Skip to selected reference
Reference StudioPublic reference · indexed
DoD Cloud Computing Security Requirements Guide

National Security Cloud Reference Studio

Cloud boundaries · Orientation

DoD Cloud Computing Security Requirements Guide

Understand what the governing source establishes, why it matters to a mission owner, and what must not be inferred.

At a glance

Publisher
Defense Information Systems Agency
Source type
Standard
Edition
Publisher-controlled current edition
Source-described impact-level scope
IL4, IL5, IL6
Source-described environment
commercial-cloud
Last verified
Aug 29, 2026

How to read the evidence

These states are independent. A state never proves the next one.

Documented
An authoritative source describes the fact within its stated scope.
Available
The provider reports the capability in the named environment and location.
Authorized / in scope
A named authorization source includes the defined boundary and conditions.
Orderable
A current acquisition path supports the defined item; JWCC service and SKU detail requires controlled confirmation.
Mission-suitable
Not determined publicly; mission authority, architecture, constraints, and evidence remain decisive.

Source abstract

Authoritative-source synthesis

The DoD cloud security model uses impact levels to express information sensitivity and the security requirements expected of cloud offerings.

Bounded plain-language source-fact abstract from the governed Defense Information Systems Agency record; use the authoritative source for its complete text.

Why it matters

Review mission-owner contextHide detail

Start with the mission information and system context; do not select a provider environment from an impact-level label alone.

Cloud Waypoint interpretation · not source authority

Boundaries · do not infer

Review applicability limitsHide detail

The SRG does not authorize a mission system, select a provider, or remove the Authorizing Official's decision.

Documented, Available, Authorized / in scope, Orderable, and Mission-suitable remain separate claims. This reader does not rank providers or make an authorization, procurement, funding, or suitability decision.

Deeper public detail

Review supported source claimsHide detail

These bounded claims preserve useful public detail while leaving governing requirements and adherence guidance in the linked source.

  1. The DoD cloud security model uses impact levels to express information sensitivity and the security requirements expected of cloud offerings.

    Standardrequirementhttps://www.cyber.mil/dccs/dccs-documents/

  2. Defines DoD cloud security requirements; does not grant a system ATO.

    Standardauthorizationhttps://www.cyber.mil/dccs/dccs-documents/

  3. Not a service-availability statement.

    Standardavailabilityhttps://www.cyber.mil/dccs/dccs-documents/

  4. Not an acquisition statement.

    StandardjwccOrderabilityhttps://www.cyber.mil/dccs/dccs-documents/

  5. Mission-specific analysis remains required.

    StandardmissionSuitabilityhttps://www.cyber.mil/dccs/dccs-documents/

Authoritative source & provenance

Publisher
Defense Information Systems Agency
Edition
Publisher-controlled current edition
Published
Not stated by publisher
Source role
primaryAuthoritative
Source health
HEALTHY
Health basis
authoritativeEditionInForce, verifiedWithinExpectedInterval
Last verified
Aug 29, 2026

Open the authoritative source (opens in new tab)

Use the governing source for the complete text, current requirements, and source-controlled detail.

Cloud boundaries · Orientation

Azure Government DoD overview

Understand what the governing source establishes, why it matters to a mission owner, and what must not be inferred.

At a glance

Publisher
Microsoft
Source type
Product documentation
Edition
Continuously maintained documentation
Source-described impact-level scope
IL4, IL5, IL6
Source-described environment
Azure Government, Azure Government Secret
Source-described region
US Gov, US DoD
Last verified
Aug 24, 2026

How to read the evidence

These states are independent. A state never proves the next one.

Documented
An authoritative source describes the fact within its stated scope.
Available
The provider reports the capability in the named environment and location.
Authorized / in scope
A named authorization source includes the defined boundary and conditions.
Orderable
A current acquisition path supports the defined item; JWCC service and SKU detail requires controlled confirmation.
Mission-suitable
Not determined publicly; mission authority, architecture, constraints, and evidence remain decisive.

Source abstract

Authoritative-source synthesis

Microsoft documents separate government environments, region types, and additional isolation considerations for some IL5 workloads.

Bounded plain-language source-fact abstract from the governed Microsoft record; use the authoritative source for its complete text.

Why it matters

Review mission-owner contextHide detail

Environment name, region availability, PA scope, and workload configuration must be checked as separate facts.

