Cloudflare announced on August 10 that Cloudflare for Government has achieved FedRAMP Class D (High) certified status, with the National Institute of Standards and Technology serving as sponsoring agency. The company paired the milestone with a stated commitment to pursue Department of Defense Impact Level 4 authorization, and separately confirmed GovRAMP Moderate authorization for state and local buyers.
The IL4 line is the one defense buyers should read twice. It is a commitment, not an authorization, and Cloudflare has not published a target date.
Class D Is the New Name for High
The terminology will trip up anyone who stopped tracking FedRAMP after 2024. Under the Consolidated Rules for 2026, FedRAMP retired the Low, Moderate and High impact labels inherited from FIPS 199 and replaced them with Certification Classes A through D. Class C corresponds to the old Moderate baseline. Class D corresponds to High. The rename was deliberate: the old vocabulary collided with DoD Impact Level numbering, and buyers were conflating FedRAMP High with IL4 or IL5 when the two frameworks are separate.
Class D carries the heaviest control set in the program, in the range of 410 to 421 controls under Rev5, and it applies to systems handling law enforcement data, emergency services, financial systems and national security information where a compromise could be catastrophic. Two structural constraints matter for anyone modelling competitor timelines. Class D must go through the agency sponsorship path, which means finding a federal agency willing to sponsor the package. And there is no FedRAMP 20x route to Class D, so the automation-first shortcut now available at the lower classes does not apply. Cloudflare had to run the long process.
Cloudflare held FedRAMP Moderate from 2022. The jump to Class D took four years.
The Architectural Bet: No Separate Government Cloud
The more consequential part of the announcement is how Cloudflare built the offering. The established pattern for cloud vendors serving federal and defense customers has been to stand up an isolated government region running a pared-down, release-lagged version of the commercial platform. AWS GovCloud and Azure Government both work this way, and the trade-off is well understood by anyone who has waited eighteen months for a feature to land in the government partition.
Cloudflare says it did not build a separate environment. Its FedRAMP High offering runs on the same machines and the same software stack that serve commercial traffic, with data residency enforced through software-defined regionality rather than physical separation. The company’s Data Localization Suite constrains traffic inspection and processing to U.S. data centers for the certified services. If that holds up under continuous monitoring scrutiny, federal and defense customers get feature parity with commercial enterprise customers rather than a snapshot of the platform from two release cycles ago.
Cloudflare also states that it designed the systems with IL4 controls in mind from the start of the FedRAMP process, which is the basis for its claim that the same infrastructure will underpin the IL4 offering. That is the argument for a faster IL4 timeline than the four-year Moderate-to-High gap would suggest.
Where This Lands in the SASE Federal Field
Cloudflare is arriving late to a market its direct competitors have occupied for years. Zscaler took Zscaler Internet Access to FedRAMP High in 2022 and holds DoD authorizations across its Zero Trust Exchange platform, including IL5 on Zscaler Private Access. Palo Alto Networks reached FedRAMP High across Prisma Access, Prisma SD-WAN and ADEM in 2024, with Prisma Access holding an IL5 provisional authorization since 2023. Netskope reached FedRAMP High in early 2024.
Against that field, Class D certification brings Cloudflare to parity on the civilian side and leaves it a tier behind on the defense side, where IL5 covers controlled unclassified information in unclassified national security systems. IL4 covers CUI without the national security systems scope. Cloudflare is committing to the lower of the two DoD tiers its competitors already hold.
What Cloudflare brings that the incumbents do not is network scale and a developer platform. Its global footprint spans more than 335 cities across 125-plus countries, and the certified offering includes Workers and the developer stack alongside Zero Trust and DDoS mitigation. For defense programs building applications rather than only securing access to them, that combination has no clean equivalent among the SSE-first vendors.
What to Watch
The near-term signal is whether a DoD sponsor materialises for the IL4 package and how quickly. Cloudflare already works with the Department of State and the Department of Commerce, but civilian agency relationships do not transfer to the DoD provisional authorization process, which runs through DISA rather than the FedRAMP PMO.
The second signal is defense industrial base uptake. Contractors handling CUI face CMMC obligations regardless of whether their cloud vendor holds IL4, and a Class D certified platform with a credible IL4 roadmap gives primes and subs a procurement argument today. Whether they act on it before the authorization lands is the question that determines how much revenue this milestone actually moves.
Leave a Reply