AWS Public Sector Blog

Run SAP workloads at DoD Impact Level 5 with SAP NS2 on AWS GovCloud (US)

Run SAP workloads at DoD Impact Level 5 with SAP NS2 on AWS GovCloud (US)

Department of Defense (DoD) organizations increasingly rely on enterprise resource planning (ERP) software to manage logistics, finance, human resources, and supply chain operations. When those workloads involve Controlled Unclassified Information (CUI) for national security systems or mission-critical data that, if compromised, could cause serious harm to national defense, they require protections at Impact Level 5 (IL5) per the Defense Information Systems Agency (DISA) Cloud Computing Security Requirements Guide (CC SRG).

SAP National Security Services (SAP NS2®) gives customers the option to run their SAP cloud portfolio on AWS GovCloud (US), which holds a DISA Provisional Authorization for IL2, IL4, and IL5 workloads. This means DoD agencies and defense organizations can run their most sensitive unclassified SAP workloads in an environment purpose-built for national security.

In this post, we explain what IL5 requires, how AWS GovCloud (US) and SAP NS2 meet those requirements together, and how defense organizations can get started.

What is Impact Level 5?

The DISA CC SRG defines six impact levels for cloud-hosted information. IL5 accommodates the following:

  1. CUI for national security systems – Information whose loss could cause serious damage to national security
  2. Unclassified national security information – Data requiring enhanced protections beyond general CUI
  3. DoD mission-critical data – Higher sensitivity than IL4, requiring additional controls around personnel, physical access, and data residency

The following table summarizes the IL5 requirements beyond FedRAMP High. FedRAMP High is the Federal Risk and Authorization Management Program’s most rigorous baseline for cloud service providers handling sensitive government data. IL5 builds on FedRAMP High with additional requirements:

Requirement IL5 enhancement
Personnel US persons only for cloud infrastructure access
Physical separation Dedicated infrastructure or equivalent logical isolation
Data residency Data must remain within the US
Incident response Enhanced timelines and DoD-specific reporting
Network isolation Dedicated interconnections; no shared commercial internet paths for CUI

AWS GovCloud (US): The IL5-authorized foundation

AWS GovCloud (US) is an isolated pair of AWS Regions designed for sensitive government workloads:

  1. DISA Provisional Authorization at IL2, IL4, and IL5
  2. FedRAMP High baseline authorization (JAB P-ATO)
  3. Operated by US citizens on US soil
  4. Physically and logically isolated from commercial Regions
  5. ITAR, CJIS, HIPAA, and EAR compliant

AWS GovCloud (US) provides over 130 services authorized at IL5, including:

SAP NS2: Enterprise application software at IL5 on AWS GovCloud

SAP NS2 is the only SAP provider authorized to deliver SAP’s enterprise application software for US national security customers. SAP NS2 offers the following solutions running on AWS GovCloud (US):

  1. SAP S/4HANA Cloud Private Edition – Mission ERP for defense logistics, finance, and procurement
  2. SAP Business Technology Platform (SAP BTP) – Integration and application development
  3. SAP Integrated Business Planning – Defense forecasting, demand management, and response and supply planning

Key architectural controls for IL5

IL5 uses the following architectural controls:

  • Network – AWS Direct Connect provides dedicated DISN connectivity. AWS PrivateLink confirms SAP application traffic doesn’t traverse the public internet. AWS Network Firewall inspects and enforces traffic policies.
  • Encryption – AWS KMS with customer managed keys provides FIPS 140-2 validated encryption for data at rest and in transit.
  • Identity – AWS Identity and Access Management (IAM) and SAP identity services enforce role-based access with multi-factor authentication (MFA). Access is by US persons.
  • Monitoring – AWS CloudTrail, Amazon GuardDuty, and AWS Security Hub provide continuous monitoring with DoD-aligned alerting timelines.
  • Data residency – Data remains within AWS GovCloud (US) Regions in the continental US.

“When the right security and innovations are seamlessly delivered together, agencies can move beyond legacy systems and accelerate transformation with confidence in security, continuity, and performance. Our SAP innovations deployed on AWS GovCloud are tailored to support the most sensitive mission needs. From Controlled Unclassified Information to mission-critical operations, we’re providing a trusted foundation for ERP, integration, and innovation at scale.”
— SAP National Security Services

Benefits for DoD organizations

SAP NS2 and AWS together provide a secure, scalable cloud foundation that supports mission needs while reducing compliance and operational burden for DoD customers. Key benefits include:

  • Compliance confidence – AWS GovCloud (US) IL5 PA + SAP NS2 FedRAMP High + IL5 Baseline with SRG IL5 Security controls. ITAR, CNSSI 1253 (DoD Privacy Overlay) and NSS overlay provides layered, validated compliance.
  • Mission readiness – Modern SAP cloud capabilities are available within DoD security boundaries.
  • Operational efficiency – Managed SAP infrastructure reduces the burden of maintaining self-hosted SAP environments in legacy data centers.
  • Faster ATO – Inheriting controls from AWS and SAP NS2 can reduce assessment scope and help mission owners streamline the authorization process.
  • Scalability – Elastic compute supports peak operational demands, such as surge logistics and mobilization planning, without requiring over-provisioning.

Get started

To get started, take the following next steps:

  1. Learn more about SAP NS2 defense solutions
  2. Explore AWS GovCloud (US) DoD SRG compliance
  3. Review the compliant framework for DoD workloads on GitHub (awslabs)
  4. Contact your AWS account team to discuss SAP at IL5 on AWS
Raj Marpu

Raj Marpu

Raj Marpu is a Principal Technologist at AWS focused on SAP workloads for US government and defense customers. He partners with DoD agencies and ISV partners like SAP NS2 to architect secure, compliant SAP environments on AWS GovCloud (US). Outside of work, Raj enjoys exploring cloud architecture patterns and mentoring early-career technologists.

Jeff Karl

Jeff Karl

Jeff Karl is a Senior Account Executive at AWS supporting SAP NS2 and the US Federal defense community. He works with DoD organizations to align SAP enterprise solutions with mission requirements on AWS GovCloud (US).