made that re-scoping; the current release is V1R7 (30 June 2026).

The short answer

IL4 and IL5 are not a tier choice you make freely; the data and the AO's categorization dictate which applies. The trap is assuming IL5 is 'IL4 plus a little': per CNSSP 32 its floor is FedRAMP High plus the CNSSI 1253 Appendix D overlays, and the cryptographic and evidence requirements are a different operational world.

DoD IL4

Your DoD workload is CUI that is not an unclassified National Security System and that the AO has not designated for higher protection. IL4 (FedRAMP Moderate or High plus a DoD overlay) is the right authorization, and the cryptographic bar is meaningfully lower than IL5.

DoD IL5

Your DoD workload is an unclassified National Security System, or CUI the AO judges to need more protection than IL4 affords. IL5 adds FIPS 140 at every internal boundary and the CNSSI 1253 Appendix D overlay on top of a FedRAMP High floor.

Side by side
DoD IL4 compared with DoD IL5 across 8 dimensions
Dimension DoD IL4 DoD IL5
Data handled DoD IL4 Controlled Unclassified Information (CUI) DoD IL5 Mission-critical CUI + unclassified National Security Systems
FedRAMP base DoD IL4 FedRAMP Moderate or High + DoD overlay DoD IL5 FedRAMP High floor + CNSSI 1253 Appendix D overlays (per CNSSP 32)
Personnel DoD IL4 U.S. Citizens, Nationals or Persons; no Foreign Persons (SRG 5.5.2) DoD IL5 Identical rule to IL4 — this is not an IL4/IL5 delta
Cryptography DoD IL4 FIPS 140-validated at external boundaries DoD IL5 FIPS 140-validated at every internal trust zone, not just external
Scope basis DoD IL4 CUI; CNSSI 1253 categorizations up to MMx or HHx DoD IL5 Unclassified NSS/NSI at CIA HHx; CUI where the AO so determines
Incident response DoD IL4 DoD overlay coordination DoD IL5 DoD CC SRG sponsor + component security team + faster cadence
Typical deployment DoD IL4 GovCloud, Azure Government, AWS US Gov DoD IL5 Same regions, with stricter isolation and operator controls
Where CSPs stall DoD IL4 Boundary scoping, overlay documentation DoD IL5 Internal FIPS 140, NSS classification handling, personnel evidence

Scroll sideways for DoD IL5 →

What actually separates IL4 from IL5

Both IL4 and IL5 are CSP SRG overlays on FedRAMP — neither is classified work. Since V1R3 (2 July 2025) the SRG titles IL4 "Controlled Unclassified Information" and IL5 "Unclassified National Security System/National Security Information," and that re-scoping is the real separation. The current release is V1R7 (30 June 2026).

IL4 handles Controlled Unclassified Information. It builds on FedRAMP Moderate or High with a DoD-specific overlay. The personnel, cryptographic, and supply-chain requirements are real but tractable for a CSP that has done FedRAMP.

IL5 handles Unclassified National Security System/National Security Information, and reaches CUI the AO determines needs more protection than IL4 affords. Per CNSSP 32 its floor is the FedRAMP High baseline, with the overlays and NSS controls in CNSSI 1253 Appendix D on top. The SRG publishes no control count for that overlay, so treat any specific number quoted for it — including the "~170" we previously carried here — as unsourced.

The three divergences that cost the most

The control count understates the impact. Three specific IL5 requirements drive most of the additional work over IL4.

FIPS 140 at every internal boundary. IL4 expects validated cryptography at external trust boundaries. IL5 expects it at every cryptographic boundary including internal trust zones: service-to-service traffic, internal data flows, internal API tokens. A CSP running a validated module at the edge with non-validated internal TLS passes the FIPS expectation at IL4 and fails it at IL5. This is architectural and hard to retrofit.

NSS classification handling. IL5 explicitly handles National Security Systems categorization for in-scope workloads: data classification scheme, NSS data-flow documentation, NSS-specific handling. IL4 does not exercise this dimension.

