---
title: Navigating FedRAMP Compliance and Cloud Complexity for the Defense Industrial Base
description: Cloud services without a FedRAMP Moderate authorization who have met the FedRAMP Moderate equivalent, also need to meet 5 additional requirements.
image: https://www.daymarksi.com/hubfs/compass-283234_1280.jpg
---

- [MICROSOFT SERVICE OFFERINGS](https://www.daymarksi.com/microsoft-service-offerings)
- [CONTACT](https://www.daymarksi.com/location-for-our-new-england-office-massachusetts)
- [SUPPORT](https://www.daymarksi.com/support)

[![DM_LogoTag_white-20yr](https://www.daymarksi.com/hubfs/brand-assets/DM_LogoTag_white-20yr.png "DM_LogoTag_white-20yr")](https://www.daymarksi.com)

- [About](https://www.daymarksi.com/about-daymark) 
    - [Why Daymark](https://www.daymarksi.com/why-daymark)
    - [Leadership](https://www.daymarksi.com/leadership)
    - [Industry Awards](https://www.daymarksi.com/industry-awards)
    - [Daymark Solutions Charitable Trust](https://www.daymarksi.com/charitable-trust)
    - [Customers](https://www.daymarksi.com/customers)
    - [Testimonials](https://www.daymarksi.com/testimonials)
    - [Technical Certifications](https://www.daymarksi.com/technical-certifications)
    - [Careers](https://www.daymarksi.com/careers)
    - [Locations](https://www.daymarksi.com/location-for-our-new-england-office-massachusetts)
- [Solutions](https://www.daymarksi.com/solutions) 
    - [Cloud Solutions](https://www.daymarksi.com/cloud)
    - [CMMC Compliance](https://www.daymarksi.com/understanding-the-cybersecurity-maturity-model-certification)
    - [Data Center Infrastructure](https://www.daymarksi.com/solutions/data-center-infrastructure-for-storage-networking-compute-security)
    - [Data Protection](https://www.daymarksi.com/solutions/data-protection-backups-recovery-restore)
    - [Networking](https://www.daymarksi.com/solutions/networking-and-security)
    - [Security](https://www.daymarksi.com/solutions/networking-and-security)
    - [Virtualization](https://www.daymarksi.com/solutions/virtualization)
    - [All Technology Partners](https://www.daymarksi.com/partners)
- Cloud 
    - [Microsoft Azure](https://www.daymarksi.com/microsoftazure)
    - [Microsoft Azure Government](https://www.daymarksi.com/protecting-government-data-for-the-defense-industrial-base)
    - [Microsoft 365](https://www.daymarksi.com/microsoft-365)
    - [Copilot for Microsoft 365](https://www.daymarksi.com/copilot-for-microsoft-365)
    - [Microsoft 365 GCC High](https://www.daymarksi.com/microsoft-gcc-high-for-defense-contractors)
    - [Mimecast](https://www.daymarksi.com/cloud)
    - [Okta](https://www.daymarksi.com/cloud)
    - [All Cloud Partners](https://www.daymarksi.com/cloud-partners)
- [Services](https://www.daymarksi.com/services) 
    - [Microsoft Service Offerings](https://www.daymarksi.com/microsoft-service-offerings)
    - [Assessment & Health Checks](https://www.daymarksi.com/services/assessment-and-health-checks)
    - [Cloud Architecture](https://www.daymarksi.com/services/custom-cloud-computing-implementations-and-services-in-new-england)
    - [CMMC Compliance Readiness](https://www.daymarksi.com/understanding-the-cybersecurity-maturity-model-certification)
    - [Contract & Maintenance Management](https://www.daymarksi.com/services/contract-maintenance-management)
    - [Documentation & Knowledge Transfer](https://www.daymarksi.com/services/documentation)
    - [Government Community Cloud](https://www.daymarksi.com/microsoft-gcc-high-for-defense-contractors)
    - [Identity Mangement](https://www.daymarksi.com/microsoft-entra-id-workshop)
    - [Implementations](https://www.daymarksi.com/services/it-project-implementation-on-budget-on-time-on-scope)
    - [Proof of Concepts](https://www.daymarksi.com/services/proof-of-concept-for-information-technology-initiatives)
    - [Solution Architecture](https://www.daymarksi.com/services/it-solution-architecture-for-complex-storage-network-and-computer-solutions)
    - [Staging & Integration](https://www.daymarksi.com/services/staging-and-integration)
- [MyDaymark](https://www.daymarksi.com/mydaymark/) 
    - [Advanced Support](https://www.daymarksi.com/mydaymark/advanced-support)
    - [Premier Support](https://www.daymarksi.com/mydaymark/premier-support)
    - [Managed Services](https://www.daymarksi.com/mydaymark/managed-services)
    - [Management Platform](https://www.daymarksi.com/mydaymark/management-platform)
    - [Security & Compliance](https://www.daymarksi.com/mydaymark/security-compliance)
- Industries 
    - [Energy & Utilities](https://www.daymarksi.com/new-england-it-project-management-and-implementation-for-energy-and-utilities-industry)
    - [Financial Services](https://www.daymarksi.com/new-england-it-project-implementation-for-financial-services-companies)
    - [Defense Industrial Base](https://www.daymarksi.com/protecting-government-data-for-the-defense-industrial-base)
    - [Healthcare](https://www.daymarksi.com/healthcare-information-technology-development-and-implementation)
    - [Life Sciences](https://www.daymarksi.com/new-england-it-initiative-implementation-for-life-sciences-companies)
- [Resources](https://www.daymarksi.com/information-technolocy-resources) 
    - [Case Studies](https://www.daymarksi.com/information-technolocy-resources?types=casestudy)
    - [Data Sheets](https://www.daymarksi.com/information-technolocy-resources?types=datasheet)
    - [Partner Resources](https://www.daymarksi.com/information-technolocy-resources?types=partnerresources)
    - [Workshops](https://www.daymarksi.com/information-technolocy-resources?types=workshop)
- [News & Events](https://www.daymarksi.com/news-events)
- Blog 
    - [Daymark IT Insights](https://www.daymarksi.com/blog)
    - [Cole Tramp's Microsoft Insights](https://www.daymarksi.com/blog/topic/cole-tramps-microsoft-insights)

