Skip to main content
CMMC Level 2 vs. DoD IL4/IL5: What Contractors Need to Know

CMMC Level 2 vs. DoD IL4/IL5: What Contractors Need to Know

CMMC Level 2 vs. DoD IL4/IL5: What Contractors Need to Know

CMMC & DoD Compliance

Clear the Confusion: CMMC Level 2 vs. DoD IL4/IL5 for Contractor Information Systems

CMMC Level 2
DoD IL4/IL5
DFARS 252.204-7012
DFARS 252.204-7021
NIST SP 800-171
The 3-step scoping test
Which framework applies to your contractor system?
Contractor system
 
 
Step 1 · Data
Stores or processes CUI?
YES
 
Step 2 · Hosting
Hosted in a cloud environment?
YES
 
Step 3 · Purpose
Built for direct use by DoD personnel?
YES
 
 
NO
 
 
NO
 
 
NO
 
 
 
 
 
FCI only
CMMC Level 1
No CUI in the system
15 FAR 52.204-21 safeguarding requirements. Annual self-assessment.
 
On-premises
CMMC Level 2
Your own servers
110 NIST SP 800-171 controls in scope. Self or C3PAO assessed.
 
Cloud-hosted
CMMC Level 2
+ FedRAMP cloud
CSP at FedRAMP Moderate or higher (or equivalent). DFARS 252.204-7012.
 
Government system
DoD IL4 / IL5
Used directly by DoD
DISA Provisional Authorization (PA) cloud plus DoD RMF ATO.
All CUI paths also carry DFARS 252.204-7021 (CMMC status) and 252.204-7012 (incident reporting).

Data classification decides what you protect. Architecture and purpose decide where it must live.

For Department of Defense (DoD) contractors navigating the regulatory landscape, few topics spark as much confusion as the interplay between CMMC Level 2 and the DoD Cloud Computing Security Requirements Guide (SRG) Impact Levels (IL4/IL5).

A common scenario that brings this confusion to light is a contractor-operated time collection system. Consider an environment where personnel working on various military projects enter the hours they work on a project. The same question comes up for nearly every business system a defense contractor runs: ERP and accounting platforms, engineering file shares, product lifecycle management (PLM) tools, email and collaboration suites, and help desk ticketing systems.

Does a system like this require compliance with CMMC Level 2? Does it need to live in a DoD IL4 or IL5 cloud environment?

The question is more urgent than ever. Since the DFARS CMMC final rule took effect on November 10, 2025, contracting officers have been inserting DFARS 252.204-7021 into new solicitations, and starting with Phase 2 on November 10, 2026, third-party Level 2 certification assessments can become a condition of award. Scoping a system wrong now means either overspending on infrastructure you don't need or walking into an assessment with a boundary that won't hold.

The blueprint below outlines the precise barometer used to determine which standards apply to your information systems.

110
NIST SP 800-171 controls in CMMC Level 2
C3PAO
Level 2 certification from Phase 2 onward
300+
Controls inherited on our FedRAMP High PaaS
25+
Years of federal hosting service

The Fundamental Barometer: Data vs. Architecture

To decipher which compliance path applies to an information system, look at two primary lenses: what the data is (Data Classification) and where the data lives (System Architecture).

Contractor systems

CMMC Level 2 (NIST SP 800-171)

This framework applies directly to non-federal information systems. These are internal corporate networks, tools, and contractor-managed environments that collect, process, store, or transmit Controlled Unclassified Information (CUI).

Contract trigger

DFARS 252.204-7012 and 252.204-7021

Validated by

Self-assessment or C3PAO certification, recorded in SPRS

Cloud service providers

DoD Impact Levels (IL4 / IL5)

These levels apply specifically to Cloud Service Provider (CSP) environments hosting DoD workloads. IL4 handles standard CUI and export-controlled data (such as ITAR), while IL5 addresses higher-sensitivity CUI, unclassified National Security Systems (NSS), and mission-essential workloads.

