Assurance

Built to the level you are held to.

FedRAMP impact levels, DoD Cloud SRG IL2–IL6, and CMMC 2.0 Levels 1–3. We design to the ladder your programme is measured against, and we say plainly where we sit on it.

“What security level are you at?” is four different questions. Each of the ladders below measures something distinct, and a supplier who does not say which one they mean is not answering. Here is where each one applies, rung by rung.

FedRAMP Impact Levels

Applies to: US civilian federal cloud services

Basis: Control baselines drawn from NIST SP 800-53

FedRAMP grades a cloud service by the damage its compromise would do. The level sets the size of the control baseline.

  1. Low

    Limited adverse effect

    Loss of confidentiality, integrity or availability would have a limited adverse effect. Includes the FedRAMP Tailored / Li-SaaS path for low-risk software-as-a-service.

  2. Moderate

    Serious adverse effect

    The workhorse level — roughly four in five FedRAMP authorisations, and the usual landing place for SaaS handling sensitive but unclassified government data.

  3. High

    Severe or catastrophic effect

    Law enforcement, emergency services, financial and health systems where failure causes severe or catastrophic harm.

DoD Cloud Computing SRG — Impact Levels

Applies to: US Department of Defense workloads

Basis: DISA maintains four active levels; IL1 and IL3 were retired or merged

The DoD grades by data sensitivity rather than service risk. FedRAMP Moderate maps to IL2; FedRAMP High maps to IL4 and IL5.

  1. IL2

    Public and non-critical mission information

    Unclassified information cleared for public release, plus non-critical mission data. Aligned with FedRAMP Moderate.

  2. IL4

    Controlled Unclassified Information (CUI)

    CUI and other mission-critical data on non-national-security systems. The level most defence-adjacent software has to reach.

  3. IL5

    Higher-sensitivity CUI and National Security Systems

    Higher-sensitivity CUI, mission-critical information, and National Security Systems — with stricter separation and personnel requirements.

  4. IL6

    Classified up to SECRET

    Classified information up to SECRET, hosted only in accredited environments connected to SIPRNet.

CMMC 2.0 Levels

Applies to: The US Defense Industrial Base

Basis: NIST SP 800-171 at Level 2 and NIST SP 800-172 at Level 3

CMMC certifies not just that a control exists but that you have been managing it — a maturity dimension is assessed at Levels 2 and 3. Phase 2 begins in November 2026, when third-party assessment becomes mandatory for contractors handling CUI.

  1. Level 1

    Foundational — 17 practices

    Basic cyber hygiene protecting Federal Contract Information (FCI). Annual self-assessment.

  2. Level 2

    Advanced — 110 practices

    The full NIST SP 800-171 control set, protecting CUI. Assessed by a C3PAO every three years unless DoD designates otherwise.

  3. Level 3

    Expert — 134 practices

    Adds NIST SP 800-172 controls for the most sensitive programmes: continuous monitoring, zero-trust architecture and proactive threat detection. Assessed by the government every three years.

CISA Zero Trust Maturity Model

Applies to: Architecture maturity, across five pillars

Basis: Identity · Devices · Networks · Applications and Workloads · Data

Not a certification but the ladder an architecture is judged on. We use it to describe where a system is today and what the next rung actually costs.

  1. Traditional

    Perimeter-based

    Manual configuration, static policy, implicit trust inside the network.

  2. Initial

    Starting automation

    Some automated provisioning and policy enforcement; visibility still partial.

  3. Advanced

    Centralised and coordinated

    Centralised visibility and identity control, policy enforced across pillars.

  4. Optimal

    Continuous and adaptive

    Continuous validation, dynamic least-privilege, automated response.

How we build to a level

Architecture

Segmentation, least privilege, and identity-aware access designed into the system rather than fitted afterwards. Every service reaches only what it must, and says so in configuration we can show an assessor.

Secrets and data

Encryption at rest and in transit, managed key material, no credential ever living in source, and data boundaries that match the impact level the programme is authorised at.

Evidence

Control evidence produced continuously by the pipeline that builds the system, so an assessment is a report on what already happens rather than a six-week scramble to reconstruct it.

AI-specific risk

Prompt injection and tool-abuse testing, output filtering, bounded agent permissions, and red-teaming of the agent path — the failure modes that traditional application security testing does not look for.

Other regimes we design against

  • NIST CSF 2.0 implementation tiers (Partial → Risk Informed → Repeatable → Adaptive)
  • SOC 2 Type I and Type II
  • ISO/IEC 27001
  • StateRAMP
  • HIPAA
  • PCI-DSS

We will also tell you when a level does not apply to you. Paying for an assurance posture your programme is not measured against is a common and expensive mistake.

Need to reach a specific level?

Tell us which one, and we will tell you what the gap actually costs.

Arrange a meeting