Cloud Waypoint interpretation · not source authority

Boundaries · do not infer

Review applicability limitsHide detail

Provider documentation describes platform capability; it is not a Cloud Waypoint endorsement or a mission-system authorization.

Documented, Available, Authorized / in scope, Orderable, and Mission-suitable remain separate claims. This reader does not rank providers or make an authorization, procurement, funding, or suitability decision.

Deeper public detail

Review supported source claimsHide detail

These bounded claims preserve useful public detail while leaving governing requirements and adherence guidance in the linked source.

  1. Microsoft documents separate government environments, region types, and additional isolation considerations for some IL5 workloads.

    Product documentationscopehttps://learn.microsoft.com/en-us/azure/azure-government/documentation-government-overview-dod

  2. Provider-reported platform scope only.

    Product documentationauthorizationhttps://learn.microsoft.com/en-us/azure/azure-government/documentation-government-overview-dod

  3. Region and service availability require service-level verification.

    Product documentationavailabilityhttps://learn.microsoft.com/en-us/azure/azure-government/documentation-government-overview-dod

  4. No JWCC ordering claim is made.

    Product documentationjwccOrderabilityhttps://learn.microsoft.com/en-us/azure/azure-government/documentation-government-overview-dod

  5. No mission suitability claim is made.

    Product documentationmissionSuitabilityhttps://learn.microsoft.com/en-us/azure/azure-government/documentation-government-overview-dod

Authoritative source & provenance

Publisher
Microsoft
Edition
Continuously maintained documentation
Published
Aug 15, 2024
Source role
primaryAuthoritative
Source health
HEALTHY
Health basis
authoritativeEditionInForce, verifiedWithinExpectedInterval
Last verified
Aug 24, 2026

Open the authoritative source (opens in new tab)

Use the governing source for the complete text, current requirements, and source-controlled detail.

Cloud boundaries · Orientation

Oracle US Defense Cloud boundary

Understand what the governing source establishes, why it matters to a mission owner, and what must not be inferred.

At a glance

Publisher
Oracle
Source type
Product documentation
Edition
Continuously maintained OCI documentation
Source-described impact-level scope
IL5
Source-described environment
Oracle US Defense Cloud, OC3
Source-described region
US DoD East, US DoD North, US DoD West
Last verified
Aug 30, 2026

How to read the evidence

These states are independent. A state never proves the next one.

Documented
An authoritative source describes the fact within its stated scope.
Available
The provider reports the capability in the named environment and location.
Authorized / in scope
A named authorization source includes the defined boundary and conditions.
Orderable
A current acquisition path supports the defined item; JWCC service and SKU detail requires controlled confirmation.
Mission-suitable
Not determined publicly; mission authority, architecture, constraints, and evidence remain decisive.

Source abstract

Authoritative-source synthesis

Oracle documents US Defense Cloud as realm OC3 with three named regions; an OC3 tenancy can subscribe only to regions in that realm.

Bounded plain-language source-fact abstract from the governed Oracle record; use the authoritative source for its complete text.

Why it matters

Review mission-owner contextHide detail

Treat realm, region, service availability, authorization scope, acquisition, and mission fit as independent checks.

Cloud Waypoint interpretation · not source authority

Boundaries · do not infer

Review applicability limitsHide detail

Oracle's service and feature exception list is explicitly non-exhaustive, so omission does not establish availability or support.

Documented, Available, Authorized / in scope, Orderable, and Mission-suitable remain separate claims. This reader does not rank providers or make an authorization, procurement, funding, or suitability decision.

Deeper public detail

Review supported source claimsHide detail

These bounded claims preserve useful public detail while leaving governing requirements and adherence guidance in the linked source.

  1. Oracle documents US Defense Cloud as realm OC3 with three named regions; an OC3 tenancy can subscribe only to regions in that realm.

