12.2 Government Cloud Tiers, FedRAMP & DoD Compliance

Key Takeaways

  • Salesforce provides four distinct cloud deployment environments for public sector entities: Commercial Cloud, Salesforce Government Cloud (FedRAMP Moderate), Salesforce Government Cloud Plus (FedRAMP High / DoD IL2), and Salesforce Government Cloud Plus - Defense (DoD IL4 / IL5).
  • FedRAMP Moderate governs 325 NIST SP 800-53 security controls, whereas FedRAMP High enforces 421 controls, addressing high-impact data where loss of confidentiality, integrity, or availability could cause catastrophic harm to public operations, finances, or human safety.
  • The Department of Defense Cloud Computing Security Requirements Guide (DoD SRG) categorizes impact levels: IL2 covers non-controlled unclassified information, IL4 covers Controlled Unclassified Information (CUI) and export-controlled data (ITAR), and IL5 covers mission-critical national security systems (NSS).
  • Government Cloud Plus and Plus - Defense run on AWS GovCloud dedicated US infrastructure, physically and logically isolated from commercial cloud regions, operated strictly by screened US citizens on US soil.
  • Selecting the correct cloud tier requires precise statutory mapping: IRS Publication 1075 (FTI) and state Medicaid systems mandate FedRAMP High (Gov Cloud Plus), while defense weapons maintenance and military supply chains mandate DoD IL4/IL5 (Gov Cloud Plus - Defense).
Last updated: September 2026

12.2 Government Cloud Tiers, FedRAMP & DoD Compliance

Exam Focus: Federal, state, local, tribal, and defense agencies cannot deploy public sector workloads onto arbitrary commercial cloud infrastructure. They are legally bound by stringent regulatory compliance frameworks including FedRAMP (Federal Risk and Authorization Management Program) and the Department of Defense Cloud Computing Security Requirements Guide (DoD SRG). The AP-222 examination tests your ability to evaluate agency data sensitivity, identify statutory mandates (CJIS, HIPAA, IRS Pub 1075, ITAR, DoD IL), and architect the correct Salesforce Government Cloud environment.


The Public Sector Cloud Spectrum: Why Commercial Cloud Falls Short

In modern enterprise IT, commercial organizations prioritize global elasticity, public content delivery networks, and multi-region failover. However, public sector agencies operate under strict statutory constraints regarding:

  • Sovereignty & Data Residency: Data must never traverse international boundaries or be stored in foreign data centers.
  • Personnel Vetting: Operational, maintenance, and support personnel with access to the underlying hypervisors and databases must be screened US citizens.
  • Physical & Logical Boundary Isolation: Multi-tenant infrastructure must provide cryptographic and hardware-enforced boundaries to prevent side-channel attacks and unauthorized lateral access.
  • Continuous Compliance Monitoring: Systems must undergo rigorous third-party assessment organization (3PAO) audits against hundreds of NIST SP 800-53 security controls.

To meet these diverse public sector mandates, Salesforce maintains four distinct cloud hosting tiers.


Exhaustive Breakdown of Salesforce Cloud Environments

+-----------------------------------------------------------------------------------+
| Salesforce Cloud Environments Hierarchy                                           |
+-----------------------------------------------------------------------------------+
| [Tier 4] Gov Cloud Plus - Defense | DoD SRG IL4 & IL5 | CUI, ITAR, NSS            |
|          AWS GovCloud Infrastructure | Cleared US Citizens on US Soil             |
+-----------------------------------------------------------------------------------+
| [Tier 3] Gov Cloud Plus           | FedRAMP High (JAB) | DoD IL2 | IRS 1075       |
|          AWS GovCloud Infrastructure | Screened US Citizens on US Soil            |
+-----------------------------------------------------------------------------------+
| [Tier 2] Salesforce Gov Cloud     | FedRAMP Moderate | Dedicated US Instances     |
|          Salesforce Infrastructure | Screened US Citizens on US Soil              |
+-----------------------------------------------------------------------------------+
| [Tier 1] Commercial Cloud         | SOC 2, ISO 27001, HIPAA BAA                   |
|          Standard Global Multi-Tenant Infrastructure                              |
+-----------------------------------------------------------------------------------+