![banner-why-daymark.jpg](https://www.daymarksi.com/hs-fs/hub/30865/file-2671640025-jpg/2015_Images/Banner_Images/banner-why-daymark.jpg?width=1400&name=banner-why-daymark.jpg "banner-why-daymark.jpg")

##### **Daymark IT Insights**

Enterprise IT, cloud, security, and AI guidance from Daymark’s technology experts.

# [Navigating FedRAMP Compliance and Cloud Complexity for the Defense Industrial Base](https://www.daymarksi.com/blog/navigating-fedramp-compliance-and-cloud-complexity-for-the-defense-industrial-base)

Posted by [Paul Netopski](https://www.daymarksi.com/blog/author/paul-netopski)

 Mon, Jul 15, 2024

- [Tweet](https://twitter.com/share)

![compass-283234_1280](https://www.daymarksi.com/hs-fs/hubfs/compass-283234_1280.jpg?width=1280&height=904&name=compass-283234_1280.jpg)

Companies performing work in the Defense Industrial Base (DIB) often contemplate whether they should use a cloud service provider for their business, then wonder which version of the cloud service they should consider. The rules and regulations passed down to the DIB from the Federal Government are quite confusing when it comes to trying to figure out what their requirements are. In this article, we will try to clear some of that up!

**FedRAMP Moderate Baseline**

The Department of Defense provides the requirements in their Defense Federal Acquisition Supplements (DFARS) for the usage of cloud services when Covered Defense Information (CDI) will be stored, processed or transmitted using that service. Other Federal Agencies will communicate their requirements in the contract directly or by referencing that Agency’s policies (which you are expected to review when bidding on the contract).

In a previous article we posted a whitepaper. “[Sensitive Unclassified Information](https://www.daymarksi.com/hubfs/resource-center/CDI-CTI-CUI-in-your-Systems.pdf),” which discusses CDI and how to identify it. This should be used as a reference and primer, so your organization understands CDI prior to deciding on the proper cloud platform. We also have an [article highlighting the use of cloud environments for ITAR regulated information](https://www.daymarksi.com/information-technology-navigator-blog/what-level-of-gcc-is-right-for-you) (even it if is not CDI or Controlled Unclassified Information (CUI)).

