FedRAMP vs. DISA Impact Levels

Federal cloud authorization, from civilian to defense

Selling software to the U.S. government means navigating two major frameworks: FedRAMP for civilian agencies, and the DoD Cloud Computing SRG for defense. Here's how they relate, when you need each, and how to operate across both.

Before FedRAMP or DISA Impact Levels, there is FIPS 199 — the standard that classifies every federal system by the impact of a security breach.

FIPS 199 rates systems across confidentiality, integrity, and availability, then categorizes each as Low, Moderate, or High. Those categories determine the required security controls. FedRAMP applies FIPS 199 to cloud systems. The DoD Cloud Computing SRG builds on FedRAMP, and Impact Levels extend those requirements for defense use.

Civilian vs. defense

Two frameworks, one lineage

FedRAMP standardizes cloud security for civilian agencies. The DoD Cloud Computing SRG takes that same baseline and adds defense-specific requirements on top.

The standard for civilian federal agencies

FedRAMP produces a standardized, reusable authorization package assessed against NIST SP 800-53. Each agency reviews that package and issues its own ATO based on mission and risk tolerance.

NIST SP 800-53 Low · Moderate · High

The framework for defense cloud security

Governed by DISA, the DoD Cloud Computing SRG applies Impact Levels (IL2, IL4, IL5, IL6) on top of FedRAMP baselines to address DoD-specific data sensitivity and mission requirements.

DISA IL2 · IL4 · IL5 · IL6

How the DoD measures data sensitivity

Controlled Unclassified Information (CUI) is sensitive government data that is not classified, but still requires protection, such as export-controlled data, critical infrastructure information, health information, law enforcement data, and mission-related operational data. Impact Levels define how sensitive DoD data is and what protection it requires.

Impact Level 2

Impact Level 4

Impact Level 5

Impact Levels extend FedRAMP. They don't replace it.

The frameworks stack. FedRAMP is the baseline. Impact Levels are a DoD construct applied on top of that baseline to address defense data sensitivity and mission requirements. Each level builds on everything below it and adds more.

Quick comparison

FedRAMP IL4 IL5
Governing body GSA / FedRAMP PMO DISA DISA
Primary use Civilian agencies DoD CUI workloads DoD NSS / NSI workloads
Security baseline NIST SP 800-53 FedRAMP Moderate or High + DoD overlays FedRAMP High + DoD overlays
Data type Low, Moderate, High CUI NSS / NSI (with some elevated CUI)
Authorization Agency ATO DISA Provisional Authorization DISA Provisional Authorization
Typical entry point Moderate IL4 IL5

FedRAMP, IL4, or IL5?

Many companies move through all three over time, FedRAMP for baseline authorization and civilian adoption, IL4 for initial DoD entry, and IL5 for deeper defense and national security work.

You need FedRAMP if

You need IL4 if

You need IL5 if

The core challenge

Regardless of framework, to work with the government a company still needs the same three things.

With Knox

Authorization in 90 days

Knox gives you a single path across FedRAMP and DoD Impact Levels — for roughly 90% less than the DIY route.

Trusted by top agencies for mission-critical needs

!

Frequently asked

FedRAMP & Impact Levels, clarified

Is IL5 higher than FedRAMP High?

No. IL5 builds on FedRAMP High and adds DoD-specific requirements.

Does FedRAMP automatically give you IL4?

No. Additional DoD requirements and authorization are required.

Do I need IL5 to sell to the DoD?

Not always. Many workloads operate at IL4.

Can a company have both FedRAMP and IL5?

Yes. Most companies expanding into DoD environments eventually need both.