UPDATED · 20 JUN 2026 · EDIT ON GITHUB
GUIDES · SECTORS

Public sector: FedRAMP & impact-level mapping.

Federal work adds a vocabulary — impact levels, ATOs, package artifacts. Here is what those terms mean for a threatDefendr deployment, and how each maps to something concrete in the platform.

12 min read Beginner By K. Singh

Impact levels

Impact level sets the controls and the environment. Most civilian workloads land at moderate; defense and higher-sensitivity workloads move to GovCloud and IL4 or IL5.

LevelForLands as
FedRAMP ModerateMost civilian agency dataCommercial region, full controls.
IL4Controlled unclassified informationGovCloud, hardened boundary.
IL5Higher-sensitivity defense dataGovCloud High, dedicated cell.

The authorization path

An ATO is a package, not a single document. The platform supplies the artifacts an assessor expects — a current boundary diagram, the control-responsibility matrix, and immutable audit evidence keyed to each control.

How it lands in the platform

The mapping is concrete: choose the impact level, deploy into the matching environment, and the evidence generates from the live system rather than from a static drawing that drifts the day after you submit it.

The package reflects what runs. Boundary diagrams and the responsibility matrix generate from the live deployment, so your SSP stays current as the system changes. The full deployment path is in GovCloud / FedRAMP High deployment.

Where to go next

← PREV OT / ICS detection patterns ALL GUIDES → Browse all guides