COMPLIANCE POSTURE

FedRAMP Moderate

The FedRAMP impact level for systems where a breach would cause serious adverse effect, and the level most federal SaaS purchases actually require.

Also called Moderate baseline, FedRAMP Class C

Last reviewed

What is FedRAMP Moderate?

FedRAMP Moderate is the middle of the three FedRAMP impact levels, and it is where most of the federal software market actually sits. The level is not a marketing tier — it comes from the government’s own standard for categorizing information systems, which sorts them by the damage a loss of confidentiality, integrity, or availability would cause. Moderate is the category for serious adverse effect: significant operational damage, significant financial loss, or significant harm to individuals, short of catastrophic.

If a federal agency will put internal government information into your product — program data, personnel data, contract data, most Controlled Unclassified Information — that categorization is Moderate, and the authorization the agency needs is a Moderate one.

Why the level is not yours to choose

This is the point companies most often get backwards. The impact level attaches to the agency’s data, not to the vendor’s product. An authorizing official categorizes the information the system will hold, and that categorization sets the required baseline. A vendor can decide which level to build toward, but cannot decide that the buyer’s data is less sensitive than the buyer says it is.

The practical consequence is a sales failure mode: a company authorizes at Low because it was faster and cheaper, then discovers that every real opportunity in its pipeline requires Moderate. The authorization is genuine, the product is fine, and it still does not clear the gate.

What separates Moderate from Low

Moderate carries a substantially larger control set than Low, and the additions are concentrated in the areas that cost engineering time rather than paperwork:

  • Access control and identity — stronger separation of duties, session management, and privileged-access handling.
  • Audit and accountability — more complete logging, protected log storage, and demonstrable review.
  • Incident response — tested procedures, not documented intentions.
  • Configuration management — baseline configurations, change control, and evidence that drift is detected.
  • Contingency planning — recovery objectives that have actually been exercised.

None of these are exotic for a company with a mature security program. All of them are expensive to retrofit onto a system that grew without them.

Where the boundary comes in

Moderate makes the authorization boundary consequential. Every component inside the boundary must meet the Moderate baseline, including the third-party services your product depends on. A single commercial integration that cannot meet the baseline — an analytics tool, a support widget, a logging service — either has to come out of the boundary, be replaced with an authorized equivalent, or be carried as a documented risk the agency has to accept.

Drawing the boundary tightly is the cheapest security work available in a FedRAMP effort, and it has to happen before the assessment rather than during it.

How Moderate is changing

Under FedRAMP 20x, Moderate becomes Class C, assessed against the full Key Security Indicator set rather than a narrative control package, with an independent assessment required. The Class C pipeline opened on August 31, 2026. The underlying idea — this is the level for serious-adverse-effect data — is unchanged.

For a company planning its path, the useful question is not “which level can I reach fastest” but “which level do my actual buyers require.” If the answer is Moderate, a Low authorization is a detour, not a step.

COMMON QUESTIONS

Why is Moderate the level most SaaS companies need?

Because of what agencies put into commercial SaaS. Most federal use of commercial cloud software involves internal government information whose loss would cause serious adverse effect — including most Controlled Unclassified Information. That categorization lands at Moderate. Low is reserved for genuinely public or low-sensitivity workloads, and High for law enforcement, emergency services, financial, and health systems.

Can I start at Low and upgrade to Moderate later?

You can, but it is rarely cheaper. The control delta between Low and Moderate is substantial, and re-assessing a system at a higher level means re-documenting the boundary, re-testing, and paying for a second independent assessment. If your buyers are asking for Moderate, going straight there usually costs less in total.

Who decides the impact level — the vendor or the agency?

The agency. Impact level follows the government's categorization of its own data under the federal information-categorization standard. A vendor can build to a level, but the buying agency's authorizing official determines what the data requires. Selling a Low-authorized product to a program that categorized its data at Moderate does not work.

What is Moderate called under FedRAMP 20x?

Class C. The 20x class model maps Class C onto the former Moderate baseline, Class B onto the former Li-SaaS and Low baselines, and Class D onto High. The impact concept is unchanged; the label and the evidence format are new.

HOW GOVEXPRESS SCORES THIS

Compliance Posture

Moderate is the level most federal buyers ask for, so a company's Compliance Posture is read against it — holding Low when your target agencies buy at Moderate reads as a gap, not as progress.

One of the 12 categories in the Federal Readiness Score. The methodology is public — including the things this platform will never claim.

FedRAMP Moderate is one signal. See all of them.

Get your free score