IL4 and IL5 authorization in environments where SaaS cannot operate.
Air-gapped deployment. eMASS integration. STIG alignment.
The tooling must operate inside the boundary.
The DoD Cloud Computing Security Requirements Guide defines impact levels for cloud services hosting DoD information. Impact Level 4 covers Controlled Unclassified Information. Impact Level 5 covers National Security Systems.
Source: DoD Cloud Computing SRG v1r4
Programs operating at IL4 and IL5 face a compliance tooling constraint that does not exist in commercial environments: the tooling must operate in the same environment as the system it monitors. A compliance platform with runtime dependencies on external cloud APIs, commercial license servers, or public vulnerability databases cannot function in a disconnected environment.
eMASS — the Enterprise Mission Assurance Support Service — is the DoD system of record for RMF authorizations. All IL4 and IL5 programs maintain their System Security Plans, POA&M items, and authorization records in eMASS. Compliance tooling that cannot integrate with eMASS creates a manual export and translation step at every authorization milestone.
DISA maintains the STIG library — Security Technical Implementation Guides that specify the technical hardening baseline for operating systems, network devices, and applications in DoD environments. STIG compliance is a condition of authorization at IL4 and IL5. Programs need to track open STIG findings, document applicable/not-applicable determinations, and maintain evidence of sustained compliance.
Three-tier eMASS integration.
eMASS integration requirements vary by classification level and network availability. REAEGIS supports three integration tiers:
CSV export for NIPRNet programs
POA&M items exported in the eMASS import format for manual upload. Artifact packages exported with the metadata structure eMASS expects. System IDs and control ID formats maintained per eMASS convention.
Self-hosted agent for IL4/IL5
A lightweight agent deployed inside the authorization boundary synchronizes POA&M status and assessment results to eMASS without requiring direct external connectivity from the REAEGIS instance.
Direct REST integration for SIPRNet-connected programs
Direct API integration where network policy permits, eliminating the manual export step entirely.
The eMASS integration format — column names, date formats, control ID notation — is maintained as authoritative configuration. Artifacts produced by REAEGIS for eMASS submission are formatted to import without manual reformatting.
No cloud dependency. No external API calls. Full compliance automation at IL5.
The REAEGIS air-gapped kit ships as a signed OCI bundle with offline vulnerability databases, an internal transparency log, and all scanner engines. The same evaluation gates, the same remediation workflow, the same OSCAL output — inside your boundary. The ISSM verifies the kit signature before installation.
Talk to the team about IL4/IL5.
IL4/IL5 deployment requires a scoping conversation. Contact us to discuss your environment and boundary constraints.
Authorization is not a destination.
It is a system property.
REAEGIS is the infrastructure that maintains it — converting every commit, scan, and approval into evidence your Authorizing Official can act on.
