CMMC & DoD Compliance
Clear the Confusion: CMMC Level 2 vs. DoD IL4/IL5 for Contractor Information Systems
Data classification decides what you protect. Architecture and purpose decide where it must live.
For Department of Defense (DoD) contractors navigating the regulatory landscape, few topics spark as much confusion as the interplay between CMMC Level 2 and the DoD Cloud Computing Security Requirements Guide (SRG) Impact Levels (IL4/IL5).
A common scenario that brings this confusion to light is a contractor-operated time collection system. Consider an environment where personnel working on various military projects enter the hours they work on a project. The same question comes up for nearly every business system a defense contractor runs: ERP and accounting platforms, engineering file shares, product lifecycle management (PLM) tools, email and collaboration suites, and help desk ticketing systems.
Does a system like this require compliance with CMMC Level 2? Does it need to live in a DoD IL4 or IL5 cloud environment?
The question is more urgent than ever. Since the DFARS CMMC final rule took effect on November 10, 2025, contracting officers have been inserting DFARS 252.204-7021 into new solicitations, and starting with Phase 2 on November 10, 2026, third-party Level 2 certification assessments can become a condition of award. Scoping a system wrong now means either overspending on infrastructure you don't need or walking into an assessment with a boundary that won't hold.
The blueprint below outlines the precise barometer used to determine which standards apply to your information systems.
The Fundamental Barometer: Data vs. Architecture
To decipher which compliance path applies to an information system, look at two primary lenses: what the data is (Data Classification) and where the data lives (System Architecture).
Contractor systems
CMMC Level 2 (NIST SP 800-171)
This framework applies directly to non-federal information systems. These are internal corporate networks, tools, and contractor-managed environments that collect, process, store, or transmit Controlled Unclassified Information (CUI).
Contract trigger
DFARS 252.204-7012 and 252.204-7021
Validated by
Self-assessment or C3PAO certification, recorded in SPRS
Cloud service providers
DoD Impact Levels (IL4 / IL5)
These levels apply specifically to Cloud Service Provider (CSP) environments hosting DoD workloads. IL4 handles standard CUI and export-controlled data (such as ITAR), while IL5 addresses higher-sensitivity CUI, unclassified National Security Systems (NSS), and mission-essential workloads.
Governing document
DoD Cloud Computing SRG
Validated by
DISA Provisional Authorization (PA)
The key insight: these are not competing frameworks. CMMC asks "Is the contractor protecting CUI?" The Cloud SRG asks "Is this cloud fit to host a DoD mission system?" A single system can answer to one, both, or neither.
Evaluating the Use Case: The 3-Step Compliance Test
To accurately scope any contractor-operated system, run it through the following three evaluative steps. We use the timekeeping system as the running example, with other common systems alongside it.
Compliance Mapping Matrix
The same test applies to any system in your environment, not just timekeeping. Find the row that describes the system, check the examples, and apply every row that matches.
System holds only Federal Contract Information (FCI), with no CUI.
CMMC Level 1
System processes or stores CUI on contractor-managed infrastructure.
CMMC Level 2
A CUI system is hosted in a commercial cloud or delivered as SaaS.
DFARS 252.204‑7012 / FedRAMP
A contractor operates the system, but it is built for direct use by DoD personnel.
DoD Cloud SRG IL4
A government-facing system handles higher-sensitivity CUI, mission-critical data, or unclassified National Security Systems (NSS) information.
DoD Cloud SRG IL5
Rows stack. A cloud-hosted system containing CUI, for example, must satisfy both the CMMC Level 2 row and the DFARS 252.204-7012 cloud row.
How DFARS 252.204-7012, 7021, and 7025 Fit Together
Much of the confusion around CMMC and Impact Levels comes from treating the DFARS clauses as interchangeable. They aren't. Each one does a distinct job, and your contract may carry all three.
252.204-7012
Safeguarding & incident reporting
Requires NIST SP 800-171 for covered defense information, 72-hour cyber incident reporting to DoD, and FedRAMP Moderate (or equivalent) for any cloud that stores CUI.
252.204-7021
The CMMC contract clause
Requires you to hold and maintain the specified CMMC status for every system that handles FCI or CUI, flow it down to subcontractors, and affirm continuous compliance in SPRS annually.
252.204-7025
The solicitation notice
Tells offerors which CMMC level the contract requires and makes having that status in SPRS a condition of award eligibility.
In short: 7012 tells you how to protect CUI, 7021 requires you to prove it, and 7025 makes that proof a prerequisite for winning the work. None of them, on their own, require a DoD IL4/IL5 environment for an internal contractor system.
