Government cloud advisory across GovCloud and DoD Impact Levels.

Lightbridge Cloud is an independent, vendor-neutral advisor that helps government and defense-supply-chain organizations map workloads to AWS GovCloud (US), Azure Government, GCC High, and the DoD Impact Levels IL2, IL4, IL5, and IL6, matching each data category to the cloud environment its sensitivity actually requires.

Lightbridge Cloud maps DoD Impact Levels and government cloud environments.

Impact Level 2 (IL2)

Covers public and other non-Controlled Unclassified Information (CUI). The baseline tier for low-sensitivity government workloads. Many commercial cloud regions can host IL2 data without a dedicated sovereign environment.

Impact Level 4 (IL4)

Covers Controlled Unclassified Information (CUI) and other mission-data not cleared for public release. IL4 typically requires a dedicated government cloud boundary with personnel and supply-chain controls beyond commercial defaults.

Impact Level 5 (IL5)

Covers higher-sensitivity CUI and unclassified National Security Systems (NSS). IL5 adds stronger tenant separation and dedicated infrastructure requirements above IL4, and is provisioned in restricted government cloud regions.

Impact Level 6 (IL6)

Covers classified information up to the SECRET level. IL6 workloads run in air-gapped, secret-cleared environments accessed only through accredited classified networks. This is the most restricted DoD cloud tier.

AWS GovCloud (US)

Isolated US regions operated by US persons, designed for CUI, ITAR-regulated data, and workloads with elevated sovereignty requirements. Region selection and IL alignment depend on the specific data category in scope.

GCC High and Azure Government

Microsoft government clouds. GCC High is intended for CUI, ITAR, and DFARS 252.204-7012 obligations and is distinct from commercial GCC, which suits less sensitive data. Azure Government provides further-isolated regions for higher impact levels.

Impact Level definitions and authorization boundaries are set by the Department of Defense and evolve over time. Confirm current criteria against the DoD CIO and the DoD Cloud Computing Security Requirements Guide before making procurement or accreditation decisions.

Lightbridge Cloud advises across vendors without selling a single platform.

Most firms steering you toward AWS GovCloud or GCC High also resell that platform. Lightbridge Cloud does not. We hold no vendor partner tier, take no reseller incentives, and resell no licenses. The recommendation you receive is driven by the sensitivity of your data and the regulatory obligations attached to it, not by a commission.

That neutrality matters most when ITAR-regulated technical data, Controlled Unclassified Information, and National Security Systems share an estate. The right answer is often a mix of environments, not a single vendor. We design the boundary, map the controls, and stay accountable for the outcome. For platform-specific architecture work, see our AWS advisory and Azure advisory.

Lightbridge Cloud aligns Impact Levels with CUI, CMMC, and FedRAMP readiness.

Government cloud selection rarely stands alone. IL4 and IL5 environments host Controlled Unclassified Information that also sits inside your CMMC scope under DFARS, while NIST SP 800-171 defines the underlying control set. Lightbridge Cloud connects these threads so the cloud boundary, the assessment posture, and the data flows tell one consistent story.

We frame every compliance engagement as readiness and advisory, never as a certification we issue or hold. Pair this advisory with our CMMC readiness and FedRAMP readiness practices, and review where your data is allowed to live in our data sovereignty guide. CMMC phase-in timing, CUI categories, and NIST control baselines change: verify current details against DoD, the NARA CUI Registry, and NIST.

Lightbridge Cloud government cloud advisory in numbers.

IL2 to IL6

Impact Level coverage

3 clouds

GovCloud, Azure Government, GCC High

Vendor-neutral

no reseller incentives

Lightbridge Cloud certifications and compliance.

ISO 27001 Certification in progress
SOC 2 Type II Certification in progress
ISO 42001 Certification in progress

Frequently asked questions.

What are the DoD Impact Levels (IL2, IL4, IL5, IL6)?

DoD Impact Levels classify how sensitive a government workload is and what cloud controls it requires. IL2 covers public and non-CUI information. IL4 covers Controlled Unclassified Information. IL5 covers higher-sensitivity CUI and unclassified National Security Systems. IL6 covers classified information up to SECRET. Lightbridge Cloud advises on which level your data category maps to, then designs the environment to match. Exact authorization scopes and requirements change: verify current criteria against the DoD CIO and the DoD Cloud Computing SRG.

