Cybersecurity | | 25 min read

FedRAMP Low vs Moderate vs High: Choose the Right Baseline


Cloud security team comparing FedRAMP Classes B, C, and D against federal system impact and evidence needs
Photo by Risto Kokkonen on Unsplash

Key Takeaways

Choose the package from the consequence and use case, not from the label

Current language

Classes now describe package assurance

Low, Moderate, and High remain familiar impact terms. Classes A through D now describe the depth of reusable FedRAMP certification information.

GS research

Current Rev5 lists contain 155, 322, and 409 items

The annual independent assessment subsets contain 35, 80, and 101 items. Counts show surface area, not the complete operating burden.

Decision rule

System impact and package class are related, not identical

Start with FIPS 199 consequences, then map the service role, data flow, agency conditions, certification path, and evidence need.

FedRAMP Low vs Moderate vs High is not a menu where the cloud provider picks the label that looks best. The agency system has an impact. The provider supplies an assurance package. Those decisions connect, but they are not the same decision.

That distinction became harder to ignore in 2026. FedRAMP replaced impact level labels for package specifications with certification Classes A through D. Low, Moderate, and High still matter when an agency assesses potential harm to confidentiality, integrity, and availability. They no longer tell the whole provider package story.

The practical rule is simple: categorize the agency use, map the service role, choose the package class that supplies enough reusable assurance, confirm the available certification path, and document every tailoring or acceptance decision.

The FedRAMP Compliance hub connects this comparison to the complete FedRAMP guide, the Class C baseline guide, the FedRAMP 20x guide, and the Ongoing Certification guide. GS Consulting supports this work through secure AI automation and cloud evidence engineering.

Set the class before the package grows around a guess.

GS Consulting helps cloud teams connect agency use, system impact, service scope, certification path, control ownership, and evidence into one reviewable decision.

Review the Class Decision

FedRAMP Low vs Moderate vs High: The Short Answer

Federal agencies still use Low, Moderate, and High to describe the potential effect of losing confidentiality, integrity, or availability. FedRAMP now uses Classes A through D to describe the certification package and assurance information available for an agency decision.

FedRAMP says the relationship is not one to one. Class B packages generally support most Low objectives. Class C supports most Low and Moderate objectives. Class D is intended to support most use cases regardless of objective, except classified information. Class A supports most nonsensitive uses and selected objectives at other impact levels.

Do not translate a FIPS 199 Moderate system straight into Class C without checking the actual service role. The agency can tailor controls, apply compensating controls, restrict information flow, and decide how a component fits inside the wider federal system.

The 2026 Terminology Changed the Comparison

Six current facts about FedRAMP Classes B, C, and D and the transition from Low, Moderate, and High labels
Current class language separates provider package assurance from the impact label used for an agency system.

The FedRAMP Marketplace now calls authorization a certification and uses Classes A through D for package specifications. It will show the previous impact labels in parentheses through December 31, 2026, then remove them in January 2027.

The change matters because buyers, providers, assessors, and search results will use both vocabularies during transition. A statement such as “we need FedRAMP Moderate” is now the start of the conversation. Ask whether the speaker means a Moderate agency system, a current Class C package, a legacy Rev5 authorization, a contract reference, or a specific data handling condition.

Write the answer down. Terminology drift becomes scope drift when sales, engineering, security, and the agency use the same word for different decisions.

Current Class B, C, and D Comparison

Current classGeneral agency fitRev5 controlsAnnual subsetPlanning consequence
Class BMost Low objectives and selected higher objectives15535Focused scope, evidence, and annual assurance
Class CMost Low and Moderate objectives and selected High objectives32280Broad control ownership and recurring evidence across the service
Class DMost use cases regardless of objective, excluding classified information409101Highest implementation, assessment, response, and coordination pressure

The class description is not permission to ignore the use case. It tells the agency how much reusable assurance information is likely available. The authorizing official still evaluates the service inside the real federal system.

The control counts are GS calculations from the official FedRAMP structured rules repository, version 2026.07.14.01. Older FedRAMP materials report 156, 323, and 410 for Low, Moderate, and High. The one item differences come from different publication contexts. Use the list that governs the certification path.

Start with the Agency System Impact

FIPS 199 categorizes potential impact separately for confidentiality, integrity, and availability. Low means a limited adverse effect. Moderate means a serious adverse effect. High means a severe or catastrophic adverse effect.

The system takes the highest effect across those security objectives. A service can look ordinary until availability becomes mission critical, integrity affects a payment or public decision, or confidentiality involves information that would cause serious harm if exposed.

Then map the cloud service role. Does it store federal data? Does it only transmit it? Can it change a system of record? Does it hold authentication material? Does it support a mission service whose outage creates a severe effect? Does an agency tenant control the sensitive configuration? Those facts shape what assurance the authorizing official needs.

Do not let the provider package label substitute for this analysis. A certification is reusable evidence. It is not the agency authorization decision for every possible use.

