Skip to main content

Compliance as code for federal DevSecOps. Now accepting design partners

REAEGIS
DOD IL4 / IL5

IL4 and IL5 authorization in environments where SaaS cannot operate.

Air-gapped deployment. eMASS integration. STIG alignment.

The IL4/IL5 constraint

The tooling must operate inside the boundary.

The DoD Cloud Computing Security Requirements Guide defines impact levels for cloud services hosting DoD information. Impact Level 4 covers Controlled Unclassified Information. Impact Level 5 covers National Security Systems.

Source: DoD Cloud Computing SRG v1r4

Programs operating at IL4 and IL5 face a compliance tooling constraint that does not exist in commercial environments: the tooling must operate in the same environment as the system it monitors. A compliance platform with runtime dependencies on external cloud APIs, commercial license servers, or public vulnerability databases cannot function in a disconnected environment.

eMASS — the Enterprise Mission Assurance Support Service — is the DoD system of record for RMF authorizations. All IL4 and IL5 programs maintain their System Security Plans, POA&M items, and authorization records in eMASS. Compliance tooling that cannot integrate with eMASS creates a manual export and translation step at every authorization milestone.

DISA maintains the STIG library — Security Technical Implementation Guides that specify the technical hardening baseline for operating systems, network devices, and applications in DoD environments. STIG compliance is a condition of authorization at IL4 and IL5. Programs need to track open STIG findings, document applicable/not-applicable determinations, and maintain evidence of sustained compliance.

eMASS Integration

Three-tier eMASS integration.

eMASS integration requirements vary by classification level and network availability. REAEGIS supports three integration tiers:

Tier 1

CSV export for NIPRNet programs

POA&M items exported in the eMASS import format for manual upload. Artifact packages exported with the metadata structure eMASS expects. System IDs and control ID formats maintained per eMASS convention.

Tier 2

Self-hosted agent for IL4/IL5

A lightweight agent deployed inside the authorization boundary synchronizes POA&M status and assessment results to eMASS without requiring direct external connectivity from the REAEGIS instance.

Tier 3

Direct REST integration for SIPRNet-connected programs

Direct API integration where network policy permits, eliminating the manual export step entirely.

The eMASS integration format — column names, date formats, control ID notation — is maintained as authoritative configuration. Artifacts produced by REAEGIS for eMASS submission are formatted to import without manual reformatting.

Air-gapped deployment

No cloud dependency. No external API calls. Full compliance automation at IL5.

The REAEGIS air-gapped kit ships as a signed OCI bundle with offline vulnerability databases, an internal transparency log, and all scanner engines. The same evaluation gates, the same remediation workflow, the same OSCAL output — inside your boundary. The ISSM verifies the kit signature before installation.

Talk to the team about IL4/IL5.

IL4/IL5 deployment requires a scoping conversation. Contact us to discuss your environment and boundary constraints.

Get started

Authorization is not a destination.It is a system property.

REAEGIS is the infrastructure that maintains it — converting every commit, scan, and approval into evidence your Authorizing Official can act on.

Explore the platform