FedRAMP impact levels compared: tiered cloud architecture for IL2, IL4, and IL5

A defense-technology founder opens her project tracker on a Wednesday morning. Her Phase 2 Small Business Innovation Research (SBIR) contract has 13 months left on the clock; she has spent 4 already on infrastructure decisions. The latest update from her authorization consultant sets the Authority to Operate (ATO) target six months out. Her program office liaison emailed yesterday asking if the application can be in user acceptance testing by month nine.

The math does not work. Six months of authorization work plus three months of integration leaves zero buffer for anything the auditor flags. She is going to miss either the technical milestone or the compliance gate, and either outcome puts the contract at risk.

This is the federal authorization timeline reality for small defense contractors. The Federal Risk and Authorization Management Program (FedRAMP) and the Department of Defense (DoD) both sort workloads by sensitivity, and FedRAMP impact levels and DoD Impact Levels (ILs) were designed for stable enterprise software with multi-year procurement cycles, not for SBIR awards trying to deliver a working capability in 12 months. Misjudging the path costs months. The teams that finish on time understand what FedRAMP, the National Institute of Standards and Technology Special Publication 800-53 (NIST 800-53) Revision 5, and the Impact Level ladder actually require, and they make architecture decisions accordingly on day one.

What you’ll learn: The concrete differences between FedRAMP, NIST 800-53, and DoD Impact Levels, which Impact Level applies to most SBIR and defense contract work, and the five architecture mistakes that add three to six months each to a small defense contractor’s authorization timeline.

FedRAMP Impact Levels, NIST 800-53, and DoD Impact Levels: What Is the Difference?

FedRAMP is a federal program that authorizes Cloud Service Providers (CSPs) to handle government data. It does not write the controls; it relies on NIST 800-53. What FedRAMP adds is the authorization process: a formal package with a System Security Plan (SSP), a Plan of Action and Milestones (POA&M), evidence of control implementation, and an Authorizing Official’s review. A FedRAMP-authorized CSP at a given Impact Level can be inherited by any federal customer at or below that level.

NIST 800-53 Rev 5 is the security and privacy control catalog. It defines hundreds of controls grouped into 20 families: Access Control, Audit and Accountability, Configuration Management, Incident Response, and so on. Each control has implementation guidance and selectable enhancements. NIST 800-53 is not specific to FedRAMP; it underpins almost every federal control framework, including DoD authorizations.

Impact Levels are the DoD framework for classifying workload sensitivity. IL2 is for non-controlled, low-sensitivity public information. IL4 is for Controlled Unclassified Information (CUI), which covers most defense contract work. IL5 is for unclassified National Security Systems (NSS) data, and since 2025 that NSS character, rather than sensitivity alone, is what places a workload there. IL6 is for classified information up to Secret. Each level requires more controls, more evidence, more isolation, and more time.

Why Does This Matter for Small Defense Contractors?

Most large defense primes already operate at one of the FedRAMP impact levels somewhere in their tech stack. They can inherit it, add an application-specific control set, and authorize the application in months. Small defense contractors and SBIR awardees usually do not. They start with no inheritable infrastructure and discover, halfway through their contract, that authorizing a workload from scratch is a 12-to-18 month project.

The contract structure makes this worse. DoD SBIR Phase 2 contracts run up to 24 months, with the Army typically at 12 to 18 months and the Navy and Air Force toward the longer end. Delivery targets land in the back half of the period of performance. SBIR Phase 3 transition timelines are even tighter. There is no slack for a multi-year authorization process, and there is no provision in the budget for one. The teams that miss this are not bad engineers; they are good engineers who chose the wrong starting point.

The fix is not faster paperwork. It is starting inside one of the FedRAMP impact levels that already matches your data, so the team inherits most of the controls and owns only the application-specific layer.

How Do FedRAMP Impact Levels Map to the IL2, IL4, and IL5 Ladder?

Choosing among the FedRAMP impact levels is the single most consequential architecture decision in a defense workload. Choose too low and the program office tells you to migrate after you have already deployed. Choose too high and you spend money on isolation and controls you do not need.

FedRAMP impact levels mapped to the DoD ladder: IL2, IL4, IL5 and IL6 with baselines, control counts and tenant separation
IL5 was rescoped around National Security Systems in July 2025. Most guidance still shows the old definition.

IL2 covers public, low-sensitivity data: marketing material, public-facing dashboards, training content, and other information that the government would publish if asked. Workloads run on standard commercial cloud regions with FedRAMP Moderate baselines. Authorization is the fastest and lowest cost of any Impact Level. If your application processes any data the government would not put on its public website, you do not belong at IL2.