For DoD contracts, and those who will be using a cloud service for processing, storing or transmitting CDI, the minimum requirement is for FedRAMP Moderate baseline with 5 additional requirements, which is communicated in DFARS 252.204-7012, section b.2.ii.D;

*If the Contractor intends to use an external cloud service provider to store, process, or transmit any covered defense information in performance of this contract, the Contractor shall require and ensure that the cloud service provider **meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline** (https://www.fedramp.gov/documents-templates/) and that the cloud service provider complies with requirements in **paragraphs (c) through (g) of this clause** **for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment**.*

This means that even if the provider has a FedRAMP Moderate authorization, it must also provide the additional 5 requirements. Not all cloud providers will provide those 5 requirements in their FedRAMP Moderate offering.

Cloud services without a FedRAMP Moderate authorization who have met the FedRAMP Moderate equivalent (as defined in the DoD CIO Memo [here](https://dodcio.defense.gov/Portals/0/Documents/Library/FEDRAMP-EquivalencyCloudServiceProviders.pdf#:~:text=To%20be%20considered%20FedRAMP%20Moderate%20equivalent%2C%20CSOs%20must,Incident%20Response%20Plan%20%28IRP%29%20Configuration%20Management%20Plan%20%28CMP%29)), also need to meet those 5 additional requirements. It will be up to the user of the cloud service (DIB company) to ensure those 5 requirements are being met by the service provider. It is also up to the DIB company to ensure that the cloud service meets the FedRAMP moderate controls by obtaining evidence that the provider complies (typically by an assessment report from a 3rd party assessment organization or 3PAO).

**Big Changes in the Cloud Computing Security Requirements Guide (SRG)**

The DoD recently published a new version of the [Cloud Service Provider SRG](https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Cloud_Computing_Y24M07_SRG.zip) on June 14, 2024, which made significant changes to the requirements since it finally transitioned from NIST SP800-53 revision 4 to Revision 5 and it was renamed from Cloud Services to Cloud Service Provider.

**Is There More?**

The FedRAMP moderate baseline and the 5 additional requirements are perfectly acceptable for CUI Basic and some CUI Specified. Definitions about these two types of information can be found in [32 CFR 2002](https://www.federalregister.gov/documents/2016/09/14/2016-21665/controlled-unclassified-information). Some CUI specified categories have dissemination requirements (information can only be shared if certain conditions are met). Your organization must also meet those in order to properly protect that CUI from unauthorized disclosure. The most frequently discussed type is information regulated under export regulations such as [EAR](https://www.bis.gov/regulations/ear-overview) or [ITAR](https://www.pmddtc.state.gov/ddtc_public/ddtc_public?id=ddtc_public_portal_itar_landing). In particular, this information requires the DIB company to ensure that information is not “exported” to a foreign business or person without an export license. Cloud Services that meet FedRAMP moderate controls did not have a requirement to use [US Persons](https://www.ecfr.gov/current/title-31/subtitle-B/chapter-V/part-560/subpart-C/section-560.314) for the physical or remote support of the environment. This means if your organization places EAR, ITAR or CUI//SP-EXPT information into a FedRAMP moderate environment, you may be exposing export-controlled information to a non-US Person. If the cloud service meets FedRAMP Moderate controls, and the FedRAMP+ Controls (CUI overlay and/or National Security Overlay) for the DoD Cloud Service Provider Security Requirements Guide (SRG) Impact level 4, 5 or 6, then they meet the US persons requirement (but not necessarily the DFARS 252.204-7012 c through g clauses). The cloud service provider may also need to provide assurance that the information remains in the [sovereign](https://techcommunity.microsoft.com/t5/public-sector-blog/understanding-compliance-between-commercial-government-and-dod/ba-p/3258326) US data centers (no replication outside of it) so you meet export requirements as well.

![FedRamp](https://www.daymarksi.com/hs-fs/hubfs/FedRamp.png?width=974&height=397&name=FedRamp.png)

Figure 1: DoD Cloud Service Provider SRG, V1R1 Table 5.1

**Summary**

If processing CDI using a cloud service provider, it must meet:

- FedRAMP Moderate (or equivalent)
- Requirements c-g of DFARS 252.204-7012

If processing CDI that is also CUI Specified or export-controlled information, the cloud service provider **may **need to meet:

- FedRAMP moderate (or equivalent)
- Requirements c-g of DFARS 252.204-7012
- US Data Sovereignty
- US Person support and access only
- FedRAMP+ controls (CUI overlay and/or NSS overlay)
- DoD Cloud Service Provider Impact level 4, 5 or 6

It can be complex, but at Daymark Solutions, we are here to assist your business to ensure you select the correct cloud service provider level that will ensure your data is compliant and secure.