Governing document

DoD Cloud Computing SRG

Validated by

DISA Provisional Authorization (PA)

The key insight: these are not competing frameworks. CMMC asks "Is the contractor protecting CUI?" The Cloud SRG asks "Is this cloud fit to host a DoD mission system?" A single system can answer to one, both, or neither.

Evaluating the Use Case: The 3-Step Compliance Test

To accurately scope any contractor-operated system, run it through the following three evaluative steps. We use the timekeeping system as the running example, with other common systems alongside it.

Data Classification: Is It FCI or CUI?

Administrative contract data, such as raw hours, invoices, contract numbers, and points of contact, is generally treated as Federal Contract Information (FCI), which only triggers basic CMMC Level 1 hygiene. A system escalates into CUI territory when users put sensitive program content into it, often without anyone planning for it:

  • Timekeeping: employees type task notes containing Controlled Technical Information (CTI).

    Example: "Completed structural stress testing on the wing assembly of the XYZ drone."
  • Help desk and ticketing: tickets describe configuration details or vulnerabilities in systems supporting a DoD program.
  • ERP and PLM: bills of materials or part records carry export-controlled (ITAR/EAR) technical data.
  • Any system: it cross-references personnel data with unclassified project codes or contract numbers in a way that reveals operational defense capabilities.

The Verdict

If the system processes or stores CUI, whatever its business purpose, it must implement the 110 security controls of CMMC Level 2.

System Architecture: How Is the Software Hosted?

The hosting model dictates how DoD cloud requirements impact your posture.

CMMC L2 only

On-Premises Infrastructure

If you run the system on your own physical servers, such as an on-premises ERP or a file server in your facility, DoD IL4/IL5 cloud requirements do not apply directly to you. Your boundary simply must be validated against CMMC Level 2 controls.

CMMC L2 + FedRAMP

Third-Party SaaS or Cloud Hosting

If the system runs in a cloud environment or is consumed as SaaS, such as cloud email or a hosted project management tool, DFARS 252.204-7012 requires the underlying cloud service to meet the FedRAMP Moderate baseline (High exceeds it) or achieve FedRAMP Moderate Equivalency.

System Purpose: Internal Corporate Tool vs. Government Service

CMMC L2

Internal Tool

If the system supports your own business operations, such as accounting, billing, engineering, or IT support, you do not need a formal DoD Provisional Authorization (PA) for IL4/IL5. You simply need to satisfy CMMC Level 2.

IL4 / IL5 PA

Government-Facing Service

If your company was contracted to build and operate a system for active use by DoD personnel, such as a timekeeping app for DoD civilians or a training portal for service members, it becomes a government system. It must be hosted within an officially authorized DoD IL4 or IL5 cloud platform and will typically need its own authorization under the DoD Risk Management Framework (DoDI 8510.01).

Compliance Mapping Matrix

The same test applies to any system in your environment, not just timekeeping. Find the row that describes the system, check the examples, and apply every row that matches.

Scenario Evaluation
Governing Framework
Mandatory Action

System holds only Federal Contract Information (FCI), with no CUI.

Examples: time and attendance with raw hours, invoicing and billing, a CRM tracking contract numbers and points of contact.

CMMC Level 1

FAR 52.204‑21
Implement the 15 basic safeguarding requirements of FAR 52.204-21 and file an annual self-assessment affirmation in SPRS.

System processes or stores CUI on contractor-managed infrastructure.

Examples: engineering file shares holding technical drawings, PLM or ERP systems with export-controlled part data, project timesheets with technical task notes.

CMMC Level 2

NIST SP 800‑171 · DFARS 252.204‑7021
Implement all 110 NIST SP 800-171 controls; complete a self-assessment or C3PAO certification as your contract specifies.

A CUI system is hosted in a commercial cloud or delivered as SaaS.

Examples: cloud email and collaboration used for program files, a cloud-hosted ERP, SaaS project management or ticketing that stores technical data.

