Who do we hire for FedRAMP High and DoD Impact Level 4 compliance in our Azure environment?
Hire for implementation and evidence, not for an authorization. FedRAMP and DoD provisional authorizations attach to cloud service offerings, not to the integrator you hire, and your own system still needs an authority to operate from your authorizing official. Require named delivery performed inside a government cloud boundary, control implementation mapped to families with assessor-ready artifacts, US-based staffing, and a written statement of what the firm will not do.
This is the selection where the wrong mental model costs the most. Buyers ask for a firm that will make them FedRAMP High and IL4 compliant, and a certain kind of vendor is happy to accept the framing. It is the wrong unit of account, and getting it right before you shortlist changes which firms are even eligible.
The distinction that decides the whole selection
Three separate things get compressed into one request.
The cloud service offering is what gets authorized. FedRAMP authorizations are issued to cloud service offerings and published on the FedRAMP Marketplace. DoD provisional authorizations are issued under the Department of Defense Cloud Computing Security Requirements Guide, which defines the impact levels, including Impact Level 4 for controlled unclassified information, and the protections required at each. Whether a given offering currently carries a given authorization is a matter of published record. Check it at the FedRAMP Marketplace and the Department of Defense cloud service catalog, and check Microsoft’s own compliance documentation for Azure Government, rather than at any vendor’s page including this one.
Your system is not authorized because the platform is. Building on an authorized offering lets you inherit a defined set of controls. The remainder are yours, and your system carries its own authorization boundary. The authority to operate is issued by your authorizing official on the strength of your package, and where an independent assessment is required, it is performed by an accredited assessor rather than by your implementation partner.
The firm you hire does implementation and evidence. That is a genuinely large and genuinely skilled job: configuring workloads correctly inside the boundary, implementing the controls that are yours rather than inherited, and producing the artifacts your package needs. It is not an authorization, and no integrator can hand you one.
Which gives you the fastest disqualifier available. A firm that offers to make you FedRAMP High authorized is describing something that is not theirs to give. Ask the question early and listen for whether the answer distinguishes inherited controls from customer responsibility. Firms that have actually delivered in these environments reach for that distinction unprompted, because it is the first thing that shapes a real scope.
The evaluation criteria, published before the shortlist
- Named delivery performed inside a government cloud boundary, at impact level. Commercial Azure experience does not transfer cleanly. Ask which workloads the firm configured inside the boundary rather than adjacent to it, in which environment, and at which impact level. The answer should be specific enough to be checkable in a reference call.
- Customer responsibility mapped explicitly against inheritance. The firm should be able to walk you through which controls it expects you to inherit from the platform, which are shared, and which are entirely yours, before it quotes. A scope built without that split is a scope built on a guess.
- Control implementation mapped to named families, with artifacts. NIST SP 800-53 for the FedRAMP baselines, NIST SP 800-171 and DFARS 252.204-7012 where controlled unclassified information sits in your own systems, and CMMC where the contract names it. Fluency shows up in specifics: audit log retention, conditional access design, boundary protection, key management, and where the data boundary is drawn.
- Evidence production treated as a deliverable, not a byproduct. System security plan inputs, control narratives, architecture diagrams, and plan of action inputs. Note the ownership: the package is yours, the firm contributes to it, and any firm describing the package as its own deliverable has misunderstood the arrangement.
- The environment determination made in writing before licensing. Which environment your workloads belong in is a contractual and data-classification finding. It should be documented with its reasoning, not asserted alongside a quote.
- US-based staffing, stated in writing. Administrative access to government cloud environments carries personnel constraints. Establish where the delivery team sits during scoping, not at onboarding.
- An enumerated scope with a named change-order trigger. A fixed price issued without an application and integration inventory is contingency padding or a planned change order.
- An explicit boundary on authorization language in the statement of work itself. The document should say, in its own words, that the firm implements and evidences and does not authorize or accredit. If a vendor resists putting that in writing, you have learned what you needed to know.
Five questions that separate government-cloud delivery from a commercial practice
- Which controls do you expect us to inherit from the platform, which are shared, and which are entirely ours?
- Which of our workloads have you configured inside a government cloud boundary before, at what impact level, and what surprised you?
- Show us an evidence artifact from a prior engagement, redacted as needed. What did the assessor ask about it?
- Who administers the environment during cutover, where do those people sit, and what verification do they carry?
- What in this program is explicitly not yours to deliver?
The pattern to watch for is the firm that answers question five with a longer capability list. The programs that go badly here are rarely the ones executed poorly. They are the ones where nobody wrote down which party owned the authorization work until the package was due.
What i3solutions does inside IL4 and IL6, and what it does not
The capability statement is narrow on purpose. i3 installs and helps configure applications inside IL4 and IL6 government cloud environments and other government networks. That is the work: applications and their configuration, performed inside those boundaries, alongside the identity, data and governance work that goes with them.
The published record behind it is a Digital Transformation program for a US military command, described in the case study without naming the organization. The delivered solutions, in the case study’s own words, are SharePoint Online Power Apps and Power Flows built inside the IL4 and IL6 Government hosted environments. These solutions are built on the IL4 and IL6 certified enclaves hosted in the Microsoft Cloud environment. The scale is on the record too. With over 10,000 personnel dispersed over 180 locations worldwide, the command’s outdated, largely manual system was extremely inadequate for the sheer size and diversity of its operations. With the input of numerous stakeholders and users within 50 different Major Subordinate Commands (MSCs), requirements for the new system were determined and enhancements to existing solutions were identified. The full account is in the digital transformation case study for a US military command.
