Classified Cloud
DoD Cloud Computing SRG and classified environment authorization
Classified cloud environments must meet stringent security requirements defined in the DoD Cloud Computing SRG at Impact Levels 4, 5, and 6. Thalorin supports classified cloud authorizations with specialized compliance workflows addressing isolation, cryptographic protection, and continuous monitoring requirements.
National Security Presidential Memorandum 12, signed on 12 June 2026, rescinded both NSD-42 of 1990 and NSM-8 of 2022 and rebuilt the governance of national security systems around a re-established Committee on National Security Systems, with the Director of the NSA as National Manager. Within ninety days the CNSS is to identify the revisions needed to CNSSP-32, the May 2022 policy on cloud security; within a hundred and twenty days it is to request configuration baselines from the providers accredited to host national security systems. Both windows are still open as this is read.
Classification is not a dial on a single regime. Up to SECRET a workload sits at IL6, where the Cloud Service Provider SRG requires a dedicated cloud infrastructure in facilities approved for classified processing, run as a closed self-contained SECRET enclave, with the CNSSI 1253 Classified Information Overlay applied on top of the FedRAMP High baseline. DCSA authorises the facility clearances and validates the assessment report jointly with DISA. Top Secret and TS/SCI hosting answers to Intelligence Community Directive 503 and IC authorities instead, and compartmented programmes bring a further authorising authority again.
What consistently catches programmes is that the compliance apparatus has to move to the high side with the workload. Scanner output, log records, configuration exports and the assessment artifacts built from them are classified at the level of the enclave that produced them, and they cannot reach the unclassified tooling the rest of the organisation runs on without a cross-domain transfer and a human review. Air-gapped regions sharpen it further: signature feeds, agent telemetry and vendor updates do not arrive on their own, so continuous monitoring designed around an internet path quietly becomes periodic.
Classification travels with the artifact in Thalorin's model, not with the environment it was last read from. A control satisfied inside a Secret enclave is recorded as satisfied at that classification, the evidence stays bound to the enclave that produced it, and a low-side view carries the state of the control without carrying the artifact behind it. Cryptographic transition dates and connection approval conditions are held against the enclave and the authority that imposed them, not against a programme calendar.
Classified environments require extraordinary controls
CNSSP-32 is under review
NSPM-12 gave the Committee on National Security Systems ninety days from 12 June 2026 to identify the revisions needed to the May 2022 cloud security policy. An architecture frozen against the current text may be answering a question about to be restated.
Connection approval is its own queue
The SRG says outright that the provisional authorization assessment does not evaluate a service's readiness to connect. IL6 enclaves are closed SIPRNet enclaves and must satisfy every SIPRNet connection approval requirement separately, on a separate timetable.
Evidence inherits the enclave's classification
Scan results, logs and assessment artifacts generated inside a Secret environment are classified at that level. Moving them to the reporting the rest of the organisation uses is a cross-domain transfer with a human review, not an export.
CNSA 2.0 has a delivery date
Under the updated CNSSP 15, new national security system acquisitions must be CNSA 2.0 compliant from 1 January 2027. The cryptographic inventory — which module protects which boundary — is the long pole, not the algorithms.
How Thalorin helps
IL4/IL5/IL6 compliance automation
Carry what IL6 adds over IL5 as distinct obligations rather than a restated baseline: the dedicated closed SECRET enclave, the CNSSI 1253 Classified Information Overlay, US-citizen-only provider personnel, SIPRNet token and PKI authentication for privileged access.
Classified enclave documentation
Build the system security plan, categorisation rationale and body of evidence for an enclave categorised under CNSSI 1253, including which overlays were applied and why, from the control state assessors read.
Cryptographic boundary controls
Record which algorithms, cryptographic modules and validation certificates protect each boundary, and hold the CNSSP 15 transition dates against the components that still have to move.
Isolation verification
Evidence what genuinely shares a boundary with what — tenants, missions, physical infrastructure — against the separation the claimed impact level requires, not a provider's description of its own architecture.
Classified CSP integration
Draw on a classified offering's own compliance surfaces — its configuration baselines, scan results and inherited control statements — from inside the enclave, so the record of the environment is built where the environment lives.
Secret and TS cloud authorization
Keep the SECRET path under the DoD SRG and the Top Secret path under ICD 503 as separate authorization records, because they are separate grants from separate authorities and neither carries the other.
Classified Cloud: common questions
What did NSPM-12 change for classified cloud hosting?
It rescinded the policy underneath it and rebuilt the governance. Signed on 12 June 2026, NSPM-12 rescinded NSD-42 and NSM-8, re-established the Committee on National Security Systems, and named the Director of the NSA as National Manager for national security systems. It tasks the CNSS with identifying revisions needed to CNSSP-32 within ninety days, with requesting agency configuration baselines from accredited providers within a hundred and twenty days, and with issuing a report on provisioning cloud capabilities at the Secret, Top Secret Collateral, TS/SCI and Top Secret Controlled levels.
Is IL6 the same thing as a Top Secret cloud?
No. IL6 is reserved for information classified up to SECRET. The Cloud Service Provider SRG requires that it be processed in a dedicated infrastructure inside facilities approved for classified processing at or above the classification held, operated as a closed self-contained SECRET enclave for the processing, storage and management planes. Top Secret and TS/SCI hosting is authorised under Intelligence Community Directive 503 by IC authorities, and compartmented programmes bring further authorising authorities of their own. A provider holding both grants holds two, not one that spans both.
Which cloud providers hold DoD IL6 authorization?
The authoritative answer is the DoD Cloud Service Catalog, which the SRG names as the record of offerings holding a provisional authorization; vendor announcements are not it. Two things make the brand-level question the wrong one. A PA is awarded per cloud service offering, so a provider can hold IL6 for one offering and nothing at that level for another. And at IL6 the facility clearances sit with DCSA, which validates the assessment report jointly with DISA, so status can turn on a facility rather than a platform.
Does an IL6 authorization include the SIPRNet connection?
No — the SRG says the provisional authorization assessment does not evaluate a service offering's readiness to connect. IL6 offerings and their management networks are required to be closed SIPRNet enclaves, and those enclaves must comply with all SIPRNet connection approval requirements, including enclave boundary protection and cyberspace defence obligations, and are authorised the way any other SIPRNet enclave connection is. Internal Cloud Access Points are required as for other SIPRNet connections, and provider privileged access must use SIPRNet token and PKI authentication.
What does CNSA 2.0 require of a classified cloud environment, and by when?
CNSA 2.0 names the quantum-resistant algorithms national security systems move to — ML-KEM-1024 for key establishment and ML-DSA-87 for signatures, with AES-256 and SHA-384 or SHA-512 alongside. NSA's published dates now come from the updated CNSSP 15 rather than a per-technology table: from 1 January 2027 all new NSS acquisitions must be CNSA 2.0 compliant, by 31 December 2030 equipment and services that cannot support the suite must be phased out, and by 31 December 2031 the algorithms are mandated for use.
Regulatory state described as of August 2026. Requirements change; verify against the current rule before relying on any date above.
Talk to us about Classified Cloud.
See how one evidence artifact satisfies Classified Cloud requirements alongside every other framework you carry.