Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Services
AI Services
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

Federal Assessments

DoD Impact Level (IL6) Assessment

Ensure your cloud environment meets the highest Department of Defense (DoD) security requirements for handling classified data. Schellman is an accredited 3PAO authorized to perform DoD IL6 assessments, helping cloud service providers (CSPs) achieve compliance to support federal agencies and DoD mission owners handling classified information. In addition to IL6 assessments, Schellman can perform NIST based assessments for classified systems, classified AICPA System and Organization Control (SOC) examinations, and penetration testing of classified systems. 

Contact a Specialist

What is DoD IL6?

Impact Level 6 (IL6) is the highest level of authorization within the DoD Cloud Computing (CC) Security Requirements Guide (SRG), designed for cloud environments processing classified information at the Secret level. IL6 builds upon the controls and requirements defined by FedRAMP and enforces the most stringent security controls to prevent unauthorized access, ensuring CSPs can securely support Department of Defense (DoD) and other federal agencies. Achieving IL6 compliance is essential for cloud providers looking to operate within classified government environments.
dod-il6-2

Benefits of DoD IL6

Achieving DoD IL6 authorization is essential for CSPs looking to handle (process, transmit, and store) classified information for federal agencies. Given the heightened security requirements, IL6 compliance not only enables CSPs to operate in classified environments but also demonstrates their commitment to the most rigorous cybersecurity standards.

Key benefits include:

  • Authorization to Operate in Classified Environments Enables CSP’s Cloud Service Offering (CSO) to process, transmit, and store classified data for DoD mission owners.
  • Enhanced Security Posture Meets the highest federal cybersecurity standards to mitigate risks and prevent unauthorized access.
  • Competitive Advantage in Federal Cloud Services Positions CSPs to work with the Department of Defense and national security agencies.
  • Regulatory and Contractual Compliance Aligns with federal mandates and procurement requirements for classified cloud services.
  • Streamlined Path to Market Leverages FedRAMP’s standardized process to reduce barriers to federal adoption.
dod-il6-2

What to Expect from your DoD IL6 Assessment

We begin each project with your end goals in mind and to provide preparation for future key project activities. Effective communication and timely coordination of project planning activities are central to our methodology with our clients.

Image

FedRAMP Ready

Core CSP Activities
Submit documentation and evidence key controls

Schellman 3PAO Activities
Schellman conducts an independent readiness assessment and issues a formal Readiness Assessment Report (RAR) per the FedRAMP Ready program guidelines.

Image

Documentation

Core CSP Activities
Develop and submit core security program documentation including the System Security Plan (SSP) and related policies and procedures to the Agency or JAB.

Schellman 3PAO Activities
Schellman performs readiness review of the SSP and supporting documentation.

While client is finalizing its SSP, Schellman begins to collaborative draft the security assessment plan.

Image

Testing

Core CSP Activities
Stage 1: Review and approve SAP prior to submission to the Agency or JAB

Stage 2: Assist Schellman by providing any required documentation and testing evidence. Document any Plan of Action and Milestones (POA&M) generated from the assessment.

Schellman 3PAO Activities
Stage 1: Draft and submit the SAP to the Agency or JAB for approval.

Stage 2: Conduct testing of all in-scope controls, complete detailed control finding matrices, and issue SAR.

Image

Finalization

Core CSP Activities
Submit security assessment package.

Schellman 3PAO Activities
Provide clarification to the Agency or JAB and/or client as required to complete the authorization process.

Image

Maintenance

Core CSP Activities
Conduct annual continuous monitoring activities as specified in the FedRAMP Annual Assessment Guidance.

Schellman 3PAO Activities
Conduct annual assessment of core controls as well as 1/3 of the remaining NIST control set along with review of POA&Ms and remediation. Conduct annual penetration testing and oversee scanning activities as required.

nick-rundhaug

Federal Practice Leader

Nick Rundhaug

Nick Rundhaug is a Managing Director and Federal Practice Leader with Schellman. Nick has over 20 years of experience in the information technology field with 15 years’ experience in Federal frameworks for information technology. With a background as a network engineer and assessor, Nick specializes in the areas of cryptography, networking, and security mechanisms in cloud environments.

Meet Nick Contact Us

nick-rundhaug

Talk to a Practice Leader