All posts
Compliance Frameworks7 min readAug 16, 2026

FedRAMP levels

Ashish / CEO/Co-Founder
FedRAMP levels

What are FedRAMP levels?

“FedRAMP levels” is an overloaded term. Many readers use it to mean the legacy FedRAMP impact terminology: Low, Moderate, and High. LI-SaaS is often discussed with those terms, but it was a tailored Low-oriented baseline, not a separate FIPS 199 impact category.

Current FedRAMP terminology also includes—or, really, uses alongside those terms—Certification Classes A–D. Those classes label FedRAMP certification packages, while federal agencies still separately determine the FIPS 199 impact category and control baseline for their own information systems under current FedRAMP guidance on what is changing in 2026.

The clean way to separate the concepts is:

  • Impact category / impact level: What would happen if confidentiality, integrity, or availability were compromised?
  • Certification class: How much information, assurance, and ongoing maintenance commitment does the provider’s FedRAMP package include?

You need both concepts in view. Not the same question.

FedRAMP impact levels: Low, Moderate, High, and LI-SaaS

FedRAMP impact scoping starts with FIPS 199, FIPS 199 defines Low, Moderate, and High based on the potential adverse effect from loss of confidentiality, integrity, or availability: Low means limited adverse effect, Moderate means serious adverse effect, and High means severe or catastrophic adverse effect (FIPS 199).

TermWhat it means for scopingPotential impact if compromisedPractical planning implication
LowThe system handles information where loss of confidentiality, integrity, or availability would have limited adverse effect.Limited adverse effect.Start by validating whether all in-scope information types and consequences remain Low across confidentiality, integrity, and availability.
LI-SaaSA former Low-Impact SaaS baseline. FedRAMP’s Rev5 transition mapping treats former LI-SaaS with former Low under Class B; it should not be treated as a separate FIPS 199 impact category.Low-oriented, subject to the specific FedRAMP criteria that applied to that tailored baseline.Treat it as Low-related transition context, then verify current FedRAMP package-class and agency expectations.
ModerateThe system handles information where compromise could have serious adverse effect.Serious adverse effect.Investigate Moderate when any in-scope information type or security objective rises above limited impact.
HighThe system handles information where compromise could have severe or catastrophic adverse effect.Severe or catastrophic adverse effect.Investigate High only when the consequence analysis supports it. Do not use High as a shorthand for “classified” or “top secret.”

As the impact rises, the expected assessment effort, evidence depth, control implementation rigor, and ongoing monitoring burden generally increase. Low is suited to limited-impact use cases, Moderate is common where consequential federal information or services are involved, High is reserved for severe-impact scenarios. The final decision must still follow the agency’s system categorization and authorization expectations.

The LI-SaaS nuance matters because FedRAMP’s transition materials describe the former LI-SaaS and Low baselines as included in Class B, while former Moderate maps into Class C and former High into Class D for transition purposes (FedRAMP authorization designation notice). That transition mapping is not the same as saying a certification class determines an agency system’s impact category.

FIPS 200 becomes relevant after categorization because it specifies minimum security requirements and a risk-based process for selecting controls, it does not replace the FIPS 199 categorization step (FIPS 200).

FedRAMP Certification Classes A-D are not the same as impact levels

FedRAMP Certification Classes describe the amount of information a cloud service provider supplies and its commitments for ongoing maintenance and reporting. FedRAMP states that requirements increase from Class A through Class D (FedRAMP Certification).

Still, that does not mean Class A, B, C, or D directly equals Low, Moderate, or High. FedRAMP’s own guidance says there is no direct correlation between Certification Class and an agency system’s impact level. Agencies may tailor controls, use compensating controls, or manage information flows when incorporating a cloud service into a system (Choosing a Certification Class).