**What is not a delta:** personnel national affiliation. SRG 5.5.2 states the rule for "Impact Level 4/5" on one line — U.S. Citizens, U.S. Nationals, or U.S. Persons, no Foreign Persons — so it applies identically at both levels, and only IL6 is citizens-only. We previously listed this as the headline IL5 differentiator and described it as a citizenship requirement. Both were wrong.

Our [IL5 assessment article](/insights/il5-assessment-controls-that-burn-csps/) covers the control-friction categories that consistently extend IL5 schedules.

Sequencing — most CSPs go IL4 then IL5

The common path is FedRAMP → IL4 → IL5, because each step reuses most of the prior step's work. A CSP that has FedRAMP High and IL4 has the foundational muscle; IL5 is the NSS overlay on top.

But the IL5 overlay is operational work, not just documentation. CSPs that treat it as "another set of controls to write up" rather than a personnel program plus an internal cryptographic architecture plus DoD-cadence continuous monitoring consistently lose quarters. The personnel dimension in particular (national-affiliation verification under SRG 5.5.2, position categorization, background-investigation tracking) takes months to execute and cannot be retrofitted under assessment deadline.

For the relationship between FedRAMP Rev 5 and the IL5 NSS overlay specifically, see our [Rev 5 + IL5 overlap analysis](/insights/fedramp-rev-5-il5-overlap/).

Frequently asked

IL4 vs IL5 — common questions.

What is the difference between DoD IL4 and IL5?
IL4 handles Controlled Unclassified Information and builds on FedRAMP Moderate or High with a DoD overlay. IL5 handles Unclassified National Security System/National Security Information, and reaches CUI the AO judges to need more protection than IL4 affords; per CNSSP 32 its floor is FedRAMP High plus the overlays and NSS controls in CNSSI 1253 Appendix D. The biggest practical differences are FIPS 140 cryptography at every internal boundary and NSS classification handling, neither of which IL4 imposes at the same depth. Personnel national-affiliation limits are often listed here too, but SRG section 5.5.2 applies them identically at IL4 and IL5, so they are not part of the delta.
Can I reuse my IL4 authorization for IL5?
The IL4 work is a strong foundation: most control content and architecture documentation carries over, and the 3PAO relationship transfers. What you add for IL5: the CNSSI 1253 Appendix D NSS overlay, FIPS 140 at internal trust zones, expanded supply-chain provenance, NSS data classification, and DoD-specific continuous monitoring cadence. Personnel affiliation rules do not change between IL4 and IL5. The document set grows substantially and the architecture may need material changes for internal cryptographic boundaries.
Is IL5 just IL4 with a few more controls?
No. That framing is the most common and most expensive mistake. IL5 carries the CNSSI 1253 NSS overlay on top of the FedRAMP High floor than the prior baseline, and the additions are concentrated in operational areas: a US-citizen workforce program, an internal FIPS 140 cryptographic architecture, and NSS classification handling. These are personnel and architecture problems that take quarters, not documentation tasks that take weeks.
Which workloads require IL5 instead of IL4?
Mission-critical CUI and unclassified National Security Systems require IL5. Standard CUI that is not mission-critical and not an NSS can use IL4. You do not choose freely; the data sensitivity and the mission criticality, as determined by the DoD customer and the workload's role, dictate which Impact Level applies.
Do both IL4 and IL5 restrict who can access the environment?
Yes, and identically. CSP SRG section 5.5.2 states that at Impact Level 4/5, CSP personnel with access to systems processing or storing DoW CUI, or to the information itself, must be U.S. Citizens, U.S. Nationals, or U.S. Persons, with no Foreign Persons permitted. U.S. Person is defined at 22 CFR 120.15 and includes lawful permanent residents, so this is not a citizens-only rule; citizens-only applies at IL6. Because the requirement is identical at both levels it is a FedRAMP-to-DoD step rather than an IL4-to-IL5 delta. What is expansive is who it covers: the SRG applies PS-3(04) and states that all CSP personnel with access to the information systems are considered administrators.
If this is a live decision
Not sure which fits your situation?

Book a scoping call.

Thirty minutes. We'll walk through your target, your current posture, and which path (or which combination) actually fits. If the answer is "neither yet," we'll say so.

Book a scoping call →