    Product documentationscopehttps://docs.oracle.com/en-us/iaas/Content/gov-cloud/govfeddod.htm

  2. Provider-reported environment boundary; no mission authorization is asserted.

    Product documentationauthorizationhttps://docs.oracle.com/en-us/iaas/Content/gov-cloud/govfeddod.htm

  3. Three named OC3 regions are documented; service and feature availability remain separate checks.

    Product documentationavailabilityhttps://docs.oracle.com/en-us/iaas/Content/gov-cloud/govfeddod.htm

  4. No acquisition or ordering-path claim is made.

    Product documentationjwccOrderabilityhttps://docs.oracle.com/en-us/iaas/Content/gov-cloud/govfeddod.htm

  5. No mission suitability claim is made.

    Product documentationmissionSuitabilityhttps://docs.oracle.com/en-us/iaas/Content/gov-cloud/govfeddod.htm

Authoritative source & provenance

Publisher
Oracle
Edition
Continuously maintained OCI documentation
Published
Not stated by publisher
Source role
primaryAuthoritative
Source health
HEALTHY
Health basis
authoritativeEditionInForce, verifiedWithinExpectedInterval
Last verified
Aug 30, 2026

Open the authoritative source (opens in new tab)

Use the governing source for the complete text, current requirements, and source-controlled detail.

Services & availability · Orientation

AWS GovCloud (US) regions

Understand what the governing source establishes, why it matters to a mission owner, and what must not be inferred.

At a glance

Publisher
Amazon Web Services
Source type
Product documentation
Edition
Continuously maintained user guide
Source-described impact-level scope
IL4, IL5
Source-described environment
AWS GovCloud (US)
Source-described region
us-gov-east-1, us-gov-west-1
Last verified
Aug 24, 2026

How to read the evidence

These states are independent. A state never proves the next one.

Documented
An authoritative source describes the fact within its stated scope.
Available
The provider reports the capability in the named environment and location.
Authorized / in scope
A named authorization source includes the defined boundary and conditions.
Orderable
A current acquisition path supports the defined item; JWCC service and SKU detail requires controlled confirmation.
Mission-suitable
Not determined publicly; mission authority, architecture, constraints, and evidence remain decisive.

Source abstract

Authoritative-source synthesis

AWS identifies two isolated GovCloud (US) regions and documents a distinct partition, endpoints, account relationship, and credentials.

Bounded plain-language source-fact abstract from the governed Amazon Web Services record; use the authoritative source for its complete text.

Why it matters

Review mission-owner contextHide detail

A listed service in the partition still needs region, feature, authorization-scope, acquisition, and mission-fit checks.

Cloud Waypoint interpretation · not source authority

Boundaries · do not infer

Review applicability limitsHide detail

GovCloud presence is not proof that every feature is available, authorized for the intended use, orderable, or suitable.

Documented, Available, Authorized / in scope, Orderable, and Mission-suitable remain separate claims. This reader does not rank providers or make an authorization, procurement, funding, or suitability decision.

Deeper public detail

Review supported source claimsHide detail

These bounded claims preserve useful public detail while leaving governing requirements and adherence guidance in the linked source.

  1. AWS identifies two isolated GovCloud (US) regions and documents a distinct partition, endpoints, account relationship, and credentials.

    Product documentationscopehttps://docs.aws.amazon.com/govcloud-us/latest/UserGuide/whatis.html

  2. Provider-reported environment scope.

    Product documentationauthorizationhttps://docs.aws.amazon.com/govcloud-us/latest/UserGuide/whatis.html

  3. Two named regions; service-level confirmation remains required.

    Product documentationavailabilityhttps://docs.aws.amazon.com/govcloud-us/latest/UserGuide/whatis.html

  4. No ordering-path claim is made.

    Product documentationjwccOrderabilityhttps://docs.aws.amazon.com/govcloud-us/latest/UserGuide/whatis.html

  5. No workload-fit claim is made.

    Product documentationmissionSuitabilityhttps://docs.aws.amazon.com/govcloud-us/latest/UserGuide/whatis.html

Authoritative source & provenance

Publisher
Amazon Web Services
Edition
Continuously maintained user guide
Published
Not stated by publisher
Source role
primaryAuthoritative
Source health
HEALTHY
Health basis
authoritativeEditionInForce, verifiedWithinExpectedInterval
Last verified
Aug 24, 2026

Open the authoritative source (opens in new tab)

Use the governing source for the complete text, current requirements, and source-controlled detail.

Services & availability · Orientation

Assured Workloads data boundary for IL4

Understand what the governing source establishes, why it matters to a mission owner, and what must not be inferred.

At a glance

Publisher
Google Cloud
Source type
Product documentation
Edition
Continuously maintained control-package documentation
Source-described impact-level scope
IL4
Source-described environment
Assured Workloads
Source-described region
United States
Last verified
Aug 29, 2026

How to read the evidence

These states are independent. A state never proves the next one.

