← All posts Industry Insights

Navigating DoW Impact Level Authorization

622+ controls, 20 families, 5 impact levels, 11 steps to Provisional Authorization. The visual guide for cloud-native companies navigating DoW IL authorization.

Optimal Team
Navigating DoW Impact Level authorization

01 · The Landscape

622+ Controls. Five Impact Levels. One Framework.

The DoW CC SRG Rev 5 layers DoW-specific requirements on FedRAMP baselines across IL2, IL4, IL5, IL6, and Top Secret (JWICS).

Impact LevelBaselineControls
IL2FedRAMP Moderate345
IL4 ModFedRAMP Moderate345
IL4 HighFedRAMP High + DoW429 (+84)
IL5 NSSCNSSI 1253 + NSS588 (+159)
IL6 NSSClassified + TEMPEST618 (+30)
Top SecretIL6 + Classified Overlay + JWICS618+ (+TS overlay)

Source: CC SRG v1r6, Section 5.1 (December 2025)

IL5 now mandates NSS controls from CNSSI 1253 per CNSSP-32. A 37% increase over IL4 High. FedRAMP High is the mandatory floor. There is no longer a path to IL5 using FedRAMP Moderate.

Beyond IL6: Top Secret / JWICS

The CC SRG formally defines IL2 through IL6. However, Top Secret / SCI workloads operate on JWICS (Joint Worldwide Intelligence Communications System) under IC-directed authorization, applying IL6 controls plus a classified overlay. JWICS environments require SCIF-grade facilities, TS/SCI-cleared personnel, and physical separation from all unclassified and non-federal infrastructure.

02 · Know Your Target

Which Impact Level Do You Need?

What data will your product handle?

Data You HandleImpact LevelControlsBaselineInfrastructure
CUI (Public-facing)IL2345FedRAMP ModerateMulti-tenant OK
CUI (Mission)IL4429 (+84)FedRAMP High + DoWCAP + DoW PKI
CUI / NSSIL5588 (+159)CNSSI 1253 NSSDedicated infra
Classified SECRETIL6618 (+30)CNSSI 1253 + TEMPESTSIPRNet classified
Classified TS/SCITop Secret618+ (+overlay)IL6 + Classified OverlayJWICS · TS/SCI

The IL4 to IL5 jump is not incremental. It’s a fundamentally different posture.

AttributeIL2IL4IL5IL6Top Secret
Controls345429588618618+
BaselineFedRAMP ModFedRAMP HighCNSSI 1253CNSSI 1253+Level 6 + Classified Overlay
SeparationMulti-tenantLogicalPhysicalPhysicalPhysical + Air-gapped
NetworkInternetNIPRNet via CAPNIPRNet via CAPSIPRNetJWICS
LocationAnyCONUS / DoW on-premCONUS / DoW on-premCONUS / DoW on-premCleared / SCIF
PersonnelN/AU.S. CitizensTier 3 / SecretTier 5 / TS/SCITS/SCI + NDA

03 · The Architecture Stack

SCCA: What Your Product Plugs Into

The DoW Secure Cloud Computing Architecture (SCCA) defines the zones your product plugs into. The same architecture applies at any Impact Level.

CSP DevSecOps Environment — a separate IL-authorized cloud account, owned by the CSP. Continuous Authority to Operate (cATO) · FIPS 140-2/3 · STIG-hardened runners.

ComponentFunction
Source RepoVersion control
SAST / DASTStatic & dynamic scanning
Container ScanImage vulnerability scanning
IaC ValidationInfrastructure-as-code checks
Image BuilderHardened image pipeline
Artifact RegistryHardened images · STIG baselines · Signed artifacts

Deploys signed artifacts to USAF, Army, DISA, and Navy — any IL2–TS environment.

TCCM Governance Boundary — government-appointed privileged access and root credential management.

Agency-Owned Cloud Account — IL-authorized region · CONUS · DoW IP space · FIPS 140-2/3 validated · any FedRAMP-authorized CSP. It contains the following zones.

VDSS — Virtual Datacenter Security Stack

ComponentFunction
FirewallL3–L7
WAFWeb application firewall
IDS / IPSDetection
Reverse ProxyTLS termination
VPC Flow LogsPacket capture · NetFlow → CSSP

Plus DDoS mitigation, GeoIP, and ACLs.