DFARS 252.204‑7012 / FedRAMP

Clause (b)(2)(ii)(D)
Host on a cloud service authorized at FedRAMP Moderate or higher, or one that meets FedRAMP Moderate Equivalency. CMMC Level 2 still applies to your side of the boundary.

A contractor operates the system, but it is built for direct use by DoD personnel.

Examples: a training LMS for service members, a logistics tracking portal for a program office, a timekeeping app used by DoD civilians.

DoD Cloud SRG IL4

Plus DoD RMF ATO
Host in a cloud holding an active DISA Provisional Authorization at IL4 or higher, and obtain an authorization to operate (ATO) for the system itself.

A government-facing system handles higher-sensitivity CUI, mission-critical data, or unclassified National Security Systems (NSS) information.

Examples: mission planning or readiness analytics, operational sustainment data for a weapon system, command-level reporting dashboards.

DoD Cloud SRG IL5

Plus DoD RMF ATO
Host in a cloud holding a DISA Provisional Authorization at IL5, with the physical and logical separation IL5 requires.

Rows stack. A cloud-hosted system containing CUI, for example, must satisfy both the CMMC Level 2 row and the DFARS 252.204-7012 cloud row.

How DFARS 252.204-7012, 7021, and 7025 Fit Together

Much of the confusion around CMMC and Impact Levels comes from treating the DFARS clauses as interchangeable. They aren't. Each one does a distinct job, and your contract may carry all three.

252.204-7012

Safeguarding & incident reporting

Requires NIST SP 800-171 for covered defense information, 72-hour cyber incident reporting to DoD, and FedRAMP Moderate (or equivalent) for any cloud that stores CUI.

252.204-7021

The CMMC contract clause

Requires you to hold and maintain the specified CMMC status for every system that handles FCI or CUI, flow it down to subcontractors, and affirm continuous compliance in SPRS annually.

252.204-7025

The solicitation notice

Tells offerors which CMMC level the contract requires and makes having that status in SPRS a condition of award eligibility.

In short: 7012 tells you how to protect CUI, 7021 requires you to prove it, and 7025 makes that proof a prerequisite for winning the work. None of them, on their own, require a DoD IL4/IL5 environment for an internal contractor system.

The CMMC Rollout Clock

 
November 10, 2025 — Phase 1
Level 1 and Level 2 self-assessments appear as conditions of award in applicable solicitations.
 
November 10, 2026 — Phase 2
DoD can require Level 2 certification assessments by an authorized C3PAO.
 
November 10, 2027 — Phase 3
Level 3 (DIBCAC) assessments are introduced for the most sensitive programs.
 
November 10, 2028 — Phase 4
Full implementation across all applicable solicitations, contracts, and option periods.

Don't confuse "more secure" with "required"

Hosting an internal contractor tool in an IL4/IL5 environment is never wrong, but it's rarely mandatory. What is mandatory is a clearly drawn CMMC assessment boundary, a cloud provider that meets the DFARS 7012 FedRAMP requirement, and documentation that shows which controls you inherit from that provider. That's where most contractors either win or lose their assessment.

Simplifying the Shared Responsibility Model

Achieving CMMC Level 2 or preparing an environment for DoD IL4/IL5 review requires significant administrative and technical overhead. Organizations can optimize this workflow by utilizing Secure Cloud Enclaves to isolate compliant workloads.

By deploying business systems such as timekeeping, ERP, engineering collaboration, or ticketing tools inside a pre-configured, hardened cloud boundary, contractors can inherit 300+ NIST SP 800-53 security controls from the underlying FedRAMP High platform, documented in a customer responsibility matrix your assessor can review. This narrows your assessment scope strictly to the application layer, reducing deployment times and simplifying your path to audit readiness.

The fastest path to CMMC Level 2 isn't implementing 110 controls from scratch. It's drawing a tight boundary around your CUI and building it on FedRAMP certified cloud infrastructure and platform that already carries most of the weight.

