StateRAMP / GovRAMP & DoD Cloud Impact Levels
Two government cloud authorization regimes that sit alongside FedRAMP — one for state/local government, one for defense. Both reuse FedRAMP’s NIST 800-53 foundation, so building to FedRAMP positions you for both.
Disclaimer. Not legal/compliance advice. Verified 2026-05-29.
StateRAMP (now “GovRAMP”)
What it is
The state and local government analog of FedRAMP. A non-profit program that verifies cloud providers against a FedRAMP-based control baseline so states, counties, cities, and education can buy cloud with a consistent security bar. StateRAMP rebranded to “GovRAMP” in 2025 to reflect expansion beyond states.
Who it applies to
Cloud providers selling to participating state/local governments use this program. The key mechanics:
- Uses NIST 800-53-based Low / Moderate / High baselines, mirroring FedRAMP.
- Honors FedRAMP reciprocity — an existing FedRAMP authorization can be converted or recognized, so you don’t start over.
- Verified by a 3PAO, listed on the program’s authorized-product list.
Builder takeaway: if you’re already building to the FedRAMP baseline, StateRAMP/GovRAMP is largely a packaging and submission exercise.
DoD Cloud Computing Impact Levels (IL2–IL6)
What it is
The Department of Defense’s overlay (per the DoD Cloud Computing SRG — Security Requirements Guide) layering additional controls on top of FedRAMP for defense workloads. Levels are by data sensitivity:
| Level | Data | Baseline |
|---|---|---|
| IL2 | Public / non-critical unclassified | ≈ FedRAMP Moderate |
| IL4 | CUI / non-critical mission data | FedRAMP Moderate + DoD controls |
| IL5 | Higher-sensitivity CUI & National Security Systems (unclassified) | FedRAMP High / IL4 + stricter separation |
| IL6 | Classified up to SECRET | FedRAMP High + controls, on SIPRNet |
(IL1 and IL3 are no longer used.)
Who it applies to
Cloud providers and workloads serving the DoD. Requires a DoD Provisional Authorization (PA) from DISA, on top of FedRAMP.
Builder takeaway: FedRAMP High is the prerequisite for IL5/IL6. Building to High keeps the DoD path open; the IL overlays add separation, US-person, and facility requirements beyond software.
Related resources
- FedRAMP — the foundation both regimes reuse
- NIST 800-171 & CMMC — the contractor-side CUI program (different from cloud ILs)
- Security Overview & decision guide
Sources (verified 2026-05-29)
| Claim | Source |
|---|---|
| StateRAMP/GovRAMP program & FedRAMP reciprocity; 2025 rebrand | GovRAMP (formerly StateRAMP) |
| DoD Cloud Computing SRG & Impact Levels IL2–IL6 | DoD Cloud Computing SRG (DISA) |