The CMMC Rollout Clock
Don't confuse "more secure" with "required"
Hosting an internal contractor tool in an IL4/IL5 environment is never wrong, but it's rarely mandatory. What is mandatory is a clearly drawn CMMC assessment boundary, a cloud provider that meets the DFARS 7012 FedRAMP requirement, and documentation that shows which controls you inherit from that provider. That's where most contractors either win or lose their assessment.
Simplifying the Shared Responsibility Model
Achieving CMMC Level 2 or preparing an environment for DoD IL4/IL5 review requires significant administrative and technical overhead. Organizations can optimize this workflow by utilizing Secure Cloud Enclaves to isolate compliant workloads.
By deploying business systems such as timekeeping, ERP, engineering collaboration, or ticketing tools inside a pre-configured, hardened cloud boundary, contractors can inherit 300+ NIST SP 800-53 security controls from the underlying FedRAMP High platform, documented in a customer responsibility matrix your assessor can review. This narrows your assessment scope strictly to the application layer, reducing deployment times and simplifying your path to audit readiness.
The fastest path to CMMC Level 2 isn't implementing 110 controls from scratch. It's drawing a tight boundary around your CUI and building it on FedRAMP certified cloud infrastructure and platform that already carries most of the weight.
How GovDataHosting Helps Defense Contractors Get It Right
GovDataHosting, a division of IT-CNP, Inc., has hosted secure systems for federal agencies and the contractors who serve them for more than 25 years. Our FedRAMP Certified Class D (High) platform and fully managed IL4/IL5-capable cloud options let you match your hosting to the outcome of the 3-step test — without paying for more than your contract requires.
FedRAMP certified cloud foundation at the High baseline, which exceeds the DFARS 252.204-7012 FedRAMP Moderate requirement for cloud-hosted CUI.
DISA STIG hardening by default on every customer Windows and Linux server and container, validated by scanning and audited annually by a 3PAO.
Bundled compliance services — continuous monitoring, vulnerability and compliance scanning, incident response support, and assessment coordination — through our Fully Managed Platform.
U.S. cloud data centers and U.S. citizen support staff only, for ITAR- and CUI-sensitive workloads.
Simple procurement through major contract vehicles, including GSA MAS and DoD ACCENT.
Whichever row of the matrix your system lands on, there's a matching platform:
Internal CUI tools
GovDataHosting Cloud Platform
FedRAMP Class D (High) PaaS with 300+ inherited controls and fixed monthly pricing.
IL4 / IL5 workloads
Managed AWS GovCloud
FedRAMP High, IL4/IL5-authorized infrastructure, fully managed by our compliance team.
Microsoft-centric DoD systems
Managed Azure Government
FedRAMP High and DoD IL5 Microsoft cloud for government-facing workloads.
Building a custom application, such as a program portal, an engineering data system, or a timekeeping tool? Our Custom App Hosting service puts it inside a compliant boundary from day one. Small businesses can also take advantage of our fast-track compliance packages built for teams without dedicated security staff. Not sure which platform fits? Compare all three side by side.
Frequently Asked Questions
Does CMMC Level 2 require a DoD IL4 or IL5 cloud?
No. CMMC Level 2 governs contractor-owned systems that handle CUI. If those systems run in the cloud, DFARS 252.204-7012 requires a cloud provider that meets the FedRAMP Moderate baseline or its equivalent. IL4/IL5 Provisional Authorization is required when the system is built for direct use by DoD personnel as a government system.
What does DFARS 252.204-7021 require?
DFARS 252.204-7021 is the CMMC contract clause. It requires contractors to hold and maintain the CMMC status specified in the contract for every information system that processes, stores, or transmits FCI or CUI, flow the requirement to subcontractors, and submit annual affirmations of continuous compliance in SPRS.
When do third-party CMMC Level 2 certifications become required?
Under Phase 2 of the CMMC rollout, effective November 10, 2026, DoD can require a CMMC Level 2 certification assessment by an authorized C3PAO as a condition of award for applicable contracts.
How do I know if a business system contains CUI?
Administrative contract data such as hours, invoices, and contract numbers is generally Federal Contract Information (FCI). A system holds CUI when users enter sensitive program content into it: technical task notes in timesheets, export-controlled part data in ERP or PLM records, or system configuration and vulnerability details in help desk tickets. Check the CUI markings and DD Form 254 or contract guidance from your contracting officer when in doubt.
CMMC Level 2 certification is a condition of award
Scope It Right. Host It Right. Pass the First Time.
Tell us about your system and contract requirements. We'll map your CUI boundary, identify which DFARS clauses apply, and recommend the right-sized CMMC, FedRAMP or IL4/IL5 environment.
Or call us directly for a quick consultation: 800-967-1004
This article is for general informational purposes and does not constitute legal advice. CMMC level, assessment type, and cloud requirements are set by each contract's DFARS clauses and your contracting officer. More insights on the GovDataHosting blog.