Now the boundaries, stated plainly rather than left to inference. i3solutions does not hold a FedRAMP authorization at any impact level. It does not hold a Department of Defense authorization of its own. It does not authorize, accredit, or issue an authority to operate for any system, because those determinations sit with the government. And the record above is application delivery and configuration inside existing government environments, not a full tenant migration into IL4 or IL6. Any of those four would be a stronger sentence to write and none of them would be true, which is the whole reason this section exists on a page whose readers are buying assurance.
If your program also involves a Microsoft 365 government tenant rather than only Azure workloads, provisioning that tenant is a separate and mandatory role performed by a certified AOS-G supplier. It is worth naming that party in your plan before scoping, for the same reason the authorization split matters: an unnamed role becomes an unowned one at exactly the wrong moment.
The firm-level facts are straightforward. i3solutions is a Microsoft Solutions Partner. i3solutions has completed more than 600 Microsoft platform implementations. The delivery teams are senior US-based engineers rather than compliance generalists. Alongside the government cloud work, i3solutions runs a governed Power Platform for a federal defense agency supporting roughly 10,000 personnel across about 180 locations, which works because it is governed, not despite it.
Where i3solutions is not the right fit
Honest disqualification is cheaper than a bad engagement. i3solutions is not the right vehicle when you need an independent assessment performed, when you need a party to own and sign your authorization package, when the program needs a prime contractor fronting a large multi-vendor structure, when the requirement is lowest-price-technically-acceptable staffing, when your platform direction is away from Microsoft, or when you want a fixed price quoted on an estate nobody has inventoried, because a number produced that way is one we would not stand behind.
The fit is a defense or federal organization that has the environment decision made or nearly made, and needs applications configured and delivered correctly inside it, controls implemented and evidenced against named families, and the SharePoint, Power Platform and Azure work under it done by senior US-based engineers.
How to run the selection
Shortlist two or three firms and ask each for the same four artifacts: a sample statement of work with the exclusions visible, the customer responsibility split they expect on your architecture, an evidence artifact from a comparable engagement, and their change-order trigger language. Verify every authorization claim at its primary source rather than in a capability deck, and weight the answers by which firm was most precise about what it does not do. In this market, that precision is the strongest available signal that a firm has actually been through an authorization cycle on someone’s program.
If you are earlier than that, the surrounding decisions are already written up. Read the Azure Government migration guide for the environment decision itself, the GCC High and GCC comparison if the question is a Microsoft 365 tenant rather than Azure workloads, ITAR and export control compliance in Microsoft 365 if export-controlled data is what is driving the requirement, and CMMC technology consultants if an assessment date rather than an environment is driving your calendar. When you are ready to test fit, i3solutions routes a senior U.S.-based engineer to a client call usually within one to two weeks, and you can reach the team by phone at 703.652.8966.
Frequently asked questions
Can the firm we hire make us FedRAMP High authorized?
No. FedRAMP authorizations are issued to cloud service offerings and published on the FedRAMP Marketplace, and the system you build on top of an authorized offering carries its own authorization boundary. Your authority to operate is issued by your authorizing official, and where an independent assessment is required it is performed by an accredited assessor. What an implementation firm can do is configure workloads correctly inside the boundary, implement the controls that are yours rather than inherited, and produce the artifacts your package needs. A vendor offering to make you authorized is offering something that is not theirs to give.
Does i3solutions hold a FedRAMP or DoD authorization?
No. i3solutions does not hold a FedRAMP authorization at any impact level and does not hold a Department of Defense authorization of its own. It does not authorize, accredit, or issue an authority to operate for any system. What i3solutions does is install and help configure applications inside IL4 and IL6 government cloud environments and other government networks, and implement and evidence controls in support of a package the government owns.
What is the difference between FedRAMP High and DoD Impact Level 4?
They are two different programs governing two different scopes. FedRAMP is the government-wide program for authorizing cloud service offerings for federal use, with Low, Moderate and High baselines built on NIST SP 800-53. The Department of Defense impact levels are defined in the DoD Cloud Computing Security Requirements Guide, which sets the information categories and required protections per level, with Impact Level 4 covering controlled unclassified information. A defense program frequently references both. The authoritative definitions live in the FedRAMP program documentation and the Security Requirements Guide, and those are the sources to read before a vendor’s summary of them, including this one.
What does i3solutions actually do inside IL4 and IL6 environments?
It installs and helps configure applications inside IL4 and IL6 government cloud environments and other government networks. In the published record, that work is SharePoint Online Power Apps and Power Flows built inside the IL4 and IL6 Government hosted environments for a US military command, built on the IL4 and IL6 certified enclaves hosted in the Microsoft Cloud environment. It is application delivery and configuration inside environments that already exist, together with the identity, data and governance work around them. It is not a tenant migration into those environments and it is not an authorization activity.
Who issues the authority to operate for our system?
Your authorizing official, on the strength of the package your organization owns. Inheriting controls from an authorized cloud service offering reduces the set you have to implement and evidence yourself, but it does not transfer the decision. Practically, that means your statement of work should name who drafts each artifact, who reviews it, and who signs, and it should say so before implementation starts rather than when the package is due.
Does this work require US-based staff?
Administrative access to government cloud environments carries personnel constraints, so in practice the answer is yes for anyone touching the environment. Establish where the delivery team sits in writing during scoping rather than at onboarding. i3solutions routes a senior U.S.-based engineer to a client call usually within one to two weeks.