DoD Cloud Computing SRG
The DoD adds its own layer on top of FedRAMP. It is not a formality.
The DoD Cloud Computing Security Requirements Guide sets impact levels above the FedRAMP baseline, each with its own requirements for the sensitivity of information handled, where it may be physically located, who may access it and how the environment connects to DoD networks.
IL4 covers controlled unclassified information. IL5 covers higher-sensitivity CUI and national security systems. IL6 covers information classified up to SECRET, which brings personnel clearance and facility requirements that most providers have never faced.
DASATECH has supported IL4, IL5 and IL6 assessment and accreditation for more than a decade, and is a cleared facility, which is what makes work at the upper impact levels possible for us at all.
- Personnel citizenship, clearance and screening requirements
- Physical location and jurisdiction constraints on the hosting environment
- Connectivity through approved boundary and access points
- Separation requirements between DoD and non-DoD tenants
- Additional controls layered above the FedRAMP baseline
- Sponsorship, mission owner engagement and provisional authorization path
Asset counts are examples. Boundary and tenancy decisions at IL5 and IL6 are architectural, not documentary.
How it runs
Engagement sequence
Impact level determination
We confirm the target impact level against the information the system will actually handle, and the requirements that follow from it.
Gap assessment
The environment is assessed against SRG requirements for that level, including personnel, location and connectivity constraints, not only technical controls.
Remediation and documentation
Documentation is built to the target level and remediation is advised, reviewed and verified as it completes.
Assessment
Controls are assessed and technical testing performed, with findings raised as they emerge rather than held to the report.
Authorization and sustainment
We support the authorization decision, mission owner questions and the continuous monitoring that follows.
Deliverables
Accreditation support deliverables
Every document is produced in the template the receiving party expects, and is written to be read by an assessor rather than filed.
- SSPSystem Security Plan reflecting SRG requirements at the target impact level
- GAPImpact level gap assessment with prioritized remediation roadmap
- ARCHBoundary, connectivity and data flow documentation for the DoD environment
- CRMCustomer responsibility matrix and control inheritance mapping
- SARAssessment report supporting the provisional authorization decision
- POA&MFindings with remediation owners, dates and closure tracking
- CONMONContinuous monitoring artifacts and reporting cadence
Outcome
What this unlocks
- Eligibility for DoD mission workloads at the impact level your contract requires
- A documented, evidenced path rather than an interpretation of the SRG
- Constraints identified early, when they are still architectural decisions
- Support at IL6 from a firm cleared to work there
- Assessment and advisory from one team that has done both across a decade
Tell us what the contract requires. We’ll tell you what it takes.
A 30-minute scoping call is usually enough to size the gap, name the deliverables and give you a realistic date for authorization.
