All posts
Compliance Frameworks7 min readAug 16, 2026

FedRAMP impact levels

Ashish / CEO/Co-Founder
FedRAMP impact levels

FedRAMP impact levels are Low, Moderate, and High. They describe the potential adverse impact if a cloud system loses confidentiality, integrity, or availability, they are determined through FIPS 199-style security categorization, not by vendor preference or market positioning.

One current source of confusion: FedRAMP Certification Classes are not the same thing as impact levels. Current FedRAMP transition materials initially map Classes B, C, and D to historical Low/LI-SaaS, Moderate, and High requirements, while Class A is a separate pilot-oriented class. But those classes describe certification scope and assessment requirements; agencies still categorize systems and make their own risk decisions.

FedRAMP impact levels vs Certification Classes: the distinction to get right first

FedRAMP impact levels answer a risk question: what is the potential harm if confidentiality, integrity, or availability is lost? Under FIPS 199, that harm is categorized as Low, Moderate, or High.

FedRAMP Certification Classes answer a different program question: what certification materials and assessment requirements apply to a FedRAMP certification package? FedRAMP explains that certification packages provide reusable security information for agencies, but they do not themselves constitute agency risk acceptance for a particular FIPS 199 system category (FedRAMP Authorization Designations).

For the 2026 transition, FedRAMP states that Class B, C, and D initially map to historical Low/LI-SaaS, Moderate, and High requirements respectively, while Class A is separate and pilot-oriented (Rev5 Program Certifications). That mapping matters operationally, but it does not replace—or, more precisely, it does not remove—the agency’s categorization and authorization decision.

The practical rule: use Low, Moderate, and High to understand impact; use Certification Classes to understand current FedRAMP certification packaging and assessment scope.

The three FedRAMP impact levels: Low, Moderate, and High

FIPS 199 defines impact values by the potential adverse effect of a loss of confidentiality, integrity, or availability: Low means limited adverse effect, Moderate means serious adverse effect, and High means severe or catastrophic adverse effect (FIPS 199).

FedRAMP High is therefore a High impact categorization: the loss of confidentiality, integrity, or availability could have a severe or catastrophic adverse effect.

Level/pathAdverse impactTypical data/use-case sensitivityBaseline implicationDecision caution
LowLimited adverse effect under FIPS 199Illustrative only: lower-sensitivity agency use where compromise would have limited mission, operational, or individual impactPoints toward the FedRAMP Low baseline or, for eligible SaaS, LI-SaaSDo not assume “low sensitivity” from the application label alone; test confidentiality, integrity, and availability separately
ModerateSerious adverse effect under FIPS 199Illustrative only: systems where disclosure, corruption, or downtime could materially affect agency operations, assets, or individualsPoints toward the FedRAMP Moderate baselineModerate is not a default commercial target; it should follow the impact analysis and agency use case
HighSevere or catastrophic adverse effect under FIPS 199Illustrative only: high-consequence systems where failure could cause severe mission, operational, asset, or individual harmPoints toward the FedRAMP High baselineHigh is not automatically “better” or universally required; it is appropriate when the adverse-impact analysis supports it
LI-SaaSLow impact onlyLow-impact SaaS that does not store PII beyond information generally needed for login, such as username, password, and email addressTailored Low option with reduced documentation and testing relative to standard LowLI-SaaS is not a fourth impact level; eligibility still depends on FedRAMP’s conditions and agency acceptance

The table is a decision aid, not a substitute for categorization. A data type or product category does not automatically determine the level; the agency mission, information types, intended use, and potential adverse effects still have to be looked at.

How FedRAMP impact level is determined under FIPS 199

FedRAMP impact-level analysis follows the same basic categorization logic used in FIPS 199: assess confidentiality, integrity, and availability separately, then use the highest value as the system’s overall impact level. This is often called the high-water mark (FIPS 199).

NIST SP 800-60 provides guidance for mapping information types to security categories. Its process includes identifying information types, assigning and reviewing provisional confidentiality, integrity, and availability impact values, determining the system category using high-water marks, and documenting the result through agency review.

A practical mini-workflow, in practical terms, looks like this:

  1. Identify the system and boundary
    Define the cloud service, components, integrations, users, and agency use case being categorized.

