---
title: "Frameworks · Consus"
description: "A plain-English guide to FedRAMP, DoD Impact Levels, and ITAR, the three compliance frameworks defense cloud customers confuse, plus the CUI label that sits across them."
canonical: https://consus.io/frameworks
---

Defense Cloud Compliance Frameworks

# Three Regimes  
_Three Axes_

A plain-English guide to **FedRAMP**, **DoD Impact Level**, and **ITAR**. The three compliance frameworks defense cloud customers keep confusing for each other, plus the **CUI** label that sits across all of them.

The mental model in one paragraph

Imagine a nightclub. _FedRAMP_ is the health inspector's certificate on the wall. The government won't enter a building without it. _DoD Impact Level_ is the velvet-rope system inside. Different VIP rooms for different levels of sensitive conversation. _ITAR_ is the bouncer at the door checking passports. Some rooms only US persons can enter, no matter what level. And _CUI_ is a label stamped on the documents people bring in. It tells everyone which rooms those documents are allowed in.

Section 01 · The cast of characters

## Four things that _are not the same_

FedRAMP

Federal cloud authorization

“Is this cloud safe enough for a federal agency to use at all?”

Who runs it

GSA / FedRAMP PMO

Applies to

Any cloud service selling to federal agencies

Levels

Low · Moderate · High

What's being rated

The cloud provider itself

DoD Impact Level

Dept. of Defense cloud only

“How sensitive is the military data we're putting on this cloud?”

Who runs it

DISA (DoD)

Applies to

DoD workloads on commercial cloud

Levels

IL2 · IL4 · IL5 · IL6

What's being rated

The cloud plus the data sensitivity

ITAR

Export control · State Dept

“Can a non-American legally be allowed to see this?”

Who runs it

DDTC (State Dept)

Applies to

Defense articles and technical data (USML)

Levels

None. You either handle it or you don't

What's being rated

Your people, processes, and physical/logical access

CUI

A data label, not a regime

“This document is sensitive but not classified. Protect it accordingly.”

Who owns the label

NARA CUI Program

What it actually is

A classification marker stamped on sensitive-but-unclassified data

Levels

None. Data is either CUI or it isn't

Governs how?

Via CMMC / NIST 800-171 for contractors (see column four)

Section 02 · The right mental picture

## Compliance is an _axis_, not a single line

DoD sensitivity →

IL2 IL4 IL5 IL6 Non-ITAR ITAR

**Public agency website**Low sensitivity, no export control. Plain FedRAMP Moderate covers it.

**Defense program mgmt data**Mission-critical CUI on a DoD system, but not on the USML. IL5, no ITAR needed.

**Commercial aerospace tech**USML-controlled but no DoD contract. ITAR applies. DoD IL does not.

**Spacecraft data on DoD contract**Both worlds. IL5 _and_ ITAR required, stacked.

Export control →

### Any given workload sits at a _point_ on this plane, not at a rank on a single ladder.

The vertical axis is DoD's framework (data sensitivity). The horizontal axis is the State Department's framework (export control). **A workload can be high on one and low on the other**, or high on both, or low on both.

This is why saying "IL5 is higher than ITAR" is a category error. It's like asking whether a driver's license is higher than a passport.

Section 03 · The actual differences

## Side by side, _in one table_

|  | FedRAMP | DoD IL | ITAR | CMMC / NIST 800-171 |
| --- | --- | --- | --- | --- |
| Legal basis | FISMA & OMB policy_Executive branch_ | DoD Cloud Computing SRG_DoD instruction_ | 22 CFR 120–130_Federal regulation_ | DFARS 252.204-7012 / -7019 / -7020 / -7021 & 32 CFR 170_CUI + assessment + CMMC clauses_ |
| Agency | GSA · FedRAMP PMO | DISA | State Dept · DDTC | DoD CIO · OUSD(A&S) |
| What it protects | Federal government data on commercial cloud | DoD-specific sensitive data, tiered by impact | Defense articles and technical data (US Munitions List) | Contractor systems that handle CUI data |
| Tiers / levels | Low · Moderate · High | IL2 · IL4 · IL5 · IL6 | None. You meet it or you don't | CMMC Level 1 · 2 · 3 |
| How you get it | 3PAO assessment → agency ATO_Months to years · expensive_ | DISA Provisional Authorization, usually inherits FedRAMP_Months · heavy paperwork_ | DDTC registration + export-controls program_Self-attested · audited if challenged_ | Self-attestation (L1) · C3PAO assessment (L2) · DoD assessment (L3)_Phase 1 enforcement began Nov 2025 · C3PAO L2 mandatory Nov 2026_ |
| US persons required? | Varies by ATO | Yes. IL4+ | Yes. Strict | Contract-dependent (usually yes) |
| Data residency | US (Moderate/High) | US | US (strict) | US (typical) |
| Rated subject | The cloud provider | Provider + workload | The handling organization | The contractor's systems |
| Who pays | Cloud vendor | Mostly the cloud vendor | The data handler | The contractor |
| Common mistake | Assuming “Moderate” covers DoD workloads. It doesn't. | Thinking IL5 subsumes ITAR. It doesn't. | Treating ITAR as “just IL5 plus.” It isn't. | Confusing the CMMC regime with the CUI label it protects. |

Section 04 · Which one do you actually need?