GovDataHosting Compliance Team

How GovDataHosting Helps Defense Contractors Get It Right

GovDataHosting, a division of IT-CNP, Inc., has hosted secure systems for federal agencies and the contractors who serve them for more than 25 years. Our FedRAMP Certified Class D (High) platform and fully managed IL4/IL5-capable cloud options let you match your hosting to the outcome of the 3-step test — without paying for more than your contract requires.

✓

FedRAMP certified cloud foundation at the High baseline, which exceeds the DFARS 252.204-7012 FedRAMP Moderate requirement for cloud-hosted CUI.

✓

DISA STIG hardening by default on every customer Windows and Linux server and container, validated by scanning and audited annually by a 3PAO.

✓

Bundled compliance services — continuous monitoring, vulnerability and compliance scanning, incident response support, and assessment coordination — through our Fully Managed Platform.

✓

U.S. cloud data centers and U.S. citizen support staff only, for ITAR- and CUI-sensitive workloads.

✓

Simple procurement through major contract vehicles, including GSA MAS and DoD ACCENT.

Whichever row of the matrix your system lands on, there's a matching platform:

Internal CUI tools

GovDataHosting Cloud Platform

FedRAMP Class D (High) PaaS with 300+ inherited controls and fixed monthly pricing.

Explore platform

IL4 / IL5 workloads

Managed AWS GovCloud

FedRAMP High, IL4/IL5-authorized infrastructure, fully managed by our compliance team.

Explore AWS GovCloud

Microsoft-centric DoD systems

Managed Azure Government

FedRAMP High and DoD IL5 Microsoft cloud for government-facing workloads.

Explore Azure Government

Building a custom application, such as a program portal, an engineering data system, or a timekeeping tool? Our Custom App Hosting service puts it inside a compliant boundary from day one. Small businesses can also take advantage of our fast-track compliance packages built for teams without dedicated security staff. Not sure which platform fits? Compare all three side by side.

Frequently Asked Questions

Does CMMC Level 2 require a DoD IL4 or IL5 cloud?

No. CMMC Level 2 governs contractor-owned systems that handle CUI. If those systems run in the cloud, DFARS 252.204-7012 requires a cloud provider that meets the FedRAMP Moderate baseline or its equivalent. IL4/IL5 Provisional Authorization is required when the system is built for direct use by DoD personnel as a government system.

What does DFARS 252.204-7021 require?

DFARS 252.204-7021 is the CMMC contract clause. It requires contractors to hold and maintain the CMMC status specified in the contract for every information system that processes, stores, or transmits FCI or CUI, flow the requirement to subcontractors, and submit annual affirmations of continuous compliance in SPRS.

When do third-party CMMC Level 2 certifications become required?

Under Phase 2 of the CMMC rollout, effective November 10, 2026, DoD can require a CMMC Level 2 certification assessment by an authorized C3PAO as a condition of award for applicable contracts.

How do I know if a business system contains CUI?

Administrative contract data such as hours, invoices, and contract numbers is generally Federal Contract Information (FCI). A system holds CUI when users enter sensitive program content into it: technical task notes in timesheets, export-controlled part data in ERP or PLM records, or system configuration and vulnerability details in help desk tickets. Check the CUI markings and DD Form 254 or contract guidance from your contracting officer when in doubt.

CMMC Level 2 certification is a condition of award

Scope It Right. Host It Right. Pass the First Time.

Tell us about your system and contract requirements. We'll map your CUI boundary, identify which DFARS clauses apply, and recommend the right-sized CMMC, FedRAMP or IL4/IL5 environment.

Or call us directly for a quick consultation: 800-967-1004

CMMC
DoD Cloud SRG
DFARS
CUI
Defense Contractors
Government Cloud

This article is for general informational purposes and does not constitute legal advice. CMMC level, assessment type, and cloud requirements are set by each contract's DFARS clauses and your contracting officer. More insights on the GovDataHosting blog.

Back to Blog