  2. Identify information types
    Map the information the system processes, stores, or transmits. NIST SP 800-60 can help structure this mapping.

  3. Assess confidentiality, integrity, and availability separately
    Ask what happens if each objective is lost. The answer may differ: a system could have Low confidentiality impact but Moderate availability impact.

  4. Apply the high-water mark
    The highest CIA impact value drives the overall system categorization. For example, if confidentiality is Low, integrity is Moderate, and availability is Moderate, the likely overall direction is Moderate.

  5. Identify the likely FedRAMP baseline direction
    Use the resulting impact level to identify whether Low, Moderate, or High baseline expectations are likely to apply.

  6. Validate with the agency or sponsor
    Treat the result as an initial baseline direction, not a vendor’s unilateral final classification. Agencies must review the categorization in the context of their own mission and risk decisions.

How impact levels map to FedRAMP baselines and LI-SaaS

Impact levels matter because they basically point to different FedRAMP baseline expectations. FedRAMP’s Rev. 5 baselines were updated to correspond with NIST SP 800-53 Rev. 5 and SP 800-53B, and the baseline expresses the control and documentation expectations applicable to the relevant FedRAMP assessment scope (FedRAMP Rev. 5 Baselines).

In practical terms:

  • Low impact generally points to the Low baseline, unless the system qualifies for LI-SaaS.
  • Moderate impact points to the Moderate baseline.
  • High impact points to the High baseline.
  • LI-SaaS is a tailored Low-impact option, not a separate impact level.

FedRAMP describes LI-SaaS and the standard Low baseline as two baseline options for low-impact systems. LI-SaaS is intended for low-impact SaaS that does not store PII beyond information generally needed for login, such as username, password, and email address; its documentation and testing requirements are reduced relative to the standard Low baseline (CSP Authorization Playbook).

Avoid relying on static control-count numbers unless they have been checked against the current applicable FedRAMP ruleset. Control scope is important, but exact counts can change as FedRAMP updates its program materials.

Who decides the FedRAMP impact level?

The agency is responsible for deciding whether a cloud service fits its FIPS 199 security category and for accepting risk. FedRAMP says it cannot make that suitability call for an agency; the certification package supplies reusable security information that agencies use in their own authorization decisions (FedRAMP Authorization Designations).

A CSP can still do useful prep work. It can prepare its information-type analysis, CIA assumptions, likely baseline direction, and proposed control scope for agency or sponsor review. That preparation helps make the discussion concrete, but it should not be presented as the final categorization.

A clean responsibility split is:

PartyPractical role
AgencyCategorizes the system in context, evaluates suitability, and accepts risk
CSPDocuments assumptions, prepares evidence, and lines up its control work with the likely baseline direction
Sponsor or agency partnerReviews the proposed direction in the context of the intended federal use case
FedRAMP certification packageProvides reusable security information; it does not replace agency risk acceptance

Common mistakes when interpreting FedRAMP impact levels

Several errors create unnecessary confusion:

  • Confusing Certification Classes with impact levels. Classes describe FedRAMP certification scope; impact levels describe potential adverse impact.
  • Treating LI-SaaS as a fourth level. LI-SaaS is a tailored Low-impact path, not a separate FIPS 199 category.
  • Assuming the CSP alone chooses the level. A CSP can prepare analysis, but agencies determine suitability and accept risk.
  • Choosing based on market ambition instead of impact. The level should follow information types, CIA impact, and agency use case.
  • Relying on outdated control counts. Use current FedRAMP materials before making scope commitments.
  • Assuming High is automatically best. High is appropriate when the adverse-impact analysis supports it; it is not a universal upgrade.

What to do after identifying a likely impact level

After you identify a likely level, validate the categorization against FIPS 199, NIST SP 800-60, current FedRAMP materials, and the agency or sponsor’s intended use case. Document the information types, CIA impact assumptions, high-water-mark reasoning, and baseline implications. Before committing to a control scope.

Ciphrix’s operational view is that teams should treat baseline preparation as work to assign owners and assemble evidence, not just to draft documents. That does not replace agency categorization or official FedRAMP guidance, but it helps keep the impact-level decision connected to the controls and evidence the team will actually need to maintain.

Get started

Ready to see Ciphrix in action?

Built by AWS Security Leaders | AWS Partner | Certified companies across 3 continents