Request Access → A plain-English guide to FedRAMP, DoD Impact Level, and ITAR. The three compliance frameworks defense cloud customers keep confusing for each other, plus the CUI label that sits across all of them.
Imagine a nightclub. FedRAMP is the health inspector's certificate on the wall. The government won't enter a building without it. DoD Impact Level is the velvet-rope system inside. Different VIP rooms for different levels of sensitive conversation. ITAR is the bouncer at the door checking passports. Some rooms only US persons can enter, no matter what level. And CUI is a label stamped on the documents people bring in. It tells everyone which rooms those documents are allowed in.
The vertical axis is DoD's framework (data sensitivity). The horizontal axis is the State Department's framework (export control). A workload can be high on one and low on the other, or high on both, or low on both.
This is why saying "IL5 is higher than ITAR" is a category error. It's like asking whether a driver's license is higher than a passport.
| FedRAMP | DoD IL | ITAR | CMMC / NIST 800-171 | |
|---|---|---|---|---|
| Legal basis | FISMA & OMB policyExecutive branch | DoD Cloud Computing SRGDoD instruction | 22 CFR 120–130Federal regulation | DFARS 252.204-7012 / -7019 / -7020 / -7021 & 32 CFR 170CUI + assessment + CMMC clauses |
| Agency | GSA · FedRAMP PMO | DISA | State Dept · DDTC | DoD CIO · OUSD(A&S) |
| What it protects | Federal government data on commercial cloud | DoD-specific sensitive data, tiered by impact | Defense articles and technical data (US Munitions List) | Contractor systems that handle CUI data |
| Tiers / levels | Low · Moderate · High | IL2 · IL4 · IL5 · IL6 | None. You meet it or you don't | CMMC Level 1 · 2 · 3 |
| How you get it | 3PAO assessment → agency ATOMonths to years · expensive | DISA Provisional Authorization, usually inherits FedRAMPMonths · heavy paperwork | DDTC registration + export-controls programSelf-attested · audited if challenged | Self-attestation (L1) · C3PAO assessment (L2) · DoD assessment (L3)Phase 1 enforcement began Nov 2025 · C3PAO L2 mandatory Nov 2026 |
| US persons required? | Varies by ATO | Yes. IL4+ | Yes. Strict | Contract-dependent (usually yes) |
| Data residency | US (Moderate/High) | US | US (strict) | US (typical) |
| Rated subject | The cloud provider | Provider + workload | The handling organization | The contractor's systems |
| Who pays | Cloud vendor | Mostly the cloud vendor | The data handler | The contractor |
| Common mistake | Assuming “Moderate” covers DoD workloads. It doesn't. | Thinking IL5 subsumes ITAR. It doesn't. | Treating ITAR as “just IL5 plus.” It isn't. | Confusing the CMMC regime with the CUI label it protects. |
Not legal advice. Consult counsel for specifics.