IL4 is the right home for the majority of defense contract workloads. It covers CUI, which the government defines broadly: contract performance data, design documents, technical drawings, mission planning information, certain personnel data, and most of what an SBIR application processes in practice. IL4 workloads run in dedicated US-based regions with stricter access controls, Federal Information Processing Standards (FIPS)-validated cryptography, and DoD-specific monitoring. Authorization takes meaningful time, but the inheritance opportunity is real.

IL5 changed materially in 2025, and this is the part most guidance still gets wrong. Revision 3 of the Cloud Service Provider Security Requirements Guide (CSP SRG), published on 2 July 2025, retitled IL5 around unclassified National Security Systems (NSS) and National Security Information.

The guide has revised several times since, reaching V1R7 on 30 June 2026, and the IL5 scoping has held throughout. Check the DoD Cloud Computing Security document library for the revision in force when you read this, because this document moves faster than most compliance guidance. IL5 is now scoped to nonpublic unclassified NSS data: intelligence activities, command and control of military forces, weapons systems, and other functions critical to military or intelligence missions. CUI can still be hosted at IL5, but only where an Authorizing Official determines it needs protection beyond IL4. The practical effect is that CUI-only workloads belong at IL4, not IL5.

The control burden moved with it. IL5 now stacks roughly 600 controls: the 410 of the FedRAMP High baseline, about 20 from the DoD CC SRG itself, and about 170 NSS controls drawn from Committee on National Security Systems Instruction (CNSSI) 1253. That is roughly a 40 percent increase over the previous IL5 requirement. Older material still describes these overlays with the shorthand “FedRAMP+”, which understates them: whatever the label, the NSS control set is what drives the IL5 cost and timeline, so size the work from the control count rather than from the name.

The separation rule is unchanged and remains specific: virtual or logical separation between DoD and federal government tenants is sufficient, but physical separation from public, commercial, and state or local government tenants is required. In practice this narrows your cloud-region options substantially. If your customer says “this is IL5,” check whether the workload is genuinely NSS before accepting the label, because the cost difference between a correct IL4 scope and an unnecessary IL5 scope is very large.

IL6 handles classified information up to Secret. It runs in entirely separate networks, requires cleared personnel, and is outside the scope of most SBIR contract work. If you are reading this and wondering whether you need IL6, the answer is almost certainly no; if you do, your contract paperwork will tell you in unambiguous language.

What Are the Five Mistakes That Add Months to Your Authorization Timeline?

The same five missteps appear over and over when a small defense contractor approaches FedRAMP impact levels and DoD authorization for the first time. Each one feels reasonable in the moment; each one adds three to six months to the schedule.

1. Under-specifying the Impact Level to move fast. Teams pick IL2 because the environment is lower cost and faster to stand up, then discover at month six that the data they are processing is CUI. The remediation involves a full migration to a higher-IL region, redoing every Identity and Access Management (IAM) policy, and starting the inheritance process from scratch. Cost: typically $200,000 and three to six months. If there is any chance your data is CUI, scope to IL4 from day one.

2. Building the application before authorizing the environment. The team writes code in a non-compliant developer cloud account because it is easier, planning to migrate later. The migration becomes its own project: every secret rotated, every dependency revalidated, every architectural decision re-examined under the compliance lens. The team that authorizes the environment first builds in the boundary from day one and avoids the migration entirely.

3. Choosing a “FedRAMP-ready” partner instead of a FedRAMP-authorized one. FedRAMP-ready means the partner has done preparation work but does not yet have an authorization an Authorizing Official will accept. By the time the partner gets fully authorized, your contract clock has run out. Confirm the authorization status, the level, and the agency sponsor in writing before signing anything.

4. Treating inheritance as a paperwork exercise. Real inheritance is operational. The platform owner runs the controls, monitors them continuously, and produces evidence on demand. A landing zone partner who hands you a Letter of Attestation and disappears is not really offering inheritance; they are selling you marketing. Ask for the platform’s SSP excerpt, current continuous monitoring reports, and an introduction to the Authorizing Official who signed the platform’s package.

5. Underestimating the application-specific control burden. Even with strong inheritance, your application owns roughly 50 to 100 application-specific controls. Identity provisioning, role-based access for application users, application logs, configuration baselines for your service, customer notification procedures, and incident response specific to your workload. Many teams discover this control set late and scramble to document it; the teams that get authorized on time have it scoped from week one.

What Does the Inheritance Opportunity Look Like Concretely?

