Fortinetics Book a call →
Menu
FedRAMP · · · 8 min read

FedRAMP to DoD CC SRG IL4 and IL5: the upgrade path most CSPs underestimate

How to sequence FedRAMP Moderate → Impact Level 4 → Impact Level 5 authorizations so DoD work does not require rebuilding the authorization package twice. Covers DoD-specific controls, DISA PA, agency sponsorship, and where CSPs repeatedly underestimate the incremental scope.

A commercial Cloud Service Provider entering the federal market typically starts with FedRAMP Moderate. It is the right choice: roughly eighty percent of federal agency workloads classify as Moderate, a Moderate authorization opens a large addressable customer base, and the technical bar is aggressive but achievable in twelve to eighteen months.

Then the DoD opportunity arrives. An Agency sponsor mentions Impact Level 4. A prime asks whether the service is authorized at IL5. Somebody on the product team asks if the existing FedRAMP Moderate authorization “counts.” The answers are nuanced in ways that matter, and the most common CSP mistake is treating IL4/IL5 as a rubber stamp on top of a completed FedRAMP. In practice, sequencing and scoping decisions made at FedRAMP time affect whether the IL4/IL5 path takes six months or eighteen.

This article is for the CSP that is either already FedRAMP-Moderate-authorized, or approaching Moderate assessment, and wants to understand the DoD upgrade path before committing to a roadmap.

The stack: FedRAMP, DoD CC SRG, DISA PA

The easiest framing is to think of the authorization structure as three stacked layers.

FedRAMP is the federal-wide baseline. It authorizes a cloud service to process federal unclassified data at a chosen impact baseline (Low, Moderate, or High). The authorization is issued by a sponsoring agency after a 3PAO-performed Security Assessment. (The Joint Authorization Board that used to offer a second route was replaced by the FedRAMP Board in May 2024, and the P-ATO path retired with it.)

DoD Cloud Computing Security Requirements Guide (CC SRG) is the DoD’s overlay. It layers DoD-specific controls on top of a FedRAMP authorization. It does not replace FedRAMP; it extends it. The CC SRG defines four Impact Levels — the superseded pre-SRG cloud security model had six, and the SRG collapsed IL1 into IL2 and IL3 into IL4 while keeping the original numbering:

  • IL2 covers low-impact, non-controlled unclassified DoD information. IL2 authorization is effectively FedRAMP Moderate equivalent with very minor DoD differences.
  • IL4 covers Controlled Unclassified Information (CUI) for DoD workloads. FedRAMP Moderate is the foundation; IL4 adds DoD-specific controls.
  • IL5 covers mission-critical CUI and unclassified National Security Systems. FedRAMP Moderate (sometimes Moderate+) or High is the foundation; IL5 adds more DoD-specific controls, including US-citizen operator requirements for certain components.
  • IL6 covers classified Secret workloads and requires SIPRNet-connected infrastructure.

DISA Provisional Authorization (PA) is the artifact you receive. The Defense Information Systems Agency issues the PA after reviewing your IL4 or IL5 package. DoD customers then issue their own DoD ATOs on top of your DISA PA, for their specific workloads.

The sequencing that works is FedRAMP first, then DISA PA at your target Impact Level, then DoD customer ATOs on top. Attempting IL4/IL5 without FedRAMP completed first is possible in specific cases but typically extends timeline significantly.

Where most CSPs under-scope the delta

The seductive story is that IL4 is “FedRAMP Moderate plus a few DoD controls.” That is technically true. In practice, the “few” DoD controls include obligations that require real architectural decisions, and three of them consistently surprise first-time CSPs.

Data residency and sovereignty. DoD requires all in-scope data, processing, and administrative access to reside within US borders. “We use AWS US-East-1” is not sufficient. The auditor wants to see every dependency, every integration, every piece of operational tooling, documented as US-resident. Third-party SaaS tools in your operations stack (ticketing, monitoring, collaboration) that route through non-US infrastructure become explicit findings. A common fix is provisioning US-only instances of those tools, or replacing them with US-only alternatives.