## Real scenarios, _matched to the right regime_

01

Commercial satellite company designing a new bus.

No DoD contract. Spacecraft engineering data is on the USML.

ITAR No DoD IL required

Pure export-control problem. ITAR Assured Workloads is the right home. IL5 is overkill and doesn't apply.

02

DoD contractor handling personnel records for a base.

Sensitive CUI. Not technical, not export-controlled.

DoD IL4 or IL5 CMMC L2

DoD CUI without ITAR. Needs IL-authorized cloud plus CMMC L2 on the contractor's side. ITAR isn't involved.

03

Prime contractor on a DoD spacecraft program.

Technical data that is both USML-controlled and DoD CUI.

DoD IL5 ITAR CMMC L2

The full stack. Both regimes apply simultaneously plus CMMC on the contractor's posture. This is where most prime-contractor workloads land.

04

Federal agency wanting to use a new SaaS tool.

Not DoD. Standard civilian agency use case.

FedRAMP Moderate

Plain civilian cloud authorization. No DoD IL, no ITAR, no CUI label unless the specific workload introduces one.

05

Startup selling to aerospace primes but no contract yet.

Pre-sales demos. No regulated data exchanged yet, but it's coming.

CMMC L2 (readiness) ITAR (readiness)

Primes flow down DFARS clauses when contracts land. Stand up CMMC and ITAR posture now. Working backwards from a signed deal is painful. FedRAMP isn't relevant here; that's for selling to federal agencies directly.

06

Intelligence community workload with classified elements.

Above CUI. Actually classified.

IL6

IL6 is for classified up to SECRET on dedicated infrastructure. Totally different operating model. Not a casual add-on.

Section 05 · Things people keep getting wrong

## Compliance myths, _busted_

“IL5 is higher than ITAR, so IL5 includes ITAR.”

Actually

Two agencies, two regulations, two separate authorizations. **IL5 gives you no ITAR cover, and ITAR compliance doesn't satisfy any DoD IL.** They're orthogonal axes from DoD and the State Department respectively.

“FedRAMP High is basically IL5.”

Actually

FedRAMP High is a **prerequisite** for IL5, not a substitute. DoD inherits from FedRAMP and layers its own requirements on top (personnel, US-only, specific encryption, DISA PA).

“CUI is just another DoD impact level.”

Actually

CUI is a **label on data**, created by a NARA program for the whole government, not just DoD. The _regime_ that governs how contractors handle CUI is **CMMC / NIST 800-171**. A separate thing from the label itself, and separate again from the cloud tier the data lives on.

Appendix · Acronym decoder

## Helpful acronyms

3PAO

Third-Party Assessment Organization. The FedRAMP-accredited auditor that assesses a cloud against FedRAMP controls.

ATO

Authority to Operate. The paper that says “yes, you can run this system.”

C3PAO

Certified Third-Party Assessor Organization. The auditor that assesses CMMC compliance.

CC SRG

DoD Cloud Computing Security Requirements Guide. Defines the IL tiers.

CMMC

Cybersecurity Maturity Model Certification. DoD's framework for contractor CUI handling.

CUI

Controlled Unclassified Information. Sensitive but not classified.

DDTC

Directorate of Defense Trade Controls. The State Department office that runs ITAR.

DFARS

Defense Federal Acquisition Regulation Supplement. DoD's contract clauses. -7012 is the CUI safeguarding clause; -7019 and -7020 cover NIST 800-171 self-assessment and SPRS reporting; -7021 is the CMMC certification clause.

DISA

Defense Information Systems Agency. Grants IL provisional authorizations.

FedRAMP

Federal Risk and Authorization Management Program. The government-wide cloud authorization program. DoD inherits from FedRAMP and layers IL requirements on top.

FISMA

Federal Information Security Modernization Act. The statute that gives FedRAMP its legal teeth.

IL

Impact Level. DoD's data-sensitivity scale for cloud hosting (2, 4, 5, 6).

ITAR

International Traffic in Arms Regulations. Export control on defense articles and technical data.

JAB

Joint Authorization Board. The legacy top-tier FedRAMP authorizer. Sunset in 2024. The current path is agency ATO only.

NARA

National Archives and Records Administration. Runs the government-wide CUI program that defines the label.

NIST 800-171

The control framework for protecting CUI on non-federal systems. 110 controls.

PA

Provisional Authorization. DISA's stamp that a cloud can host a given IL.

SRG

Security Requirements Guide. DoD's document defining IL tiers.

USML

United States Munitions List. The catalog of items that are export-controlled under ITAR.

Not legal advice. Consult counsel for specifics.