Tier 1: Commercial Multi-Tenant Cloud

  • Compliance Certifications: SOC 1/2/3, ISO 27001/27017/27018, PCI-DSS Level 1, HIPAA Business Associate Agreement (BAA) eligible.
  • Infrastructure: Standard global Salesforce multi-tenant data centers and public cloud infrastructure (Hyperforce) distributed worldwide.
  • Operations & Support: Follow-the-sun global engineering support. Personnel may be located outside the United States.
  • Target Public Sector Workloads: Municipal public parks and recreation bookings, non-sensitive civic engagement, tourism promotion, public transportation schedules, and municipal 311 citizen inquiries that contain zero confidential constituent disclosures, tax information, or law enforcement records.

Tier 2: Salesforce Government Cloud (FedRAMP Moderate)

  • Compliance Certifications: FedRAMP Moderate Authorized (Joint Authorization Board / Agency ATO), CJIS-ready, HIPAA BAA eligible. Satisfies the FedRAMP Moderate baseline — 323 NIST SP 800-53 Rev 5 controls (the Rev 4 baseline was 325).
  • Infrastructure: Dedicated, physically and logically isolated multi-tenant pods located exclusively within the continental United States (CONUS) hosted in Salesforce data centers.
  • Operations & Support: Operated and supported exclusively by US citizens on US soil. All support engineers, system administrators, and infrastructure personnel undergo background investigations.
  • Target Public Sector Workloads: Federal civilian agencies, state and local government licensing, permitting, and inspection systems where data loss or compromise would cause moderate adverse impact (e.g., operational disruption, financial loss, or individual distress).

Tier 3: Salesforce Government Cloud Plus (FedRAMP High & DoD IL2)

  • Compliance Certifications: FedRAMP High JAB Provisional Authority to Operate (P-ATO), DoD Cloud Computing SRG Impact Level 2 (IL2), CJIS compliant, IRS Publication 1075 (Federal Tax Information) compliant, HIPAA compliant. Evaluated against the FedRAMP High baseline — 410 NIST SP 800-53 Rev 5 controls (the Rev 4 baseline was 421).
  • Infrastructure: Hosted on AWS GovCloud (US) infrastructure, isolated from commercial AWS regions. Features enhanced perimeter security, dedicated hardware cryptographic modules, FIPS 140-2/140-3 validated encryption, and private fiber connectivity.
  • Operations & Support: Strictly operated and maintained by screened US citizens residing on US soil. Support calls and tickets are routed exclusively to US-based support queues.
  • Target Public Sector Workloads: State health and human services (Medicaid, SNAP, Child Welfare), state departments of revenue (handling federal tax data), federal law enforcement administration, veterans' health affairs, and public assistance programs managing critical constituent PII, ePHI, and financial disclosures.

Tier 4: Salesforce Government Cloud Plus - Defense (DoD Impact Levels 4 & 5)

  • Compliance Certifications: Department of Defense Cloud Computing Security Requirements Guide (DoD SRG) Impact Level 4 (IL4) and Impact Level 5 (IL5) JAB P-ATO.
  • Infrastructure: Hosted within isolated AWS GovCloud (US) defense partitions. Orgs use salesforce.mil fully qualified domain names routed through the Defense Information Systems Agency (DISA) Boundary Cloud Access Point (BCAP) and NIPRNet IP ranges, with EEMSG email security, cryptographic separation, and continuous vulnerability scanning. Note that IL5 covers unclassified national security information — it is a NIPRNet capability, not a SIPRNet (Secret) one, and Salesforce does not offer a Top Secret environment.
  • Operations & Support: Operated strictly by US citizens on US soil holding active DoD security clearances and background investigations (Tier 3 / Secret eligibility).
  • Target Workloads & Data Classifications:
    • Controlled Unclassified Information (CUI): Sensitive government data that requires safeguarding or dissemination controls pursuant to applicable laws, regulations, and government-wide policies (e.g., military supply chain data, personnel records, defense research).
    • International Traffic in Arms Regulations (ITAR) & Export Administration Regulations (EAR): Technical data regarding defense articles, munitions, and tactical aerospace components.
    • DoD IL5 (Unclassified National Security Information, U-NSI): Mission-critical defense operations, military readiness tracking, tactical equipment maintenance, unclassified intelligence mission support, and defense nuclear security programs.