GS FedRAMP Class Assurance Pressure Index

GS Consulting built a derived planning model across Rev5 Classes B, C, and D. Two public inputs come from the current FedRAMP data: total controls and enhancements, plus the published annual independent assessment subset. Three one to five GS ratings capture potential consequence, implementation reach, and response urgency.

The base model weights total controls at 30 percent, the annual subset at 20 percent, potential consequence at 25 percent, implementation reach at 15 percent, and response urgency at 10 percent. The sensitivity case shifts five points from total controls to the annual subset.

GS FedRAMP Class Assurance Pressure Index comparing Class B, Class C, and Class D
Class D carries the greatest modeled coordination pressure, while Class C is more than twice the Class B score.

Class D scores 100.0. Class C scores 72.5. Class B scores 33.3. The sensitivity case preserves the order and moves no score by more than 0.2 points.

The conclusion is not “always choose lower.” It is “do not choose higher without a reason.” Every step up expands the formal surface and the operating proof around it. The model estimates coordination pressure after the class decision. It does not choose the class, measure security effectiveness, or determine agency acceptance.

This is a GS Consulting derived planning tool, not an official FedRAMP score, FIPS categorization, legal opinion, audit result, certification decision, or regulatory determination. The workbook, CSV files, source register, assumptions, formulas, sensitivity results, and editable figures are preserved in the research package.

Control Counts Show Surface Area, Not Effort

Paired bars comparing FedRAMP Rev5 baseline and annual assessment item counts for Classes B, C, and D
The annual independent assessment subset grows from 35 items in Class B to 101 in Class D.

Moving from Class B to Class C adds 167 controls and enhancements to the current list. Moving from Class C to Class D adds another 87. The annual subset grows by 45 and then by 21.

That arithmetic still understates the change. A new control can pull in a system owner, customer setting, inherited provider, legal term, incident duty, log source, test procedure, and recurring artifact. The count is the index. The work lives in the connections.

Use the numbers to test completeness and compare formal surface. Estimate effort from the actual architecture, inheritance, shared responsibility, evidence source, assessor procedure, customer configuration, and operating cadence.

A Practical FedRAMP Class Selection Path

Five stage FedRAMP class selection path from FIPS 199 categorization through agency acceptance
Choose the class from the agency use case outward, then keep the rationale with the authorization record.
  1. Categorize the agency system. Record confidentiality, integrity, and availability consequences, the affected mission or business process, and the decision owner.
  2. Map the service role. Trace federal data, authentication, administration, system dependencies, customer settings, external services, and failure effects.
  3. Select the package class. Decide what assurance depth gives the authorizing official enough reusable information for the intended use.
  4. Confirm the certification path. Set 20x or Rev5, Program or Agency path, assessor role, sponsor need, transition date, and package format.
  5. Record tailoring and acceptance. Name compensating controls, information flow limits, customer conditions, residual decisions, approvals, and review triggers.

Review the decision when the service adds a data type, region, administrative path, external dependency, model capability, customer action, or mission function. A class decision built on an old service is not current evidence.

Four Use Cases That Expose the Real Decision

Use caseFirst questionLikely package directionEvidence that matters
Public information scheduling serviceCan loss of integrity or availability create more than limited harm?Class A or B may be enough, subject to agency useService scope, identity, change control, availability, and customer configuration
Federal case management softwareWould disclosure, alteration, or outage cause a serious adverse effect?Class C is a common directionData flow, access, audit, protection, recovery, incidents, and shared duties
Public safety or mission command supportCould failure create a severe or catastrophic effect?Class D may be requiredResilience, response, recovery, communications, integrity, and independent assurance
Component inside a wider Moderate systemCan information flow and agency controls limit the component risk?A lower class may be usable with documented conditionsTailoring, compensating controls, data restrictions, architecture, and acceptance

These are planning examples, not automatic classifications. The authorizing agency decides whether the package and use conditions support its system decision.

Class Does Not Choose 20x or Rev5 for You

The current FedRAMP path guide separates 20x and Rev5. FedRAMP 20x currently uses the Program Certification path for Classes A, B, and C. Class D is planned for 2027. Rev5 Class B and C can use limited Program paths or generally required Agency paths, while Rev5 Class D uses the Agency path.

The architecture of the proof differs. Rev5 uses controls and enhancements. 20x uses Key Security Indicators, measures, persistent validation, machine readable information, a Security Decision Record, and current certification data. Both require real scope, implementation, validation, independent review, and ongoing operation.

Do not decide the path after the evidence is built. The path changes what gets recorded, how automation supports validation, what history is needed, how the package is shared, and who makes the certification decision. Read the FedRAMP 20x guide before treating it as a faster version of the same package.

