Request Access →
Defense Cloud Compliance Frameworks

Three Regimes
Three Axes

A plain-English guide to FedRAMP, DoD Impact Level, and ITAR. The three compliance frameworks defense cloud customers keep confusing for each other, plus the CUI label that sits across all of them.

The mental model in one paragraph

Imagine a nightclub. FedRAMP is the health inspector's certificate on the wall. The government won't enter a building without it. DoD Impact Level is the velvet-rope system inside. Different VIP rooms for different levels of sensitive conversation. ITAR is the bouncer at the door checking passports. Some rooms only US persons can enter, no matter what level. And CUI is a label stamped on the documents people bring in. It tells everyone which rooms those documents are allowed in.

Section 01 · The cast of characters

Four things that are not the same

FedRAMP
Federal cloud authorization
“Is this cloud safe enough for a federal agency to use at all?”
Who runs it
GSA / FedRAMP PMO
Applies to
Any cloud service selling to federal agencies
Levels
Low · Moderate · High
What's being rated
The cloud provider itself
DoD Impact Level
Dept. of Defense cloud only
“How sensitive is the military data we're putting on this cloud?”
Who runs it
DISA (DoD)
Applies to
DoD workloads on commercial cloud
Levels
IL2 · IL4 · IL5 · IL6
What's being rated
The cloud plus the data sensitivity
ITAR
Export control · State Dept
“Can a non-American legally be allowed to see this?”
Who runs it
DDTC (State Dept)
Applies to
Defense articles and technical data (USML)
Levels
None. You either handle it or you don't
What's being rated
Your people, processes, and physical/logical access
CUI
A data label, not a regime
“This document is sensitive but not classified. Protect it accordingly.”
Who owns the label
NARA CUI Program
What it actually is
A classification marker stamped on sensitive-but-unclassified data
Levels
None. Data is either CUI or it isn't
Governs how?
Via CMMC / NIST 800-171 for contractors (see column four)
Section 02 · The right mental picture

Compliance is an axis, not a single line

DoD sensitivity →
IL2 IL4 IL5 IL6 Non-ITAR ITAR
Public agency websiteLow sensitivity, no export control. Plain FedRAMP Moderate covers it.
Defense program mgmt dataMission-critical CUI on a DoD system, but not on the USML. IL5, no ITAR needed.
Commercial aerospace techUSML-controlled but no DoD contract. ITAR applies. DoD IL does not.
Spacecraft data on DoD contractBoth worlds. IL5 and ITAR required, stacked.
Export control →

Any given workload sits at a point on this plane, not at a rank on a single ladder.

The vertical axis is DoD's framework (data sensitivity). The horizontal axis is the State Department's framework (export control). A workload can be high on one and low on the other, or high on both, or low on both.

This is why saying "IL5 is higher than ITAR" is a category error. It's like asking whether a driver's license is higher than a passport.

Section 03 · The actual differences

Side by side, in one table

FedRAMP DoD IL ITAR CMMC / NIST 800-171
Legal basis FISMA & OMB policyExecutive branch DoD Cloud Computing SRGDoD instruction 22 CFR 120–130Federal regulation DFARS 252.204-7012 / -7019 / -7020 / -7021 & 32 CFR 170CUI + assessment + CMMC clauses
Agency GSA · FedRAMP PMO DISA State Dept · DDTC DoD CIO · OUSD(A&S)
What it protects Federal government data on commercial cloud DoD-specific sensitive data, tiered by impact Defense articles and technical data (US Munitions List) Contractor systems that handle CUI data
Tiers / levels Low · Moderate · High IL2 · IL4 · IL5 · IL6 None. You meet it or you don't CMMC Level 1 · 2 · 3
How you get it 3PAO assessment → agency ATOMonths to years · expensive DISA Provisional Authorization, usually inherits FedRAMPMonths · heavy paperwork DDTC registration + export-controls programSelf-attested · audited if challenged Self-attestation (L1) · C3PAO assessment (L2) · DoD assessment (L3)Phase 1 enforcement began Nov 2025 · C3PAO L2 mandatory Nov 2026
US persons required? Varies by ATO Yes. IL4+ Yes. Strict Contract-dependent (usually yes)
Data residency US (Moderate/High) US US (strict) US (typical)
Rated subject The cloud provider Provider + workload The handling organization The contractor's systems
Who pays Cloud vendor Mostly the cloud vendor The data handler The contractor
Common mistake Assuming “Moderate” covers DoD workloads. It doesn't. Thinking IL5 subsumes ITAR. It doesn't. Treating ITAR as “just IL5 plus.” It isn't. Confusing the CMMC regime with the CUI label it protects.
Section 04 · Which one do you actually need?