Documented
An authoritative source describes the fact within its stated scope.
Available
The provider reports the capability in the named environment and location.
Authorized / in scope
A named authorization source includes the defined boundary and conditions.
Orderable
A current acquisition path supports the defined item; JWCC service and SKU detail requires controlled confirmation.
Mission-suitable
Not determined publicly; mission authority, architecture, constraints, and evidence remain decisive.

Source abstract

Authoritative-source synthesis

Google documents an IL4 control package with supported services, location controls, and customer prerequisites.

Bounded plain-language source-fact abstract from the governed Google Cloud record; use the authoritative source for its complete text.

Why it matters

Review mission-owner contextHide detail

The supported-products list is operationally volatile and should be verified close to a decision, not treated as a durable catalog snapshot.

Cloud Waypoint interpretation · not source authority

Boundaries · do not infer

Review applicability limitsHide detail

A control package supports configuration; it does not decide the system boundary, authorization, acquisition route, or mission suitability.

Documented, Available, Authorized / in scope, Orderable, and Mission-suitable remain separate claims. This reader does not rank providers or make an authorization, procurement, funding, or suitability decision.

Deeper public detail

Review supported source claimsHide detail

These bounded claims preserve useful public detail while leaving governing requirements and adherence guidance in the linked source.

  1. Google documents an IL4 control package with supported services, location controls, and customer prerequisites.

    Product documentationscopehttps://docs.cloud.google.com/assured-workloads/docs/control-packages/il4

  2. Provider-reported control-package scope.

    Product documentationauthorizationhttps://docs.cloud.google.com/assured-workloads/docs/control-packages/il4

  3. Only the currently documented in-scope products and regions.

    Product documentationavailabilityhttps://docs.cloud.google.com/assured-workloads/docs/control-packages/il4

  4. No JWCC ordering claim is made.

    Product documentationjwccOrderabilityhttps://docs.cloud.google.com/assured-workloads/docs/control-packages/il4

  5. Customer prerequisites and mission constraints remain decisive.

    Product documentationmissionSuitabilityhttps://docs.cloud.google.com/assured-workloads/docs/control-packages/il4

Authoritative source & provenance

Publisher
Google Cloud
Edition
Continuously maintained control-package documentation
Published
Not stated by publisher
Source role
primaryAuthoritative
Source health
HEALTHY
Health basis
authoritativeEditionInForce, verifiedWithinExpectedInterval
Last verified
Aug 29, 2026

Open the authoritative source (opens in new tab)

Use the governing source for the complete text, current requirements, and source-controlled detail.

Services & availability · Orientation

Assured Workloads data boundary for IL5

Understand what the governing source establishes, why it matters to a mission owner, and what must not be inferred.

At a glance

Publisher
Google Cloud
Source type
Product documentation
Edition
Continuously maintained control-package documentation
Source-described impact-level scope
IL5
Source-described environment
Assured Workloads, Data Boundary for IL5
Source-described region
United States
Last verified
Aug 30, 2026

How to read the evidence

These states are independent. A state never proves the next one.

Documented
An authoritative source describes the fact within its stated scope.
Available
The provider reports the capability in the named environment and location.
Authorized / in scope
A named authorization source includes the defined boundary and conditions.
Orderable
A current acquisition path supports the defined item; JWCC service and SKU detail requires controlled confirmation.
Mission-suitable
Not determined publicly; mission authority, architecture, constraints, and evidence remain decisive.

Source abstract

Authoritative-source synthesis

Google states that a product not listed for Data Boundary for IL5 is unsupported for that package and may still share an API endpoint with supported products.

Bounded plain-language source-fact abstract from the governed Google Cloud record; use the authoritative source for its complete text.

Why it matters

Review mission-owner contextHide detail

For this Google control package, the supported-products list defines scope; endpoint reachability is not evidence of support or authorization.

Cloud Waypoint interpretation · not source authority

Boundaries · do not infer

Review applicability limitsHide detail

This provider-specific absence rule does not transfer to another provider, establish mission authorization, or make the volatile product table a durable catalog.

Documented, Available, Authorized / in scope, Orderable, and Mission-suitable remain separate claims. This reader does not rank providers or make an authorization, procurement, funding, or suitability decision.