Your Product — Mission Owner VPC (Cloud Service Offering)

ComponentFunction
ComputeVMs / Containers
DatabaseRelational / NoSQL
Object StorageFIPS endpoint
Auth / IdPDoW PKI · CAC
Message BusQueue / Stream
Secrets MgmtKMS · HSM
Load BalancerInternal · TLS 1.2+ only
VPN / Transit GatewayCross-network peering · IPSec

Runs in DoW IP space, CONUS only, on a FedRAMP High+ baseline with AES-256 at rest and FIPS endpoints. All traffic is inspected.

VDMS — Virtual Datacenter Managed Services

ComponentFunction
ACASVulnerability scanning
HBSSHost security
STIG AuditCompliance
Patch MgmtAutomated
SIEMLog aggregation · Correlation · Alerting

Plus config management, IaC enforcement, and golden-image compliance.

CSSP VPC — Cybersecurity Service Provider

ComponentFunction
Log ReplicationCross-account sync
Stream IngestReal-time feeds
MonitoringMetrics & alarms
CSSP AgentsEndpoint telemetry

Provides a 24/7 SOC, IR coordination, and JFHQ-DoWIN situational awareness.

Cloud-Native Security Services

Continuous monitoring and compliance, with CSP-agnostic equivalents: CSPM, Threat Intel, Audit Logs, Config, Inspector, IAM, and Data Classification.

External Networks

NetworkAccess
DoW UsersCAC / PKI auth
NIPRNetUnclassified DoW
CAP (Cloud Access Point)DISA-operated
InternetCommercial (IL2)
SIPRNetClassified (IL6)
JWICSTop Secret / SCI
Client VPN / ZTNAIPSec · OIDC · MFA

TCCM — Trusted Cloud Credential Manager: government-appointed, holds root credentials and privileged access. Not your cloud admin.

Key architecture notes

  • CSP vs Agency — Your DevSecOps pipeline lives in a separate CSP-owned cloud account. Signed artifacts deploy into agency-owned accounts (USAF, Army, DISA, Navy). Same architecture, any IL.
  • CAP — DISA-operated boundary. Plan for East + West redundancy. Circuit provisioning takes months, so start early.
  • CSSP VPC — Non-negotiable at IL4+. Log replication, real-time streaming, and SOC coordination with JFHQ-DoWIN. Start the MOU 6 months out.
  • TCCM — Government-appointed by the Mission Owner’s AO. Manages root credentials and privileged access. Not your cloud admin.
  • CSP-agnostic — This architecture applies across any FedRAMP-authorized CSP. Terminology maps to equivalent services on each platform.

04 · The Authorization Journey

11 Steps from Contact to Connection

Per DoW Cloud Connection Process Guide v3 (December 2025). PA is granted to the CSO, not the CSP.

StepPhaseMilestoneDetail
1CSP / CSOSubmit Initial Contact FormVia DCAS portal to initiate DoW cloud registration
2CSP / CSODoW Cloud Kickoff MeetingTechnical Exchange Meeting (TEM) with all stakeholders
3CSP / CSOJVT Reviews Artifacts & 3PAO AssessmentSSP, SAR, architecture diagram review
4CSP / CSOInitial Risk Review → IATT & CATCInterim Authorization to Test and Cloud Authority to Connect issued
5CSP / CSOJVT Artifact ValidationRuns concurrent with Step 6
6CSP / CSOSCCA Connects CSO to CAPNetwork connectivity established
7CSP / CSODSAWG Review & RecommendationCross-service board reviews authorization package
8CSP / CSODISA AO Issues PAProvisional Authorization granted to the CSO
9CSP / CSOSustainment & ConMonContinuous monitoring; USCYBERCOM OPORD compliance begins
10Mission OwnerC-ITP RegistrationMission Owner registers Cloud IT Project via SNAP
11Mission OwnerMission Owner ATOAuthority to Operate; mission system goes live

Required artifacts: SSP, SSP Addendum, SAP, Architecture Diagram, Onboarding Questionnaire, SNAP/PPSM Registration.