NIST 800-53 Rev 5 includes roughly 1,200 controls and enhancements across its full catalog, but only a subset apply at any given baseline. FedRAMP impact levels set that subset: the Rev 5 Moderate baseline carries 323 controls and the High baseline carries 410. IL4 now builds on either the Moderate or the High baseline with DoD adjustments applied, landing near 344 or 428 controls depending on which you start from; IL5 builds on FedRAMP High and adds the CNSSI 1253 NSS overlay on top.

A FedRAMP-authorized landing zone can inherit between 70 and 85 percent of those baseline controls depending on the platform’s scope, leaving your application team owning roughly 50 to 100 application-specific controls, the majority of which are configuration choices specific to your service.

FedRAMP impact levels inheritance split showing 70 to 85 percent of baseline controls inherited from the platform and 50 to 100 owned by the application
The controls you inherit are the ones you do not have to build, document, or monitor yourself.

The math is the difference between a cold-start authorization of 12 to 18 months and roughly 90 days to authorized operations inside an environment that is already authorized. A team starting with no inheritable infrastructure is building a full-baseline compliance program from zero. A team owning 50 to 100 application-specific controls inside a known boundary is doing focused work on a finite list. The first team rarely makes its delivery date; the second team usually does.

If you want a deeper architectural treatment of how inheritance works in practice, our Mission App Builder Guide walks through the inheritance map, the boundary documentation, and the 90-day plan from contract award to authorized deployment. It pairs naturally with this framework discussion.

Where Do You Get the FedRAMP/NIST Readiness Checklist?

If you are evaluating FedRAMP impact levels, NIST 800-53, or DoD Impact Level decisions for the first time, we built a free FedRAMP/NIST Readiness Checklist focused on small defense contractors and SBIR teams. It covers the Impact Level decision tree, the control families you will own at each level, the inheritance documentation to require from any landing zone partner, and the most common findings that extend authorization timelines.

Each item is written for a founder, principal investigator, or technical lead, not a federal compliance specialist. You can work through it with your engineering team in an afternoon and emerge with a clear scope of what your team owns, what you need to inherit, and where the timeline pressure points sit.

Download the free FedRAMP/NIST Readiness Checklist

How Do You Price Each of the FedRAMP Impact Levels?

The right Impact Level depends on your workload, your customer, and your budget, and FedRAMP impact levels drive the cost of each path. Our free Cost Calculator includes scenarios for Impact Level 2, 4, and 5 so you can see the dollar trade-off between paths before you commit. Compare the status quo, a do-it-yourself transformation, and a managed Bridge subscription at each level, with the FedRAMP and NIST 800-53 control inheritance factored into the math.

Open the Cost Calculator

Key Takeaways

  • Of the FedRAMP impact levels, IL4 is the correct one for most SBIR and defense contract work; under-scoping to IL2 because it costs less and discovering the data is CUI at month five typically costs $200,000 and three to six months to remediate.
  • A FedRAMP-authorized landing zone can inherit 70 to 85 percent of the FedRAMP Moderate baseline’s approximately 323 controls, leaving the application team with roughly 50 to 100 application-specific controls; this is the difference between a 12-to-18 month cold-start authorization and roughly 90 days to authorized operations.
  • “FedRAMP-ready” and “FedRAMP-authorized” are not the same; inheriting from a FedRAMP-ready partner means the controls are not yet validated and no Authorizing Official will accept the inheritance.
  • IL5 was rescoped in 2025 around unclassified National Security Systems, and now stacks roughly 600 controls against IL4’s 344 to 428; CUI-only workloads belong at IL4, so confirm a workload is genuinely NSS before accepting an IL5 label.
  • IL5 requires physical separation from public, commercial, and state or local government tenants; the region selection, tenant-separation guarantee, and Authorizing Official evidence requirements are all materially different from IL4 from day one.

Next Steps

Authorization against the FedRAMP impact levels is achievable for small defense contractors, but only when the architecture decisions match the contract clock. The teams that hit their delivery dates start in an authorized environment, scope their application-specific controls early, and treat inheritance as the operational reality it is. The teams that miss their dates usually inherited the opposite assumption from a generalist cloud architect who never worked a federal authorization.

Pandora Cloud builds and operates compliant cloud landing zones at IL2, IL4, and IL5 for small defense contractors and SBIR teams. Our team comes from Amazon and government cloud architecture, and we run the inheritance documentation, the continuous monitoring, and the Authorizing Official engagement so your engineers can focus on the mission.

If you want to understand which of the FedRAMP impact levels fits your contract and what inheritance would look like for your application, let’s talk.