If you already run on AWS, the boundary belongs here.
AWS GovCloud (US) is FedRAMP High authorized and covers DoD SRG Impact Levels 2, 4, and 5. That means it satisfies the DFARS 7012 cloud requirement directly — no second estate. We build and operate the CUI boundary inside your GovCloud accounts.
Build on AWS GovCloudAuthorized, on the Marketplace. That's the distinction that matters.
The December 2023 DoD memo is clear: a FedRAMP-authorized cloud on the Marketplace satisfies DFARS 7012 directly, while an "equivalent" cloud makes you prove 100% of the FedRAMP Moderate baseline with no open POA&Ms. AWS GovCloud is authorized. You inherit that authorization instead of defending an equivalence claim.
The shared-responsibility split, written down.
| Inherited from AWS | Built & run by Aletheon | Owned by you | |
|---|---|---|---|
| Physical & environmental | Data centers, hardware | — | — |
| Cloud FedRAMP authorization | FedRAMP High ATO | — | — |
| Account & network architecture | — | Designed & deployed | — |
| Identity, encryption, logging | Service primitives | Configured to controls | — |
| Evidence, SSP, monitoring | — | Maintained continuously | Reviewed with you |
| Your CUI, users & business decisions | — | Guided | Yours to own |
GovCloud services, configured to the controls.
Already on AWS? Let's scope the boundary.
A readiness check maps your GovCloud footprint to the 110 controls and tells you what's left.