Readiness check
Platforms / AWS GovCloud (US)

If you already run on AWS, the boundary belongs here.

AWS GovCloud (US) is FedRAMP High authorized and covers DoD SRG Impact Levels 2, 4, and 5. That means it satisfies the DFARS 7012 cloud requirement directly — no second estate. We build and operate the CUI boundary inside your GovCloud accounts.

Build on AWS GovCloud
FedRAMPHigh (authorized)
DoD SRGIL2 · IL4 · IL5
DFARS 7012 cloud req.Satisfied directly
ITAR dataUS-person controls
Why it counts

Authorized, on the Marketplace. That's the distinction that matters.

The December 2023 DoD memo is clear: a FedRAMP-authorized cloud on the Marketplace satisfies DFARS 7012 directly, while an "equivalent" cloud makes you prove 100% of the FedRAMP Moderate baseline with no open POA&Ms. AWS GovCloud is authorized. You inherit that authorization instead of defending an equivalence claim.

Who owns what

The shared-responsibility split, written down.

Inherited from AWS Built & run by Aletheon Owned by you
Physical & environmental Data centers, hardware
Cloud FedRAMP authorization FedRAMP High ATO
Account & network architecture Designed & deployed
Identity, encryption, logging Service primitivesConfigured to controls
Evidence, SSP, monitoring Maintained continuouslyReviewed with you
Your CUI, users & business decisions GuidedYours to own
Physical & environmental
Inherited from AWS Data centers, hardware
Built & run by Aletheon
Owned by you
Cloud FedRAMP authorization
Inherited from AWS FedRAMP High ATO
Built & run by Aletheon
Owned by you
Account & network architecture
Inherited from AWS
Built & run by Aletheon Designed & deployed
Owned by you
Identity, encryption, logging
Inherited from AWS Service primitives
Built & run by Aletheon Configured to controls
Owned by you
Evidence, SSP, monitoring
Inherited from AWS
Built & run by Aletheon Maintained continuously
Owned by you Reviewed with you
Your CUI, users & business decisions
Inherited from AWS
Built & run by Aletheon Guided
Owned by you Yours to own
What we build with

GovCloud services, configured to the controls.

IAM & Identity Center
AC · IA
KMS & CloudHSM
SC
CloudTrail & Config
AU · CM
GuardDuty & Security Hub
SI · IR
VPC & Network Firewall
SC
Organizations & SCPs
AC · CM
Macie & S3 controls
MP · SC
CodePipeline (DevSecOps)
CM · SA
Service list illustrative; exact architecture set during the Enclave build. [confirm — per engagement]

Already on AWS? Let's scope the boundary.

A readiness check maps your GovCloud footprint to the 110 controls and tells you what's left.