Daymark’s Government Community Cloud (GCC) Team provides a white glove approach to architecting and implementing Microsoft 365 GCC High and Azure Gov services across the entire landscape of solutions that includes:

- Tenant security baseline hardening
- Governance and compliance solutions
- Identity and endpoint management
- Email and data migrations
- Data protection threat intelligence and protection solutions

As an AOS-G Government Services Partner, Microsoft Direct Cloud Service Provider and **Microsoft AI Cloud Partner,** Daymark has the breadth and depth of proven expertise to design, implement and provide on-going support of highly customized secure enclaves in Microsoft 365 GCC High and Azure Gov cloud. We can help your team along your journey to CMMC 2.0 Compliance. [Contact us](https://www.daymarksi.com/cmmc-compliance-starts-here) to learn more.

 

 

### Subscribe to Daymark Insights

### Latest Posts

### Browse by Tag

- [Microsoft (88)](https://www.daymarksi.com/blog/topic/microsoft)
- [Cloud (70)](https://www.daymarksi.com/blog/topic/cloud)
- [Cole Tramp's Microsoft Insights (58)](https://www.daymarksi.com/blog/topic/cole-tramps-microsoft-insights)
- [Azure (55)](https://www.daymarksi.com/blog/topic/azure)
- [Security (49)](https://www.daymarksi.com/blog/topic/security)
- [Data Protection (43)](https://www.daymarksi.com/blog/topic/data-protection)
- [Microsoft Fabric (41)](https://www.daymarksi.com/blog/topic/microsoft-fabric)
- [Data Governance (38)](https://www.daymarksi.com/blog/topic/data-governance)
- [AI (35)](https://www.daymarksi.com/blog/topic/ai)
- [Partners (33)](https://www.daymarksi.com/blog/topic/partners)
- [Compliance (31)](https://www.daymarksi.com/blog/topic/compliance)
- [Data Center (30)](https://www.daymarksi.com/blog/topic/data-center)
- [CMMC (27)](https://www.daymarksi.com/blog/topic/cmmc)
- [Backup (26)](https://www.daymarksi.com/blog/topic/backup)
- [Daymark News (23)](https://www.daymarksi.com/blog/topic/daymark-news)
- [Storage (22)](https://www.daymarksi.com/blog/topic/storage)
- [GCC High (19)](https://www.daymarksi.com/blog/topic/gcc-high)
- [Veritas (18)](https://www.daymarksi.com/blog/topic/veritas)
- [Virtualization (18)](https://www.daymarksi.com/blog/topic/virtualization)
- [Cybersecurity (17)](https://www.daymarksi.com/blog/topic/cybersecurity)
- [Azure AI Foundry (16)](https://www.daymarksi.com/blog/topic/azure-ai-foundry)
- [Featured Gov (16)](https://www.daymarksi.com/blog/topic/featured-gov)
- [Government Cloud (16)](https://www.daymarksi.com/blog/topic/government-cloud)
- [Disaster Recovery (15)](https://www.daymarksi.com/blog/topic/disaster-recovery)
- [Cloud Backup (14)](https://www.daymarksi.com/blog/topic/cloud-backup)
- [Managed Services (13)](https://www.daymarksi.com/blog/topic/managed-services)
- [Copilot (11)](https://www.daymarksi.com/blog/topic/copilot)
- [Industry Expertise (9)](https://www.daymarksi.com/blog/topic/industry-expertise)
- [NIST SP 800-171 (7)](https://www.daymarksi.com/blog/topic/nist-sp-800-171)
- [Hybrid Cloud (6)](https://www.daymarksi.com/blog/topic/hybrid-cloud)
- [Networking (6)](https://www.daymarksi.com/blog/topic/networking)
- [Power BI (6)](https://www.daymarksi.com/blog/topic/power-bi)
- [Pure Storage (4)](https://www.daymarksi.com/blog/topic/pure-storage)
- [Reporting (3)](https://www.daymarksi.com/blog/topic/reporting)
- [Services (3)](https://www.daymarksi.com/blog/topic/services)
- [AI for Defense (2)](https://www.daymarksi.com/blog/topic/ai-for-defense)
- [Cloud Security (2)](https://www.daymarksi.com/blog/topic/cloud-security)
- [Everpure (2)](https://www.daymarksi.com/blog/topic/everpure)
- [GDPR (2)](https://www.daymarksi.com/blog/topic/gdpr)
- [Microsoft Purview (2)](https://www.daymarksi.com/blog/topic/microsoft-purview)
- [Apple (1)](https://www.daymarksi.com/blog/topic/apple)
- [CMMC 2.0 Requirements (1)](https://www.daymarksi.com/blog/topic/cmmc-2-0-requirements)
- [FedRamp AI (1)](https://www.daymarksi.com/blog/topic/fedramp-ai)
- [Mobile (1)](https://www.daymarksi.com/blog/topic/mobile)
- [Power Automate (1)](https://www.daymarksi.com/blog/topic/power-automate)