Deeper public detail

Review supported source claimsHide detail

These bounded claims preserve useful public detail while leaving governing requirements and adherence guidance in the linked source.

  1. Google states that a product not listed for Data Boundary for IL5 is unsupported for that package and may still share an API endpoint with supported products.

    Product documentationscopehttps://docs.cloud.google.com/assured-workloads/docs/control-packages/il5

  2. Provider-reported control-package scope; no government or mission authorization is asserted.

    Product documentationauthorizationhttps://docs.cloud.google.com/assured-workloads/docs/control-packages/il5

  3. Only currently listed products are supported for this package; endpoint access is not a support signal.

    Product documentationavailabilityhttps://docs.cloud.google.com/assured-workloads/docs/control-packages/il5

  4. No acquisition or ordering-path claim is made.

    Product documentationjwccOrderabilityhttps://docs.cloud.google.com/assured-workloads/docs/control-packages/il5

  5. Customer and authorizing-agency review remain required.

    Product documentationmissionSuitabilityhttps://docs.cloud.google.com/assured-workloads/docs/control-packages/il5

Authoritative source & provenance

Publisher
Google Cloud
Edition
Continuously maintained control-package documentation
Published
Not stated by publisher
Source role
primaryAuthoritative
Source health
HEALTHY
Health basis
authoritativeEditionInForce, verifiedWithinExpectedInterval
Last verified
Aug 30, 2026

Open the authoritative source (opens in new tab)

Use the governing source for the complete text, current requirements, and source-controlled detail.

Authorization & evidence · Orientation

Risk Management Framework for Information Systems and Organizations

Understand what the governing source establishes, why it matters to a mission owner, and what must not be inferred.

At a glance

Publisher
National Institute of Standards and Technology
Source type
Standard
Edition
NIST SP 800-37 Rev. 2
Source-described environment
system-boundary
Last verified
Aug 24, 2026

How to read the evidence

These states are independent. A state never proves the next one.

Documented
An authoritative source describes the fact within its stated scope.
Available
The provider reports the capability in the named environment and location.
Authorized / in scope
A named authorization source includes the defined boundary and conditions.
Orderable
A current acquisition path supports the defined item; JWCC service and SKU detail requires controlled confirmation.
Mission-suitable
Not determined publicly; mission authority, architecture, constraints, and evidence remain decisive.

Source abstract

Authoritative-source synthesis

NIST SP 800-37 Rev. 2 describes a system life-cycle risk-management process with explicit authorization and ongoing-monitoring activities.

Bounded plain-language source-fact abstract from the governed National Institute of Standards and Technology record; use the authoritative source for its complete text.

Why it matters

Review mission-owner contextHide detail

Cloud inheritance can reduce duplicated evidence work, but the mission still defines its system, assesses remaining controls, and routes residual risk to its authorization authority.

Cloud Waypoint interpretation · not source authority

Boundaries · do not infer

Review applicability limitsHide detail

A cloud service's authorization package is evidence input; it does not transfer the mission system's authorization decision.

Documented, Available, Authorized / in scope, Orderable, and Mission-suitable remain separate claims. This reader does not rank providers or make an authorization, procurement, funding, or suitability decision.

Deeper public detail

Review supported source claimsHide detail

These bounded claims preserve useful public detail while leaving governing requirements and adherence guidance in the linked source.

  1. NIST SP 800-37 Rev. 2 describes a system life-cycle risk-management process with explicit authorization and ongoing-monitoring activities.

    Standardrequirementhttps://csrc.nist.gov/pubs/sp/800/37/r2/final

  2. The Authorizing Official retains the risk decision.

    Standardauthorizationhttps://csrc.nist.gov/pubs/sp/800/37/r2/final

  3. Not a service-availability statement.

    Standardavailabilityhttps://csrc.nist.gov/pubs/sp/800/37/r2/final

  4. Not an acquisition statement.

    StandardjwccOrderabilityhttps://csrc.nist.gov/pubs/sp/800/37/r2/final

  5. RMF process does not prescribe a provider or architecture.

    StandardmissionSuitabilityhttps://csrc.nist.gov/pubs/sp/800/37/r2/final

Authoritative source & provenance

Publisher
National Institute of Standards and Technology
Edition
NIST SP 800-37 Rev. 2
Published
Dec 20, 2018
Source role
primaryAuthoritative
Source health
HEALTHY
Health basis
authoritativeEditionInForce, verifiedWithinExpectedInterval
Last verified
Aug 24, 2026

Open the authoritative source (opens in new tab)

Use the governing source for the complete text, current requirements, and source-controlled detail.