Comprehensive Cloud Tier Compliance Mapping Matrix

Architectural DimensionCommercial CloudGovernment CloudGovernment Cloud PlusGovernment Cloud Plus - Defense
FedRAMP BaselineN/A (Commercial)FedRAMP ModerateFedRAMP HighFedRAMP High
DoD SRG LevelN/AN/ADoD Impact Level 2 (IL2)DoD Impact Level 4 & 5 (IL4/IL5)
NIST 800-53 Rev 5 ControlsCommercial baseline (not FedRAMP)323 (FedRAMP Moderate)410 (FedRAMP High)410 + DoD SRG enhancements
Permitted Data TypesPublic data, non-sensitive PIIGeneral PII, licensing, standard government dataSensitive PII, ePHI, IRS 1075 (FTI), CJIS, Public AssistanceDoD CUI, ITAR, EAR, Mission-Critical National Security Systems
Underlying InfrastructureCommercial Salesforce / HyperforceDedicated US Salesforce PodsAWS GovCloud (US)AWS GovCloud (US) Defense Enclaves
Personnel & OperationsGlobal support personnelUS Citizens on US SoilUS Citizens on US SoilCleared US Citizens on US Soil (DoD Vetted)
Network ConnectivityStandard Internet / Public CDNInternet / Direct ConnectInternet / AWS Direct Connect / GovCloud PeeringDISA Boundary Cloud Access Point (BCAP) / NIPRNet ranges / salesforce.mil FQDNs

Mapping Agency Requirements to the Correct Cloud Tier: The Evaluation Algorithm

On the AP-222 exam, candidates are presented with complex agency RFP scenarios and asked to select the appropriate cloud tier. Use the following decision algorithm:

+---------------------------------------------------------------------------------+
| Cloud Tier Selection Decision Algorithm                                         |
+---------------------------------------------------------------------------------+
| 1. Does the workload involve DoD CUI, ITAR technical data, or Mission Systems?  |
|    --> YES: Select Government Cloud Plus - Defense (DoD IL4/IL5)                |
|                                                                                 |
| 2. Does the agency process IRS 1075 (FTI), Medicaid ePHI, or FedRAMP High PII?   |
|    --> YES: Select Government Cloud Plus (FedRAMP High / DoD IL2)               |
|                                                                                 |
| 3. Is it a US federal civilian, state, or local agency requiring US soil ops?   |
|    --> YES: Select Salesforce Government Cloud (FedRAMP Moderate)               |
|                                                                                 |
| 4. Is the workload purely public civic engagement with zero confidential data?  |
|    --> YES: Commercial Cloud is acceptable                                      |
+---------------------------------------------------------------------------------+

Crucial Exam Decision Rules:

  1. IRS Publication 1075 (FTI): If an agency handles Federal Tax Information from the IRS, it must be deployed on Salesforce Government Cloud Plus (or higher) to satisfy mandatory FedRAMP High physical/logical segregation and encryption mandates.
  2. DoD and Defense Contractors: Any project involving the US Department of Defense, Armed Forces branches (Army, Navy, Air Force, Marines, Space Force), or defense contractors handling defense supply chain records containing CUI or ITAR must use Government Cloud Plus - Defense (IL4/IL5).
  3. State Health and Human Services: Medicaid management information systems (MMIS), SNAP benefits, and integrated eligibility systems handling sensitive public assistance records require Government Cloud Plus (FedRAMP High) due to the catastrophic impact of data breaches on vulnerable populations.
  4. General Licensing & Municipal Permitting: Standard municipal pet licensing, commercial building permits, and business registrations that do not involve criminal justice or tax data are fully supported on Salesforce Government Cloud (FedRAMP Moderate).