[see all](https://www.daymarksi.com/blog/navigating-fedramp-compliance-and-cloud-complexity-for-the-defense-industrial-base#)

### How Can We Help?  [![Speak With An Expert](https://no-cache.hubspot.com/cta/default/30865/5de282fd-640c-49b2-bf45-603dbee66842.png)](https://cta-redirect.hubspot.com/cta/redirect/30865/5de282fd-640c-49b2-bf45-603dbee66842)

#### About

Daymark Solutions is an experienced technology integration and solutions provider that helps organizations effectively architect, implement, and deploy customized solutions to help their customers grow and scale their IT infrastructure. Specializing in AI, cloud and modern data center solutions, Daymark’s unique combination of in-depth technical knowledge, extensive experience, and proven methodologies enable its customers to successfully address even the most difficult technology challenges.

#### Connect

<https://twitter.com/daymarksi>     <https://twitter.com/daymarksi><https://www.linkedin.com/company/daymark-solutions-inc./>

#### Links

- [About](https://www.daymarksi.com/about-daymark)
- [Industry Expertise](https://www.daymarksi.com/industry-experience-in-finance-healthcare-energy-utilities-and-life-sciences)
- [Solutions](https://www.daymarksi.com/solutions)
- [Services](https://www.daymarksi.com/services)
- [Cloud](https://www.daymarksi.com/services/custom-cloud-computing-implementations-and-services-in-new-england)
- [Resources](https://www.daymarksi.com/whitepapers-videos-analyst-reports-and-case-studies-on-information-technologies)
- [News & Events](https://www.daymarksi.com/news-events)
- [Blog](https://www.daymarksi.com/blog)

#### Contact

**Corporate Headquarters**  
Daymark Solutions  
131 Middlesex Turnpike  
Burlington, MA 01803

**Corporate:** [+1 781-359-3000](tel:17813593000)

**Email:** [info@daymarksi.com](mailto:info@daymarksi.com)

![DM_LogoTag_white.png](https://www.daymarksi.com/hs-fs/hubfs/Daymarksi-2017/Image/DM_LogoTag_white.png?width=176&name=DM_LogoTag_white.png "DM_LogoTag_white.png")

© 2026 Daymark Solutions, Inc. All rights reserved.  |  [Daymark Privacy Policy](https://www.daymarksi.com/hubfs/Daymark%20-%20Privacy%20Policy.pdf)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Paul Netopski",
    "url" : "https://www.daymarksi.com/blog/author/paul-netopski"
  },
  "dateModified" : "2024-07-15T15:36:54.444Z",
  "datePublished" : "2024-07-15T15:36:54.000Z",
  "headline" : "Navigating FedRAMP Compliance and Cloud Complexity for the Defense Industrial Base",
  "image" : [ "https://www.daymarksi.com/hubfs/compass-283234_1280.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.daymarksi.com/blog/navigating-fedramp-compliance-and-cloud-complexity-for-the-defense-industrial-base",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.daymarksi.com/hubfs/v2/images/daymark-logo.png"
    },
    "name" : "Daymark Solutions, Inc."
  }
}
```