National-affiliation limits on who can touch the boundary (IL4 and IL5 alike). SRG 5.5.2: personnel with access to systems processing or storing DoW CUI at IL4/5, or to the information itself, must be U.S. Citizens, U.S. Nationals, or U.S. Persons; no Foreign Persons. “U.S. Person” is the 22 CFR 120.15 term and covers lawful permanent residents, so this is narrower than the “US citizens only” you will read elsewhere — including in earlier versions of this article. Citizens-only bites at IL6. What makes it a program rather than a policy is reach and evidence: the SRG states that all CSP personnel with access to the information systems count as administrators for this purpose. CSPs with globally distributed SRE teams discover this mid-program and spend quarters restructuring on-call and deployment workflows.

Deployment location. IL4 permits standard commercial GovCloud regions (AWS GovCloud, Azure Government, sometimes Oracle US Government Cloud). IL5 typically requires more restricted environments: AWS GovCloud with additional isolation, Azure Government DoD/GCC High, or specific AWS Secret Region for cleared workloads. The CSP has to decide which cloud regions to support for each Impact Level, and those decisions drive service-catalog and pricing decisions for the commercial product.

Sequencing that saves six months

The biggest time saver is designing the authorization boundary with the IL5 endpoint in mind, even during FedRAMP Moderate planning. Specifically:

Design the System Security Plan for the harder case, not the easier one. If there is a plausible chance you will pursue IL4 or IL5 within eighteen months, write the FedRAMP SSP with boundary definitions and data-flow documentation that would hold up under DoD scrutiny. This means being explicit about US-only processing paths, clearly documenting which components handle CUI, and using DoD-compatible cryptographic modules (FIPS 140-2 or 140-3 CMVP-validated) from day one.

Select GovCloud from day one. Deploying FedRAMP Moderate to commercial cloud and then re-deploying to GovCloud for IL4 is a significant architectural rework. Deploying to GovCloud for FedRAMP Moderate adds marginal cost at the time but eliminates a migration project later.

Staff the boundary to the DoD affiliation rule during FedRAMP preparation. If the people who operate the authorization boundary already satisfy the U.S. Citizen / National / Person test during FedRAMP, the move to IL4 or IL5 does not require a personnel restructure. CSPs that grow their federal operations team with the DoD endpoint in mind find this far easier than those who discover the requirement later.

Pre-coordinate the DISA PA timeline with your Agency sponsor. Agency ATO and DISA PA processes are independent. Many CSPs discover that completing FedRAMP Moderate does not automatically trigger DISA review. It requires a separate submission to DISA, a distinct review cycle (typically 3-6 months), and acceptance by your first DoD customer. Start that conversation with the Agency sponsor during FedRAMP so the DISA path is active when Moderate wraps.

Choosing the sponsor for the FedRAMP foundation

Older planning material presents this as a fork — an Agency ATO from a sponsoring agency, or a JAB P-ATO from the Joint Authorization Board, weighed against each other on speed versus portability. There is no fork. GSA replaced the JAB with the FedRAMP Board in May 2024 and retired the P-ATO path with it; existing P-ATOs were redesignated rather than reissued. Agency sponsorship is the route.

What remains a real decision is which agency. An agency sponsor is a specific federal customer that commits to using your service and sponsors your authorization. The authorization is reusable by other agencies through the FedRAMP Marketplace, but each adopting agency still reviews on its own timeline, so the first sponsor shapes both your schedule and the boundary the package is written around.

For DoD work specifically, the sequence that usually works is a sponsor from the DoD component you are actually selling into, combined with a DISA PA at your target Impact Level. That keeps the boundary documentation aimed at DoD scrutiny from the first draft rather than being retrofitted after a civilian-agency authorization lands.

What CSPs wish they had known six months earlier

Five recurring themes in our engagements with CSPs who entered FedRAMP, then began IL4/IL5 work six to eighteen months later:

First, the boundary definition is load-bearing for the entire authorization lifecycle. Rework at assessment time is expensive. Design conservatively and explicitly.

Second, continuous monitoring is not an afterthought. DoD has specific expectations about monthly deliverables: vulnerability scan results, POA&M updates, system change notifications. Building the operational muscle for ConMon during FedRAMP is substantially easier than retrofitting it during IL4.

Third, FIPS 140-2 or 140-3 CMVP validation is real, and “FIPS-compliant” is not the same thing. Every cryptographic module in the authorization boundary must have a documented CMVP certificate. CSPs using third-party libraries (TLS implementations, disk encryption, key management) need to verify each one; the audit team will request certificates during assessment.