What is the difference between GCC High and commercial GCC?

GCC High is a Microsoft government cloud built for organizations handling Controlled Unclassified Information, ITAR-regulated technical data, and DFARS 252.204-7012 obligations, operated under stricter personnel and isolation controls. Commercial Government Community Cloud (GCC) suits less sensitive government data and does not carry the same ITAR and CUI posture. Lightbridge Cloud is vendor-neutral and helps you confirm which environment fits your data category. Microsoft, GCC High, and Azure Government are trademarks of Microsoft Corporation; Lightbridge Cloud is not affiliated with Microsoft.

When does a workload need AWS GovCloud (US) versus a commercial region?

AWS GovCloud (US) is built for CUI, ITAR-regulated data, and workloads with elevated US-sovereignty requirements, operated by vetted US persons in isolated regions. Public and many non-CUI (IL2) workloads can often run in commercial regions. The deciding factor is the data category and the regulatory obligations attached to it, not preference. Lightbridge Cloud assesses scope before recommending a region. AWS and AWS GovCloud are trademarks of Amazon.com, Inc. or its affiliates; Lightbridge Cloud is not an AWS partner and is not affiliated with Amazon.

How do IL4 and IL5 relate to CMMC and CUI handling?

CUI handling, CMMC readiness, and DoD Impact Levels overlap but are distinct. IL4 and IL5 describe the cloud environment controls for hosting CUI and higher-sensitivity data. CMMC describes the assessed maturity of your organization handling that data under DFARS. NIST SP 800-171 defines the underlying CUI controls. Lightbridge Cloud aligns the cloud boundary with your CMMC posture as advisory readiness work, not a certification. See our CMMC readiness advisory at /services/cmmc-compliance. Verify current CMMC phase-in details against DoD and the CMMC program office.

Does Lightbridge Cloud sell AWS GovCloud or Azure Government licenses?

No. Lightbridge Cloud is an independent, vendor-neutral advisor. We do not resell licenses or hold a vendor partner tier with AWS or Microsoft, and we take no vendor incentives. Our recommendations are driven by data sensitivity, Impact Level fit, and regulatory obligations. We advise across AWS GovCloud, Azure Government, and GCC High and help you procure directly or through your existing channels. For platform-specific architecture, see /services/aws and /services/azure.

How does ITAR affect cloud region and Impact Level selection?

ITAR-regulated technical data generally must stay within US borders and be accessible only to US persons, which steers workloads toward AWS GovCloud (US), GCC High, or Azure Government rather than commercial multi-region clouds. EAR-controlled data carries related but separate constraints. Lightbridge Cloud maps your data classification to the right environment and access controls. ITAR and EAR specifics change: verify current rules against DDTC (ITAR) and BIS (EAR). This is general guidance, not legal advice.

What does a Lightbridge Cloud government cloud advisory engagement include?

A typical engagement starts with a data classification and Impact Level assessment, then an environment design across AWS GovCloud, Azure Government, or GCC High, a controls mapping to NIST SP 800-171 and the relevant SRG, and a migration and governance roadmap. We frame all compliance work as readiness and advisory. Lightbridge Cloud also coordinates with our FedRAMP readiness and data sovereignty practices at /services/fedramp-readiness and /guides/data-sovereignty.

This page provides general guidance only and is not legal, audit, or accounting advice. Impact Level criteria, CUI categories, ITAR and EAR rules, and CMMC and FedRAMP requirements change over time. Verify specifics against the official sources, including acquisition.gov, the DoD CIO and OUSD, NIST, the NARA CUI Registry, DCSA, and DDTC and BIS, before acting. AWS and AWS GovCloud are trademarks of Amazon.com, Inc. or its affiliates. Microsoft, Azure, Azure Government, and GCC High are trademarks of Microsoft Corporation. Lightbridge Cloud is independent and is not affiliated with, or a partner of, Amazon or Microsoft.

Get a government cloud readiness assessment.

We classify your data, map it to the right Impact Level and environment, and deliver an independent advisory roadmap across AWS GovCloud, Azure Government, and GCC High.