Authorization & evidence · Orientation

Azure Government IL5 isolation guidance

Understand what the governing source establishes, why it matters to a mission owner, and what must not be inferred.

At a glance

Publisher
Microsoft
Source type
Authorization evidence
Edition
Continuously maintained documentation
Source-described impact-level scope
IL5
Source-described environment
Azure Government
Source-described region
US Gov, US DoD
Last verified
Aug 24, 2026

How to read the evidence

These states are independent. A state never proves the next one.

Documented
An authoritative source describes the fact within its stated scope.
Available
The provider reports the capability in the named environment and location.
Authorized / in scope
A named authorization source includes the defined boundary and conditions.
Orderable
A current acquisition path supports the defined item; JWCC service and SKU detail requires controlled confirmation.
Mission-suitable
Not determined publicly; mission authority, architecture, constraints, and evidence remain decisive.

Source abstract

Authoritative-source synthesis

Microsoft identifies services and configurations that require additional compute or storage isolation for IL5 use in some government regions.

Bounded plain-language source-fact abstract from the governed Microsoft record; use the authoritative source for its complete text.

Why it matters

Review mission-owner contextHide detail

Authorization scope and required configuration should be traced independently; neither is captured by a single 'IL5 available' label.

Cloud Waypoint interpretation · not source authority

Boundaries · do not infer

Review applicability limitsHide detail

The mission is responsible for its design and for controls outside the provider boundary.

Documented, Available, Authorized / in scope, Orderable, and Mission-suitable remain separate claims. This reader does not rank providers or make an authorization, procurement, funding, or suitability decision.

Deeper public detail

Review supported source claimsHide detail

These bounded claims preserve useful public detail while leaving governing requirements and adherence guidance in the linked source.

  1. Microsoft identifies services and configurations that require additional compute or storage isolation for IL5 use in some government regions.

    Authorization evidenceauthorizationhttps://learn.microsoft.com/en-us/azure/azure-government/documentation-government-impact-level-5

  2. Provider guidance is not a mission ATO.

    Authorization evidenceauthorizationhttps://learn.microsoft.com/en-us/azure/azure-government/documentation-government-impact-level-5

  3. Service availability is a separate source check.

    Authorization evidenceavailabilityhttps://learn.microsoft.com/en-us/azure/azure-government/documentation-government-impact-level-5

  4. No ordering-path claim is made.

    Authorization evidencejwccOrderabilityhttps://learn.microsoft.com/en-us/azure/azure-government/documentation-government-impact-level-5

  5. Required configuration and mission context must be assessed.

    Authorization evidencemissionSuitabilityhttps://learn.microsoft.com/en-us/azure/azure-government/documentation-government-impact-level-5

Authoritative source & provenance

Publisher
Microsoft
Edition
Continuously maintained documentation
Published
Not stated by publisher
Source role
primaryAuthoritative
Source health
HEALTHY
Health basis
authoritativeEditionInForce, verifiedWithinExpectedInterval
Last verified
Aug 24, 2026

Open the authoritative source (opens in new tab)

Use the governing source for the complete text, current requirements, and source-controlled detail.

Authorization & evidence · Orientation

Reading AWS provider-reported DoD CSP scope

Understand what the governing source establishes, why it matters to a mission owner, and what must not be inferred.

At a glance

Publisher
Amazon Web Services
Source type
Product documentation
Edition
Continuously maintained compliance scope
Source-described impact-level scope
IL2, IL4, IL5, IL6
Source-described environment
AWS GovCloud (US), AWS classified regions
Last verified
Aug 30, 2026

How to read the evidence

These states are independent. A state never proves the next one.

Documented
An authoritative source describes the fact within its stated scope.
Available
The provider reports the capability in the named environment and location.
Authorized / in scope
A named authorization source includes the defined boundary and conditions.
Orderable
A current acquisition path supports the defined item; JWCC service and SKU detail requires controlled confirmation.
Mission-suitable
Not determined publicly; mission authority, architecture, constraints, and evidence remain decisive.

Source abstract

Authoritative-source synthesis

AWS states that absence from its current DoD CSP scope table does not by itself mean a service cannot be used, and that some services sit outside DISA review without an approval or disapproval decision.