ConceptWhat it answersExamples / labelsWho uses itWhat it does not mean
Impact category / impact levelWhat is the potential impact if the system or information is compromised?Low, Moderate, High; LI-SaaS as legacy Low-oriented contextAgencies, CSPs, assessors, and advisors during categorization and scopingNot a label for how deep the FedRAMP certification package is
Certification classHow much package information, assurance, and ongoing commitment is supplied?Classes A–DAgencies reviewing whether a package may be sufficient for their use caseNot a direct replacement for Low, Moderate, or High

The practical takeaway: do not say “Class D equals High” or “Class B equals Low” as a scoping rule. A class may matter to an agency’s review of a package, but the agency still has to evaluate its own system impact and use case.

How to decide which FedRAMP level to investigate

Basically, use FIPS 199 as the starting point for scoping conversations, not as a self-certification shortcut.

FIPS 199 requires you to identify the information types in scope, assess confidentiality, integrity, and availability impacts, and use the highest applicable impact value across the system’s resident information types for each security objective (FIPS 199).

A practical starting workflow:

  1. List the federal information types the cloud service will process, store, or transmit.
  2. Assess confidentiality impact: What happens if information is disclosed without authorization?
  3. Assess integrity impact: What happens if information is modified or destroyed improperly?
  4. Assess availability impact: What happens if information or services are unavailable?
  5. Identify the highest impact result across the in-scope information and security objectives.
  6. Validate the result with the agency, qualified advisor, assessor, and current FedRAMP requirements before committing to a path.

Use this worksheet as a scoping aid only:

QuestionReader inputWhy it matters
What federal information types are in scope?Information types drive categorization.
What happens if confidentiality is compromised?Low / Moderate / HighDetermines disclosure impact.
What happens if integrity is compromised?Low / Moderate / HighDetermines improper modification or destruction impact.
What happens if availability is compromised?Low / Moderate / HighDetermines service or information unavailability impact.
What is the highest impact rating?Provides the starting point for the impact level to investigate.
What agency or assessor validation is needed?Prevents treating internal assumptions as final authorization decisions.

Do not pick a level based only on business ambition, competitor claims, system complexity, or a preference for a lighter review. A more complex product is not automatically High, and a product team’s desire to reduce effort does not make a Moderate or High impact scenario Low.

Common FedRAMP level mistakes to avoid

The most expensive scoping mistakes usually come from mixing labels that serve different purposes.

Avoid these errors:

  • Treating LI-SaaS as a standalone fourth impact level. It is better understood as former Low-oriented FedRAMP baseline context, not a separate FIPS 199 category.
  • Assuming Certification Classes replace impact categorization. Classes label certification packages; agencies still determine system impact and control baseline needs.
  • Mapping Classes A–D directly to Low, Moderate, and High. FedRAMP says there is no direct correlation between class and agency system impact level.
  • Choosing High for optics. High means severe or catastrophic potential adverse effect under FIPS 199, not “we want to look more secure.”
  • Choosing Low to reduce work. If any in-scope confidentiality, integrity, or availability consequence is serious or severe, Low may be the wrong starting assumption.
  • Equating FedRAMP High with classified handling. FIPS 199 High is an impact category; FIPS 199 excludes classified information and national security systems from its applicability.
  • Importing unrelated framework language into FedRAMP scoping. Keep FedRAMP impact categorization grounded in FIPS 199 and current FedRAMP guidance.

What to do after you understand the likely level

Once you have a likely impact level to investigate, document the reasoning before you plan controls or package work. Capture the information types, confidentiality/integrity/availability impact assumptions, highest-impact result, and the agency or advisor inputs still needed.

Then verify:

  • which current FedRAMP certification class considerations may apply;
  • which control baseline and tailoring expectations the agency needs to evaluate;
  • what evidence, ownership, and operational processes will be needed to support the package over time.

The key is to treat level selection as a risk categorization decision first, not a paperwork preference. Start with FIPS 199 impact, confirm the agency’s expectations, and only then plan the package depth, evidence model, and control operations needed for the FedRAMP path later.

Get started

Ready to see Ciphrix in action?

Built by AWS Security Leaders | AWS Partner | Certified companies across 3 continents