Architectural & Integration Implications of Government Cloud

When architecting solutions for Government Cloud tiers, architects must account for operational boundaries:

  1. Feature Release Parity: While Salesforce strives for simultaneous releases, certain bleeding-edge AI or platform services must undergo formal FedRAMP 3PAO security audits and JAB approval before being authorized in Gov Cloud Plus or Gov Cloud Plus - Defense. Always consult the official Salesforce Government Cloud Trust and Compliance documentation to verify feature authorization status.
  2. Outbound Integrations & IP Whitelisting: Government Cloud environments employ strict perimeter firewalls. Integrations with on-premises state mainframes or state agency databases require pre-allocating dedicated egress IP ranges, configuring mutual TLS (mTLS), or establishing dedicated network tunnels via AWS Direct Connect or GovCloud VPC Peering.
  3. Identity Federation (PIV/CAC): Federal and defense agencies require multi-factor authentication using Personal Identity Verification (PIV) or Common Access Cards (CAC). PSS in Gov Cloud natively integrates with external Identity Providers (such as Okta for Government, Microsoft Entra ID Government, or PingFederate) via SAML 2.0 and OpenID Connect (OIDC).

💡 Real-World Exam Scenarios & Case Analysis

Scenario 1: State Department of Motor Vehicles Modernization

A state Department of Motor Vehicles (DMV) is replacing its driver licensing and vehicle registration platform. The system will store driver facial biometric images, Social Security Numbers, organ donor declarations (HIPAA), and direct integration with the FBI's National Crime Information Center (NCIC) via the state police for real-time warrant checks (CJIS). The state IT governance board mandates that all systems processing CJIS and biometric records must operate at FedRAMP High.

Which Salesforce environment must the consultant recommend?

  • Recommendation: Salesforce Government Cloud Plus.
  • Justification: Gov Cloud Plus holds FedRAMP High JAB authorization, is hosted on isolated AWS GovCloud infrastructure, is operated exclusively by US citizens on US soil, and natively meets the stringent technical controls mandated by the FBI CJIS Security Policy and HIPAA.

Scenario 2: Defense Logistics & Base Facility Permitting

A commercial aerospace contractor is managing construction, hazardous materials storage, and secure facility access permits for a naval air station under contract with the US Department of the Navy. The blueprints and chemical inventories are classified as Controlled Unclassified Information (CUI) and subject to International Traffic in Arms Regulations (ITAR).

Which deployment tier satisfies these statutory mandates?

  • Recommendation: Salesforce Government Cloud Plus - Defense.
  • Justification: CUI and ITAR technical data require Department of Defense Impact Level 4 (IL4) or Impact Level 5 (IL5) compliance. Only Government Cloud Plus - Defense satisfies DoD SRG IL4/IL5 and provides DISA Cloud Access Point connectivity with cleared US citizen operational staffing.
Loading diagram...
Salesforce Cloud Tiers, Compliance Frameworks & Impact Levels
Test Your Knowledge

A major aerospace defense contractor is collaborating with the US Air Force on military base maintenance operations. The solution will process building permits, hazardous materials storage registrations, and flight line inspection checklists containing Controlled Unclassified Information (CUI) and technical data governed by International Traffic in Arms Regulations (ITAR). Which Salesforce environment must be selected to satisfy these defense compliance mandates?

A
B
C
D
Test Your Knowledge

A state Department of Health and Human Services is architecting an integrated eligibility system managing Medicaid enrollments, SNAP nutritional assistance, and state tax verification data governed by IRS Publication 1075. Compromise of this data would result in catastrophic financial and identity harm to vulnerable constituents. What is the minimum Salesforce cloud environment required to satisfy these statutory compliance mandates?

A
B
C
D
Test Your Knowledge

Which operational and security control is strictly enforced across all Salesforce Government Cloud and Government Cloud Plus environments?

A
B
C
D