ISO/IEC 17020 accredited inspection body · Cleared facility (FCL)
Home / Services / DoD Impact Level Accreditation

Defense & national security

DoD Impact Level Accreditation

Assessment, accreditation and compliance support for systems operating at Impact Levels 4, 5 and 6 under the DoD Cloud Computing SRG.

DoD Cloud Computing SRG

The DoD adds its own layer on top of FedRAMP. It is not a formality.

The DoD Cloud Computing Security Requirements Guide sets impact levels above the FedRAMP baseline, each with its own requirements for the sensitivity of information handled, where it may be physically located, who may access it and how the environment connects to DoD networks.

IL4 covers controlled unclassified information. IL5 covers higher-sensitivity CUI and national security systems. IL6 covers information classified up to SECRET, which brings personnel clearance and facility requirements that most providers have never faced.

DASATECH has supported IL4, IL5 and IL6 assessment and accreditation for more than a decade, and is a cleared facility, which is what makes work at the upper impact levels possible for us at all.

What changes as impact level rises
  • Personnel citizenship, clearance and screening requirements
  • Physical location and jurisdiction constraints on the hosting environment
  • Connectivity through approved boundary and access points
  • Separation requirements between DoD and non-DoD tenants
  • Additional controls layered above the FedRAMP baseline
  • Sponsorship, mission owner engagement and provisional authorization path
BEFORE: FLAT NETWORK 40 assets in scope Every host must meet all 110 requirements AFTER: CUI ENCLAVE 6 assets in scope Remaining 34 fall outside the boundary CUI ENCLAVE
Impact level drives separation: what shares infrastructure, and what cannot.

Asset counts are examples. Boundary and tenancy decisions at IL5 and IL6 are architectural, not documentary.

How it runs

Engagement sequence

Impact level determination

1 week

We confirm the target impact level against the information the system will actually handle, and the requirements that follow from it.

Gap assessment

2–4 weeks

The environment is assessed against SRG requirements for that level, including personnel, location and connectivity constraints, not only technical controls.

Remediation and documentation

6–12 weeks

Documentation is built to the target level and remediation is advised, reviewed and verified as it completes.

Assessment

3–5 weeks

Controls are assessed and technical testing performed, with findings raised as they emerge rather than held to the report.

Authorization and sustainment

Ongoing

We support the authorization decision, mission owner questions and the continuous monitoring that follows.

Deliverables

Accreditation support deliverables

Every document is produced in the template the receiving party expects, and is written to be read by an assessor rather than filed.

  • SSPSystem Security Plan reflecting SRG requirements at the target impact level
  • GAPImpact level gap assessment with prioritized remediation roadmap
  • ARCHBoundary, connectivity and data flow documentation for the DoD environment
  • CRMCustomer responsibility matrix and control inheritance mapping
  • SARAssessment report supporting the provisional authorization decision
  • POA&MFindings with remediation owners, dates and closure tracking
  • CONMONContinuous monitoring artifacts and reporting cadence

Outcome

What this unlocks

  • Eligibility for DoD mission workloads at the impact level your contract requires
  • A documented, evidenced path rather than an interpretation of the SRG
  • Constraints identified early, when they are still architectural decisions
  • Support at IL6 from a firm cleared to work there
  • Assessment and advisory from one team that has done both across a decade

Tell us what the contract requires. We’ll tell you what it takes.

A 30-minute scoping call is usually enough to size the gap, name the deliverables and give you a realistic date for authorization.