Real scenarios, matched to the right regime

01
Commercial satellite company designing a new bus.
No DoD contract. Spacecraft engineering data is on the USML.
ITAR No DoD IL required
Pure export-control problem. ITAR Assured Workloads is the right home. IL5 is overkill and doesn't apply.
02
DoD contractor handling personnel records for a base.
Sensitive CUI. Not technical, not export-controlled.
DoD IL4 or IL5 CMMC L2
DoD CUI without ITAR. Needs IL-authorized cloud plus CMMC L2 on the contractor's side. ITAR isn't involved.
03
Prime contractor on a DoD spacecraft program.
Technical data that is both USML-controlled and DoD CUI.
DoD IL5 ITAR CMMC L2
The full stack. Both regimes apply simultaneously plus CMMC on the contractor's posture. This is where most prime-contractor workloads land.
04
Federal agency wanting to use a new SaaS tool.
Not DoD. Standard civilian agency use case.
FedRAMP Moderate
Plain civilian cloud authorization. No DoD IL, no ITAR, no CUI label unless the specific workload introduces one.
05
Startup selling to aerospace primes but no contract yet.
Pre-sales demos. No regulated data exchanged yet, but it's coming.
CMMC L2 (readiness) ITAR (readiness)
Primes flow down DFARS clauses when contracts land. Stand up CMMC and ITAR posture now. Working backwards from a signed deal is painful. FedRAMP isn't relevant here; that's for selling to federal agencies directly.
06
Intelligence community workload with classified elements.
Above CUI. Actually classified.
IL6
IL6 is for classified up to SECRET on dedicated infrastructure. Totally different operating model. Not a casual add-on.
Section 05 · Things people keep getting wrong

Compliance myths, busted

“IL5 is higher than ITAR, so IL5 includes ITAR.”
Actually
Two agencies, two regulations, two separate authorizations. IL5 gives you no ITAR cover, and ITAR compliance doesn't satisfy any DoD IL. They're orthogonal axes from DoD and the State Department respectively.
“FedRAMP High is basically IL5.”
Actually
FedRAMP High is a prerequisite for IL5, not a substitute. DoD inherits from FedRAMP and layers its own requirements on top (personnel, US-only, specific encryption, DISA PA).
“CUI is just another DoD impact level.”
Actually
CUI is a label on data, created by a NARA program for the whole government, not just DoD. The regime that governs how contractors handle CUI is CMMC / NIST 800-171. A separate thing from the label itself, and separate again from the cloud tier the data lives on.
Appendix · Acronym decoder

Helpful acronyms

3PAO
Third-Party Assessment Organization. The FedRAMP-accredited auditor that assesses a cloud against FedRAMP controls.
ATO
Authority to Operate. The paper that says “yes, you can run this system.”
C3PAO
Certified Third-Party Assessor Organization. The auditor that assesses CMMC compliance.
CC SRG
DoD Cloud Computing Security Requirements Guide. Defines the IL tiers.
CMMC
Cybersecurity Maturity Model Certification. DoD's framework for contractor CUI handling.
CUI
Controlled Unclassified Information. Sensitive but not classified.
DDTC
Directorate of Defense Trade Controls. The State Department office that runs ITAR.
DFARS
Defense Federal Acquisition Regulation Supplement. DoD's contract clauses. -7012 is the CUI safeguarding clause; -7019 and -7020 cover NIST 800-171 self-assessment and SPRS reporting; -7021 is the CMMC certification clause.
DISA
Defense Information Systems Agency. Grants IL provisional authorizations.
FedRAMP
Federal Risk and Authorization Management Program. The government-wide cloud authorization program. DoD inherits from FedRAMP and layers IL requirements on top.
FISMA
Federal Information Security Modernization Act. The statute that gives FedRAMP its legal teeth.
IL
Impact Level. DoD's data-sensitivity scale for cloud hosting (2, 4, 5, 6).
ITAR
International Traffic in Arms Regulations. Export control on defense articles and technical data.
JAB
Joint Authorization Board. The legacy top-tier FedRAMP authorizer. Sunset in 2024. The current path is agency ATO only.
NARA
National Archives and Records Administration. Runs the government-wide CUI program that defines the label.
NIST 800-171
The control framework for protecting CUI on non-federal systems. 110 controls.
PA
Provisional Authorization. DISA's stamp that a cloud can host a given IL.
SRG
Security Requirements Guide. DoD's document defining IL tiers.
USML
United States Munitions List. The catalog of items that are export-controlled under ITAR.

Not legal advice. Consult counsel for specifics.