Fourth, sponsor relationships matter more than the technical package. A strong Agency sponsor advocating for your authorization moves schedules; a weak sponsor relationship produces delays. Treat sponsor communication as a program deliverable.

Fifth, the personnel affiliation rules are a people problem before they are a technical one, and they arrive at IL4, not IL5. Start it early.

The practical sequence

For a CSP planning to reach IL5 within three years:

  • Year 1: Plan FedRAMP Moderate with IL4/IL5 in mind (boundary, cloud selection, ConMon architecture). Secure an Agency sponsor with clear DoD connection. Begin FedRAMP Moderate assessment.
  • Year 1.5: Complete FedRAMP Moderate; receive Agency ATO. Begin DISA PA engagement for IL4.
  • Year 2: IL4 DISA PA; begin onboarding DoD customers under the PA. Begin IL5 gap analysis.
  • Year 2.5: Complete personnel/boundary adjustments required for IL5. Submit IL5 package to DISA.
  • Year 3: IL5 DISA PA; onboard mission-critical DoD workloads.

Compressed timelines are possible but require more concurrent work and a well-funded federal operations team. The sequence above is defensible without heroics.

When to engage

The sooner, the better. The decisions that most affect your IL4/IL5 timeline are made during FedRAMP boundary design, sometimes twelve months before the question of DoD even comes up. A scoping call during FedRAMP planning can prevent the most expensive form of rework.

Our FedRAMP and DoD CC SRG practice covers the full ladder from FedRAMP Low through IL6. For CSPs specifically preparing for IL5 assessment, the eight controls that burn CSPs first in IL5 assessment breaks down the operational gaps that extend timelines.

Frequently asked

Common questions.

What's the difference between DoD Impact Level 4 and Impact Level 5?
IL4 covers Controlled Unclassified Information generally. IL5 covers mission-critical CUI, unclassified National Security Systems, and CUI whose compromise could have serious impact on operations or personnel. Control-baseline-wise the delta is narrow. IL5 adds US-citizen operator verification, FIPS 140-validated cryptography everywhere, deeper supply-chain evidence, and stricter continuous monitoring cadence. The harder part of the IL5 upgrade is not the controls themselves; it's the operational maturity the controls require.
Can we go straight from FedRAMP Moderate to IL5 without IL4?
Technically yes if your sponsor and mission require it; the DoD CC SRG does not mandate IL4 as a prerequisite. Practically, most CSPs step through IL4 first because the incremental controls are smaller and the operational muscle for monthly ConMon deliverables, US-citizen workflow, and boundary discipline is easier to build in stages. Skipping IL4 is usually a schedule decision driven by a specific DoD customer, not a strategic one.
How long does the FedRAMP Moderate → IL4 upgrade take?
Three to six months for a CSP with a clean FedRAMP Moderate ATO and a sponsor engaged on the IL4 path. The work is concentrated in DoD overlay control implementation, authorization-boundary documentation updates, US-GovCloud (or equivalent) migration if not already there, and the DISA provisional authorization review. IL4 → IL5 adds another four to six months, mostly driven by the NSS overlay and FIPS 140 boundary evidence. The personnel affiliation workflow is not part of that delta — it already applies at IL4.
Who is allowed to access an IL4 or IL5 environment?
CSP SRG section 5.5.2 sets the limit by national affiliation, and it is the same at both levels: personnel with access to systems processing or storing DoW CUI at Impact Level 4/5, or to the information itself, must be U.S. Citizens, U.S. Nationals, or U.S. Persons, and no Foreign Persons may have such access. U.S. Person is defined at 22 CFR 120.15 and includes lawful permanent residents, so this is not a citizens-only rule. Citizens-only applies at IL6, and to digital escorts under section 5.17. The SRG also applies PS-3(04) with the statement that all CSP personnel with access to the information systems are considered administrators, so the population is wider than named privileged roles. The requirement is easy to write into policy; what the assessor wants is the operational artifact: HR-to-IdP integration at onboarding and reconciliation against access lists.
Who issues the IL5 authorization?
DISA issues the Provisional Authorization for IL4 and IL5 after the 3PAO assessment and agency review. The Provisional Authorization is the gating document for DoD components to issue mission-specific ATOs on top. IL6 operates under a different model (SIPRNet, classified) with additional agency authorities and is out of scope for IL5 planning.