AWS Public Sector Blog
Run SAP workloads at DoD Impact Level 5 with SAP NS2 on AWS GovCloud (US)

Department of Defense (DoD) organizations increasingly rely on enterprise resource planning (ERP) software to manage logistics, finance, human resources, and supply chain operations. When those workloads involve Controlled Unclassified Information (CUI) for national security systems or mission-critical data that, if compromised, could cause serious harm to national defense, they require protections at Impact Level 5 (IL5) per the Defense Information Systems Agency (DISA) Cloud Computing Security Requirements Guide (CC SRG).
SAP National Security Services (SAP NS2®) gives customers the option to run their SAP cloud portfolio on AWS GovCloud (US), which holds a DISA Provisional Authorization for IL2, IL4, and IL5 workloads. This means DoD agencies and defense organizations can run their most sensitive unclassified SAP workloads in an environment purpose-built for national security.
In this post, we explain what IL5 requires, how AWS GovCloud (US) and SAP NS2 meet those requirements together, and how defense organizations can get started.
What is Impact Level 5?
The DISA CC SRG defines six impact levels for cloud-hosted information. IL5 accommodates the following:
- CUI for national security systems – Information whose loss could cause serious damage to national security
- Unclassified national security information – Data requiring enhanced protections beyond general CUI
- DoD mission-critical data – Higher sensitivity than IL4, requiring additional controls around personnel, physical access, and data residency
The following table summarizes the IL5 requirements beyond FedRAMP High. FedRAMP High is the Federal Risk and Authorization Management Program’s most rigorous baseline for cloud service providers handling sensitive government data. IL5 builds on FedRAMP High with additional requirements:
| Requirement | IL5 enhancement |
|---|---|
| Personnel | US persons only for cloud infrastructure access |
| Physical separation | Dedicated infrastructure or equivalent logical isolation |
| Data residency | Data must remain within the US |
| Incident response | Enhanced timelines and DoD-specific reporting |
| Network isolation | Dedicated interconnections; no shared commercial internet paths for CUI |
AWS GovCloud (US): The IL5-authorized foundation
AWS GovCloud (US) is an isolated pair of AWS Regions designed for sensitive government workloads:
- DISA Provisional Authorization at IL2, IL4, and IL5
- FedRAMP High baseline authorization (JAB P-ATO)
- Operated by US citizens on US soil
- Physically and logically isolated from commercial Regions
- ITAR, CJIS, HIPAA, and EAR compliant
AWS GovCloud (US) provides over 130 services authorized at IL5, including:
- Compute – Amazon Elastic Compute Cloud (Amazon EC2)
- Storage – Amazon Simple Storage Service (Amazon S3)
- Databases – Amazon Relational Database Service (Amazon RDS)
- Analytics – Amazon Redshift
- AI and machine learning – Amazon Bedrock, Amazon SageMaker
- Security services – AWS Key Management Service (AWS KMS), AWS CloudTrail, Amazon GuardDuty
SAP NS2: Enterprise application software at IL5 on AWS GovCloud
SAP NS2 is the only SAP provider authorized to deliver SAP’s enterprise application software for US national security customers. SAP NS2 offers the following solutions running on AWS GovCloud (US):
- SAP S/4HANA Cloud Private Edition – Mission ERP for defense logistics, finance, and procurement
- SAP Business Technology Platform (SAP BTP) – Integration and application development
- SAP Integrated Business Planning – Defense forecasting, demand management, and response and supply planning
Key architectural controls for IL5
IL5 uses the following architectural controls:
- Network – AWS Direct Connect provides dedicated DISN connectivity. AWS PrivateLink confirms SAP application traffic doesn’t traverse the public internet. AWS Network Firewall inspects and enforces traffic policies.
- Encryption – AWS KMS with customer managed keys provides FIPS 140-2 validated encryption for data at rest and in transit.
- Identity – AWS Identity and Access Management (IAM) and SAP identity services enforce role-based access with multi-factor authentication (MFA). Access is by US persons.
- Monitoring – AWS CloudTrail, Amazon GuardDuty, and AWS Security Hub provide continuous monitoring with DoD-aligned alerting timelines.
- Data residency – Data remains within AWS GovCloud (US) Regions in the continental US.
“When the right security and innovations are seamlessly delivered together, agencies can move beyond legacy systems and accelerate transformation with confidence in security, continuity, and performance. Our SAP innovations deployed on AWS GovCloud are tailored to support the most sensitive mission needs. From Controlled Unclassified Information to mission-critical operations, we’re providing a trusted foundation for ERP, integration, and innovation at scale.”
— SAP National Security Services
Benefits for DoD organizations
SAP NS2 and AWS together provide a secure, scalable cloud foundation that supports mission needs while reducing compliance and operational burden for DoD customers. Key benefits include:
- Compliance confidence – AWS GovCloud (US) IL5 PA + SAP NS2 FedRAMP High + IL5 Baseline with SRG IL5 Security controls. ITAR, CNSSI 1253 (DoD Privacy Overlay) and NSS overlay provides layered, validated compliance.
- Mission readiness – Modern SAP cloud capabilities are available within DoD security boundaries.
- Operational efficiency – Managed SAP infrastructure reduces the burden of maintaining self-hosted SAP environments in legacy data centers.
- Faster ATO – Inheriting controls from AWS and SAP NS2 can reduce assessment scope and help mission owners streamline the authorization process.
- Scalability – Elastic compute supports peak operational demands, such as surge logistics and mobilization planning, without requiring over-provisioning.
Get started
To get started, take the following next steps:
- Learn more about SAP NS2 defense solutions
- Explore AWS GovCloud (US) DoD SRG compliance
- Review the compliant framework for DoD workloads on GitHub (awslabs)
- Contact your AWS account team to discuss SAP at IL5 on AWS