docs/main/security-guide/compliance-frameworks/dod-il-4-5.mdx
<AttestationStatus framework="DoD IL4 / IL5" status="roadmap" asOf="2026-05-11" detailsHref="https://mattermost.com/trust/" />
<EditionAvailability tiers="enterprise,enterprise-advanced" /> <DeploymentAvailability modes="self-hosted,cloud-government,air-gapped" />This page documents Mattermost's posture against the DoD Cloud Computing Security Requirements Guide (CC SRG) Impact Level (IL) 4 and Impact Level 5 baselines. IL4 covers Controlled Unclassified Information (CUI) including export-controlled and mission-critical data. IL5 covers National Security Systems data and unclassified information requiring a higher level of protection than IL4.
:::important Status
Current status is Roadmap — see the <AttestationStatus> badge above. Mattermost is FedRAMP Moderate–aligned (see FedRAMP Moderate), which is the standard prerequisite for IL4 sponsorship. IL5 additionally requires US-citizen-only operational support and dedicated infrastructure.
This page documents the gap honestly: what controls are met today via the FedRAMP Moderate baseline, what additional controls IL4/IL5 require beyond FedRAMP Moderate, and the customer's role in deploying Mattermost inside an authorized boundary. :::
| Level | Data classification | Network | Mattermost availability |
|---|---|---|---|
| IL2 | Non-controlled, non-CUI | Internet-accessible | Standard Mattermost Cloud is suitable; no special configuration required. |
| IL4 | CUI (including export-controlled, PHI, FOUO) | DISA NIPRNet boundary (CAP) | Self-Hosted Enterprise on AWS GovCloud (US) or Azure Government, customer-managed authorization boundary. |
| IL5 | National Security Systems, mission-critical | DISA NIPRNet (dedicated) | Self-Hosted Enterprise on AWS GovCloud (US) or Azure Government, dedicated single-tenant infrastructure, US-citizen-only operational support, customer-managed authorization boundary. |
| IL6 | Classified up to Secret | SIPRNet | Self-Hosted Enterprise in customer-managed enclave (out of scope for this page — see Air-Gapped Operations). |
A Mattermost deployment that meets the configuration on the FedRAMP Moderate page inherits the majority of the IL4 / IL5 control baseline. The CC SRG explicitly maps DoD impact levels to NIST 800-53 baselines:
Customers pursuing IL4 / IL5 authorization should start with the FedRAMP Moderate configuration as the baseline.
| Requirement | Mattermost support |
|---|---|
| FIPS 140-3 validated cryptographic modules in all data paths | Deploy using the FIPS-compliant container image. See FIPS / STIG container builds. |
| TLS 1.2+ exclusively; no TLS 1.0 / 1.1 | Configure in NGINX / reverse proxy per Setup TLS. |
| Data-at-rest encryption | See Encryption Options. |
| Key management aligned with NIST 800-57 | Customer-managed via HSM, AWS KMS, Azure Key Vault, or equivalent. |
IL4 / IL5 require traffic to traverse a DISA CAP. Mattermost does not provide the CAP; customers deploy Mattermost behind their authorized CAP.
| Requirement | Mattermost support |
|---|---|
| Audit log immutability and retention ≥ 1 year (IL4) / ≥ 3 years (IL5) | JSON audit log + customer-managed SIEM export. Configure retention at the SIEM and the storage tier. |
| Audit log content includes all NIST 800-53 AU-3 fields | Documented in Audit Log Reference (Phase 2). |
| Real-time audit log monitoring | Customer-managed via SIEM integration (Splunk, ELK, OpenSearch, etc.). |
| Tamper-evident audit log integrity controls | Customer-managed at the SIEM tier; Mattermost does not sign audit log entries at emission. |
| Requirement | Mattermost support |
|---|---|
| PIV / CAC smart-card authentication | Supported via SAML federation with a customer-managed IdP that supports CAC (Entra ID + ADFS with CAC, Okta with CAC, etc.). |
| Multi-factor authentication for all users | Enforced via the IdP. Mattermost honors the IdP's MFA assertion. |
| Account inactivity lockout | Configured via the IdP. |
| Privileged account separation | Custom roles + ABAC (Enterprise Advanced). |
IL5 specifically: Operational support personnel with access to Mattermost infrastructure must be US citizens. Mattermost provides Enterprise support tiers; for IL5 deployments, customers either:
IL5 requires dedicated, non-shared infrastructure. Mattermost Cloud (multi-tenant) is not suitable for IL5. Self-Hosted on customer-dedicated infrastructure (AWS GovCloud single-tenant, Azure Government single-tenant, or on-premises) is the supported path.
A Mattermost deployment aligned with IL4 / IL5 requires, at minimum:
DoD IL authorizations are customer-led. Mattermost provides the validated configuration and feature support documented on this page; customers are responsible for:
Mattermost will provide attestation letters, FIPS certificates, and configuration evidence to support a customer's authorization package on request via https://mattermost.com/trust/.