05 · Control Family Heatmap

Where the Weight Falls

Not all families scale equally. Some nearly double from IL4 High to IL5.

Control FamilyTotalIL2IL4MIL4HIL5IL6
Access Control654343506165
Sys & Comms Protection673333385967
Sys & Services Acquisition702626296970
Sys & Info Integrity542424355254
Config Management432727344343
Audit & Accountability371717273537
Identification & Auth372727303737
Contingency Planning352323353535
Incident Response331717243333
Physical & Environmental331919262833
Supply Chain Risk Mgmt221212142222
Maintenance231111132023
Risk Assessment181111131718
Security Assessment & Auth201414162020
Personnel Security161111121416
Media Protection1577101015
Awareness & Training126661212
Planning117771111
DoW General Readiness10101010106

Biggest Jumps: IL4 High → IL5

Control FamilyChange (IL4 High → IL5)Increase
Systems & Services Acquisition (SA)29 → 69+138%
Systems & Communications Protection (SC)38 → 59+55%
Systems & Information Integrity (SI)35 → 52+49%

06 · Data Type Overlays

Controls Stack by Data Type

CNSSI 1253 overlays add controls based on the data your system processes. These are additive to your IL baseline.

OverlayAdded Controls
NSS303
CUI249
Classified212
PHI / HIPAA138
Export Control108
PII / Privacy58

Cumulative impact: An IL5 system processing CUI + PHI could face 588 baseline controls plus overlay deltas. Your SSP must document which overlays apply.

07 · Personnel & Clearance Tiers

Who Can Touch Your System

Personnel investigation requirements escalate sharply by Impact Level. Source: CC SRG v1r6, Table 5-1.

RequirementIL2IL4IL5IL6Top Secret
Privileged AccessTier 1 / NACITier 3 / MBITier 3 / SecretTier 5 / TS/SCITier 5 / TS/SCI + NDA
Non-PrivilegedN/ATier 1Tier 3 / SecretTier 5 / TS/SCITier 5 / TS/SCI + NDA
CitizenshipNo requirementU.S. CitizensU.S. CitizensU.S. CitizensU.S. Citizens
Data LocationAnyCONUSCONUSCONUSSCIF / Cleared facility

08 · General Readiness Gates

10 Pass/Fail Gates Before Assessment

Binary requirements. You pass or you don’t. Evaluated before a single control is assessed.

  1. DoW PKI / CAC Authentication
  2. DoW IP Addressing (DISA NIC)
  3. U.S. Data Residency (CONUS)
  4. Mgmt Plane Segregation
  5. Personnel Requirements Met
  6. CAP Private Connections
  7. Internet Dependencies Documented
  8. NIPRNet Portal Access
  9. Backdoor Prevention
  10. Defense in Depth

09 · Bottom Line

What This Means for Your Product

Targeting IL4

  • Start with FedRAMP High (429 controls)
  • Architect for CAP + DoW PKI from day one
  • Budget for CSSP engagement
  • Circuit provisioning takes months. Start early

Targeting IL5

  • Everything above + physically separated infrastructure
  • Full CNSSI 1253 NSS overlay (588 controls)
  • 24/7 SOC with CSSP coordination
  • Supply chain controls across vendor ecosystem

Targeting IL6

  • SIPRNet classified enclave
  • TEMPEST/EMSEC + continuous physical guards
  • 618 controls with classified data handling
  • DISA retains pen testing rights

Targeting Top Secret

  • Everything IL6 + JWICS network (not SIPRNet)
  • Level 6 + Classified overlay controls
  • SCIF-grade facilities. Physically separate from unclassified
  • All personnel require favorably adjudicated TS/SCI + NDA
  • IC-directed authorization. Separate from standard PA pathway

DoW cloud authorization is a product architecture decision, not a compliance checkbox.

Data sourced from NIST 800-53 Rev 5 · DoW CC SRG v1r6 (Dec 2025) · Cloud CPG v3 (Dec 2025) · CNSSI 1253

DoWImpact LevelIL2IL4IL5IL6FedRAMPDISACC SRGNIST 800-53CNSSI 1253SCCAProvisional Authorizationcloud authorization

Bring your organization through the Gateway.

Request access →