Bounded plain-language source-fact abstract from the governed Amazon Web Services record; use the authoritative source for its complete text.

Why it matters

Review mission-owner contextHide detail

Read a listed status as a positive provider claim for that row and date; treat non-listing as not shown, not as a negative authorization or availability finding.

Cloud Waypoint interpretation · not source authority

Boundaries · do not infer

Review applicability limitsHide detail

The underlying table is dynamic provider material. Cloud Waypoint does not reproduce its service rows or treat provider text as a mission authorization decision.

Documented, Available, Authorized / in scope, Orderable, and Mission-suitable remain separate claims. This reader does not rank providers or make an authorization, procurement, funding, or suitability decision.

Deeper public detail

Review supported source claimsHide detail

These bounded claims preserve useful public detail while leaving governing requirements and adherence guidance in the linked source.

  1. AWS states that absence from its current DoD CSP scope table does not by itself mean a service cannot be used, and that some services sit outside DISA review without an approval or disapproval decision.

    Product documentationscopehttps://aws.amazon.com/compliance/services-in-scope/DoD/

  2. Provider-reported assessment scope; mission approval and authorization remain external decisions.

    Product documentationauthorizationhttps://aws.amazon.com/compliance/services-in-scope/DoD/

  3. The scope table does not establish current regional or feature availability.

    Product documentationavailabilityhttps://aws.amazon.com/compliance/services-in-scope/DoD/

  4. No acquisition or ordering-path claim is made.

    Product documentationjwccOrderabilityhttps://aws.amazon.com/compliance/services-in-scope/DoD/

  5. Shared-responsibility and mission review remain required.

    Product documentationmissionSuitabilityhttps://aws.amazon.com/compliance/services-in-scope/DoD/

Authoritative source & provenance

Publisher
Amazon Web Services
Edition
Continuously maintained compliance scope
Published
Not stated by publisher
Source role
primaryAuthoritative
Source health
HEALTHY
Health basis
authoritativeEditionInForce, verifiedWithinExpectedInterval
Last verified
Aug 30, 2026

Open the authoritative source (opens in new tab)

Use the governing source for the complete text, current requirements, and source-controlled detail.

Strategies & updates · Orientation

DoD Software Modernization Strategy

Understand what the governing source establishes, why it matters to a mission owner, and what must not be inferred.

At a glance

Publisher
U.S. Department of Defense
Source type
Strategy
Edition
Approved February 2022
Source-described environment
DoD enterprise
Last verified
Aug 24, 2026

How to read the evidence

These states are independent. A state never proves the next one.

Documented
An authoritative source describes the fact within its stated scope.
Available
The provider reports the capability in the named environment and location.
Authorized / in scope
A named authorization source includes the defined boundary and conditions.
Orderable
A current acquisition path supports the defined item; JWCC service and SKU detail requires controlled confirmation.
Mission-suitable
Not determined publicly; mission authority, architecture, constraints, and evidence remain decisive.

Source abstract

Authoritative-source synthesis

DoD stated that the Software Modernization Strategy builds upon, evolves, and replaces the 2018 DoD Cloud Strategy.

Bounded plain-language source-fact abstract from the governed U.S. Department of Defense record; use the authoritative source for its complete text.

Why it matters

Review mission-owner contextHide detail

Cloud decisions should be read inside the broader software-delivery, enterprise-service, and continuous-authorization direction—not as infrastructure placement alone.

Cloud Waypoint interpretation · not source authority

Boundaries · do not infer

Review applicability limitsHide detail

Strategy supplies direction, not a workload-specific acquisition, architecture, funding, or authorization decision.

Documented, Available, Authorized / in scope, Orderable, and Mission-suitable remain separate claims. This reader does not rank providers or make an authorization, procurement, funding, or suitability decision.

Deeper public detail

Review supported source claimsHide detail

These bounded claims preserve useful public detail while leaving governing requirements and adherence guidance in the linked source.