Six Class Selection Failures

Six FedRAMP class selection failures involving preference, labels, control counts, path timing, and agency context
A familiar label can hide a weak decision when the use case, path, and agency conditions are missing.
  • Sales chooses the class. A market claim replaces a system and agency use analysis.
  • Moderate automatically becomes Class C. The team treats an agency impact and a provider package as identical.
  • High becomes the safe default. The scope expands without a stated mission, data, contract, or agency reason.
  • Control counts become the estimate. Boundary, inheritance, customer duty, and operating evidence disappear from the plan.
  • The path is chosen late. A Rev5 package is forced into 20x language, or automated measures are designed after implementation.
  • Agency context stays outside operations. Tailoring and acceptance exist in email but never reach configuration, monitoring, or customer guidance.

A 90 Day Class Decision Plan

Days 1 through 30: define the use

  • Identify the agency system, mission process, information types, security objectives, data owners, and authorizing stakeholders.
  • Map the service boundary, regions, administration, dependencies, external services, customer settings, and information flows.
  • Record known contract language, acquisition conditions, sponsor expectations, and current certification timing.

Days 31 through 60: compare the packages

  • Compare Classes B, C, and D against the intended agency decision rather than the provider market position.
  • Estimate control or KSI ownership, inherited services, evidence sources, assessor work, customer duties, and recurring operations.
  • Select the 20x or Rev5 path and record why the rejected path creates more risk, delay, or mismatch.

Days 61 through 90: approve and operationalize

  • Approve the class rationale, scope, assumptions, tailoring, compensating controls, and unresolved agency questions.
  • Turn the decision into architecture requirements, evidence backlog, assessment plan, customer guidance, and monitoring duties.
  • Set review triggers for data, service, region, dependency, customer, contract, and mission changes.

Minimum Class Selection Evidence Packet

Eight item FedRAMP class selection evidence packet for impact, service scope, rationale, path, duties, tailoring, and approval
The decision should remain reviewable after the people who made it move to another project.

Keep the packet with the certification and authorization record. Link each assumption to an owner and review trigger. A current class decision should explain not only what was selected, but why it still fits the service the customer uses today.

Bottom Line

FedRAMP Low vs Moderate vs High is now a two layer problem. The agency categorizes system impact. The provider chooses a certification package that gives the agency enough assurance for the actual use.

Do not sell a label, count controls, and hope the agency context appears later. Categorize the consequence, map the service, choose the class, set the path, record the conditions, and keep the decision current.

That is the standard: enough assurance for the real use, no invented certainty, and no package built around the wrong question.

Need a defensible FedRAMP class and path decision?

GS Consulting helps providers and regulated cloud teams turn impact, architecture, ownership, assessment, and evidence into a practical certification roadmap.

Request a FedRAMP Review

Research Sources and Caveats

FedRAMP rules, paths, terms, dates, and package expectations can change. Confirm the current rules and agency agreement before relying on this guide. GS models are derived planning tools, not official legal, audit, compliance, FIPS, NIST, FedRAMP, OMB, agency, certification, authorization, or regulatory determinations.

Frequently Asked Questions

What is the difference between FedRAMP Low, Moderate, and High?

Low, Moderate, and High describe potential impact to federal information and systems. FedRAMP now uses certification Classes A through D for package specifications. Class B generally supplies enough assurance information for most Low objectives, Class C for most Low and Moderate objectives, and Class D for most use cases regardless of objective, excluding classified information. The mapping is not automatic.

Does FedRAMP Class C replace FedRAMP Moderate?

Class C is the current package class most closely associated with familiar Moderate work, but FedRAMP says there is no direct correlation between certification class and impact level. The agency system impact, service role, information flow, tailoring, and authorizing official decision still matter.

How many controls are in FedRAMP Low, Moderate, and High?

GS counted 155 controls and enhancements in the current Rev5 Class B list, 322 in Class C, and 409 in Class D using the official FedRAMP structured rules dated July 14, 2026. These current counts differ by one from older published summaries of 156, 323, and 410, so teams should name the governing list and version.

Should a provider choose FedRAMP High to be safe?

Not by default. A higher class expands implementation, assessment, evidence, incident, and operating pressure. Choose the class that supplies enough assurance for the intended agency use, then document the decision. A needlessly broad package can waste time without improving the actual authorization decision.

Can a Class B service be used in a Moderate system?

Potentially, but not automatically. FedRAMP explains that an agency can use tailoring, compensating controls, and information flow restrictions when deciding whether a service fits inside a system. The authorizing official needs enough information to understand and accept the residual risk for the actual use case.

Is the FedRAMP 20x path available for every class?

FedRAMP 20x currently supports Classes A, B, and C through the Program Certification path. Class D is planned for 2027. Rev5 remains available on defined Program and Agency paths during transition. Providers should confirm current availability before committing architecture or assessment plans.

Suggested Future Reading

© GS Consulting, LLC . All Rights Reserved | For more information, contact us at info@gsconsultingllc.com. Image credit: ©iStock.com/Vertigo3d. Privacy Policy | Terms of Use