  1. DoD stated that the Software Modernization Strategy builds upon, evolves, and replaces the 2018 DoD Cloud Strategy.

    Strategyscopehttps://www.defense.gov/News/Releases/Release/Article/2924187/dod-software-modernization-strategy-approved/

  2. Department strategy; no system authorization.

    Strategyauthorizationhttps://www.defense.gov/News/Releases/Release/Article/2924187/dod-software-modernization-strategy-approved/

  3. No service-availability claim.

    Strategyavailabilityhttps://www.defense.gov/News/Releases/Release/Article/2924187/dod-software-modernization-strategy-approved/

  4. No specific ordering claim.

    StrategyjwccOrderabilityhttps://www.defense.gov/News/Releases/Release/Article/2924187/dod-software-modernization-strategy-approved/

  5. No workload-specific prescription.

    StrategymissionSuitabilityhttps://www.defense.gov/News/Releases/Release/Article/2924187/dod-software-modernization-strategy-approved/

Authoritative source & provenance

Publisher
U.S. Department of Defense
Edition
Approved February 2022
Published
Feb 4, 2022
Source role
primaryAuthoritative
Source health
HEALTHY
Health basis
authoritativeEditionInForce, verifiedWithinExpectedInterval
Last verified
Aug 24, 2026

Open the authoritative source (opens in new tab)

Use the governing source for the complete text, current requirements, and source-controlled detail.

Strategies & updates · Orientation

JWCC and next steps to rationalize cloud use

Understand what the governing source establishes, why it matters to a mission owner, and what must not be inferred.

At a glance

Publisher
Department of Defense Chief Information Officer
Source type
Policy
Edition
Memorandum dated August 2, 2023
Source-described environment
unclassified, secret, top-secret
Last verified
Aug 24, 2026

How to read the evidence

These states are independent. A state never proves the next one.

Documented
An authoritative source describes the fact within its stated scope.
Available
The provider reports the capability in the named environment and location.
Authorized / in scope
A named authorization source includes the defined boundary and conditions.
Orderable
A current acquisition path supports the defined item; JWCC service and SKU detail requires controlled confirmation.
Mission-suitable
Not determined publicly; mission authority, architecture, constraints, and evidence remain decisive.

Source abstract

Authoritative-source synthesis

The memorandum describes JWCC as an acquisition vehicle rather than a hosting environment and gives covered components cloud-procurement direction.

Bounded plain-language source-fact abstract from the governed Department of Defense Chief Information Officer record; use the authoritative source for its complete text.

Why it matters

Review mission-owner contextHide detail

A vehicle-level policy answers neither whether a specific service is on a current catalog nor whether it fits a mission system.

Cloud Waypoint interpretation · not source authority

Boundaries · do not infer

Review applicability limitsHide detail

Public policy scope, CSP availability, current orderability, authorization, and mission suitability are separate checks.

Documented, Available, Authorized / in scope, Orderable, and Mission-suitable remain separate claims. This reader does not rank providers or make an authorization, procurement, funding, or suitability decision.

Deeper public detail

Review supported source claimsHide detail

These bounded claims preserve useful public detail while leaving governing requirements and adherence guidance in the linked source.

  1. The memorandum describes JWCC as an acquisition vehicle rather than a hosting environment and gives covered components cloud-procurement direction.

    Policyrequirementhttps://dodcio.defense.gov/Portals/0/Documents/Library/NextStepRationalizeCloudUse.pdf

  2. Acquisition policy for named organizational scope.

    Policyauthorizationhttps://dodcio.defense.gov/Portals/0/Documents/Library/NextStepRationalizeCloudUse.pdf

  3. No claim about a specific CSP service.

    Policyavailabilityhttps://dodcio.defense.gov/Portals/0/Documents/Library/NextStepRationalizeCloudUse.pdf

  4. Vehicle exists; item-level current orderability is not asserted.

    PolicyjwccOrderabilityhttps://dodcio.defense.gov/Portals/0/Documents/Library/NextStepRationalizeCloudUse.pdf

  5. No mission-specific provider or service recommendation.

    PolicymissionSuitabilityhttps://dodcio.defense.gov/Portals/0/Documents/Library/NextStepRationalizeCloudUse.pdf

Authoritative source & provenance

Publisher
Department of Defense Chief Information Officer
Edition
Memorandum dated August 2, 2023
Published
Aug 2, 2023
Source role
primaryAuthoritative
Source health
HEALTHY
Health basis
authoritativeEditionInForce, verifiedWithinExpectedInterval
Last verified
Aug 24, 2026

Open the authoritative source (opens in new tab)

Use the governing source for the complete text, current requirements, and source-controlled detail.